Last updated: October 10, 2026. Map & Mingle is an 18+ social service that connects adults nearby. This policy explains what we collect, how we protect it, and what we will and won't do with it.
Signing in with Google
If you choose "Continue with Google", we ask Google only for your basic profile and email address (the openid, email and profile permissions): your email address and whether Google has confirmed it, your name, your Google account ID and your profile picture. The email and account ID create your account and sign you back in; your first name (never your surname) is offered as your display name; your picture becomes your first profile photo only if it is a real photo. We never contact Google on your behalf after sign-in, have not stored Google's sign-in tokens since 9 October 2026 (older ones are never used), never read your contacts, calendar, Gmail or Drive, and do not sell Google user data, use it for advertising or use it to train AI models. Closing your account deletes it; you can also remove access at myaccount.google.com/permissions. Our use of information received from Google follows the Google API Services User Data Policy, including its Limited Use requirements.
Pins and Location
A pin is something you publish on purpose — you choose the spot and what it says, and it stays on the map for the time you pick when you drop it (an hour, a few hours, today, or a week). Then it comes off the map and is deleted, unless you turned on My map diary. Delete any pin at any time. Separately, we keep your latest approximate position to place you on the map; we do not build a movement history unless you turn on My map diary (Premium, private to you, deletable any time), and we do not sell or share your precise location.
Photos: what is automated, and what is not
We do not run automated content judgement on photos: no service decides whether a picture is explicit, and no service estimates anyone's age from a face. Photos are looked at by people on the team, and a new photo may be held, visible only to its owner, until a person has seen it. When a photo is uploaded, Amazon Rekognition is asked one question — where are the faces — and the rectangles are used to blur a face on request and to ask for everyone's consent in a group photo.
We do not create, store or retain a faceprint, face template or any other biometric identifier. We do not use facial recognition to identify anyone, do not match faces against any database or against other users, and do not sell, lease, trade or profit from facial data. The rectangles are used for that one step and then discarded. If you live in Illinois, Texas, Washington or another state with a biometric privacy law, treat this as the written notice those laws contemplate. Uploading a photo is optional; nothing else about the service requires one.
The farthest-friend contest
From 15 Oct to 31 Dec 2026, when an invited friend is credited we record the city-level distance between you (rounded to 10 km) and the two countries. Only the top distances and countries are shown publicly; never names, cities or photos.
Viv, the AI assistant — ElevenLabs, only if you start it
Viv is an AI, not a person, speaking in a synthetic voice. When you start it, your voice or typing goes from your browser to ElevenLabs, Inc. (elevenlabs.io), which transcribes it, replies using a language model it runs for us (currently Google’s Gemini, through ElevenLabs), and speaks the reply. It also receives your first name, time zone and local time; never your location, messages or anything about other members. Audio is not recorded; the text transcript is kept by ElevenLabs for up to 7 days. We keep only session start times and lengths. Nothing it prepares is posted until you tap to confirm.
Place search — Photon (komoot), only when you search
When you search the map for a business, venue or address, our server sends what you typed and a rough area of about 5 km (never your position) to Photon, an OpenStreetMap search service run by komoot GmbH (photon.komoot.io). The request comes from our server, so komoot does not receive your IP address or account details. A “here now” pin never shows the place’s name to anyone.
The Intro conversation — OpenAI, only if you choose it
When you join you can answer a few questions in a short chat instead of a form. What you type is sent to OpenAI (api.openai.com) to produce the next question and draft a short profile record in your words; OpenAI processes it on our behalf, may not train on it, and may retain it up to 30 days for abuse monitoring. The chat never asks for gender, orientation, age, health, religion, ethnicity or politics. We keep no transcript, nothing is saved to your profile until you read it and tap Save, and skipping the chat changes nothing. If you tap the microphone, your browser’s own speech recognition turns your voice into text before anything reaches us; depending on the browser (Chrome and Edge, for example) that audio may be processed by the browser’s maker under its own terms. We never receive the audio, only the words, which travel exactly as typed text does. If you choose the spoken Intro, your browser also reads our side of the conversation aloud with its own text-to-speech; depending on the browser, that text (our questions, which can echo what you said) may be sent to the browser’s maker to produce the voice, and we ask the browser for an on-device voice first. Nothing more reaches us because of it.
Analytics — only with your consent
Google Analytics and Vercel Web Analytics do not load at all until you accept the banner. Declining changes nothing about how the service works. If you accept, your IP is truncated and Google's advertising and audience features are switched off.
Messages may be reviewed by the operator
Map & Mingle is run by one person, and that person reads messages sent on the Service — routinely, not only when something is reported — to enforce the Community Guidelines and to meet legal obligations, including the duty to report suspected child exploitation. Messages are not private from the operator. Every such review is itself recorded. Nobody else reads them, and they are never shared, sold or used for advertising.
Information We Collect
Account details (name, email, date of birth, profile), your device location with permission, optional "available now" session status, messages, and usage data. Data that may reveal sensitive information, such as who you want to meet, is used only to operate the service — never sold, never used for third-party advertising.
Location: What Others See
Other users never see your exact location. Coordinates shown to anyone else are snapped to a grid of roughly 500 feet (~165 meters), and the snapping is deterministic so it can't be averaged into your true position. Only you see your own exact spot.
Everyone who opens the site is first asked to confirm they are 18 or older. That answer is kept only in your browser for 30 days on that device, then asked again; signed-in members, who gave a date of birth at signup, are not asked again. It is not tied to your IP address.
Child Safety Reports — what we send
We report apparent child sexual abuse material to NCMEC as 18 U.S.C. §2258A requires. The law leaves the contents of a report to our discretion (§2258A(b)); our practice is to include everything we hold that could help identify a child or an offender — account id, email and self-reported profile details, signup and most-recent IP addresses with timestamps, stated age and any date of birth, approximate location from IP, the image itself, and the relevant message thread. Submitting a report is treated in law as a request to preserve that material for one year (§2258A(h)) and we preserve it for at least that long. A deletion request does not remove it.
Payments — Stripe, as merchant of record
Subscriptions and one-time unlocks are sold to you by Stripe, Inc. under its Managed Payments service: Stripe is the seller on your receipt and statement, chooses the payment methods, collects any sales tax or VAT, and handles refunds and disputes. Stripe collects your name, email, billing address, payment method and device signals as an independent controller under the Stripe Privacy Policy, not only on our behalf; Stripe's terms require us to tell you this. Your card number never reaches our servers.
Data Retention
If you are in Brazil, Mexico or Quebec
Brazil (LGPD): our encarregado is the operator named in Section 1 of the Terms, privacy@mapandmingle.com; you have the article 18 rights and may complain to the ANPD. Mexico: our aviso de privacidad in Spanish explains your ARCO rights. Quebec (Law 25): the person in charge of personal information is the operator named in Section 1 of the Terms, privacy@mapandmingle.com.
Account data and messages are deleted within 30 days of account deletion. We keep your latest position, not a movement history, unless you turn on your own private map diary. Refused underage signups are stored only as a one-way email hash. Reports and moderation actions (the rule enforced, when, how, and any notice sent) are kept after an account is deleted, with the name, email and profile removed and only a one-way email hash kept to match the record; we may produce them to regulators, courts or law enforcement where the law requires or allows. Other safety and legal records may be retained longer where the law requires.
Text Messages
Verification codes and meet-up safety alerts happen because you asked for them. Texts about account activity are off until you turn them on and agree to the disclosure shown beside the switch — we store that disclosure word for word, with the date and IP, so there is a record of what you were told. Message frequency varies and message and data rates may apply. Reply STOP to any text and we stop permanently; reply HELP for contact details.
Your Rights
Access, correct, delete, and export your data any time. California residents have CCPA/CPRA rights, including over sensitive personal information, which we use only to provide the service and never to infer characteristics about you. We do not sell or share personal information as defined by the CCPA/CPRA.
If you are in the EEA, the UK or Switzerland, we process your data to perform our contract with you, on our legitimate interests in running and securing the service, and — for the special-category data a dating service necessarily involves — on your explicit consent, which you can withdraw at any time.
Contact us at privacy@mapandmingle.com for any privacy-related questions.