privacy policy

terrain stores almost nothing that isn't already on your public profile. no ads, no trackers, no profiling — and when you leave, your data actually leaves with you.

last updated 2026-06-11 · draft pending legal review

who is responsible

the data controller for terrain.movmnt is [operator name, address — M5 gate]. for anything in this policy, write to [contact email — M5 gate].

what we store, and why

  • your email and session — the whole account. needed to sign you in (passwordless magic links) and to send the few transactional emails the product has. legal basis: performing our contract with you.
  • profile content you publish — public by design: that's the product. a practitioner's location is stored and shown at city/area level only; there is no field for a person's precise coordinates. only spaces have precise pins. legal basis: contract.
  • profile images — the images you upload, stored with our storage provider and shown on your profile. legal basis: contract.
  • reports — if you report a profile, the report and the optional contact details you choose to include, kept for moderation. legal basis: legitimate interest in keeping the directory safe.
  • anonymous usage statistics — aggregate counts of interactions (e.g. how often map filters are used), recorded without identifiers of any kind. nothing in them can be tied to you — which also means there is nothing in them to erase or export.

what we never do

no advertising, no third-party trackers, no behavioural profiling, no selling or sharing data for marketing, no marketing email of our own — every email terrain sends is transactional, triggered by something you did. terrain has no feed and no engagement metrics to optimise; it has no incentive to know more about you than it does.

cookies

terrain sets exactly one cookie: the session that keeps you signed in. it is strictly necessary, so there is no consent banner — there is nothing to consent to. browsing the map needs no cookies at all.

who handles data for us

terrain runs on a small set of processors, each bound by a data processing agreement:

  • vercel — hosting and compute.
  • neon — the database.
  • cloudflare — profile image storage (R2).
  • resend — sending the transactional emails.
  • maptiler — map tiles. when the map loads, your browser requests tiles directly from maptiler, so your IP address reaches them.

some of these process data outside the EU. [confirm DPA / standard-contractual-clauses status per vendor — legal review]

public by design

published profiles are public — visible to anyone, on the map and in the directory, without an account. you control whether each profile may also be indexed by search engines; that toggle controls terrain's signals, not copies third parties already made (the terms say the same thing, because it bears repeating).

how long we keep things

  • deleting your account permanently deletes your profiles and images within 30 days — erasure, not unpublishing.
  • sign-in links expire within minutes and work once; sessions expire on their own schedule.
  • anonymous aggregate statistics are kept indefinitely — by construction they contain no personal data.

your rights

under the GDPR you can access, correct, export, and erase your data. on terrain, most of that is self-serve: your profiles are editable and deletable from your account, and deleting the account erases everything. for a full data export, email [contact email — M5 gate] and it will be fulfilled manually. you also have the right to complain to a supervisory authority — [name the competent authority once the jurisdiction is fixed — M5 gate].