Privacy
Last updated July 30, 2026
You can use every part of this map without an account. An account exists for one reason: to remember the places you save. This page says exactly what is stored if you make one, and how to take it back or delete it.
What is stored
If you create an account, the database holds four things:
- Your email address. It is the name you sign in with. It is never shown to other people, and nothing is ever emailed to it: there is no mailing list and no password-reset mail.
- A one-way hash of your password (PBKDF2-SHA256, 200,000 iterations, unique salt). The password itself is never written down anywhere, which is also why it cannot be recovered if you forget it.
- Which places you saved, and when you saved each one.
- When each sign-in began and was last used, so old sessions can expire.
That is the complete list. There is no name field, no location history, no record of what you looked at, and no profile built about you.
What is not stored
- No advertising identifiers, no ad networks, no data brokers.
- Nothing that identifies you personally is sent to any analytics service. The account database and the analytics are not joined and cannot be.
- No IP addresses. Sign-in attempts are rate-limited to stop password guessing, and the counter stores a one-way hash of the address rather than the address, discarded within minutes.
- Nothing is sold, rented, or shared with anyone for marketing. There are no data brokers involved.
Analytics
This site uses Microsoft Clarity to see how people actually use the map: which filters get touched, where the layout confuses, where a page gets abandoned. Clarity records anonymised session replays and builds heatmaps of clicks and scrolling. It is a third party, it sets its own cookies, and it processes on Microsoft's infrastructure under Microsoft's terms.
What it does not get: your email, your password, your saved places, or any link between a session and an account. Clarity masks text input by default, so anything typed into the search box or the sign-in form is not captured.
You can opt out of Clarity everywhere at once by turning on Do Not Track or Global Privacy Control in your browser, or by blocking clarity.ms with any content blocker. The map works identically either way, and nothing on this site is withheld from anyone who blocks it.
Cookies
One cookie, named acm_s. It holds a random session token (not your email, not your password) and exists only to keep you signed in. It is marked HttpOnly so scripts cannot read it, Secure so it only travels over HTTPS, and SameSite=Lax so other sites cannot use it. It expires after 30 days, or immediately when you sign out.
Microsoft Clarity sets its own cookies to recognise a returning session for its heatmaps. Those are analytics cookies, not strictly necessary ones, so under the ePrivacy Directive they need consent in the jurisdictions that enforce it. That is an honest statement of the position rather than a claim to have solved it: a consent banner is not built yet, and until it is, blocking clarity.ms or enabling Do Not Track is the reliable way to refuse it.
Why it is stored (lawful basis)
Under the UK and EU GDPR, the basis is performance of a contract (Article 6(1)(b)). You asked the site to remember your saved places, and it cannot do that without an account to attach them to. The rate-limiting counter rests on legitimate interests (Article 6(1)(f)) in keeping accounts from being broken into.
Analytics rests on consent (Article 6(1)(a)) where consent is required, which is the gap described under Cookies above.
No processing here relies on consent, and none of it involves special-category data.
How long it is kept
- Account and saved places: until you delete the account. Then they are gone.
- Sessions: 30 days from last use, then deleted automatically.
- Rate-limit counters: minutes.
Your rights, and how to use them
Both of these are buttons in the account menu. Neither requires emailing anybody or waiting.
See everything held about you (Article 15). Account → Download my data gives you a JSON file with your email, your saved places, and your session times.
Delete everything (Article 17). Account → Delete account asks for your password and then erases the account, the saved places and the sessions. It is immediate and cannot be undone. There are no backups from which the data is later restored.
You also have the right to correct inaccurate data, to object to processing, and to portability, the export above is a machine-readable format and satisfies portability. To change your email address, or for anything else, use the contact below.
If you think this site has mishandled your data you can complain to your national data protection authority; in the UK that is the Information Commissioner's Office.
Where it is stored
Accounts live in a Cloudflare D1 database and the site is served by Cloudflare Workers. Cloudflare acts as a data processor, as does Microsoft for the analytics described above. Depending on the network, data may be processed on servers in the United States; Cloudflare's transfer safeguards are described in its own GDPR documentation.
Children
This site is not directed at children and does not knowingly hold accounts for anyone under 13. If you believe a child has made an account, use the contact below and it will be deleted.
Public information
The number of people who have saved a place is shown publicly on that place's card. It is a count and nothing else. Nobody can see who saved what, including the site's operator, without reading the database directly. Your saved list is visible only to you.
Changes
If this policy changes in a way that affects what is collected or why, the date at the top changes and the change is described here rather than quietly applied.
Contact
Questions about your data, corrections, or a copyright concern about anything published on the map: privacy@rawstates.com.