Privacy
Last updated September 2, 2026
You can use every part of this map without an account. An account exists for one reason: to remember the places you save. This page says exactly what is stored if you make one, and how to take it back or delete it.
What is stored
If you create an account, the database holds these things:
- Your email address. It is the name you sign in with, and it is never shown to other people, sold, or shared with anyone for their own marketing. Two things may be sent to it. A sign-in link, only ever when you ask for one on the sign-in screen. And occasional email about new Raw States tools. If you create an account from the United States you are added to that list when the account is made, and the create-account screen says so above the button before you press it. If you create an account from anywhere else you are not added at all, and the switch in your account menu is how you join if you want to. Either way, every one of those emails carries a one-click unsubscribe that needs no sign-in and takes effect immediately, and the switch in your account menu turns them off at any time without sending anything.
- Whether you are on that list, and when that was decided. The database records the date and the exact sentence that was on screen, so there is a record of what you were told or asked. Withdrawing is recorded the same way. Two things never change: an address that has unsubscribed stays unsubscribed even if a brand new account is later made with it, and accounts created before 14 August 2026 were told that no mailing list existed, so none of them are on one and none can be added without asking again.
- What this page said before 2 September 2026. Until that date the email above went out “only if you ticked the box asking for it”, and the box “starts unticked, and leaving it alone means you never hear from us”. That box is gone, replaced by the notice described above for accounts created in the United States. The old wording is quoted here rather than deleted, because a promise that changed should be visible as a change and not simply disappear.
- A one-way hash of your password (PBKDF2-SHA256, 200,000 iterations, unique salt). The password itself is never written down anywhere, which is also why it cannot be recovered if you forget it.
- Which places you saved, and when you saved each one.
- When each sign-in began and was last used, so old sessions can expire.
That is the complete list. There is no name field, no location history, no record of what you looked at, and no profile built about you.
What is not stored
- No advertising identifiers, no ad networks, no data brokers.
- Your name, your email and your saved places are never sent to any analytics service. The account database and the analytics are not joined and cannot be. What Google Analytics does receive is listed below.
- No IP addresses. Sign-in attempts are rate-limited to stop password guessing, and the counter stores a one-way hash of the address rather than the address, discarded within minutes.
- Nothing is sold, rented, or shared with anyone for marketing. There are no data brokers involved.
Analytics
Two counters run here, and it is worth being exact about which does what.
The first is this site's own, on this site's own servers, and every figure the site publishes about itself comes from it. The second is Google Analytics, added on 27 August 2026 for one narrow reason: advertisers and ad networks verify a site's audience through Google or they do not verify it at all, and a number this site reports about itself is not evidence to them. It measures the same readers the first counter measures, and it decides nothing about what you see here.
Microsoft Clarity was used until 19 August 2026, only ever after an explicit opt-in, and has been removed entirely. Nothing replaced it: session recording, heatmaps and anything that watches what you do inside a page are gone and are not coming back.
The site's own counter records which pins were opened, which filters were touched, roughly how long the tab was actually being looked at, the page you arrived from, and the country and region your connection appears to come from. Your IP address is never stored.
Visits are deliberately hard to string together. The identifier is rebuilt from scratch every day, so a visit today and a visit tomorrow cannot be joined into one person. That is a design choice, and it costs real detail on purpose.
One number is kept on your own device rather than on the server: how many times you have been here and roughly how long ago the last time was. Your browser works that out and sends only a summary, so the site can tell how many readers come back without anyone here being able to tell who. Nothing about it is shown to you, and clearing your browser storage erases it.
What Google receives: the address of each page and each pin you open here, the page you arrived from, and the ordinary things any web server is told, including your IP address, which Google uses to work out a rough location and then discards rather than storing. It is not told your email, your account, or anything you have saved. Google's advertising features are switched off at the source: ad storage, ad personalisation and ad-user-data are denied on every request and are never granted, so nothing collected here can be used to target advertising, here or anywhere else.
In the EU, the EEA, the UK and Switzerland, Google Analytics runs with storage denied. It writes nothing to your device and reads nothing from it, so it cannot recognise you on a later visit or join today to tomorrow. That is why there is still no consent banner: in the places consent would be required, nothing is being stored to ask about.
Google is also never loaded at all for anyone the site has already decided not to count: opted-out browsers, crawlers, automated tools, and the site's own operator. Both counters are fed by one decision, which is the only way two counts of the same audience can honestly agree.
You can refuse all of this at once with Global Privacy Control in your browser, which this site honours without asking, and which stops Google as firmly as it stops the counter next to it. A private window has the same effect. The map works identically either way, and nothing here is withheld from anyone who opts out.
Cookies
Two kinds, and only the first is set without asking.
Strictly necessary: no consent, cannot be declined
acm_s, a cookie holding a random session token (not your email, not your password), which exists only to keep you signed in.HttpOnlyso scripts cannot read it,Secureso it only travels over HTTPS,SameSite=Laxso other sites cannot use it. Thirty days, or gone the moment you sign out.acm_o, a ten-minute cookie that exists only during a Google sign-in, to prove the trip to Google and back was one you started.- Browser storage on your own device, holding your choices: the filters you set, whether the AI search box is on, your recent searches, and whether you dismissed the Dark Mode strip. None of it is sent to us.
These are exempt from consent under the ePrivacy Directive's Article 5(3) because they exist to deliver something you asked for. They are listed here because being exempt from asking is not the same as being exempt from telling.
Analytics cookies
The site's own counter sets one, acm_r, holding four numbers and nothing else: the day this browser first came, the day of the visit before the latest one, the latest visit, and how many different days it has come. It exists so the owner can see whether readers come back. It names nobody, cannot be joined across devices or to an account, never leaves this site, and expires after 400 days. It is set by the server rather than by a script, because Safari erases script-written storage after seven days and a reader back on day eight was being counted as new. It is not set in the EU, the EEA, the UK or Switzerland, not set when the region cannot be told, and not set when Global Privacy Control is on.
Until 10 September 2026 this paragraph said the site's own counter set no cookies, and never had. That was true: the same four facts were kept in the browser's own storage instead. Moving them into a cookie the server sets is the whole change, and it is recorded here as one.
Google Analytics sets one, _ga, holding a random number and nothing else, so that two pages you open a few minutes apart can be recognised as one visit rather than two strangers. It is first-party, it names nobody, and it expires after two years. It is not set at all in the EU, the EEA, the UK or Switzerland, where storing it would require consent this site does not ask for.
Until 27 August 2026 this section said there were no analytics cookies here of any kind, and that a third party would be asked about before it loaded. Google Analytics is that third party and it is not asked about, because in every place a browser is asked, it is instead denied storage outright. The old wording is quoted here rather than deleted, since a promise that changed should be visible as a change and not just disappear.
Why it is stored (lawful basis)
Under the UK and EU GDPR, the basis is performance of a contract (Article 6(1)(b)). You asked the site to remember your saved places, and it cannot do that without an account to attach them to. The rate-limiting counter rests on legitimate interests (Article 6(1)(f)) in keeping accounts from being broken into.
Both analytics rest on legitimate interests (Article 6(1)(f)): understanding how the map is used, and being able to show an advertiser what this site's audience is without asking them to take its word for it. Neither identifies you, and in the UK, EU, EEA and Switzerland neither stores anything on your device or reads anything from it, so the ePrivacy consent requirement for storage does not arise. You can object at any time, and Global Privacy Control is the one-switch way to do it.
No processing here relies on consent, and none of it involves special-category data.
How long it is kept
- Account and saved places: until you delete the account. Then they are gone.
- Sessions: 30 days from last use, then deleted automatically.
- Rate-limit counters: minutes.
Your rights, and how to use them
Both of these are buttons in the account menu. Neither requires emailing anybody or waiting.
See everything held about you (Article 15). Account → Download my data gives you a JSON file with your email, your saved places, and your session times.
Delete everything (Article 17). Account → Delete account asks for your password and then erases the account, the saved places and the sessions. It is immediate and cannot be undone. There are no backups from which the data is later restored.
You also have the right to correct inaccurate data, to object to processing, and to portability, the export above is a machine-readable format and satisfies portability. To change your email address, or for anything else, use the contact below.
If you think this site has mishandled your data you can complain to your national data protection authority; in the UK that is the Information Commissioner's Office.
Where it is stored
Accounts live in a Cloudflare D1 database and the site is served by Cloudflare Workers. Cloudflare acts as a data processor, as does Google for the analytics described above. Depending on the network, data may be processed on servers in the United States; Cloudflare's transfer safeguards are described in its own GDPR documentation.
Children
This site is not directed at children and does not knowingly hold accounts for anyone under 13. If you believe a child has made an account, use the contact below and it will be deleted.
Public information
The number of people who have saved a place is shown publicly on that place's card. It is a count and nothing else. Nobody can see who saved what, including the site's operator, without reading the database directly. Your saved list is visible only to you.
Changes
If this policy changes in a way that affects what is collected or why, the date at the top changes and the change is described here rather than quietly applied.
Contact
Questions about your data, corrections, or a copyright concern about anything published on the map: privacy@rawstates.com.