FaceHeatMap | Privacy Policy · Terms of Service · ← Back to Map

Privacy Policy

Last Updated: May 1, 2026 · Effective: May 1, 2026

Summary: FaceHeatMap does not sell your data. We collect minimal technical data needed to operate the service. We do not require account registration. You have full rights to access, correct, or delete any data we hold about you.

1. Who We Are

FaceHeatMap ("we," "us," "our") is operated by VPDLNY (Vulnerable Persons Defense League of New York), a collective of technologists and artists dedicated to transparency and civil liberties. Our primary contact for privacy matters is: contact@faceheatmap.app

2. Information We Collect

2.1 Automatically Collected Technical Data

When you visit FaceHeatMap, our web server (Cloudflare Workers) automatically logs:

  • Your IP address (processed by Cloudflare — see Cloudflare's privacy policy)
  • Browser type and version (User-Agent string)
  • Pages requested and timestamps
  • Referring URL (if you clicked a link to reach us)
  • Country-level geolocation (derived from IP, not stored)

This data is processed by Cloudflare under their standard infrastructure logging. We do not have persistent access to this data beyond error reports.

2.2 Consent Records

When you agree to our Terms of Service, we store a consent record in your browser's localStorage. This record contains: timestamp of consent, and a truncated User-Agent string. This data stays on your device and is not transmitted to our servers.

2.3 JavaScript Error Reports

If a JavaScript error occurs in your browser while using the app, an automated error report may be sent to our /api/error endpoint. This report contains: the error message, the URL where it occurred, and a truncated User-Agent string. No personally identifiable information is included.

2.4 Contact Form Submissions

If you voluntarily submit our contact form, we collect: your name, email address, subject, and message. This data is stored in our secure database and used only to respond to your inquiry. We do not use contact form data for marketing.

2.5 Data We Do NOT Collect

  • We do not require or create user accounts
  • We do not use advertising tracking pixels or cookies
  • We do not use Google Analytics or third-party analytics
  • We do not collect biometric data from users
  • We do not sell, rent, or trade any user data
  • We do not use cross-site tracking technologies

3. How We Use Your Information

Technical log data is used solely for: debugging errors, preventing abuse and DDoS attacks, and understanding aggregate usage patterns. Contact form data is used solely to respond to your message.

4. Data Sharing and Third Parties

4.1 Cloudflare

Our site is hosted on Cloudflare Workers and Cloudflare D1. Cloudflare processes request metadata as part of infrastructure operations. Cloudflare's privacy policy governs their data handling: cloudflare.com/privacypolicy

4.2 External Data Sources

The surveillance data displayed on FaceHeatMap comes from public sources (EFF, USASpending.gov, MuckRock, ACLU, NewsAPI). We link to these sources but do not control their privacy practices.

4.3 No Advertising Partners

We have no advertising partners and do not share data with ad networks, data brokers, or marketing platforms.

4.4 Legal Requirements

We may disclose information if required by valid legal process (court order, subpoena) after consultation with legal counsel. We will notify affected users when legally permitted to do so.

5. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Right to Access: Request a copy of data we hold about you
  • Right to Correction: Request correction of inaccurate data
  • Right to Deletion: Request deletion of your data (contact form submissions)
  • Right to Portability: Receive your data in a machine-readable format
  • Right to Object: Object to certain processing activities
  • CCPA Rights (California): Right to know, delete, opt-out of sale (we do not sell data)
  • GDPR Rights (EU/UK): All rights under GDPR Article 15-22

To exercise any right, contact us at contact@faceheatmap.app. We will respond within 30 days (or 45 days where permitted by law).

6. Data Security

We implement reasonable technical security measures including: HTTPS/TLS encryption for all data in transit, Cloudflare DDoS protection and WAF, no storage of sensitive personal data, regular security reviews. However, no internet transmission is 100% secure. We cannot guarantee absolute security.

7. Data Retention

  • Contact form submissions: retained for 2 years, then deleted
  • Error reports: retained for 30 days in logs
  • Cloudflare infrastructure logs: subject to Cloudflare's retention policies (typically 72 hours)
  • Consent records: stored locally in your browser, deleted when you clear browser data

8. Children's Privacy

FaceHeatMap is not directed at children under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, contact us immediately at contact@faceheatmap.app.

9. International Users

FaceHeatMap is operated in the United States. If you access our service from outside the US, your data may be processed in the US. By using our service, you consent to this transfer. We process data in accordance with applicable law.

10. Changes to This Policy

We may update this Privacy Policy. Material changes will be indicated by updating the "Last Updated" date at the top of this page. Continued use of FaceHeatMap after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related requests, data deletion, or questions about this policy:

Email: contact@faceheatmap.app

Subject line: "Privacy Request" or "Data Deletion Request"

Response time: 30 days or less. For urgent matters, include "URGENT" in your subject line.