Skip to main content

Privacy Policy

Last updated 2026-07-27.

Boulder Lens has no accounts, no login, and no user profiles. This page lists, plainly and completely, the handful of things the app does collect, who else ever sees any of it, and how to remove what's yours.

If you turn on event notifications

Your browser creates a push subscription — an endpoint URL and two keys it uses to receive messages — and we store that so we can deliver the notifications you asked for. We do not receive your name, email, or location as part of this; it's a token your browser controls, not an identity. You can remove it yourself at any time by turning notifications back off in the app, which deletes your subscription from our database immediately.

If you send feedback or report an issue

Your message is stored so we can review it. If you choose to leave a contact email (it's always optional — never required to submit feedback), we store that too, only so we can reply if needed. Right now there's no self-service way to delete a submitted feedback report or the email attached to it — email boulderlens@gmail.com and we'll remove it by hand.

Everyone else who ever sees anything

Four services touch data as part of running this site, and here's exactly what each gets:

  • Supabase (our database host) stores the push subscriptions and feedback reports described above. It's the processor behind our own database — nothing here is a separate handoff of your data to a third party for their own use.
  • Cloudflare Web Analytics (cloudflare.com/web-analytics) gives us aggregate visit counts — how many people came, which pages they opened, and roughly where from. It is cookieless, sets no identifiers, builds no profiles, and does not follow you to other sites. It cannot identify you. There is no session recording. (A different cookieless analytics script used to load here; it was removed in August 2026 once we found it had never been connected to an account and so had never recorded anything at all.)
  • Sentry, our error-monitoring service, receives a report only when something breaks — the error message and technical details needed to fix it, explicitly configured to exclude personal information (device identity, IP, etc.).
  • CARTO serves the map tiles you see. Loading a map tile is a normal web request like loading an image, so it necessarily reaches CARTO's servers with your IP address and the map area you're viewing, the same as any map provider (Google Maps, Apple Maps, etc.) would receive.

Nothing collected here is sold, rented, or shared with advertisers.

What we don't do

  • No accounts, no login, no passwords to leak.
  • No location tracking — "Use My Location" asks your browser for a one-time position through the browser's own permission prompt; we don't store a history of where you've been.
  • No advertising, no ad trackers, no cross-site profiles.
  • No selling or renting any data to anyone.
  • No session recording or replay — nobody watches a recording of your visit.
  • We stop short of claiming "no tracking whatsoever". Our analytics count visits in aggregate, serving the site at all means our host and CDN see ordinary request logs, and error reports reach Sentry when something breaks. None of that identifies you, and we'd rather say so plainly than overclaim.

Questions or a removal request

Email boulderlens@gmail.com for anything not covered by the self-service options above. This policy may be updated as the app changes; the date at the top will always reflect the latest revision.