1. Overview

Sierra Nevada Placer Claims is a screening map. It has optional user accounts and no third-party analytics. Free use of the map may show advertising (see Section 8); paid Supporter accounts see no ads. The data it handles falls into four groups: data needed to serve the map, optional account data, feedback you choose to send, and a small local browser record of your Terms acceptance.

We do not sell your personal information for money, and we never have. We do want to be precise about one point rather than reassuring: California law defines "selling" and "sharing" broadly, and serving personalized ads passes an advertising identifier to Google and its partners. That can count as "sharing" for cross-context behavioral advertising under the CCPA/CPRA even though no money changes hands. You can turn personalized advertising off at any time in Your Privacy Choices, and we honor Global Privacy Control signals automatically. Section 10 sets out your California rights in full.

2. Data Used to Operate the Map

When you use the map, your browser requests map data from this app's server. Like most web servers, the server keeps standard request logs (such as IP address, request path, time, and user agent) for security and operations. Candidate and screening content comes from cached copies of public datasets (BLM, USDA Forest Service, and USGS). The basemap is served by OpenStreetMap, so your browser or iOS app requests the tiles needed for the area you are viewing directly from OpenStreetMap.

3. Feedback You Send

The Feedback form is optional. If you submit it, the app stores your message, the problem type you selected, optional contact information you provide, and technical context that helps investigate the report: the map center and zoom at submission time, the selected candidate plot (if any), which layers were visible, your browser's user-agent string, and the referring page. This context is stored so data problems can be reproduced and fixed.

4. Optional Contact Information

Contact details submitted with feedback are used only to follow up on that feedback. They are not used for marketing and are not shared, except as required by law.

5. Location Data

The web app does not request device GPS location. In the iOS companion app, location is optional and requested only when you tap Center on my location. A one-time when-in-use reading is used to center the map and draw an accuracy circle; the app does not start background location updates or save that reading to your account.

Centering the map causes the same map-area requests as manually panning there: the app server may receive the visible candidate-data bounding box and OpenStreetMap receives the basemap tile requests for that area. If you later submit Feedback, the current map center and zoom are included as described in Section 3. The device marker and accuracy circle are approximate field context, not a survey, claim-boundary, or legal-location measurement.

6. Local Storage on Your Device

The app stores a small record in your browser's local storage noting which version of the Terms acceptance and safety acknowledgement you accepted, so you are not prompted on every visit. The app also uses standard browser caching (including an offline shell cache) to load faster. These stay on your device and can be cleared through your browser settings; clearing them re-triggers the acceptance prompt.

7. Retention

Feedback submissions are retained in the active feedback store for up to 90 days and are accessible only to the application operator for investigation and follow-up. The store is also capped by entry count and file size, so older submissions may be removed sooner. Server logs rotate on a standard operational schedule.

Account data is kept while your account remains open. If you request deletion, the account is deactivated for a 30-day recovery period and then permanently deleted from the active account database. Operational account snapshots retain the newest 14 nightly local copies (about 14 days), and client-side-encrypted offsite account snapshots are deleted by a 30-day lifecycle rule. Daily VM disk snapshots are retained for 14 days.

Data removed from an active store may therefore remain in a protected backup for up to 30 additional days. Backups are access-restricted, used only for security and disaster recovery, and are not restored merely to extend retention or reactivate a deleted account. Expired backup copies are removed on their normal schedule.

8. Accounts, Advertising, and Tracking

Accounts are optional and are needed only for Supporter features. If you create one, the app stores your email address, a securely hashed password, your subscription status, and a session cookie that keeps you signed in. Payments are processed by Stripe; this app never stores card numbers.

If you explicitly save a candidate plot, the account stores that plot's identifier, save time, source generation and rules version, rating snapshot, and a geometry fingerprint so the app can distinguish saved evidence from the current published result. Saving a plot does not upload your device GPS position or field notes. Saved places remain in the account after a subscription ends until you remove them or delete the account, and they are included in the account-data export.

If you request a GPX, KML, or CSV candidate export, the app receives the candidate plot identifiers you selected, resolves their current published screening records, and sends the generated file to your browser. The app does not store a separate server copy of the planning file or add your device GPS position or field notes to it. The downloaded file contains candidate coordinates and/or screening geometry, so you control where that local file is stored or shared.

Anonymous and free-tier use of the map may display advertising served by Google AdSense. Supporter subscribers see no ads. When ads are shown, Google and its partners may use cookies and similar identifiers to serve and measure ads and, where you have consented, to personalize them. Visitors in regions that require it (such as the EEA and UK) are shown a consent message before any personalized advertising. See How Google uses information from sites that use its services and Google's Privacy Policy. You can control personalized advertising at Google Ad Center.

There are no other third-party analytics or cross-site tracking. If usage metrics or other tracking are introduced in the future, this policy will be updated before those features launch.

9. Your Privacy Choices

You can turn off personalized advertising for this browser. Ads will still appear on the free tier, but they will not be personalized using an advertising identifier, and the identifier sharing described in Section 8 stops.

JavaScript is required to change this setting here. You can also send a request through the in-app Feedback form, or use a browser that sends a Global Privacy Control signal.

Global Privacy Control. If your browser or extension sends a Global Privacy Control signal, we treat it as a valid opt-out automatically: personalized advertising is switched off without you doing anything else, and the control above will show as on and locked. You do not need an account for this to work.

This choice is stored in your browser, not in an account, so it applies per browser and per device. Clearing site data clears the choice. Supporter subscribers see no ads at all, which makes the question moot for them.

10. California Privacy Rights (CCPA/CPRA)

This section describes rights California residents have under the California Consumer Privacy Act as amended by the CPRA. We provide these choices to everyone who asks, regardless of where they live, and we do not require an account to use them.

Categories of personal information

We collect this information from you directly and from your device when you use the app. We do not knowingly collect sensitive personal information as CPRA defines it, we do not use it to infer characteristics about you, and we do not sell or share the personal information of anyone we know to be under 16.

Your rights

How to make a request

Send a request through the in-app Feedback form on the map page, or use the account panel for export and deletion. We will acknowledge within 10 business days and respond within 45 days, extending once by a further 45 days where permitted and telling you if we do. To protect your data we need to verify the request: for account holders that normally means acting from the signed-in account or the registered email; for anonymous use we may be unable to link a request to any stored record, and we will say so rather than guess. An authorized agent may submit a request with written proof of authority, and we may still verify with you directly.

Some records may be retained after a deletion request where the law requires it, such as accounting, tax, audit, and fraud-prevention records. Backups are governed by the schedule in Section 7.

11. Changes to This Policy

This Policy carries a version number and effective date at the top of the page; this is version 1.0, effective 2026-08-04. A material change raises the version number and triggers a fresh in-app acceptance prompt. Non-material corrections update the effective date without a new prompt.

12. Contact

Questions, corrections, or deletion requests can be sent through the in-app Feedback form on the map page.