Privacy Policy
Last updated: [EFFECTIVE DATE]
Saltmarch is operated by [ENTITY] ("Saltmarch", "we", "us"). Saltmarch is two things in one app: a community-edited map and directory of public events, and a home for private, membership-only spaces — communities, families, and events (including conferences and festivals) — where members share media, posts, and messages with each other, not the public. This policy explains what we collect across both, why, and the choices you have. We've tried to keep it plain and honest.
What we collect
- Account information. Your email address and password (stored only as a secure hash, never in plain text), a handle and display name (required at signup, so people can find and invite you without confusing you with someone else), and optionally a short bio, profile photo, and a default city.
- Public commons content. Events and edits you add to the commons, check-ins (which record the place and time you check in), and lists. A check-in is private by default — visible only to you — unless you explicitly mark it public.
- Private community, family, and event content. If you're a member of a community, family, or private event, that space may have its own Library media, announcements, comments, and chat. Photos, videos, captions, posts, comments, and messages you post there are visible only to the other members of that space — never to the public, and never used for advertising or to train AI models. Because families and communities often include photos of children, this content may depict minors; see "Children" below.
- Media captured or uploaded through the app. Photos and videos you capture with the app's camera or choose from your photo library to upload. On iOS, when Photos access permits, in-app captures are also saved to your device's photo library. If Photos access is unavailable, Saltmarch keeps an app-managed source on that device while the operation is pending.
- Device and notification data. If you enable push notifications, we store a device push token (via Apple's APNs) so we can deliver them. We don't use this token for anything else.
- Technical essentials. A session cookie and a CSRF token, which keep you signed in and protect forms. For basic website traffic measurement we use Plausible — a privacy-friendly, cookieless analytics tool that collects no personal data, sets no cookies, and never tracks you across other sites. We do not use advertising trackers or any tool that builds a profile of you. In our iOS app, we collect a small allowlisted set of interface actions — such as opening a media filter or accepting a proposed save destination — to learn whether defaults are understandable. Those events contain no account, media, Event, family, community, member, location, or stable device identifier. A random app-launch session is kept only as a one-way digest; raw events are deleted after 14 days and anonymous daily totals after 180 days. You can turn this collection off on that device in Account & Privacy. A few interface preferences (theme, layout) are stored locally in your browser or device, not on our servers.
- Location, only when you ask. If you tap a "use my location" control, your browser or device asks your permission and sends coordinates for that one action. We do not track or store a continuous history of your device's location.
How we use it
- To run the service and show you events relevant to your area.
- To provide community, family, and event features — Library media, announcements, comments, and messaging — to the members you choose to share them with, and no one else.
- To sign you in and keep your account secure.
- To send essential emails and push notifications — confirming your address, resetting your password, notifying you of activity in your communities, and important account or service notices. We don't send marketing email or notifications without your consent.
- To keep everyone safe — including scanning uploaded media for harmful content (including child sexual abuse material), platform-wide. This applies to every upload, public or private. For public commons content, this scan happens before the content becomes visible to others. For private community, family, and event content — where members are already known to each other and accountable — content is visible to fellow members right away, and the scan runs immediately afterward as a backstop; anything flagged is quarantined or removed.
- To prevent abuse, spam, and vandalism.
Who we share it with
We don't sell your personal data, and we never share it for advertising. We do rely on a small set of service providers ("sub-processors") to operate:
- Cloudflare R2 — primary storage and delivery for uploaded photos, videos, and other media.
- Backblaze B2 — cold object storage for older, inactive uploaded media originals. Media stored there remains protected by Saltmarch's access controls and is retrieved only for authorized requests.
- Amazon Web Services. Automated content-safety scanning of media (Rekognition), and secure, restricted- access quarantine storage for content flagged by that scan.
- Postmark — sending transactional email (confirmations, password resets, notifications).
- Apple (APNs) — delivering push notifications to the iOS app, using the device token described above.
- Twilio. If you enable phone-based two-factor authentication, Twilio sends the verification code to your phone. We don't use Twilio for anything else, and you don't need a phone number unless you turn this on.
- Anthropic (Claude) and OpenAI. We send scraped event-source pages and flyers to Claude to extract and classify event details, and use OpenAI for transcribing audio (for example, spoken captions) you choose to add. Neither receives your account information, and neither receives private community/family/event content except the specific item you're transcribing.
- OpenStreetMap / Nominatim, Mapbox, Google, MapTiler, and Stadia Maps — address and place lookups, used while importing event and venue data or rendering maps (not your personal data).
- Cloudflare Stream — hosting and delivery for live streams and uploaded video, when that feature is used.
- Fly.io — application hosting (United States).
- Langfuse — internal diagnostics, and only when that integration is explicitly enabled.
- Plausible — privacy-friendly, cookieless traffic analytics (aggregate page counts and referrers; no personal data, no cross-site tracking).
- Saltmarch first-party product metrics — a closed set of identity-free iOS interaction counts, processed on Saltmarch's own application and database infrastructure; no advertising or cross-site tracking.
Public commons vs. private spaces — who can see what
Events, edits, check-ins you choose to make public, and your public profile are visible to anyone. How others may reuse them depends on the kind of event: your events stay yours and are not commons-licensed, while everyone's events (the open, anyone-can-edit listings) are part of the public commons. The Terms of Service (Section 5) spells out both. Please treat anything you post publicly as publicly visible.
Content inside a private community, family, or event — Library media, posts, comments, chat — is different: it is visible only to that space's members, is never part of the public commons, and is never commons-licensed or reused. Who counts as a "member" is controlled by that space's admins/organizers (invite links, QR codes, or approval), and you can see your current memberships in the app at any time.
Cookies
We use only a session cookie and a CSRF-protection token — both required for the site to work. Our website analytics (Plausible) is cookieless, and we set no third-party tracking or advertising cookies. The iOS product metrics described above use no cookie or stable device identifier.
Your choices and rights
You can access, correct, or delete your account at any time — email [email protected] . When you delete your account, we remove your personal account data. To preserve the integrity of the public commons (the same way Wikipedia does), your past public contributions are kept but re-attributed to a steward account rather than to your name.
Content you contributed to a private community or family's shared media pool is different: because other members' shared memories depend on it, it stays in that space's pool for the other members unless the space's admin removes it — the same way leaving a shared photo album elsewhere doesn't delete it for everyone else who has it. Your account information and anything visible only to you are deleted either way. You can also ask a community or family admin to remove specific items you contributed before you leave.
Retention and security
We keep account data while your account is active and delete it on request. Passwords are stored hashed (bcrypt), and traffic is encrypted in transit (HTTPS).
Children
Saltmarch accounts aren't intended for anyone under 13, and we don't knowingly let anyone under 13 create an account or knowingly collect account data from them.
That's separate from a different, common situation: an adult member of a family or community space may post photos or videos that depict their own or another member's children. That content is controlled by the adult account holder who posted it, is visible only to that space's members, and is covered by the content-safety scanning described above. If you're a parent or guardian with a concern about content depicting a minor, email [email protected] and we'll act on it directly.
Changes to this policy
We may update this policy as the service evolves. We'll revise the "Last updated" date above, and for material changes we'll give notice in the app or by email.