Trust
Security and privacy
Maplivo is local-first: your maps, notes and attachments are stored on your device, not on our servers. This page explains what that means for you and your company's security review.
Last updated 28 September 2026
Where your maps live
Maps, notes, images, audio notes, version history and settings are saved in your browser's local database (IndexedDB) on the device you use. Maplivo has no server-side copy of map content, so there is no central store to breach, subpoena or mine, and the data sits wherever your device is.
- Nothing is synced between devices. Move maps with a portable export file or a folder backup.
- Clearing this site's browser data deletes the maps on that device. Keep exports as backups.
- Share links carry the map inside the link itself (after the #), which browsers do not send to our server.
- Your device's own protections apply: disk encryption, screen lock and your company's device management.
What leaves your device, and when
| When | What is sent | Where |
|---|---|---|
| You create an account or sign in | Name, email address, sign-in details | Clerk |
| You subscribe or manage Pro | Billing details and invoices (card data is handled by the payment provider) | Lemon Squeezy |
| You send feedback | Only what you type, an optional rating and email, and the page you were on | A private Google Sheet (Google Apps Script) |
| AI features | Coming soon: no map content is sent to any AI service | — |
| You use the app at all | Standard web requests (IP address, browser) | Our hosting provider |
Using Maplivo without signing in, and editing maps while signed in, sends no map content anywhere. AI features are coming soon; until then nothing is sent to an AI service.
Service providers (subprocessors)
| Provider | Purpose | Data |
|---|---|---|
| Clerk | Accounts and sign-in | Account profile, sessions, subscription status |
| Lemon Squeezy | Payments, tax, invoices (merchant of record) | Billing details, subscription |
| Google (Apps Script, Sheets) | Collecting feedback | Feedback you submit |
| Vercel | Hosting the web app | Request logs |
How the service is protected
- All traffic uses HTTPS.
- Billing actions check the request origin to block cross-site requests.
- Payment webhooks are verified with an HMAC signature (constant-time comparison) before changing any plan.
- Secrets live in the hosting provider's encrypted environment settings, never in the browser.
- Feedback submissions are validated, size-limited and rate-limited.
- Imported files are validated against a strict schema, and unsafe links are rejected.
- Exports to spreadsheets neutralize formulas, so a topic can't run code when opened in Excel.
- You can delete your account from the Account page. This removes your account and subscription records; your maps stay on your device until you clear them.
For company security reviews
| Requirement | Status today |
|---|---|
| Map data residency | On the user's device, in any region |
| Encryption at rest | Provided by the device (for example BitLocker or FileVault) |
| Company single sign-on (SAML / OpenID Connect) | Not available yet |
| Admin console, audit logs, user provisioning (SCIM) | Not available yet |
| SOC 2 / ISO 27001 certification | Not certified |
| Data processing agreement | Available on request through Feedback |
| Accessibility conformance | See the accessibility statement |
For a questionnaire or a data processing agreement, send a request with the Feedback button and include a contact email.