← Back to Maplivo

Trust

Security and privacy

Maplivo is local-first: your maps, notes and attachments are stored on your device, not on our servers. This page explains what that means for you and your company's security review.

Last updated 28 September 2026

Where your maps live

Maps, notes, images, audio notes, version history and settings are saved in your browser's local database (IndexedDB) on the device you use. Maplivo has no server-side copy of map content, so there is no central store to breach, subpoena or mine, and the data sits wherever your device is.

  • Nothing is synced between devices. Move maps with a portable export file or a folder backup.
  • Clearing this site's browser data deletes the maps on that device. Keep exports as backups.
  • Share links carry the map inside the link itself (after the #), which browsers do not send to our server.
  • Your device's own protections apply: disk encryption, screen lock and your company's device management.

What leaves your device, and when

WhenWhat is sentWhere
You create an account or sign inName, email address, sign-in detailsClerk
You subscribe or manage ProBilling details and invoices (card data is handled by the payment provider)Lemon Squeezy
You send feedbackOnly what you type, an optional rating and email, and the page you were onA private Google Sheet (Google Apps Script)
AI featuresComing soon: no map content is sent to any AI service—
You use the app at allStandard web requests (IP address, browser)Our hosting provider

Using Maplivo without signing in, and editing maps while signed in, sends no map content anywhere. AI features are coming soon; until then nothing is sent to an AI service.

Service providers (subprocessors)

ProviderPurposeData
ClerkAccounts and sign-inAccount profile, sessions, subscription status
Lemon SqueezyPayments, tax, invoices (merchant of record)Billing details, subscription
Google (Apps Script, Sheets)Collecting feedbackFeedback you submit
VercelHosting the web appRequest logs

How the service is protected

  • All traffic uses HTTPS.
  • Billing actions check the request origin to block cross-site requests.
  • Payment webhooks are verified with an HMAC signature (constant-time comparison) before changing any plan.
  • Secrets live in the hosting provider's encrypted environment settings, never in the browser.
  • Feedback submissions are validated, size-limited and rate-limited.
  • Imported files are validated against a strict schema, and unsafe links are rejected.
  • Exports to spreadsheets neutralize formulas, so a topic can't run code when opened in Excel.
  • You can delete your account from the Account page. This removes your account and subscription records; your maps stay on your device until you clear them.

For company security reviews

RequirementStatus today
Map data residencyOn the user's device, in any region
Encryption at restProvided by the device (for example BitLocker or FileVault)
Company single sign-on (SAML / OpenID Connect)Not available yet
Admin console, audit logs, user provisioning (SCIM)Not available yet
SOC 2 / ISO 27001 certificationNot certified
Data processing agreementAvailable on request through Feedback
Accessibility conformanceSee the accessibility statement

For a questionnaire or a data processing agreement, send a request with the Feedback button and include a contact email.