Privacy
Last updated 2 August 2026
The short version
You can plan rides without an account, and everything you build stays in your browser. If you create an account, we store your email and the rides you save so they follow you across devices. We show no ads and sell nothing about you. We count page visits, without cookies and without anything that identifies you.
Planning without an account
Routes, stops, chats and settings live in your browser's own storage. We have no copy. Clearing your browser data deletes them, which is also why an account exists.
As you use the map, your browser talks directly to the services that power it, and they receive the technical data any web request carries, such as your IP address. These requests are how the product works, not tracking.
If you create an account
We store your email address, used only to sign you in with a code and for service notices. No passwords. We store the rides you save: their stops, names, options and the routed line, so your collection syncs between devices. A sign-in session records when it expires, not where you were: we do not keep your IP address or browser details against your account. Deleting your account (My account → Delete account, confirmed by a link we email you) removes all of this.
Shared routes
Publishing a share link stores a frozen copy of that route so everyone who opens the link sees the same ride and downloads the same GPX. Share pages are unlisted, never indexed, show the ride and never your name or email, and can be revoked at any time. A revoked link stops working.
The assistant
The assistant is not currently available. When it is, and when you use the chat, your messages and the route context needed to answer them are sent to an AI provider (Google, Anthropic or OpenAI, whichever is configured when it launches) to generate the reply. These providers do not use API data to train their models by default. Don't put anything in the chat you wouldn't want processed this way.
Services we rely on
A small set of providers runs the app. What each one receives:
- Mapbox renders the map and satellite imagery and powers the place search box. Your browser requests tiles and search results directly, so Mapbox receives your IP address and what you type in search.
- LocationIQ names places for stops. Your browser never contacts it: the request goes through our server, so LocationIQ sees our address and the coordinates, not yours.
- Our own routing server, in Canada, calculates routes and elevation from OpenStreetMap and NASA data. It receives the coordinates being routed, and nothing that identifies you.
- Our own tile server (on Cloudflare) serves the map imagery behind share pages and route videos. Like any image request, your browser sends it your IP address and which tiles it needs.
- Neon hosts the account database. Vercel hosts the app. Resend delivers sign-in codes to your email (processed in Japan).
- An AI provider (Google, Anthropic or OpenAI) would power the assistant, as described above. The assistant is not switched on today; this is here so the list is complete if it is.
What we don't do
No advertising, no selling or sharing of personal data for marketing, no tracking pixels, no cross-site tracking, no profiles of you built from your rides.
We do count page visits: no cookie, nothing that identifies you, nothing that follows you to other sites. A number, and the site that linked you here.
Deletion and your rights
You can delete your account yourself: My account → Delete account sends you a confirmation link, and opening it removes the account and everything stored under it, including your share links. You can also ask us to do it, and you can ask what we hold about you. Local, account-less data is under your control in your own browser.
Cartorider is operated by Javier Alvear in New South Wales, Australia. Ask us anything, including to delete your account, at hello@cartorider.com.