1. Who We Are
Ciss AI ("we", "us", "our") operates the real-time location sharing platform at cissai.com and the anonymous map at maps.cissai.com. For questions about this policy, contact us at [email protected].
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- •Email address (used for authentication and transactional emails only)
- •Display name (shown on your map marker and profile)
- •Avatar image (optional, uploaded by you and stored on Cloudflare R2)
- •OAuth provider identity tokens when you sign in with Google
- •Account creation date and email verification status
- •Visibility preference (all, friends only, or hidden)
- •Friends list (user IDs of accepted friend connections)
2.2 Location Data
When you enable location sharing, your browser sends GPS coordinates (latitude and longitude) to our servers. We collect:
- •Current latitude and longitude (updated every 30–45 seconds depending on plan)
- •Timestamp of the last location update
- •Your display name and avatar URL, stored alongside your coordinates so other users can identify your marker
- •Your visibility state (all, friends only, or hidden) — determines who sees your location
2.3 Anonymous Mode
Users of maps.cissai.com do not provide any personal information. A random temporary identity is assigned for the session. No data is written to a persistent database — location is held only in server memory and is erased when you leave the page.
2.4 Chat Messages
Chat messages sent on the map are stored temporarily in our database and deleted when you disconnect or within the time limit for your plan. Free-tier messages are not persisted across sessions.
2.5 Usage and Technical Data
We may automatically collect:
- •Browser type and version
- •Operating system
- •IP address (used for abuse prevention, not stored long-term)
- •Pages visited and time spent (via Vercel Analytics — anonymized)
- •Error logs for debugging
3. How We Use Your Information
- •Providing the Service — displaying your location marker and avatar to other users on the map
- •Authentication — verifying your identity when you log in
- •Communication — sending transactional emails (email verification, password reset) via our SMTP provider
- •Security — detecting and preventing abuse, unauthorized access, and Terms violations
- •Service improvement — understanding aggregate usage patterns to improve performance and features
- •Legal compliance — meeting obligations under applicable law
We do not use your data for behavioural advertising, user profiling, or sale to third parties.
4. Data Storage and Security
4.1 Infrastructure
Your data is stored and processed using the following providers:
- •Supabase (Mumbai, India) — PostgreSQL database, authentication, and realtime presence
- •Cloudflare R2 — avatar image storage, served via cdn.cissai.com
- •Vercel — Next.js application hosting and serverless functions
- •Resend — transactional email delivery (welcome emails, notifications)
4.2 Security Measures
- •All data in transit is encrypted using TLS 1.2 or higher
- •Passwords are hashed using bcrypt via Supabase Auth — we never store plain-text passwords
- •Database access is protected by Row-Level Security (RLS) policies
- •Service role keys are never exposed to the client
- •Avatar files use per-user fixed filenames — no public directory listing
5. Data Sharing
We share your data only in these limited circumstances:
- •Other users — your display name, avatar, and current location are visible according to your visibility setting: to all users, friends only, or no one (hidden)
- •Infrastructure providers — Supabase, Cloudflare, and Vercel process data as part of service delivery under their respective data processing agreements
- •Legal requirements — we may disclose information if required by law, court order, or to protect the safety of users or the public
We do not share data with advertisers, data brokers, marketing platforms, or analytics companies beyond the anonymized Vercel Analytics described above.
6. Cookies and Local Storage
Ciss AI uses HTTP cookies solely for authentication session management (set by Supabase Auth). We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie consent banner is required because we use only strictly necessary cookies.
7. Your Rights
You have the right to:
- •Access — request a copy of the personal data we hold about you
- •Correction — update your username, avatar, or email from your Dashboard
- •Deletion — delete your account at any time from the Dashboard; this permanently removes your profile, avatar from R2, and all associated data
- •Portability — request an export of your account data
- •Opt-out of location sharing — toggle visibility off at any time; your coordinates are deleted immediately
To exercise any of these rights, contact us at [email protected].
8. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it promptly.
9. Third-Party Links
The Service may contain links to third-party websites (e.g., Facebook marketplace listings via NPC markers). We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date at the top of this page. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy inquiries, data requests, or concerns, contact us at: [email protected] or via X @cissai8.