Last updated: 2026-07-31

App Store Privacy Policy

FindPlayPlace helps parents find safe places nearby for their children to visit. This page explains what the app collects, what we store, and what we do not. We keep it plain so you can decide quickly whether the app fits your family.

Most of the app needs no account: you can browse the map and search for places without ever signing in. Contributing anything — telling us whether a place has a playground, adding a place, writing a review, or posting a photo — uses Sign in with Apple. This page covers what we handle both when you are just browsing and when you contribute.

We do not sell data. We do not run ad networks. We do not build a profile of you. When something is uncertain, we say so.

Location

The iOS app asks for "While Using the App" location access (the iOS prompt backed by NSLocationWhenInUseUsageDescription). We use your location to find places near you.

Location is only read while the app is open and visible. We do not track location in the background. We do not collect location while the app is closed or suspended.

Your coordinates stay on your device. We do not store your location on our servers. The app uses your location locally to ask our backend "what places are near these coordinates?" — we receive that query, return the matching places, and keep no record tying the query back to you.

Signing In with Apple

You do not need an account to browse the map or search for places. You do need one to contribute anything — to tell us whether a place has (or no longer has) a playground, add a place, write a review, post a photo, tag an amenity, or save bookmarks. That account is created with Sign in with Apple, and it is the only sign-in we offer. We require it for contributions so that every submission is tied to an accountable identity, which is what lets us enforce our safety rules and keep banned users out. Browsing stays open to everyone, with no login.

When you sign in, Apple gives us a stable identifier for your account. If you choose to share them, we may also receive your name and email — Apple lets you hide or relay your email, and that choice is yours. We store the identifier, whatever name or email you shared, and an encrypted copy of the token Apple gives us. We keep that token for one reason: so that if you delete your account, we can tell Apple to revoke the connection. We never post anything to your Apple account, and we never receive your Apple password.

Content You Contribute

When you are signed in, the things you add — places, reviews, photos, amenity tags, edits, and reports about whether a place has a playground — are stored on our servers and linked to your account, so we can display them, let you manage them, and apply our safety rules. Bookmarks and folders you create are stored the same way and are private to you. Public listings show only content that has passed review; content that is pending, reported, or removed is not shown to other users.

Photos are stored on Vercel Blob at a random path like <random-uuid>.<ext>; the file name reveals nothing about you, though the photo is associated with your account internally so you and our moderators can manage it. Free-text you write — a note or a review — is checked before we save it, and anything that looks like an email address or a phone number is rejected rather than stored, so contact details do not end up in a public-feeling field by accident.

You can block another user to hide their content from your view. Blocks are private — the other person is not notified. You can also report content, which hides it from public view immediately, pending review by our team.

How We Screen Contributed Content

We screen contributed content for safety before it is published, and that screening touches your data in specific, limited ways worth spelling out here.

Text you submit — a place name, a note, a review — is sent to an automated safety screen (run through the Vercel AI Gateway) to judge whether it is suitable for a family app. Only the text itself is sent. Your name, email, account identifier, and IP address are never part of that check.

Photos are handled with extra care. Before a photo ever leaves your phone, the app automatically obfuscates the faces it can detect, so what we receive is already redacted wherever detection succeeded. Detection is best-effort and can miss faces, so we encourage you to blur any others yourself before posting; by posting a photo that shows faces, you take responsibility for sharing them. The photo — and only the photo, with no identifier attached — is then sent to the automated safety screen. A photo that does not clearly pass is not stored.

Third-Party Services

A few outside services help the app work. Here is exactly what each one sees:

Observability and Error Reporting

To keep the app working, we use two services that help us notice when something is broken: Sentry for crash and error reporting, and Axiom for structured logging on the server.

Per our internal security policy, we do not send personal information to either service. That means no emails, no IP addresses, no full names, no auth tokens, and no photo bytes — not in error reports, not in stack traces, not in log lines. Our code sanitizes these payloads before they leave the app or the server.

Sentry session replay, when it is enabled, masks all text inputs and report photos by default. If a replay is recorded, what appears in it is a blurred-out version of the screen — your typing and your photos are not visible.

Child Safety and CSAM Detection

Photos submitted to FindPlayPlace by signed-in users are screened for child sexual abuse material (CSAM). If content is identified as apparent CSAM, we are required by U.S. federal law (18 U.S.C. §2258A) to preserve it and report it to the National Center for Missing & Exploited Children (NCMEC). In that case — and only in that case — we preserve the image, your account identifier, your IP address, your device's user agent, and the time of upload in an isolated, secured evidence store, and we provide that information to NCMEC and to law enforcement. This evidence data is kept separate from the app's normal operation, is never used for analytics or advertising, and is retained only as long as the law requires before secure deletion. This is a distinct, legally-mandated process, applied only to photos and only in this narrow, legally-defined case — it is not part of the app's ordinary handling of your data.

Deleting Your Account

If you signed in, you can delete your account from within the app. When you do, we tell Apple to revoke the sign-in connection and we remove your profile. Content you contributed — places, reviews, photos, amenity tags, and edits — is not deleted with you; instead we sever its link to you so it survives anonymized, with no way to attribute it back. Personal-only data, such as your bookmarks, folders, and blocks, is deleted. Purchase records are kept as required for accounting, with your account identifier stripped out. The one exception is content preserved under the child-safety law described above, which we are legally required to retain.

Your Choices

You can revoke location access at any time in iOS Settings → Privacy & Security → Location Services → FindPlayPlace. The app will still open and show a map, you will just need to pan to find a neighborhood.

You can use the app fully without ever contributing — browsing and searching need no account. Signing in is only needed to contribute (adding a place, reporting a playground, writing a review, or posting a photo), and even then a review or report never requires attaching a photo. You can delete your account whenever you like, as described above.

Quebec and Canada

For users in Quebec, Candace Henson (Noeta Labs, LLC) is our designated privacy officer under Quebec's Act respecting the protection of personal information in the private sector (Law 25). You can reach the privacy officer at the Contact address below.

If an incident affecting your personal information carries a risk of serious injury, we will notify Quebec's Commission d'accès à l'information and you, without undue delay. We keep a confidentiality-incident register for every incident, regardless of severity.

Our infrastructure is hosted in the United States (see Third-Party Services and Observability above), so using the app involves transferring your information outside Quebec. We only work with established providers under their own data-processing terms, and we send them the minimum data described throughout this page — never more than the service needs to do its job.

Contact

Questions about this policy or about how the app handles your information — including Quebec privacy-officer inquiries? Reach out at privacy@findplayplace.app.

Changes to This Policy

If we make material changes to this policy, we will reflect them by updating the Last updated line at the top of this page. We will not silently change what the app does with your information — if the answer to "what does FindPlayPlace collect?" changes, this page changes too, and the date moves with it.