Privacy
Draft privacy disclosure for the current Litterbugs product model. It explains the data boundaries in the repository while final legal purposes, rights language, retention periods, and contact details remain under review.
Data the product is designed to use
The launch data model is limited to information needed for product operation, safety, payment, fraud prevention, legal obligations, and support. It includes:
- Account, authentication, adult-eligibility, profile, notification, privacy-preference, and legal-acceptance records.
- Report titles, descriptions, approximate public areas, restricted exact locations, safety answers, property authorization, and report history.
- Private report and cleanup media, approved public derivatives, media metadata needed for validation, and moderation or privacy findings.
- Funding, contribution, claim, evidence, review, receipt, refund, dispute, transfer, payout, audit, support, and incident records.
- Restricted device and push-installation data needed for native notifications and security operations.
Location and media privacy
Visitors and ordinary authenticated users receive server-generated approximate report geometry. Exact address or coordinates are restricted to the report creator, an eligible claimant after successful claim acceptance, and properly authorized operational actors with a documented need.
Raw uploads use private storage and short-lived access. Public display uses approved derivatives that can remove metadata and blur, crop, or mask faces, children, license plates, house numbers, documents, and other identifiers. Exact coordinates and raw evidence are not public map, notification, or ordinary analytics data.
Payments and AI processing
Payment-provider onboarding is intended to keep sensitive bank and tax identity with the payment provider whenever possible. Litterbugs records the financial, receipt, refund, dispute, ledger, and reconciliation information needed to operate the funding and payout model, including the disclosed 10% administration/platform fee.
The owner-approved AI model is minimized to named tasks such as safety, duplicate, privacy, and cleanup-evidence review. Payment credentials, bank details, full tax identity, authentication secrets, unrelated messages, and unrelated account history are excluded. AI output is restricted operational data and cannot directly change authoritative payment or legal state.
Analytics, cookies, and consent
Essential security, authentication, payment, and core-service storage is necessary for the product to operate. Nonessential analytics, advertising, session recording, and personalization are intended to depend on the applicable consent policy and jurisdiction.
The launch architecture calls for PostHog product analytics and Sentry error/performance monitoring. Sensitive locations, raw photos, payment details, legal identity, safety incidents, private messages, and sensitive form content must stay out of ordinary analytics. Session recording must exclude or mask forms, payment surfaces, photos, exact map coordinates, and private dashboards.
Retention, legal holds, and public history
Retention is designed around configurable classes rather than one universal duration. Ordinary evidence can be deleted or archived after final resolution when fraud, dispute, insurance, safety, and legal needs permit. Financial, tax, refund, transfer, ledger, audit, disputed, incident, and legally held records may need longer preservation.
Verified public cleanup history may remain as anonymized civic history. Precise location evidence is not retained indefinitely without a continuing purpose. Legal holds override ordinary deletion and must be scoped, recorded, reviewed, and released.
Export, deletion, and privacy controls
Signed-in users can use the account privacy page to request a portable export covering the supported profile, reports, claims, contributions, payouts, preferences, and legal-acceptance records. The same page provides the account-deletion request entry point.
Deletion is designed to remove or anonymize public identity, revoke sessions, stop marketing, disable the account, and schedule deletion of data that is not required for finance, safety, fraud, contracts, disputes, legal holds, or public-history integrity. The product does not promise a universal deletion timeline.
Draft status and privacy requests
This page is not a final privacy policy, does not state an effective date, and does not create legal acceptance. Final purposes, rights language, lawful-basis wording, retention periods, jurisdiction coverage, and privacy contact details require external legal review and owner-approved provisioning.
Use the account privacy entry point for supported export and deletion requests. Do not put exact locations, raw evidence, credentials, payment details, or legal identity into an unapproved support channel.
