popup is a map you explore. Exploring needs no account, there are no analytics on it, and your precise location never leaves your device. The popups we list do have an account — the second half of this page says exactly what that involves.
If you are exploring
Your location
When you ask popup to find where you are, your browser asks you for permission and hands the answer to the page. It is used there, to move the camera and to work out how far you are from things, and it is gone when you close the tab. Your coordinates are not stored and not sent anywhere.
To show you the real popups near you, the app asks our server which popups are out in the squares of map around where you are looking — squares about half a kilometre across, the same way the map tiles work. The square is sent; your position inside it is not. While the app is open, the live channel below is told the same squares, so a popup that packs up fades from your map at once. We do not keep a log of these requests, and the squares are not stored. Press P at any time and your position is snapped to a coarse grid as well.
You can take the permission back whenever you like, in your browser's site settings for popup.app. The map still works; it just starts where it always starts instead of where you are.
Popups you keep
Keeping a popup is remembered on your device, not on an account. While the app is open it tells our live channel the usernames you keep, so you hear the moment one of them pops up. That list, like the squares above, is held only while you are connected, is not stored, and is not tied to who you are; the only thing a popup can see is a count of how many open apps keep it right now.
Reporting a page or a picture
If you report a popup's page or one of its pictures, we receive which page or picture, the reason you picked, and your note if you wrote one. Nothing about you goes with it: no account, email or location. To stop floods of reports we count them per IP address, stored as a scrambled fingerprint and deleted within a day. We keep a report for a year after we have dealt with it, so we can see whether a popup keeps being reported.
What is kept on your device
popup uses your browser's own storage to remember a few things between visits, all of them on your device only:
- whether you want the readouts and the sound on;
- the popups you have chosen to keep;
- whether you have seen the entry card before.
None of it identifies you. Clearing site data for popup.app in your browser deletes all of it.
If you have a popup
Businesses join by invite or by asking us, and we check each one before it is listed. If you registered one, this is what we keep, who can see it, and for how long.
- Your email address — the one we sent your invite to, or the one you gave and confirmed. It is private. If you ask to be listed and never confirm it, we delete the request, email included, after an hour. We use it only to send you sign-in links and notices about your account (such as a sign-in from a new device), and it is never shown on the map, sold or shared.
- Your business name, username and what you sell — public: they are your page at popup.app/username and what explorers search for.
- Where you registered from — private. It is where the map starts your setup, and nobody else sees it.
- Where we can see you — if you gave us a link or an account when you registered, so we could check it's really you. Only we see it.
- Your bio and links — public, on your page.
-
Your pictures — public, on your page, served from
cdn.popup.app. When you add one, our server makes a new copy of it at a set size and throws away the file you sent. The copy carries none of the hidden details a phone adds to a photo — no GPS location, camera or date. A picture you remove from your page is deleted within an hour, and so is one you upload but never add. - How pictures are checked — every picture is checked for nudity, sex and violence before anyone else can see it. First on your own device, by a small model inside the app, so a picture it won't take never leaves your phone. Then on our server, by an AI model that Cloudflare runs for us, so no other company sees it. The server's check may refuse a picture, in which case it is not kept. Or it may hold one for a person at popup to look at, in which case only you and we can see it until we have. We keep what the check said about a picture for as long as we keep the picture, and a note that an upload was refused, without the picture.
- When you pop up — where you are standing, the street, your offer and how long you are out are public while you are out, and taken off the map the moment you pack up or your time runs out. The position we show is rounded to about 10 metres: close enough to find you, not your phone's exact fix. You are never out for more than 12 hours: if you forget to pack up, we do it for you when your time runs out. We keep a record of your nights (when, which street, the offer) so the app can show you your own history; it is not public, it never holds map coordinates, and the street is deleted after 30 days.
- Signing in — one cookie on api.popup.app that keeps you signed in. It cannot be read by the page, is used for nothing else, and ends after 30 days, or 7 days unused, or when you sign out. With it we keep a short device description such as "Safari on iPhone", so we can tell you about new sign-ins. We do not store your IP address. The one-time links we email you are stored only as a scrambled fingerprint, and expire within an hour.
- A record of account actions — your username, what happened (signed in, popped up, changed your page) and when. No email, IP address or device.
To stop abuse, we count requests per IP address and per email for sign-in links and registrations. Those counters are stored as scrambled fingerprints rather than the address itself, and are deleted within a day.
We keep your account for as long as you have a popup. Write to privacy@popup.app from your account's email and we will delete it and everything above; copies in our backups age out within 30 days.
When something breaks
If the app hits an error it didn't expect, it tells our server what broke: the error message, where in our code it happened, and which version of the app you have. The server adds a short device description such as "Safari on iPhone". It does not send the page's address, your location, your IP address or your account, and anything in the message that looks like an email address, a sign-in link or coordinates is removed before it is kept. Errors are grouped and counted, so we can fix them, and deleted 30 days after they last happened.
Cookies and tracking
If you are exploring, there are none. If you have a popup, there is the one sign-in cookie above, which is strictly necessary for your account to work. There are no advertising or analytics scripts, no fingerprinting, no third-party tags, no session recording, and no profile of anyone — which is also why you were not asked to accept anything on your way in.
Who else sees a request
popup is built on other companies' services. Each of them sees your IP address and what was asked for, as every server on the internet does, and each has its own privacy terms:
-
OpenFreeMap (
tiles.openfreemap.org) serves the map tiles. Which tiles you fetch indicates roughly what part of the world you are looking at. -
AWS Open Data (
s3.amazonaws.com) serves the terrain data, the same way. -
Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) serves the two typefaces. - Amazon Web Services (CloudFront and S3) serves the site itself. Access logging is off, so no record of your visit is written for us.
-
Cloudflare runs our server and database at
api.popup.app, stores popups' pictures, runs the AI model that checks them, and serves them fromcdn.popup.app. It also compares the pictures it serves against known images of child sexual abuse. When you register without an invite, its Turnstile check makes sure a person filled in the form. It answers for popup.app's domain names, and passes email sent to our@popup.appaddresses on to our inbox. We keep error logs only, not a log line for every request. - Resend sends our emails, so it handles the address and the content of each email we send.
- Stripe takes payment when a popup pays to be featured. It handles the card on its own page, and we pass it the popup's email for the receipt. We never see or keep card details. We keep a record of each payment (which popup, which night, the amount, and whether it was refunded) for our accounts.
If you tap directions on a place, that opens Google Maps, which is Google's site and not ours.
Popups on the map
Most of the popups standing in the world today are invented — sample businesses, made up to show what the map is for, and labelled as samples wherever they appear. Real popups are businesses we have checked, and what they say about themselves is theirs.
Children
popup is not directed at children under 13, and we do not knowingly collect anything from them.
Your rights, including in California
California's privacy law gives you the right to know what personal information a business has collected about you, to have it deleted, to correct it, and to opt out of its sale or sharing. If you are exploring, popup has collected nothing that identifies you. If you have a popup, what we hold is listed above: an identifier (your email), your business details, and location (where you registered from, and where you stand while you are out). None of it has been sold or shared for advertising, and it never will be. We do not offer financial incentives and we do not discriminate against anyone for exercising a privacy right.
The same goes for the equivalent rights elsewhere — access, deletion, correction, portability, objection. Write to us and we will answer.
Changes
This page changes when the app does, and the date at the top changes with it. The next substantial change will be the one that brings uploaded pictures and live location for popups; neither exists today.
Contact
privacy@popup.app for anything on this page, or security@popup.app to report a vulnerability.