Last updated: August 2026
AntiFreeze is built so that using it reveals as little about you as possible. There is no account, no sign-up, and nothing here asks who you are. Two goals shape every decision on this page: hold as little as possible about the people who use this, and still keep the map trustworthy by stopping anyone who tries to poison it. Those two pull against each other, and where they do, this policy tells you exactly where we drew the line and why. What follows is a plain description of every piece of data the app touches, who else can see it, and why each one exists — including the places where perfect privacy isn't possible, so you can judge the trade-offs yourself.
We never ask for your name, email address, phone number, postal address, or date of birth, and there is no account to create. You can install AntiFreeze, read the map, and report a sighting without ever telling us who you are. We cannot hand over information we never collected. That is the whole reason it is built this way.
Because there are no accounts, we recognize devices rather than people. Two identifiers are involved: • A random ID created on your device the first time you open the app. It is stored in your browser and is not derived from anything about you. • A device fingerprint, produced by ThumbmarkJS, which recognizes your device by its browser and hardware characteristics. The fingerprint exists for one reason. Without accounts, it is the only thing standing between the map and one person flooding it with fake sightings, and it is what makes a ban actually stick. ThumbmarkJS has confirmed to us that fingerprints are not shared, linked, or correlated across their other customers — your device's fingerprint here cannot be matched to your activity on any other site that uses their service. They do use sampled, anonymized data for their own quality assurance. Alongside each fingerprint we store the abuse signals that arrive with it — whether the connection looks like a bot, a VPN, a Tor exit node, or a datacenter, and how distinctive the device appears to be. We keep those to defend against flooding. They describe a connection, not a person, and they never change what you are allowed to see. These identifiers are pseudonymous, not anonymous. They hold no name, but they are stable over time, and we would rather say that plainly than claim a perfect anonymity no app can actually deliver.
Location is optional and stays off until you turn it on. You can use AntiFreeze with live location, with a manually typed address, or with neither. If you enable live location, we store a single latitude and longitude for your device. Each update overwrites the last one — there is no location history and no record of everywhere you have been. It decides which sightings appear in your feed (a 25-mile radius) and which alerts are worth sending you. If you type an address instead, it is looked up through our server rather than from your browser, so Google's address service receives the text of the address but never your IP address. The address you typed is remembered on your device, and stored on our side as that same single point. You can turn location off at any time in Settings.
A sighting is a public post. Its location, address, notes, and photos are visible to everyone using the app — that is what makes the map worth having. Please treat anything you write in the notes as public. What is not public is you. The public sightings feed never includes the ID of the device that reported a sighting. We keep that link internally for 72 hours so we can rate-limit and ban abusive reporters; after 72 hours it is erased from the live record, and from then on the app itself cannot tell which device reported it. Database backups are the one exception, and we explain that below rather than bury it. Every photo is re-encoded on our server before it is stored. That removes all embedded metadata — including the GPS coordinates, capture time, and camera model that phones write into image files. The photo that gets published contains the picture and nothing else.
Your IP address is never written to our application logs or our web server logs. Those logs show Cloudflare's addresses, not yours. Sighting coordinates and the addresses they resolve to are kept out of those logs as well. A sighting plainly stores its own location — that is the entire point of the map, and it is how we know who to alert — but there is no reason for that location to be copied into a log file on top of that, so it isn't. There is one place an IP is used, briefly. For roughly 2% of devices that cannot produce a fingerprint — usually because of a content blocker — our server converts the connecting IP into a one-way salted hash and uses that as a substitute device ID. The hash cannot be turned back into an IP address, and the address itself is never stored. We cannot claim your IP is invisible to everyone, because it isn't. Cloudflare sits in front of AntiFreeze and therefore sees the IP of every visitor. That is a trade we made on purpose: without a network edge absorbing attacks, an app like this one would be trivial to knock offline, and a map that is down protects nobody. We chose Cloudflare partly on their privacy record. They publish regular transparency reports covering government and law-enforcement demands, state that they do not sell personal data, and say they keep logs containing visitor IPs only for a limited period rather than indefinitely. We are enrolled in Project Galileo, the program through which they provide this protection free of charge to human-rights and public-interest projects. How they handle that data is governed by Cloudflare's own privacy policy, and we would rather send you to the source than paraphrase a company we do not control. ThumbmarkJS also sees your IP at the moment a fingerprint is created.
Notifications are off until you turn them on, and turning them on is the only way we ever receive a push subscription for your device. A subscription is an address at your browser vendor's push service — Apple, Google, or Mozilla, depending on the browser — together with the encryption keys that let only your device read our messages. We store it so we can send you alerts. Every notification is encrypted to your browser, so the push service delivers it without being able to read it. Turning alerts off in Settings stops the sending. Uninstalling the app or clearing site data invalidates the subscription entirely.
We run Umami, an open-source analytics tool, on our own server. No analytics company receives anything about you, because there is no analytics company involved. It records page views — which pages get opened and roughly how often — along with coarse technical details such as browser, device type, and operating system. The country and city it shows come from Cloudflare's edge headers, not from looking your IP address up, and we have checked the analytics database directly: no IP address is stored in it. The web server hosting it logs Cloudflare's addresses, not yours. One detail worth stating precisely rather than glossing over: to count a visit without using cookies, Umami turns your IP address into a salted hash and uses that as a session ID. The salt rotates every day, so the hash cannot be turned back into an address, and yesterday's visit cannot be linked to today's. It sets no cookies, builds no profile, and cannot follow you from one website to another.
AntiFreeze sets no cookies for ordinary users. Session cookies exist only for signing in to the admin and Watchdog panels, which virtually nobody uses. The app does keep a few values in your browser's local storage: your random device ID, your language, your last known coordinates, your default view, and whether you have finished setup. These stay on your device. Clearing your browser's site data erases them, which also detaches you from your previous device ID.
We would rather name these specifically than hide behind "trusted partners," so you can check each one yourself: • Cloudflare — sits in front of the app for DDoS protection (Project Galileo) and stores the photos you upload. Sees visitor IP addresses. • ThumbmarkJS — creates the device fingerprint. Sees device characteristics and your IP at that moment. • Google Maps Platform — address autocomplete and geocoding. Requested by our server, so Google sees the address text but not your IP. • OpenStreetMap / Nominatim — turns a sighting's coordinates into a street address. Also requested by our server. • CARTO and OpenStreetMap — supply the map tiles. These load directly in your browser, so unlike the others they can see your IP address and which part of the map you are looking at. • Apple, Google, and Mozilla push services — deliver notifications, encrypted, to your device. We do not sell your data, we do not share it for advertising, and there are no ads in this app.
Sightings are kept indefinitely, so the map keeps a history worth studying. The app itself only shows the last 48 hours. The reporter's device ID is stripped from each sighting after 72 hours, as described above. Your device record — its identifiers, your single stored location, your notification subscription, and your settings — stays until you ask us to remove it. To have it deleted, open Settings, copy the User ID shown there, and send it to us. That ID is how we find your row; it is the only thing we can look you up by, because we hold nothing else about you. Deleting your device record does not remove sightings you have already posted — after 72 hours there is nothing left connecting them to you. We also take periodic backups of the database, which is what stops a server failure from wiping the map. A backup is a snapshot of the database as it stood at that moment, so a copy taken while a sighting was still inside its 72-hour window holds the reporter link until that backup is rotated out and destroyed. The same applies to a device record you have asked us to delete. We point this out because it is the one place where “erased” means erased going forward rather than erased everywhere, and you deserve to hear that from us rather than assume otherwise.
A small number of trusted contributors have Watchdog accounts, which do use a username and password. For those accounts we store the username, a hashed password, a display name, and a default map area. None of this applies to ordinary use of the app. You never need an account to read the map, receive alerts, or report a sighting.
Traffic is encrypted in transit. Passwords, where they exist at all, are stored hashed and never in plain text. Access to the database is limited to the people who run the service. No system is perfectly secure, and we would be lying if we promised otherwise. What we can promise is that we have tried to hold as little as possible, so that a breach would expose as little as possible.
The app links out to donation pages, a merchandise store, legal resources, and similar sites. Once you follow one of those links you are on someone else's site, under their privacy policy rather than ours. We have no control over what they collect and cannot answer for it.
AntiFreeze is not directed at children under 13, and we do not knowingly collect information from them. Because we collect no names, emails, or ages, we usually have no way to tell. If you believe a child's information has reached us, contact us and we will remove it.
When the app changes what it collects, this page changes with it. The date at the top tells you when it was last revised. There is no mailing list to notify you with — that is rather the point — so we recommend checking back here after major updates.
If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us.
contact@antifreeze.app