mapily
Back to home

Privacy Policy

Last updated: 25 August 2026

Mapily turns the places in a creator's posts into a map their audience can explore. This policy explains what we do with personal information, whether you run a map or you are simply looking at one.

  • Who we are
  • Who this applies to
  • What we collect
  • Why, and our legal basis
  • What becomes public
  • Who we share it with
  • International transfers
  • How long we keep it
  • Cookies and analytics
  • Security
  • Your rights
  • Children
  • Changes
  • Contact

Who we are

Mapily is a product of Akili Tech Labs Ltd (akililabs.org), a company registered in England and Wales, company number 16370732. In this policy "Mapily", "we" and "us" mean Akili Tech Labs Ltd. Akili Tech Labs Ltd is the data controller for the personal information described here.

If you have a question about this policy, or want to exercise any of the rights below, email hello@mapily.app.

Who this applies to

Three different people meet Mapily, and we handle their information differently:

  • Creators. You connect a public Instagram or TikTok account and we build a map from posts you have already published.
  • Map visitors. You follow a creator's link and browse their map. You do not need an account and we do not ask you for anything.
  • Website visitors. You read mapily.app, and perhaps ask to join.

What we collect

If you sign up as a creator

Your name, email address, the platform you post on, your handle, and anything you choose to write in the free-text box on the form. Later, the account details and any settings and notes you add to your map.

Content we read from your public posts

Once you connect an account, we retrieve posts that are already public on it and read them to find the places you have named. That means captions, tags, hashtags, text shown on screen in images and video, spoken audio, post links and dates, and your public profile name and picture. We do not access private accounts, private messages, follower lists, or anything else behind a login.

If a post mentions a person rather than a business, that mention is processed in the same pass. We only ever keep the places, never the people.

If you are viewing a creator's map

Nothing that identifies you. There is no account, no sign-in and no profile. Our servers keep short-lived request logs, including your IP address, to keep the service up and to stop abuse.

If you tap Near me, your browser asks your permission and then gives your approximate location to the page so it can sort places by distance. That happens entirely on your device. Your location is never sent to us and we never store it.

If you use the website

Short-lived request logs as above. We record the IP address of anyone submitting the join form for one hour, so that a single source cannot flood it. We do not keep it alongside your submission.

Why we use it, and our legal basis

Building and hosting your map
Performance of our contract with you
Reading your public posts to find places
Performance of our contract with you
Answering your questions and support
Our legitimate interest in running the service
Keeping the service secure and preventing abuse
Our legitimate interest in protecting the service
Understanding which features are used, in aggregate
Our legitimate interest in improving the product
Sending you product or marketing email
Your consent, withdrawable at any time
Meeting legal and accounting obligations
Compliance with a legal obligation

We do not sell personal information, and we do not use it to build advertising profiles or share it with advertisers.

What becomes public

A map is private until you publish it. When you do, the map page shows your handle, your profile picture, the places you kept, any notes you wrote, and links back to the posts each place came from. Anyone with the link can see it, and search engines may index it.

You choose what goes on the map. You can remove a place, unpublish the map, or delete it outright at any time, and the public page stops working. Copies already cached by search engines or saved by other people are outside our control.

Who we share it with

We do not sell personal information, and we do not share it with advertisers.

We use a small number of suppliers to run Mapily. They act only on our instructions, may use what we send them solely to provide their service to us, and are bound by contract to protect it. They fall into these categories:

  • Cloud hosting and infrastructure, which runs the website, the application and our databases.
  • Content processing, including machine learning providers, which read the captions, images, on-screen text and audio in your posts to identify the places you have named.
  • Mapping, geocoding and location data providers, which match a place name to a real location and supply the map imagery you see. Loading a map necessarily sends your IP address to whoever serves the map tiles.
  • Content delivery networks and font providers, which serve the code and typeface the pages need. These also receive your IP address, because your browser has to request those files from them.
  • Communication and messaging tools, which we use to reach you and to be notified when someone asks to join.
  • Business tools such as payment processing, accounting and customer support.

You have the right to know which specific companies these are. Email hello@mapily.app and we will tell you.

We may also disclose information where the law requires it, to establish or defend legal claims, or to protect someone's safety. If Mapily is ever sold or merged, information may transfer with the business, and we will tell you before it does.

International transfers

Some of the suppliers above are based outside the UK and the European Economic Area, mainly in the United States. Where information is transferred outside the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on standard contractual clauses or the UK International Data Transfer Addendum, together with appropriate technical safeguards. You can ask us for details.

How long we keep it

Your account and your map
While your account is open, then up to 12 months after you close it
Post content we processed
While it supports a place on your map. Deleted with the map
Sign-up and enquiry details
Up to 24 months from your last contact with us
Marketing consent records
Until you withdraw consent, plus a record that you did
Analytics measurements
Aggregated. No identifiers are stored against them
Server request logs
A short rolling window, typically days
Rate-limiting IP records
One hour, in memory only
Records we must keep by law
For the period the relevant law requires

Cookies and analytics

Mapily does not set cookies. There is no advertising pixel, no session tracking and no fingerprinting, on the website or on creators' map pages, which is why you are not being asked to accept anything.

We do measure how the site is used, because we need to know which pages people find useful and whether the service works. We use a privacy-focused analytics provider chosen specifically because it sets no cookies, does not create a profile of you, and cannot follow you to any other website. It records things like the page you viewed, the site that referred you, your country, and whether you are on a phone or a desktop. It does not record your name, your email address or your precise location, and we cannot use it to identify you.

We rely on our legitimate interest in understanding and improving the service. If your browser sends a Do Not Track or Global Privacy Control signal, we honour it and record nothing.

The third parties that serve map imagery, the typeface and the map library necessarily receive your IP address, because your browser has to ask them for those files. We do not ask them to identify you, and they do not report back to us about you.

If we ever introduce cookies or advertising technology, we will update this policy and ask for your consent first.

Security

Traffic is encrypted in transit. Access to production systems is limited to people who need it, credentials are held in a secrets manager rather than in our code, and we keep our dependencies current. No service can promise perfect security, but if a breach affects your rights we will tell you and the Information Commissioner's Office as the law requires.

Your rights

If you are in the UK or the EEA you have the right to:

  • ask what personal information we hold about you, and get a copy;
  • have inaccurate information corrected;
  • have your information deleted;
  • restrict or object to how we use it, including profiling;
  • receive it in a portable, machine-readable format;
  • withdraw consent at any time, without affecting what we did beforehand.

Email hello@mapily.app and we will respond within one month. There is no charge unless a request is clearly unfounded or excessive.

If you think we have handled your information badly, please tell us first so we can put it right. You can also complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.

Children

Mapily is not for people under 16. We do not knowingly collect information from anyone under 16, and if we find that we have, we will delete it. If you believe a child has given us information, email us and we will act on it.

Changes to this policy

We update this policy when what we do changes. The date at the top always shows the current version. If a change materially affects you, we will tell account holders by email before it takes effect.

Contact

Email hello@mapily.app for anything relating to privacy, your information, or this policy.

mapily
Privacy Policy Terms of Service