Skip to main content

Privacy Policy

Plain-English, no dark patterns.

We wrote this in plain English on purpose. If anything here is unclear, message me on Threads and I'll explain.

What we collect

  • Account info: your email, the username you choose, and a hashed password.
  • Your saves: the places you save, the notes you write, ratings (disliked / meh / liked / loved), visited status, and the people you follow.
  • Product analytics: which pages were viewed and which product actions were taken — processed by PostHog in cookieless mode. When you are signed in, these events can be associated with your Cerca account so we can understand and improve product usage.
  • Technical basics: IP address and browser type, used to serve the app and keep it secure.

What we don't do

  • We don't sell your data. Ever.
  • We don't run third-party advertising trackers.
  • We don't load Meta, TikTok, X, or any other social-network pixel.
  • We don't read your contacts, calendar, or other apps.

Who can see your saves

Your saves are private to you by default. They become visible to other people only when:

  • You make your profile public — then anyone with the link can see your saved places.
  • You accept a follow request — that person can see your saves.

Want-to-go notes are private. Rating notes are public on your profile; avoid including personal information in them.

AI assistants you connect

When you connect an assistant such as ChatGPT or Claude and authorize it, Cerca sends the data requested by its tools to that assistant: your saved and rated places, notes, guides, taste profile, and other people's places you are allowed to see. With write access, the assistant can save, rate, update notes, remove places, import places, and create draft guides in your account when you ask. The assistant provider handles returned data under its own privacy policy.

Cerca receives the tool requests your assistant sends, including place names, locations, notes, and import links supplied in those requests. Cerca does not receive your full conversation. We record tool usage, errors, and timing for product analytics and operation of the service. Access tokens connect the assistant to your account; personal access tokens and OAuth access and refresh tokens are stored as hashes.

You can revoke a connection in Settings → AI assistants. Revoking it prevents further access through that connection; it does not delete data already returned to the assistant provider. Account data and deletion requests follow the retention and rights sections below.

Third parties that touch your data

  • Fly.io — hosts the app and the database. Data is stored in the United States.
  • Google Places API — when you search for a place, we query Google for the details (name, address, photo).
  • Mapbox — renders the map tiles you see.
  • PostHog — processes product-usage events for analytics. Cerca configures PostHog without analytics cookies.

If you choose to connect an AI assistant, its provider also receives the data returned through that connection, as described above.

Cookies

  • A session cookie, so you stay logged in.
  • A CSRF token cookie, so forms can't be forged.

No third-party ad cookies. No social-network tracking pixels. PostHog is configured in cookieless mode and does not set analytics cookies.

Your rights

You can ask us to:

  • Show you a copy of everything we have on you.
  • Give it to you in a portable format.
  • Delete your account and everything in it.

Message me on Threads for any of the above. I respond within seven days.

How long we keep your data

As long as your account is active. If you delete your account, we wipe your data within 30 days. Backups roll off within 60 days after that.

Kids

Cerca isn't for kids under 13. If you find out a kid under 13 has an account, message me on Threads and I'll delete it.

Changes to this policy

If we change this policy, we'll update the date below. If we make a material change (e.g. a new third party touches your data, or we change what we collect), we'll email everyone with an account.

Last updated: October 7, 2026

Questions? Message me on Threads.