Privacy policy
Last updated: 19 August 2026. This policy describes how DeFlock handles personal data. We aim to meet GDPR and CCPA-style rights even when we operate for a U.S. audience.
What we collect
- Email (stored encrypted; a one-way HMAC is used to look up the account)
- Password hash (bcrypt)
- Optional phone number if you choose SMS verification (encrypted)
- Browser fingerprint hash, recent IP history, and user-agent hash — used only to detect duplicate accounts, bots, and ban evasion
- Session records in the database
- Camera reports and verifications you submit, including coordinates and photos at that moment
- Coarse “presence cells” (about 500 meters) while the map is open, without your user id
What we do not do
We do not sell personal data. We do not store live GPS tracks. We do not collect license plate numbers. We do not run advertising profiles.
Fingerprinting
A script in your browser builds a hash from canvas and similar signals. We store the hash, not a marketing profile. It exists so that clearing cookies is not enough to mass-create accounts after a ban. You can read this policy and the disclaimer before registering.
Legal process
We will comply with lawful subpoenas and court orders. We will not volunteer extra data. IP addresses in audit logs are stored in binary form.
Your rights
You may request access or deletion from your account page (GDPR-style request). We may retain a minimal record of the request and of bans needed to stop abuse. California residents may request information about categories of data collected; we do not sell personal information.
Cookies
We use a single httpOnly session cookie to keep you signed in. It is not a third-party ad cookie.
Processors
Optional: Cloudflare Turnstile (captcha), your host’s email/SMTP, Twilio if the operator enabled SMS. Map tiles may be loaded from OpenStreetMap or another tile URL the operator configured.