Places legal
Privacy Statement
Places is a location journal with local-only and iCloud modes. This statement explains what the app and this website process, why, where information is stored, what other people may see, and the choices available to you.
Complete Places and original photos synchronize through your private CloudKit database. To support the Feed and other social features, Places also automatically creates reduced public previews after a successful private sync. Those previews exclude exact coordinates, street and postal addresses, private notes, full visit dates, and original-resolution photos.
1. Account modes and profiles
You can use Places in local-only mode or iCloud mode. Local-only mode keeps your profile and journal on that device and does not create an iCloud profile. Synchronization, social features, and shared Trips are unavailable in that mode.
In iCloud mode, Places receives a pseudonymous CloudKit account record identifier so it can associate data with the correct iCloud account. We do not receive your Apple ID password. The current app does not ask for your Apple ID email address or phone number.
You may provide a display name, biography, website, profile photo, notification preferences, Hide from Discovery setting, and related profile statistics. Profile, relationship, and compatibility records are stored in the app's public CloudKit database so social features can work. Legacy profile records may also retain information entered in older versions, such as email, phone, registration time, device UUID values, and older relationship or Place-list fields, although the current app does not request or use those contact fields.
2. Information Places processes
Places and photos
A saved Place can include its name, category, notes, full visit date, precise latitude and longitude, street, city, region, country, country code, postal code, up to 20 photos, photo order and capture dates, and the identifiers and timestamps needed to save and synchronize it.
In iCloud mode, a reduced public preview can include the Place name, visit month represented by its first day, coordinates rounded to about 0.1 degree, city or region, country and country code, category, owner name and identifier, update metadata, and a small thumbnail derived from the cover photo. It does not include the precise coordinate, street or postal code, private notes, full visit date, or original photo.
Trips and collaboration
A Trip can include a title, status, start and end dates, summary, cover reference, participant and access identifiers, ordered stops, saved Place references or copied snapshots, stop names, dates, status, notes, coordinates, addresses, and timestamps. Private Trips live locally and, in iCloud mode, in the owner's private CloudKit database.
When an owner invites participants or enables link sharing, Apple CloudKit places the shared Trip hierarchy in eligible participants' shared databases. The current sharing flow grants accepted participants editing access to that Trip. Sharing a Trip does not by itself share unrelated Places, private notes outside the Trip, or original Place photos.
Social relationships, blocks, and reports
Places processes follower and following identifiers and timestamps in public CloudKit records. Blocking attempts to remove both follow directions and hides that account from social surfaces in the app. Blocked-account identifiers, display names, dates, mutation metadata, and reset state are stored locally and mirrored through Apple's private iCloud key-value storage.
A safety report can contain the reporter, target, content and owner identifiers, content type, reason, optional details, status, and timestamp. Reports use CloudKit permissions intended to limit app access to their creator; the developer can review them through CloudKit administration tools to enforce safety rules.
Photo-library workflows
The system photo picker lets you choose particular images without granting broad library access. Temporary selection copies and embedded metadata are processed locally and cleaned up through the app's completion, cancellation, replacement, and error paths.
Build Places from Photo History requests full or limited Photos authorization, which iOS presents as read/write access although Places uses it to read eligible assets. The app can process asset identifiers, capture dates, locations, dimensions, favorite and hidden status, and whether an item is a screenshot, panorama, Live Photo, or burst. Hidden images are excluded, and filters let you reduce what is considered.
Grouping happens on your device. Suggestion coordinates are sent to Apple's geocoding service before approval so Places can propose recognizable names and addresses. Suggestions, completed asset identifiers, filters, and progress can be kept in protected local storage to resume work and avoid duplicates. Only content you approve becomes a saved Place and, in iCloud mode, uploads as that Place. Images without usable dates or locations are skipped from automatic creation. Apple Photos may download an original stored in iCloud Photos when an import needs it.
Location, maps, and search
Places requests When In Use location permission to center the map, show nearby content, and use your current location when creating or editing a Place. It does not request continuous background location. A device location is transient unless you choose to save it in a Place or Trip. Coordinates and search text can be processed by Apple Maps, search, and geocoding services.
Notifications, diagnostics, and feedback
Notification preferences can cover follower activity, new Places from people you follow, shared Trip activity, upcoming Trip reminders, and recap reminders with selected timing. Places stores these preferences and CloudKit subscription state; timestamped preference snapshots can sync through private iCloud key-value storage. Pending local reminders contain the Trip identifier, title, reminder type, and scheduled time. Apple Push Notification service processes technical delivery information.
Apple MetricKit supplies performance and diagnostic payloads such as launch, hang, energy, and crash information. Places keeps a bounded local set—up to 200 fixed-event breadcrumbs and up to 12 payload files totaling no more than 5 MiB. Its own breadcrumbs do not include names, notes, addresses, coordinates, photos, or account identifiers, and diagnostics are not sent to us automatically.
Help and Feedback lets you enter a category, title, and description and optionally preview a privacy-safe technical summary containing app and OS versions, locale, time zone, account mode, aggregate sync counts, and fixed diagnostic events. You choose the destination through the system share sheet.
Local settings and technical state
Places stores settings such as Library sorting and map clustering, caches, synchronization and outbox state, notification state, import checkpoints, migration inventories and fingerprints, temporary picker and export files, deletion recovery state, and other identifiers required to safely operate the app.
3. How information is used
Places uses information to:
- create and maintain profiles, journals, Places, photos, and Trips;
- synchronize data across your devices through iCloud;
- generate photo suggestions, propose names, and prevent duplicate imports;
- provide maps, search, feeds, follows, invitations, collaboration, notifications, sharing, and exports;
- create reduced social previews without publishing complete Place records;
- recover interrupted synchronization and legacy migration;
- support blocking, reporting, moderation, reliability, and user-requested help; and
- comply with law and protect users, rights, and the service.
Places does not use personal information for targeted advertising, third-party marketing, credit decisions, or data-broker profiling. The current app does not send your journal or photo library to an external artificial-intelligence service.
4. Storage and visibility
On your device
Places keeps a local database, imported images, caches, settings, import and synchronization state, diagnostics, temporary files, and recovery markers. Selected sensitive files use iOS data protection. Removing the app generally removes its local container but does not delete iCloud data or copies you exported or shared.
Apple iCloud and CloudKit
- Private database: complete Places, original Place photos, private Trips and stops, migration state, and Trip-access metadata.
- Shared database: Trip content an owner explicitly shares with participants or eligible link recipients.
- Public database: profiles and profile photos, relationship and revocation records, reduced Place previews and thumbnails, legacy compatibility fields, and safety reports with more restrictive intended permissions.
- Private iCloud key-value storage: block state and timestamped notification-preference snapshots.
Apple provides iCloud, CloudKit, Photos, Maps, geocoding, MetricKit, push notifications, and system sharing and may process technical information needed to provide and secure those services. See Apple's Privacy Policy.
What other people can see
Other people can see information made available through public profile, relationship, and reduced preview records. Hide from Discovery removes a profile from Find People; it does not remove existing followers, make public records confidential, or delete previews. Blocking changes what a specific account appears to you in the app.
Trip participants and eligible link recipients can see and edit content in the shared Trip. Recipients may keep screenshots, exports, or other copies outside Places.
Legacy records
Versions released before the private-storage migration used public CloudKit records for complete Places and original photos. Verified legacy copies can remain during migration. Delete Legacy Data permanently removes verified old public Places and photos without deleting the current private library.
5. When information is disclosed
Information is disclosed only as needed to:
- use the Apple services described above;
- show public social records or a Trip you explicitly share to other Places users;
- send content to a destination you choose through a share sheet, CloudKit link, or ZIP export;
- investigate reports, enforce terms, protect safety or rights, prevent abuse, or comply with valid legal process; or
- transfer responsibility for Places in a merger, acquisition, reorganization, or asset sale, subject to this statement and applicable law.
We do not sell personal information or disclose it to advertising networks, data brokers, or third-party analytics SDKs.
6. Retention
Data generally remains until you delete the relevant item, reset a workflow, use Delete All User Data, uninstall local-only data, or the operating system prunes a cache. Safety reports remain while reasonably necessary to review and act on the report, prevent repeat abuse, maintain an appropriate audit record, resolve a dispute, or meet legal obligations.
Leaving a Trip owned by someone else removes your participation, not the owner's Trip. Deleting a Trip you own removes its shared CloudKit hierarchy, subject to copies recipients already kept. Apple may retain backups, security logs, service records, or legal records under its own practices.
7. Your choices, export, and deletion
- Grant, limit, or revoke Photos and Location access in iOS or iPadOS Settings.
- Change notification categories in Places or all notification permission in System Settings.
- Use Hide from Discovery, blocking controls, Trip sharing controls, and Photo History filters or Start Over.
- Edit or delete individual profile fields, Places, photos, and Trips in the app.
Your Data can prepare a local journal ZIP containing profile and notification preferences, account mode, complete owned Places, Place-photo records, locally available images, precise locations, addresses, notes, dates, and identifiers. The current journal export does not include Trips and stops, relationships, blocks, reports, import and migration history, or diagnostics.
Delete All User Data removes eligible local data, private CloudKit zones, public previews and profile, owned Trip shares, shared-Trip participation, outgoing relationships, submitted reports, subscriptions, legacy records, active block data, notification snapshots, import state, diagnostics, and caches. It requires the owning iCloud account and a network connection and can be retried if interrupted.
Incoming follower records created by other users can remain in public CloudKit; the app creates revocation records so those relationships no longer appear. Public records whose creator or required ownership fields cannot be authenticated can also remain. A minimal block reset marker and protected local account-deletion tombstone can remain to prevent deleted state from reappearing or automatic re-onboarding. Deletion cannot remove your Apple ID, recipient copies, exports, or Apple service records.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing, or obtain a portable copy. Contact chen@stpdchen.com for requests not available in the app. We may need to verify that a request concerns your account. California residents may also request applicable categories, specific pieces, correction, deletion, and disclosure information. We do not sell personal information or share it for cross-context behavioral advertising.
8. Security and international processing
Places uses measures intended to protect information, including CloudKit access controls, private and shared databases, iOS data protection for selected local files, bounded caches, and ownership checks for destructive operations. No storage or transmission method is perfectly secure. Protect your device and iCloud account and use care when sharing links or exports.
Apple and the developer may process information outside your country. Where required, processing and transfers use protections recognized by applicable law. Apple's processing is also governed by its service terms and privacy commitments.
9. Children's privacy
Places is a general-audience location journal and is not designed for children under 13. We do not knowingly request a child's birth date or parental information. Contact us if you believe a child supplied personal information without legally required authorization.
10. This website
This product website has no account, contact form, advertising, behavioral tracking, or app-specific analytics cookies. Its hosting infrastructure may process ordinary request information—such as IP address, browser or device information, timestamps, and security logs—to deliver, operate, and protect the site. If website practices change, this statement will be updated first.
11. Changes and contact
We may update this statement when Places, its data practices, or legal requirements change. The Last updated date identifies the current version. When required, we will provide additional notice or request consent before a materially different use begins.
For privacy questions, rights requests, or complaints, email chen@stpdchen.com. Please do not email passwords, full exports, private photos, or precise home addresses unless specifically necessary to resolve your request.