Everything your IT security team needs to know before approving Mapsurvey
for institutional use.
Data Privacy (GDPR)
Survey respondents stay anonymous: no account, no name, no email. Below is the full list of what is recorded when someone answers a survey — including the technical details most vendors leave out.
No login required for survey respondents — anyone with the link can participate
No identity — responses carry no name, email, account or persistent identifier for the respondent
No IP addresses stored with survey responses
No tracking cookies on survey pages — respondents receive only a strictly necessary session cookie that remembers their progress through the survey
Browser and referring page are recorded with each survey session — the user-agent string and the page the respondent arrived from. This powers the drop-off and traffic reports the survey creator sees, and it stays in our database
No analytics scripts of any kind on survey pages, thanks pages and public results pages — no third-party analytics provider receives a request from them
Map tiles and interface libraries on survey pages load from third-party CDNs (map tiles, Leaflet, icons, fonts). Those providers see the request. Self-hosting removes this — see below
No advertising scripts, ad networks, or cross-site profiling anywhere on the platform — and none of it is ever sold or shared
Survey creators need an account (email and password only) — no further personal data required
Product analytics on creator-facing pages only — our marketing, account and editor pages use PostHog (EU-hosted) so we can see how the tool itself is used. It is enforced never to load where respondents answer surveys. Marketing pages also set one first-party cookie that remembers which page and referrer a visitor arrived from, so that a later registration can be attributed to its source; it holds no identifier and expires after 90 days
Editor sessions of signed-in creators may be recorded — a replay of what happened on screen while someone builds a survey, so we can see where the tool confuses people. What creators type is masked in their browser and never transmitted: question wording, section names, organisation names and email addresses in forms. Recordings are kept for 30 days and then deleted. People answering surveys are never recorded — the analytics script does not load on survey or public-results pages at all
Optional AI drafting sends the creator's brief to Google — a creator who asks the AI to draft a survey has the description they typed processed by Google's Gemini API in the United States. It is optional: the empty-survey path never calls it. Survey responses are never sent to an AI provider, and our account is on the paid tier, where Google does not use the content to train its models
Hosting & Data Residency
Our hosted service runs in the United States. If your organisation requires EU data residency, self-hosting is the route today — the platform is AGPLv3 and deploys on your own infrastructure.
Hosted on Render.com — Oregon, United States. Application servers, background workers and the PostgreSQL database all run in Render's Oregon region
Data is transferred outside the EEA when you use our hosted service. Institutions bound by EU-residency requirements should self-host rather than rely on the hosted offering
Self-hosting gives full data sovereignty — run Mapsurvey in your own EU data centre, or any jurisdiction you choose. No feature is withheld from the self-hosted build
An EU-region deployment of the hosted service is planned. This page will say so plainly the day it is live, and not before
Render is SOC 2 Type II certified — independently audited security controls
PostgreSQL database with encrypted connections (TLS)
Cloudflare fronts the hosted service as CDN and reverse proxy — every request to mapsurvey.org, including product-analytics traffic, passes through Cloudflare's network before reaching our servers
Product analytics for our own creator-facing pages is stored in the EU (PostHog Cloud EU) and never touches survey responses. Its traffic transits Cloudflare's network, which normally terminates EU requests at EU edges but is not contractually guaranteed to
Open Source & Transparency
The entire codebase is publicly available for audit and review.
Password hashing — user passwords stored using PBKDF2 with SHA-256 (Django default)
Registration abuse defenses — honeypot field, per-IP rate limiting and Cloudflare Turnstile (one use of Cloudflare among several; see Hosting & Data Residency), with an audit log of what was blocked
Third-party code in the survey flow is limited to map and interface assets — map tiles, Leaflet, icons and fonts. No analytics, advertising or profiling scripts. Self-hosting lets you serve these from your own infrastructure
Survey creators retain full ownership of all collected data.
Your data is yours — Mapsurvey claims no rights over survey content or responses
Export at any time — download responses as GeoJSON and CSV with a single click
Delete at any time — deleting a survey removes it and its responses from your account; deleted items are permanently purged by a scheduled job
Account deletion on request — there is no self-serve button yet; email konuchovartem@mapsurvey.org and we remove your account, surveys, responses and personal information
No vendor lock-in — standard data formats ensure portability to other tools
Who is behind Mapsurvey
Mapsurvey is an independent open-source project created and maintained by Artem Konuchov.
It is not affiliated with any government, corporation, or commercial entity.
The project is driven by the need for accessible, privacy-respecting participatory mapping tools.
Data Processing Agreement
If your institution requires a Data Processing Agreement under Article 28 GDPR,
get in touch and we will work one through with you — covering the data categories,
security measures and sub-processors described above.
We previously offered a ready-to-sign template here. It has been withdrawn while it
is revised and reviewed: a signable agreement should be accurate about where data is
hosted and who processes it, and it should not commit either side to terms neither
has taken advice on. We would rather agree one with you than hand you a document we
cannot stand behind.