Trust & Security

Built for institutional confidence

Everything your IT security team needs to know before approving Mapsurvey for institutional use.

Data Privacy (GDPR)

Survey respondents stay anonymous: no account, no name, no email. Below is the full list of what is recorded when someone answers a survey — including the technical details most vendors leave out.

  • No login required for survey respondents — anyone with the link can participate
  • No identity — responses carry no name, email, account or persistent identifier for the respondent
  • No IP addresses stored with survey responses
  • No tracking cookies on survey pages — respondents receive only a strictly necessary session cookie that remembers their progress through the survey
  • Browser and referring page are recorded with each survey session — the user-agent string and the page the respondent arrived from. This powers the drop-off and traffic reports the survey creator sees, and it stays in our database
  • No analytics scripts of any kind on survey pages, thanks pages and public results pages — no third-party analytics provider receives a request from them
  • Map tiles and interface libraries on survey pages load from third-party CDNs (map tiles, Leaflet, icons, fonts). Those providers see the request. Self-hosting removes this — see below
  • No advertising scripts, ad networks, or cross-site profiling anywhere on the platform — and none of it is ever sold or shared
  • Survey creators need an account (email and password only) — no further personal data required
  • Product analytics on creator-facing pages only — our marketing, account and editor pages use PostHog (EU-hosted) so we can see how the tool itself is used. It is enforced never to load where respondents answer surveys. Marketing pages also set one first-party cookie that remembers which page and referrer a visitor arrived from, so that a later registration can be attributed to its source; it holds no identifier and expires after 90 days
  • Editor sessions of signed-in creators may be recorded — a replay of what happened on screen while someone builds a survey, so we can see where the tool confuses people. What creators type is masked in their browser and never transmitted: question wording, section names, organisation names and email addresses in forms. Recordings are kept for 30 days and then deleted. People answering surveys are never recorded — the analytics script does not load on survey or public-results pages at all
  • Optional AI drafting sends the creator's brief to Google — a creator who asks the AI to draft a survey has the description they typed processed by Google's Gemini API in the United States. It is optional: the empty-survey path never calls it. Survey responses are never sent to an AI provider, and our account is on the paid tier, where Google does not use the content to train its models

Hosting & Data Residency

Our hosted service runs in the United States. If your organisation requires EU data residency, self-hosting is the route today — the platform is AGPLv3 and deploys on your own infrastructure.

  • Hosted on Render.com — Oregon, United States. Application servers, background workers and the PostgreSQL database all run in Render's Oregon region
  • Data is transferred outside the EEA when you use our hosted service. Institutions bound by EU-residency requirements should self-host rather than rely on the hosted offering
  • Self-hosting gives full data sovereignty — run Mapsurvey in your own EU data centre, or any jurisdiction you choose. No feature is withheld from the self-hosted build
  • An EU-region deployment of the hosted service is planned. This page will say so plainly the day it is live, and not before
  • Render is SOC 2 Type II certified — independently audited security controls
  • PostgreSQL database with encrypted connections (TLS)
  • Cloudflare fronts the hosted service as CDN and reverse proxy — every request to mapsurvey.org, including product-analytics traffic, passes through Cloudflare's network before reaching our servers
  • Product analytics for our own creator-facing pages is stored in the EU (PostHog Cloud EU) and never touches survey responses. Its traffic transits Cloudflare's network, which normally terminates EU requests at EU edges but is not contractually guaranteed to

Open Source & Transparency

The entire codebase is publicly available for audit and review.

  • Full source code available on GitHub
  • Licensed under AGPLv3 — guarantees source availability and user freedom
  • Anyone can audit the code, verify claims, and inspect data handling
  • No obfuscation — what you see in the repository is what runs in production

Security

Industry-standard security practices are enforced at every layer.

  • HTTPS everywhere — all traffic encrypted in transit via TLS
  • Django security framework — built-in CSRF protection, XSS prevention, SQL injection safeguards, clickjacking protection
  • Password hashing — user passwords stored using PBKDF2 with SHA-256 (Django default)
  • Registration abuse defenses — honeypot field, per-IP rate limiting and Cloudflare Turnstile (one use of Cloudflare among several; see Hosting & Data Residency), with an audit log of what was blocked
  • Third-party code in the survey flow is limited to map and interface assets — map tiles, Leaflet, icons and fonts. No analytics, advertising or profiling scripts. Self-hosting lets you serve these from your own infrastructure
  • Regular dependency updates — security patches applied promptly

Data Ownership

Survey creators retain full ownership of all collected data.

  • Your data is yours — Mapsurvey claims no rights over survey content or responses
  • Export at any time — download responses as GeoJSON and CSV with a single click
  • Delete at any time — deleting a survey removes it and its responses from your account; deleted items are permanently purged by a scheduled job
  • Account deletion on request — there is no self-serve button yet; email konuchovartem@mapsurvey.org and we remove your account, surveys, responses and personal information
  • No vendor lock-in — standard data formats ensure portability to other tools

Who is behind Mapsurvey

Mapsurvey is an independent open-source project created and maintained by Artem Konuchov. It is not affiliated with any government, corporation, or commercial entity. The project is driven by the need for accessible, privacy-respecting participatory mapping tools.

Data Processing Agreement

If your institution requires a Data Processing Agreement under Article 28 GDPR, get in touch and we will work one through with you — covering the data categories, security measures and sub-processors described above.

We previously offered a ready-to-sign template here. It has been withdrawn while it is revised and reviewed: a signable agreement should be accurate about where data is hosted and who processes it, and it should not commit either side to terms neither has taken advice on. We would rather agree one with you than hand you a document we cannot stand behind.

Request a DPA