Privacy

El Nido Map has no advertising, and the whole guide works without an account. This page says what the app and the website do with data, and what they hand to somebody else.

Last updated on October 2, 2026

The app

Reading the guide needs no account, and asks for no name, address, email or phone number. There is no advertising in it, and nothing profiles you or personalises what you see. What you star, list or note is written to a file on your phone: we never receive it and cannot read it. On Android, your phone’s own backup may copy that file to your Google account along with the app’s other data, which you can switch off in your device’s backup settings.

Signing in

You need an account only to send us something about a place. Sign-in goes through Google or Apple, so we never see a password, and there is no way to create one here. We store which account you signed in with, and nothing else from it: the name and picture on your Google or Apple account are not copied here, and nothing appears under your name unless you type it yourself. Firebase Authentication holds the email address attached to that account — with Apple that can be a relay address which hides your real one, and the name there is optional and may be declined. Signing out changes nothing on your phone.

Your profile

A profile is optional, separate from signing in, and empty until you fill it in. It holds only what you type — a name, which part of town you are in, and a line about what you do — plus a photograph if you add one. Nothing is taken from the account you signed in with. Today nothing in the app or on this site shows your profile to anybody else, and the screen says so; it exists so that a public profile can be built from it later, and this page will say so before that happens. Two things are worth knowing now: anyone signed in who already has your account’s identifier can read what you typed, and a photograph you add is stored at an ordinary web address that needs no sign-in, so treat it as public. You can clear any field or remove the photograph whenever you like, and write to us to have the whole profile removed.

What you send us

If you send us opening hours, a phone number, a photograph or a correction, we keep what you wrote, the photographs attached to it, the place it was about, and which account sent it. Nothing you send appears on the site or in the app on its own: a person reads it, checks it, and edits the page only if it is right. Your name is not published beside a correction. We keep the submission afterwards, because it is how anyone can later tell where a fact on a page came from. Write to us to have a submission or your account removed.

Your location

If you ask the app to show where you are, it requests the location permission. Once you have allowed it, the app reads your position when you open it, and keeps the last one on the phone so that it only moves the map when you have moved. That position is used on the device: it centres the map and works out how far a place is from you. It is never sent to us, and deleting the app deletes it. Refuse the permission and every screen still works — the map opens on the town instead of on you.

Counting the app

The app records one row about itself so we can tell how many copies exist and how many are opened each day — the app stores do not tell us that, and it is how we decide which version to keep supporting. The row holds when the app was first opened on this phone, when it was last opened, the dates of the last 30 days it was opened on, the app version, the device model, the operating system version and the phone’s language. It is identified by a random number the app makes up on first launch and stores in its own files: it is not read from your phone, it matches nothing else, and deleting the app deletes it. If you have signed in, the row also carries which account, so that we do not count one person twice. There is no advertising identifier, and nothing here records what you look at. If you turn notifications on, your phone tells Google which subjects it wants — news, advisories, replies on your own thread, and each channel you belong to. For those we never receive a device identifier: the list of who is subscribed is Google’s, not ours, and turning notifications off leaves it. One case is different. If somebody names you in a room, that message is addressed to you rather than to a subject, so your phone gives us an identifier for itself — which we keep against your account, use only to send you that notification, and delete when you delete your account or the app.

Crash reports

When the app closes unexpectedly it sends a crash report to Firebase Crashlytics: what the code was doing at the moment it failed, the device model, and the version of the operating system. The report carries no name and no account. It exists so that a bug which only happens on one kind of phone can be found and fixed rather than guessed at.

What the app downloads

Listings, photographs and prices come from Google Firebase. The map comes from Mapbox. Loading either means your device makes a request to that company, and a request carries your IP address and basic technical details, the same way opening any website does. We do not receive that information, and their own terms govern what they do with it. Mapbox also collects map-usage telemetry under its terms. Once loaded, the catalogue stays on the device so it can be read without signal.

The website

elnidomap.com counts visits with Umami. It sets no cookies and builds no profile: it records the page, where the visit came from and a rough country, and nothing that identifies a person. There is no consent banner because there is nothing to consent to.

Asking us

Write to intbh@laposte.net with any question about this, including a request to see or delete what we hold about you — which, unless you have signed in and sent us something, is nothing.