50,000 free calls a month, card-free. Get an API key →

Legal

What MapMap collects

Last updated: 19 July 2026

The short version: we count our own gateway traffic (usage, error classes, hashed monthly-active users and activation milestones) to improve the service. We never collect coordinates tied to identity beyond the documented probe consent, never put API keys in analytics, never store transcripts, and ship no client-side telemetry in production SDK builds. The detail follows.

1. The principle

MapMap measures its own service, not your users. Everything listed below is derived from traffic our gateway must handle anyway to serve your requests, processed for service improvement. There is no client-side telemetry in production SDK builds, no tracking pixels, and nothing that phones home from inside your application.

2. What we collect (gateway-side)

Usage counters: metered calls per API key, per day, per endpoint: the same numbers that drive your quota, your bill and the usage panel on your account page.

Error classes: counts of response status codes (for example 401, 402, 422, 429) per key and endpoint, so we can see when developers are hitting friction; a storm of 401s is a documentation gap, not a customer to ignore.

Monthly-active-user hashes: when you meter SDK seats via the X-MapMap-User header, we store a salted hash to count distinct users. We cannot reverse it, and we never see who the user is.

Activation events: service milestones on your key, such as the timestamp of your first successful route. We use these to improve onboarding and, for early customers, to say hello.

Website analytics on mapmap.ai are cookieless and aggregate (EU-hosted PostHog and Plausible): page views, docs feedback clicks and playground interactions, never tied to an API key.

3. What we never collect

No coordinates tied to identity. Route coordinates are processed to answer the request and are not stored against your identity. The only location telemetry MapMap ever retains is the separately documented, consent-gated probe programme, which is off unless you explicitly enable it.

No API keys in analytics. Keys are bearer credentials, never analytics identifiers, and never leave the gateway's own auth path.

No transcripts. Agent feedback (see the Agent Feedback Programme) carries only structured fields; never your conversation, prompts or code.

No client-side telemetry from production SDK builds. SDK telemetry is hard-off in shipped apps: anything on an end user's device belongs to you and your privacy policy, not ours to take.

4. Retention

Feedback submissions (agent retros, map-issue reports, docs feedback): 24 months, then deleted.

Usage and error counters: 365 days at daily granularity, then aggregated or deleted. Billing records are kept as long as law requires.

5. Where it lives

Gateway telemetry and feedback are stored on EU infrastructure. Website analytics use EU-region processing (PostHog EU; Plausible is EU-based). Nothing in this document is transferred to ad networks or data brokers; MapMap does not sell data, full stop.

6. Questions

If anything here is unclear, or you want something we hold about your key deleted, email hello@mapmap.ai. You will get an answer from a person.

Related: the Agent Feedback Programme (what an AI agent may submit on your behalf), the privacy policy and the terms of service. Questions: hello@mapmap.ai.