Popup is a map you explore. Exploring needs no account, there are no analytics on it, and while you explore, your precise location never leaves your device. The popups we list do have an account — the second half of this page says exactly what that involves.
If you are exploring
Your location
When you ask Popup to find where you are, your browser asks you for permission and hands the answer to the page. It is used there, to move the camera and to work out how far you are from things, and it is gone when you close the tab. Your coordinates are not stored and not sent anywhere.
If you turn on Follow me, the page keeps reading your position as you move, and on a phone its compass, to turn the view the way you are facing. Both stay on your device in the same way, and it stops the moment you turn it off or close the tab.
To show you the real popups near you, the app asks our server which popups are out in the squares of map around where you are looking — squares about half a kilometre across, the same way the map tiles work. The square is sent; your position inside it is not. While the app is open, the live channel below is told the same squares, so a popup that packs up fades from your map at once. We do not keep a log of these requests, and the squares are not stored. Press P at any time and your position is snapped to a coarse grid as well.
When the app opens, it chooses where to start. If you have already let popup.app know where you are, it uses that without asking again, and asks our server for the popups out nearest you — sending your position rounded to about 10 km, never the point itself. If you haven't, our server looks up the rough city your IP address comes from (our host, Cloudflare, works this out for every request) and answers with that city and the popups out nearest it. Neither is stored. If nobody is out near you, the map opens beside the nearest popup that is.
You can take the permission back whenever you like, in your browser's site settings for popup.app. The map still works; it just starts near your city, or beside the nearest popup out, instead of where you are.
Popups you save
Saving a popup is remembered on your device, not on an account. While the app is open it tells our live channel the usernames you have saved, so you hear the moment one of them pops up. That list, like the squares above, is held only while you are connected, is not stored, and is not tied to who you are; the only thing a Popup can see is a count of how many open apps have it saved right now.
Reporting a page or a picture
If you report a popup's page or one of its pictures, we receive which page or picture, the reason you picked, and your note if you wrote one. Nothing about you goes with it: no account, email or location. To stop floods of reports we count them per IP address, stored as a scrambled fingerprint and deleted within a day. We keep a report for a year after we have dealt with it, so we can see whether a popup keeps being reported.
What is kept on your device
Popup uses your browser's own storage to remember a few things between visits, all of them on your device only:
- whether you want the readouts on;
- whether you want the compass on;
- whether you want the sound on;
- the popups you have saved;
- while a popup's owner is signing in with an emailed code, the address it went to, in that tab only, until they sign in, close the tab or 15 minutes pass.
Apart from that sign-in address, none of it identifies you. Clearing site data for popup.app in your browser deletes all of it.
If you have a popup
Businesses join by invite or by asking us, and we check each one before it is listed. If you registered one, this is what we keep, who can see it, and for how long.
- Your email address — the one we sent your invite to, or the one you gave and confirmed. It is private. If you ask to be listed and never confirm it, we delete the request, email included, after an hour. We use it only to send you sign-in links and notices about your account (such as a sign-in from a new device), and it is never shown on the map, sold or shared.
- Your business name, username and what you sell — public: they are your page at popup.app/username and what explorers search for.
- Where you registered from — private. It is where the map starts your setup, and nobody else sees it.
- Where we can see you — if you gave us a link or an account when you registered, so we could check it's really you. Only we see it.
- Your bio and links — public, on your page.
-
Your pictures — public, on your page, served from
cdn.popup.app. When you add one, our server makes a new copy of it at a set size and throws away the file you sent. The copy carries none of the hidden details a phone adds to a photo — no GPS location, camera or date. A picture you remove from your page is deleted within an hour, and so is one you upload but never add. - How pictures are checked — every picture is checked for nudity, sex and violence before anyone else can see it. First on your own device, by a small model inside the app, so a picture it won't take never leaves your phone. Then on our server, by an AI model that Cloudflare runs for us, so no other company sees it. The server's check may refuse a picture, in which case it is not kept. Or it may hold one for a person at Popup to look at, in which case only you and we can see it until we have. We keep what the check said about a picture for as long as we keep the picture, and a note that an upload was refused, without the picture.
- When you pop up — where you are standing, the street, your offer and how long you are out are public while you are out, and taken off the map the moment you pack up or your time runs out. The position we show is rounded to about 10 metres: close enough to find you, not your phone's exact fix. We use it only to show you on the map while you are out, never to work out anything else about you. You are never out for more than 12 hours: if you forget to pack up, we do it for you when your time runs out. We keep a record of your nights (when, which street, the offer) so the app can show you your own history; it is not public, it never holds map coordinates, and the street is deleted after 30 days.
- Signing in — one cookie on api.popup.app that keeps you signed in. It cannot be read by the page, is used for nothing else, and ends after 90 days, or 30 days unused, or when you sign out. With it we keep a short device description such as "Safari on iPhone", so we can tell you about new sign-ins. We do not store your IP address. The one-time links and codes we email you are stored only as a scrambled fingerprint, and expire within an hour.
- A record of account actions — your username, what happened (signed in, popped up, changed your page) and when. No email, IP address or device.
To stop abuse, we count requests per IP address and per email for sign-in links and registrations. Those counters are stored as scrambled fingerprints rather than the address itself, and are deleted within a day.
We keep your account for as long as you have a popup. Write to privacy@popup.app from your account's email and we will delete it and everything above; copies in our backups age out within 30 days. Your username stays reserved for 90 days after, so nobody else can take it and pass for you.
When something breaks
If the app hits an error it didn't expect, it tells our server what broke: the error message, where in our code it happened, and which version of the app you have. The server adds a short device description such as "Safari on iPhone". It does not send the page's address, your location, your IP address or your account, and anything in the message that looks like an email address, a sign-in link or coordinates is removed before it is kept. Errors are grouped and counted, so we can fix them, and deleted 30 days after they last happened.
Cookies and tracking
If you are exploring, there are none. If you have a popup, there is the one sign-in cookie above, which is strictly necessary for your account to work. There are no advertising or analytics scripts, no fingerprinting, no third-party tags, no session recording, and no profile of anyone — which is also why you were not asked to accept anything on your way in.
Who else sees a request
Popup is built on other companies' services. Each of them sees your IP address and what was asked for, as every server on the internet does, and each has its own privacy terms:
-
OpenFreeMap (
tiles.openfreemap.org) serves the map tiles. Which tiles you fetch indicates roughly what part of the world you are looking at. -
AWS Open Data (
s3.amazonaws.com) serves the terrain data, the same way. -
Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) serves the two typefaces. -
Cloudflare serves the site itself, runs our server and
database at
api.popup.app, stores popups' pictures, runs the AI model that checks them, and serves them fromcdn.popup.app. When you register without an invite, its Turnstile check makes sure a person filled in the form. It answers for popup.app's domain names, and passes email sent to our@popup.appaddresses on to our inbox. We keep error logs only, not a log line for every request. - Resend sends our emails, so it handles the address and the content of each email we send.
- Stripe takes payment when a popup pays to be featured. It handles the card on its own page, and we pass it the popup's email for the receipt. We never see or keep card details. We keep a record of each payment (which popup, which night, the amount, and whether it was refunded) for our accounts.
If you tap directions on a place, that opens Google Maps, which is Google's site and not ours.
Popups on the map
Every popup on the map is a real business that registered with us and that we checked. What it says about itself is its own. If you buy from one, what it does with your details is between you and that business; this page covers only Popup.
Children
Popup is not directed at children under 13, and we do not knowingly collect anything from them.
Your rights, including in California
California's privacy law gives you the right to know what personal information a business has collected about you, to have it deleted, to correct it, and to opt out of its sale or sharing. If you are exploring, Popup has collected nothing that identifies you. If you have a popup, what we hold is listed above: identifiers (your email and username), your business details, commercial information (the featured nights you paid for), the pictures you upload, and location (where you registered from, and where you stand while you are out). We collect each for the reason given beside it above, and keep it for as long as it says. None of it has been sold or shared for advertising, and it never will be. We do not offer financial incentives and we do not discriminate against anyone for exercising a privacy right.
The same goes for the equivalent rights elsewhere — access, deletion, correction, portability, objection. Write to privacy@popup.app from your account's email and we will answer within 45 days. We may keep what the law requires us to, such as payment records for our accounts, after the rest is deleted.
Changes
This page changes when the app does, and the date at the top changes with it. If a change affects what we keep about popups, we will email them before it takes effect.
Contact
privacy@popup.app for anything on this page, or security@popup.app to report a vulnerability.