Privacy Policy
Last updated: September 7, 2026
Who We Are
Baladi Map is an independent, free civic platform for reporting local problems that Lebanon's municipalities are responsible for. It is not a government service and is not affiliated with any government body, municipality, or political party. We show no ads, we sell no data, and we make no money from users. This policy explains, in plain language, what data we collect, why we collect it, and what happens to it.
Information We Collect
We collect only what the platform needs to work:
- Account details: your email address and, optionally, a display name and username. You can browse, report, and vote without an account.
- Report content: the title, description, category, and severity you write, and any photo you choose to attach.
- Location: the spot you place on the map for a report. Sharing your device's GPS location is optional. You can always place the pin manually or simply pick your municipality from a list. If a photo you choose has coordinates saved by the camera, your device reads them and offers them as the report's location. They are used only if you accept, and a photo's own metadata is removed before anything is uploaded.
- Your activity: the reports you file, comments you post, "I'm affected" votes you cast, and issues you follow.
- Municipality claims: if you submit the claim form as a town official, the name, role, email address, and optional phone number you provide.
- Anonymous participation: if you use the platform without an account, a random token stored in a browser cookie lets you report and vote without telling us who you are.
- Technical data: anonymous usage analytics, page-performance measurements, and error diagnostics.
- Repair reports: if you say a problem is fixed and attach a photo, we store that photo and your note. The photo stays private until a person at Baladi Map has reviewed it and published a blurred copy; if it is refused or withdrawn, it is deleted.
- Added photos: the person who filed a report, or someone who said it affects them, can add a photo to it later. It is handled like a repair photo: private until a person at Baladi Map has reviewed it and published a blurred copy, and deleted if refused.
- Municipal desks: for a council that holds a desk, the sign-in identifier we issued, the email address the council gave for alerts, its actions on reports, and when the desk was last opened. Officials prove their role before a desk is opened, and that proof is kept only as long as needed to check it.
- Telegram reporting: if you report through our Telegram bot, we store a pseudonymous identifier derived from your Telegram account so your reports can be grouped and rate-limited. Your Telegram name is never stored with a report or published.
How We Use Your Information
We use this data to:
- publish approved civic reports on the public map and issue pages
- show how many people each problem affects and build the municipality scoreboard statistics
- send you notifications about issues you reported or follow
- review reports before publication and keep the platform safe (moderation, rate limits, abuse prevention)
- diagnose errors and improve how the platform works
- tell a municipality, at the address it gave, when a report is published in its area and how its reports stand each week
- help our moderators draft replies to comments and flags (a person reads and sends every reply; see AI Processing)
We never use your data for advertising, and we never sell it to anyone.
What Is Public
Baladi Map is a public accountability platform, so parts of it are public by design. Once a report is approved, its title, description, category, photo (with faces and license plates blurred), map location, and the reporter's display name are visible to everyone on the internet. Your email address and phone number are never shown publicly. If you would rather not be named, you can report without an account, or choose a display name that does not identify you. What a municipality does on a report is public too: its acknowledgement, its public replies, a photo of the repair once published, and any referral to another body with the reason it gave. A council's sign-in identifier and alert email address are never shown.
Service Providers We Work With
We do not run our own servers. A small number of service providers process data on our behalf, each receiving only what it needs for its job:
- Supabase. Hosts our database, sign-in system, and file storage. It holds account data, reports, photos, votes, comments, follows, municipal desk data, and repair photos.
- Vercel. Hosts the website and app. It receives standard technical logs (such as IP addresses) and collects anonymous, aggregated visit and page-speed statistics (Vercel Analytics and Speed Insights).
- Sentry. Receives crash and error reports when diagnostics are enabled. These can include device and browser details and what the app was doing when the error happened.
- Google. If you choose "Sign in with Google", Google confirms your email address to us. This is optional; email sign-in works without it.
- Google Gemini (AI). Report photos and repair photos are processed to blur faces and vehicle license plates before publication, and a report's title and category may be used to generate an illustration when no photo is attached.
- OpenRouter and DeepSeek (AI). When a moderator replies to a comment or a flag, the comment text and the report title may be sent to an AI model to draft the reply. A person reads and sends it.
- Namecheap Private Email. Sends our email: sign-in codes, moderation notices, and municipality alerts. It receives the recipient's address and the message.
- Telegram. If you use our Telegram bot, Telegram handles that conversation under its own privacy policy.
- Pollinations.ai. A fallback service for generating report illustrations. It receives only a report's title and category, never photos or personal data.
These providers process data under their own privacy policies and only in order to provide their services to us.
AI Processing
We use AI in three narrow, disclosed ways. First, to protect privacy: every photo attached to a report, and every photo sent as proof of a repair, is automatically processed (currently by Google Gemini) to blur faces and vehicle license plates before it is published. Second, for illustrations: if a report has no photo, its title and category may be used to generate a neutral illustration. Third, to help our moderators: when they reply to a comment or a flag, an AI model (currently DeepSeek, through OpenRouter) may draft the reply from the comment and the report title, and a person reads, edits and sends it. No AI decides whether a report is published, fixed, referred, or removed; those are decisions people make.
Voting and Anonymous Participation
When you press "I'm affected too" on an issue, we store which issue was voted on, when, and either your account ID (if you are signed in) or your anonymous browser token (if you are not). This is what limits everyone to one vote per issue. We use these votes to show how many people each problem affects and to build aggregate statistics for the municipality scoreboard.
Individual votes are never shown publicly, only totals, such as "47 people affected".
Municipal Councils on the Platform
Municipalities can hold a desk on Baladi Map to see and respond to reports in their area. A desk is opened after an official has proved their role to us. For a desk we hold the sign-in identifier we issued (it is not a mailbox and receives nothing), the email address the council chose for alerts, when the desk was last opened, and everything the council does on reports. Council actions are part of the public record and are shown on the report, credited to the municipality by name and never to the individual official. Alert emails go only to the address the council entered, and only for two things: a report published in its area, and a weekly summary. A council can change or remove that address on its desk at any time, and can ask us to close the desk.
Cookies and Analytics
We use essential cookies to keep you signed in, plus the cookie that holds the anonymous participation token described above. Our analytics are anonymous and aggregated, and do not track you across other websites. We do not use advertising or cross-site tracking cookies.
How Long We Keep Data
Published reports, their photos, comments, and what municipalities did on them remain on the platform as part of the public record, until they are deleted or anonymized. Repair photos that are refused or withdrawn are deleted at once; published ones stay with the report. Account data is kept for as long as your account exists, and a council's desk data for as long as its desk is open. Error and analytics data is kept only for our providers' standard, limited retention periods. If you want something specific removed, contact us at admin@baladimap.com.
Deleting Your Account and Data
You can delete your account inside the app (Dashboard → Settings), or request deletion at any time through the request page at baladimap.com/account/delete. No app required. When your account is deleted, your private data (email address, name, phone number, watchlist, notifications) is deleted. Published civic reports and comments are anonymized rather than erased: they remain on the map as part of the public record, but your name is removed and they can no longer be linked to you. If you also want specific reports or photos taken down, email admin@baladimap.com and we will review the request. A municipality can ask us to close its desk: access is revoked and the alert address is deleted, while the council's public actions stay on the record, attributed to the municipality.
Your Rights and Controls
You stay in control of your data. You can:
- browse, report, and vote without creating an account
- report without attaching a photo and without sharing your GPS location
- view and edit your display name in your dashboard settings
- unfollow issues and stop notifications at any time
- delete your account and request removal of your data (see the section above)
- ask us what data we hold about you, or ask us to correct it, at admin@baladimap.com
Data Security
Data is encrypted in transit and at rest by our hosting providers. Access to private data is restricted by database-level security rules, and moderation actions are limited to authorized administrators. No online service can promise perfect security, but we deliberately keep the amount of personal data we hold small.
International Data Transfers
Our service providers (listed above) store and process data on servers outside Lebanon, mainly in the United States and the European Union. By using Baladi Map, you understand that your data is transferred to and processed in those countries, where data-protection laws may differ from those of Lebanon.
Changes to This Policy
We may update this policy as the platform evolves. The date at the top always shows the current version. For significant changes we will post a notice on the platform and, where appropriate, email registered users.
Contact Us
Baladi Map is run as a public-good project. For any privacy question, request, or complaint, email us at admin@baladimap.com and we will respond as soon as we can.