OpenHunt for Android is on Google Play — take your plan into the field. Send it to your phone →

OpenHunt

Privacy

Last updated August 14, 2026 · Draft pending legal review

The plain-language version

Your hunting spots are the most sensitive thing we hold, and we treat them that way. We collect the minimum the service needs, sell nothing, run no ad tech, and delete your data when you delete your account. The software is open source, so all of this is auditable. The hosted service is operated by Erudition Labs, LLC (San Diego, California).

What we collect

Account: email, a salted password hash, and optionally a display name. Your content: waypoints, routes, recorded tracks, Hunt Records, Watch targets, rules, preferences, and inbox history — only if you sign in and sync; the free tier keeps everything on your device. Operational: session records (client type, IP, timestamps) for account security, and server logs kept briefly for debugging. Product telemetry: how you use the app — detailed in the next section, because it deserves more than a clause. That’s the list. No advertising identifiers, no ad tech, nothing sold or brokered, and no location collection outside the tracks you explicitly record. This section is our notice at collection under California law: we collect these categories for the purposes described on this page, and we do not sell them or share them for advertising.

Watch notifications and delivery

Watch stores the location or hunt selector you ask it to monitor, the rule that matched, immutable notice evidence, and delivery status. Personal Hunt History comparisons stay scoped to your account and do not train an aggregate model. Precise geometry, personal outcomes, notification text, and recipients are excluded from operational metrics and logs. Push tokens are encrypted at rest with rotatable keys; a one-way digest is used for uniqueness. Resend receives the email address and message needed to deliver email. Expo receives the device token and a private deep-link payload containing only a schema, notification id, and canonical Watch path. Delivery receipts and webhook metadata retain provider ids/status only. Watch notices and match evidence are retained for up to two years; delivery attempts for one year; invalid or revoked push tokens for 30 days.

Analytics and product telemetry

On the hosted service we run PostHog to understand how the product gets used — which pages open, which features get touched, what errors people hit, and where they give up. This is for building the thing, not for selling you or your data. None of it is sold, brokered, or used for advertising.

What that includes: page views, clicks and interactions, performance measurements, unhandled errors, and session replays — recordings of your interaction with the interface, so we can see where the design confuses people. When a request fails on our servers we record that too, tagged with your account id so we can tell which failure belonged to which session; the failure text is stripped of links and email addresses and truncated before it is sent.

What it deliberately excludes. The map itself is never recorded: a replay shows the buttons and panels around the map, and a blank space where the map is. It never shows where you were looking. Waypoint, route and party-board names, map search results, and landowner names shown on the identify panel are masked before anything leaves your browser. Share and party-invite links are stripped out of every event. Signed in, events carry your account id, email, display name and plan so we can tell one person’s use from another’s; signing out or deleting your account breaks that link.

Self-hosting. None of this exists in a self-hosted build. It is not switched off — it is compiled out. No analytics code, no recording, nothing to disable and nothing to trust us about, which is the point.

Who else touches data

Paddle processes payments as merchant of record — card details go to Paddle, never to us. Resend delivers transactional email (verification, password resets). PostHog receives the product-analytics events above as our processor, on our instructions and nobody else’s; it is not permitted to sell them or use them for its own purposes. Map base tiles and terrain data load from public tile services; those requests carry your IP like any web request, but no account identity. We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as California law defines that term — your waypoints are visible to exactly you, plus anyone you hand a share link to, until you revoke it.

Where your spots live

Synced content is stored encrypted at rest in our database. Share links are stored as digests — a database leak exposes no live link. Session tokens are likewise digest-only. Recorded tracks include timestamped GPS positions by design; recording is always an explicit action you start and stop. Precise geolocation is sensitive personal information under California law, and we treat your tracks and waypoints accordingly: we use them solely to provide the service you asked for — storing, syncing, and displaying them back to you — never for profiling, advertising, or sale.

Deletion

Account deletion is immediate and hard: your content rows are removed, not flagged. Tombstones used by sync replication age out within 180 days. Export everything first — GPX and GeoJSON export is free, always.

Landowner names

The map displays parcel ownership drawn from county public records — the same records anyone can request from the county assessor. If you own land and want your name removed from OpenHunt’s display, email tristan@eruditionlabs.com with the county and parcel (or an address or map link) and we’ll suppress the name from the hosted service within 30 days. Removal here doesn’t change the county’s record, which remains public at the source.

Your California privacy rights

California residents can ask us to disclose what personal information we hold, to correct it, to delete it, or to receive a copy in a portable format — email tristan@eruditionlabs.com and we’ll verify the request against your account email. You may use an authorized agent. We do not sell or share personal information, so there is nothing to opt out of, and we use sensitive personal information (your recorded locations) only for the service purposes described above, so no “limit use” request is needed — though you can make one. We will never treat you differently for exercising any of these rights. Most of them are also self-service: export is free and always available, and account deletion is immediate and hard.

Self-hosting

Run OpenHunt yourself and none of this involves us at all — the same code, your infrastructure, your rules. That option existing is your leverage against us ever degrading this policy.

Contact

tristan@eruditionlabs.com for anything, including data export or deletion requests.