Privacy
LetMeP answers one question: where is the nearest toilet they will let you in, and what will it cost. Looking for one never needs an account. This page covers what does: adding a toilet, rating one, confirming its entry requirements, correcting its details, uploading or reporting a photo, and reporting a problem with one; and what happens to your data either way.
Who runs this
The data controller is LetMeP, a one-person hobby project. Reach it at privacy@letmep.com for any question about your data, including the requests below.
What's collected
- An email address, from whichever sign-in method you use (an emailed link, or Google). Signing in with Google also has Google itself hand LetMeP your name and avatar, which land in Supabase's own
auth.usersaccount record; no page in this app shows either to anyone else, but the auth record holds them all the same. - Ratings and tags you leave on a toilet, and the toilets you add, if you add any.
- A report, if you ever flag a toilet as wrong or unsafe, or a photo as the wrong kind, showing a person, or otherwise unfit: every one of these is linked to your account, because a moderator needs to be able to follow it up.
- A photo, if you add one of a toilet's door, entrance or sign. It is held privately until a moderator approves it; only then does anyone else see it, and even then never who took it. A moderator can look up who uploaded any photo, published or not, the same way one can look up who filed a report or wrote a review.
- Your approximate location, only while a page is open and only if you share it, to search near you or center a map. It is never saved against your account, but it does reach LetMeP's own database to run the search, and (only the first time anyone searches a given area) an external toilet-data provider (Geoapify) to import it. A rough, roughly-5 km marker of which areas have already been imported is kept permanently so the same ground is never re-imported, but it carries no link to who searched it and is not precise enough to find a street or an address.
Supabase, the platform LetMeP is built on, processes all of the above on LetMeP's behalf under its own Data Processing Agreement: it never sees your reason for using the app, only the rows above. The map's tiles are served by MapTiler, and a first-time area search is handed to Geoapify; both receive only the coordinates needed to answer, never your account. Every request also passes through Cloudflare, which hosts the app and sees your IP address the way any web host does.
What's public, and what never is
A review's content (its star rating, the day it was left, and the tags picked) is public, because a review nobody can read is not a review. Toilets and their entry requirements are public for the same reason the app exists: so anyone can find them.
Who left a review is never public. No public page, and no other signed-in reader, can ever see which named person wrote a given review; only that someone did, and what they said. The one exception is a moderator, who can look up any review's author the same way they look up any report: that access exists so a moderator can act on abuse, and is not available to anyone else. Joining a review to a person is exactly the kind of fact this app keeps apart from every ordinary reader, because for many people here the toilets they rate say something about their health.
How long it's kept
Until you delete it. There is no separate retention clock: your profile, reviews, tags and photos stay only as long as your account does, and deleting your account (below) removes them immediately, not on a schedule. A photo a moderator rejects has its image bytes removed as a best-effort step at the same time, even though your account stays open; only the record that it was rejected, and why, is kept.
Deleting your data
Open You and choose Delete account. That one action removes your profile, every review and review tag you left, every report you filed (open or already resolved), and your sign-in itself, all at once, not gradually. Every photo you uploaded goes the same way: its record is gone in that same action, and its stored file is cleared out right after as a best-effort step, so on the rare failure only the record, not the file, is guaranteed gone immediately. A toilet you added is kept: toilet data stays open for everyone to use and correct, but it stops being linked to you: it becomes exactly the kind of unowned, crowd-editable row an imported toilet already is. If you would rather ask by email than use the button, write to privacy@letmep.com and the same deletion is done by hand.
The legal basis
LetMeP is a Swiss project, so its home law is the Federal Act on Data Protection (FADP). If you believe your data has been mishandled, you may complain to the Federal Data Protection and Information Commissioner (FDPIC). If you are in the EU, the same rights and the same complaint route are also available under the GDPR, through your own country's data protection authority.