Privacy notice
Understand where land data goes and what you can delete.
Effective June 11, 2026
Local analysis first
Terrain calculations run in your browser. Drawing a boundary does not by itself create an account. Browser-only projects and interface preferences stay in your browser storage until you remove them or clear that storage.
A location submitted from the homepage is held once in storage scoped to the current browser tab, removed before the app submits the search and not added to the app navigation URL. Submitted location searches still use the search providers and short-lived cache described below.
Saved projects and uploaded terrain
When online project storage is available and you save a project, TopoDesigner stores the project record in its Cloudflare-hosted database. If you select a GeoTIFF elevation file, it is analyzed on your device first and may also be stored in private Cloudflare file storage so an authorized shared view can reproduce the analysis. The saved project and its revisions retain a private file-access secret. Public and read-only responses and account exports do not include that secret.
Sharing choices
Private editor and viewer links contain separate unguessable access secrets. Treat those links as secrets. An editor can optionally add a separate private-viewer password; TopoDesigner stores only a salted password hash and does not place the password in the viewer URL, saved project JSON, browser fallback cache or export. A public project can be opened by anyone with its URL, and viewers can retrieve a referenced uploaded elevation file through the project. The file-access secret itself is not returned to public or read-only viewers.
Operational counters and external sources
A configured deployment stores expiring, privacy-limited quota counters to reduce abusive use of external services and storage. Its short-lived cache keeps location-search text and results for up to 24 hours, ArcGIS suggestion text and results for up to 1 hour, and rounded point-preview coordinates and results for up to 30 days. Esri imagery requests go directly from your browser. Terrain, location-search and point-preview elevation requests pass through TopoDesigner server routes. Those providers apply their own terms and privacy practices.
Accounts and billing
The prepared example does not require an account. If you request a sign-in link, TopoDesigner stores your email address, expiring login token and session records in its account database and sends a transactional message through Cloudflare Email Sending. Signed-in sessions can continue a selected custom site and reopen account-owned results across devices without placing a private editor secret in the dashboard URL. Stripe processes payment details. TopoDesigner stores the related customer, purchase, subscription and access-status references in its account database.
Optional communication preferences
A signed-in user can separately and explicitly choose optional product updates, research invitations or Pro product updates and a frequency. Those choices are not required for analysis, saving or account access. TopoDesigner records the selected categories, frequency, source, timestamp, privacy/copy version and broad request country when available. Withdrawal, marketing-profile deletion and account deletion leave a one-way email hash and minimal suppression record so marketing stays off. Any future approved marketing message can use a signed one-click unsubscribe link that records the opt-out without requiring sign-in. Exact sites, project content and terrain findings are never marketing-profile fields.
Professional research requests
A Professional workflow research request is separate from account data and optional marketing preferences. TopoDesigner stores the email address, optional company name and volunteered broad workflow answers in its research database, sends one requested transactional confirmation and may reply only about that research request. It is not a purchase, sales sequence or marketing subscription.
The confirmation contains a private manage link whose access secret stays in the URL fragment and browser; the research database stores only a one-way hash. The link can review, update or delete the request without an account. Do not include exact sites, private project details or client information in the request.
Analytics collection
The reference application includes a strict first-party funnel event contract and a private anonymous deletion secret, but production collection is disabled until its purpose, retention period and jurisdictional consent behavior are approved. It does not use a third-party analytics beacon, join analytics to an account or email, or collect exact sites, project content, private access secrets, raw searches or free text.
Loading analytics preference...
Delete your data
An editor can delete a saved project from the workspace. TopoDesigner verifies editor authority, removes any legitimately owned stored GeoTIFF, removes the online project record and forgets the browser copy. You can clear browser-only projects by deleting them in the workspace or clearing browser storage. A signed-in Free or canceled account can also be deleted from the account page; TopoDesigner removes its account-owned projects and verified stored uploads, live optional marketing profile and outstanding sign-in links. The account page also provides an account-data export and separate marketing-profile deletion. Minimal consent/suppression evidence contains no raw email address and remains so a withdrawn or deleted user is not marketed to again. Cancel an active subscription in the billing portal first.
The current paid implementation targets seven years for minimized, detached billing evidence and physical deletion of inaccessible private result objects within 30 days. Those periods, along with retention for consent receipts, suppressions, research requests and analytics records, still require operator and counsel approval before the affected production features are enabled.
Contact
Questions about a hosted TopoDesigner deployment should be directed to its operator. For the reference deployment, contact hello@hello.topodesigner.com.