PROJECT LEMONADE
PRIVACY
Release 0.9 draft — publication requires owner approval.
Lemonade uses Clerk for sign-in and Supabase for your private saved places, Instagram source references, tags, notes, import inbox, and outing plans, and private visit history. Public Instagram metadata and Google Places help match the places you choose to save.
Optional read-only sharing
Plans stay private until you choose to enable a sharing link. Before enabling it, review the separate public title, the place names and optional locations you write, their order, and available Google Maps links. These public fields are not automatically filled from your private plan title or imported provider text. Only enter information you intend anyone with the link to see.
Anyone with the link can view and forward it without an account. Changes to the plan and its public details appear on the next retrieval. Adding a place without a public name makes the shared page unavailable until that name is supplied. Private notes, journals, ratings, visit dates, tags, favorites, saved-place status, account details and Instagram sources are not automatically included.
Disabling or replacing a link prevents future retrieval using the old link. Deleting a plan or your account invalidates its links; deleting a saved place removes it from shared output. These actions cannot remove content already displayed, screenshots or copies made by others. Treat sharing links as sensitive: browsers, clipboard tools and the messaging services you choose may retain them.
Loading shared content does not request new Instagram or Google Places data. Opening an external Google Maps link sends the destination to Google under its own privacy policy. No public-view analytics are added. Hosting providers process network requests and may retain operational or security records, including request or response data. Provider access and retention settings must be reviewed before this draft's sharing feature is published.
Your private visit journal
Visits contain a calendar date, an optional personal rating and reflection, creation/update timestamps, and the device time zone used for date validation. Logging a visit does not request location or contact Google or Instagram. Journal data belongs to your account. Deleting a saved place removes its visits; deleting your account removes all visit history. Sign-out and account changes clear journal data held in app memory.
Optional map and nearby features
Opening Map does not request your device location or resolve place coordinates. You deliberately load up to 20 eligible saved places. Google receives the stored Google Place IDs through our server to resolve positions; device location is not included in these requests.
Foreground location is requested only after you choose Near me / use my location. Approximate permission is accepted. A single fix is held in memory and used locally to calculate approximate straight-line distances. There is no background location, continuous tracking, location history, home/work inference, or route calculation. The current fix is discarded when it expires, on sign-out, on account change, and when the process ends.
Resolved place coordinates are also kept only in memory during your account session. Device coordinates, accuracy and derived distances are not written to our database, local preferences, files, exports, analytics or error reports.
The Google Maps SDK contacts Google to render maps and may process network/device information and map interactions under Google's policies. Keeping Lemonade's location calculation local does not mean the map renderer is offline. External Google Maps directions may use location according to the separate Google Maps application's permissions.
Operational records and deletion
We retain short-lived daily map-attempt counters containing the UTC date, user identity, count and update time, plus a project-wide counter. They contain no place identifiers or location. Rows older than two UTC dates are removed opportunistically on the next reservation; without further usage, cleanup waits until the next reservation. Account deletion removes your user-scoped counters and private product records; the project-wide aggregate remains.
Portable export uses schema 6 and includes complete visit history, including dates, ratings, reflections and validation time zones. The temporary copy is removed after the share sheet closes. Copies saved elsewhere remain under your control. It contains your product data, not coordinates, device location or operational abuse-prevention counters. Account deletion instructions.
Sharing uses separate project-wide usage counters and short-lived account-scoped counters for owner actions. They contain no sharing tokens, public titles, place details or device location. Today and yesterday's sharing counters are retained; older counters are removed on the next sharing reservation. Account deletion removes your account-scoped sharing counters. Aggregate project counters remain.
Diagnostics
PostHog records allowlisted actions; Sentry receives scrubbed technical failures. Map telemetry contains no location, distance, viewport, place IDs, names, addresses, tags, notes, search text, credentials or provider responses. Permission denial is not an application error. Journal telemetry contains only bounded actions and outcomes, never reflections, ratings, dates, time zones, visit or place identifiers.
Map features are subject to the Google Privacy Policy. See our Terms of Use.