Privacy policy
Last updated: 19 July 2026
The short version. Quick Topo is designed to work without an account. The topos you create stay in your own browser and are never sent anywhere until you choose to share, back up or sign in.
We don't use advertising, we don't sell your data, and there are no third-party analytics or tracking cookies on the site.
This policy explains what data Quick Topo ("we", "the site") handles, when, and who else is involved. It covers the site at quick-topo.app.
1. Topos stored in your browser
When you make a topo, it is saved locally in your browser's storage on your device — the crag photo(s), the climbs you draw, grades, descriptions, notes and settings. This data stays on your device and is not transmitted to us. Clearing your browser storage (or using private browsing) removes it, so treat the browser as working storage, not a backup.
We also store a small preference in your browser's local storage for your chosen light/dark theme.
2. Topos you share or back up
If you use Share & back up, a hosted copy of that topo is created on our servers so it can be viewed by link, synced across your devices, and recovered if you lose your device. The hosted copy contains the topo's content, which may include:
- The crag photo(s) you added (and reduced-size preview and thumbnail versions we generate). Photos can contain embedded metadata such as GPS coordinates; the app also reads GPS from a photo, in your browser, to offer to pre-fill the crag location.
- The climbs you drew and their details (names, grades, star ratings, lengths, first-ascent and description text).
- Crag information you entered — the topo title, crag and parking coordinates, approach and access notes, external links, and tags.
Each shared topo has a private edit link. The secret in that link is what grants editing; we store only a one-way (SHA-256) hash of it, never the secret itself, and it is not included in the addresses your browser sends to our servers. Anyone you give the edit link to can edit the topo, so share it carefully. You can invalidate it at any time with Rotate edit link.
When a shared topo changes, we keep a short version history (at most one snapshot every 10 minutes, and only the newest 20) so an older version can be restored.
3. Making a topo public
A shared topo is private by default (reachable only by its link). If you tick List publicly, that topo — its photo, climbs and crag information — becomes publicly visible on the Quick Topo home page and the /topos directory, is included in our sitemap, and can be indexed by search engines. If you are signed in, you can optionally show a "by <name>" credit using your display name. You can make a topo private again, or delete it, at any time.
4. Accounts (optional)
You can optionally create an account so your topos follow you across devices. We use passwordless magic-link sign-in, so we store:
- Your email address (used to send sign-in links and to identify your account).
- Your display name, if you set one, and your saved preferences (theme, preferred length units, and default topo settings).
- Sign-in and session tokens, stored only as one-way hashes. Sign-in links are single-use and expire after 15 minutes; sessions expire after about 90 days of inactivity.
Sign-in emails are sent through Cloudflare's email service (see §8). We do not use your email for marketing.
5. Cookies & local storage
We keep cookie use to the minimum needed to run the site:
- A session cookie (
qt_session) is set only when you sign in, to keep you signed in. It isHttpOnlyandSameSite=Lax. - Browser local storage holds your local topos and your theme preference, as described above.
- The bot-check widget (see §8) and, for site administrators, Cloudflare Access may set their own cookies needed for those functions.
There are no advertising or cross-site tracking cookies.
6. Preventing abuse
To protect the service from spam and abuse:
- Your IP address is used for short-lived rate limiting when creating topos and requesting sign-in links.
- Creating a shared topo and requesting a sign-in link are protected by Cloudflare Turnstile, a privacy-respecting bot check. Verifying it sends the challenge token and your IP address to Cloudflare.
- If someone uses Report this topo on a public topo, we record which topo was reported, the time, and the reporter's IP address, so we can review it.
7. Maps & location
When you open the map picker or view the home-page map, map tiles are loaded from OpenStreetMap (tile.openstreetmap.org); as with any embedded map, that provider receives your IP address in order to serve the tiles. "Open in maps" links point to Google Maps, and are only followed if you click them. GPX waypoint files are generated in your browser.
8. Service providers
The site runs on Cloudflare, which hosts the application and stores its data on our behalf: the app and API run on Cloudflare Workers, topo and account records in Cloudflare D1, uploaded images in Cloudflare R2, sign-in emails via Cloudflare's email service, bot protection via Cloudflare Turnstile, and administrator access via Cloudflare Access. Cloudflare processes this data as our infrastructure provider. We do not use third-party analytics, advertising, or social-media tracking.
9. Keeping & deleting data
- Local topos: you control these — clear them from your browser at any time.
- Shared topos: use Delete share to remove the hosted copy, its images and its version history from our servers.
- Version history is automatically limited to the newest 20 snapshots per topo.
- Sessions expire automatically; you can also sign out to end a session.
- To delete your account and associated data, contact us (see §12).
10. Children
Quick Topo is a general-audience tool for climbers and is not directed at children. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy as the site evolves. Material changes will be reflected here with a new "last updated" date.
12. Contact
For any privacy question, or to request deletion of your account, contact us at privacy@quick-topo.app.