Privacy policy
Last updated: 2026-09-09
DanskThe short version
- Finding a toilet needs no account, no cookie and no consent. Search, filters, facility pages and reports work with everything else switched off.
- We collect the minimum. Your precise position is used in memory to sort nearby results and is never stored.
- No analytics or advertising runs unless you explicitly consent — and even then it is coarse and documented.
Your location
“Use my location” reads your position only after you press that button; the browser then asks for permission separately. The position is used in memory to find and sort nearby toilets for that one request and is then discarded — not written to any database, not logged, not sent to analytics, and not embedded in shareable URLs. URLs carry place queries and facility identifiers, never coordinates.
Reports
Reports are anonymous: no account, no session, no cookie is created. What we store per report:
- The issue categories you ticked and, if you wrote one, the sanitized free-text description.
- An optional email address, used only for moderator follow-up on that report. It is never published, never shown in routine administrative lists, and never sent to analytics.
- A hashed anti-abuse identifier: your network address is never stored raw — only an HMAC-SHA256 hash, truncated to 16 hexadecimal characters, computed with a secret we rotate periodically (rotation deliberately de-links historical submissions). Your browser is recorded only as a coarse family summary such as “iOS Safari 17”.
- Abuse limits: at most 5 submissions per 10 minutes per hashed address, and identical duplicate reports (same facility and categories) within one hour are quietly collapsed.
Photos
Photo submission is a separately switchable feature; when it is on, this is the contract:
- Uploads are private until a moderator approves them: they sit in a private storage bucket and are only reachable through this site after approval.
- Metadata (EXIF and similar) is stripped from JPEG and PNG files before anything is stored. WebP files cannot be fully stripped without re-encoding — the metadata flags are cleared, but please do not include people, licence plates or documents in any photo.
- Rejected uploads are deleted immediately — only the moderation decision record remains, without the image bytes.
- Takedown: write to privacy@publictoilet.dk with the page or photo address and we remove it. Already-cached copies may linger in CDN caches until they expire; the origin stops serving the photo immediately.
- Submitted photos are never used to train AI models or for marketing.
Server logs
Our logs are single-line structured events: timestamps, routes, durations, statuses and correlation identifiers (request, report, facility). They never contain coordinates, report free text, email addresses, upload filenames or raw user content — the logger structurally redacts or drops those fields. Logs are kept for a limited operational window for debugging and abuse detection and are not used to profile visitors.
If you volunteer an email with a report — and only then — we send exactly one receipt through our email provider Maileroo, and only while the email feature is enabled on the deployment. Emails carry no open or click tracking. The receipt deliberately excludes your report text; it contains the facility name and a report reference id. Our logs record only your email’s domain, never the full address. Moderators may receive a new-report alert containing the facility and the issue categories — never your description.
Analytics and advertising
Analytics and advertising scripts are absent by default. They load only when the deployment’s feature flags are switched on AND you have consented, and refusing is exactly as easy as accepting. Measurement is coarse — pages, languages and outcomes, not individuals; report text, email addresses, precise coordinates and upload filenames never reach any analytics provider. The cookie page lists the categories and vendors in detail.
Your choices and contact
You can change or withdraw consent at any time (see the cookie page). You can block all cookies and site storage — the toilet finder keeps working. To have a report’s email address or an approved photo removed, write to privacy@publictoilet.dk; include the report reference id from your receipt or the photo’s page address. We handle deletion requests for content you can identify; we cannot look reports up by person, because we deliberately store no personal identities.