Privacy
Last updated October 4, 2026
Who is responsible
Arne Kellmann
Odenwaldstr. 134L, 64372 Ober-Ramstadt, Deutschland
In short
- Loonaut sets one cookie, and only after you choose to sign in with a passkey.
- Loonaut has no analytics and no advertising.
- Fonts, icons and the service worker come from our own domain.
- The only third-party script is Cloudflare Turnstile. It loads only when you send a confirmation, a report or a correction, or when you create an account.
- You need no account. An account is optional.
Your position and your search
To find a toilet, your browser sends your position to our server. It rounds the position to about 10 metres first. The map sends the area that you see, as a box of coordinates. A place search sends the text that you type.
We use this data to answer the request. Our code does not write it to a database.
The request address contains the data. Our hosting provider (see below) processes request addresses to deliver the page and to protect the service.
Cloudflare keeps a sample of the request logs and traces for 7 days. The sample includes the request address with your position, the map area or the search text. We use the sample to find errors.
Legal basis: Article 6 (1) (f) GDPR, our interest in a safe and working service.
Data on your device
Loonaut saves the data below in your browser. It never leaves your device. Clear the site data of your browser to delete it.
- loonaut.pos: last position, 30 minutes
- loonaut.last: last result, for offline use
- loonaut.filters: filter choice
- loonaut.lang: language choice
- loonaut.account: marks a signed-in browser, so it skips the human check
- loonaut.device: a random number that makes your corrections and ratings count once
- loonaut.confirmed: the toilets that you confirmed today, so the question does not come back
- loonaut.ratings: your cleanliness ratings, so you can see and change them
The service worker keeps copies of pages that you open, so they work offline. It does not keep positions, search texts or API answers.
Legal basis: Article 6 (1) (f) GDPR and section 25 (2) no. 2 TDDDG. The storage is strictly needed to give you the service that you ask for.
Hosting
Cloudflare, Inc. (US): hosting, content delivery, database and file storage. Cloudflare may process the IP address and the request.
Cloudflare may process data outside the EU. The transfer rests on the data processing terms of the provider.
Place search
When you search for a place, our server sends the search text to Nominatim. The OpenStreetMap Foundation (United Kingdom) runs Nominatim.
Our server sends the request. Your IP address does not go to Nominatim.
We store a hash of the search text and the found position for 30 days. We do not store the search text.
Legal basis: Article 6 (1) (f) GDPR. The United Kingdom has an adequacy decision of the EU Commission.
Confirmations, reports and corrections
You can confirm that a toilet is still there, rate its cleanliness and report a problem. You need no account and give no name.
You can also correct the facts about a toilet: access, fee, wheelchair access, changing table, who can use it, opening hours, name, operator and whether it still exists. Each correction is a vote. You have one vote per field, and a new vote replaces your old one. The value that most people vote for replaces the value from OpenStreetMap. A moderator decides whether a toilet still exists. The toilet page states the rule.
A cleanliness rating works like a vote, but without a majority rule. You have one rating per toilet, and a new rating replaces your old one. The average on the toilet page counts each person once.
Your browser makes a random number once and keeps it as loonaut.device. We store only a hash of this number and of the toilet with your vote or your rating. So the same browser can change its vote, but cannot vote twice. Nobody can follow your browser from one toilet to another. The hash tells us nothing about who you are. We store no IP address with a vote.
A vote counts for 24 months. Then we delete it. We also delete a rating after 24 months. The counted result stays, without any key.
When you confirm a toilet, your browser remembers it for the rest of the day in loonaut.confirmed. It shows your cleanliness rating in loonaut.ratings. Both stay on your device.
We store what you send, and no address. The list below shows each stored item and how long we keep it.
- toilets: Toilet data from open sources, with counters for confirmations and ratings. Kept.
- places: Places from OpenStreetMap (countries, regions, cities, districts, stations and landmarks) with toilet counts. Kept.
- toilet_places: The places that each toilet belongs to. Kept.
- place_names: Search keys for place names. Kept.
- rate_limits: A hash of your request address, the action and the time window. It limits how often you can send. Deleted after 2 days.
- geocode_cache: A hash of a place search and the found position. Deleted after 30 days.
- confirmations: The toilet and the time. Older rows also hold a cleanliness rating from 1 to 5. No address, no name. Deleted after 365 days.
- reports: The toilet, the kind of problem, your note, the time and the OpenStreetMap note number. No address, no name. Deleted after 365 days.
- submissions: A proposed toilet: position, name, access, fee, opening hours, wheelchair and changing table facts. It also holds your note and the review state. If you are signed in, it holds your account identifier. Deleted after 365 days.
- toilet_votes: Your correction of a fact about a toilet, or your cleanliness rating: the toilet, the field, your value, the time and a voter key. The key is a hash of a random number in your browser and of the toilet. If you are signed in, the key is your account identifier. No address, no name. Deleted after 730 days.
- toilet_resolved: The value that most people chose for a fact, with the number of votes. No personal data. Kept.
- toilet_effective: The same values in one row per toilet, for fast reads. No personal data. Kept.
- admin_audit: Each moderation decision: the email address of the moderator, the action, the target, the reason and the time. Deleted after 730 days.
- accounts: A random identifier and the creation time. No name, no email address. Kept.
- passkeys: The public key of your passkey, its name, its use counter and the times of creation and last use. Kept.
- auth_sessions: A hash of your sign-in token, your account identifier and the times of sign-in and expiry. Deleted after 30 days.
- passkey_challenges: A one-time challenge for a passkey sign-in or registration, and its expiry time. Deleted after 1 day.
The database has a daily backup in private storage. We keep seven backups. A row that we delete leaves the backups within a week.
A report about a toilet from OpenStreetMap can become an anonymous OpenStreetMap Note. The note holds the position of the toilet and your text. It is public. The OpenStreetMap Foundation (United Kingdom) runs the service.
You can also propose a new toilet. A moderator reads every proposal before it goes live. A report about a toilet from OpenStreetMap goes to OpenStreetMap at once, and a moderator reads it later. Do not write personal data in a note. A filter hides spam.
Moderators sign in through Cloudflare Access. The audit log stores the email address of the moderator for each decision.
Legal basis: Article 6 (1) (f) GDPR, our interest in correct toilet data and in protection against abuse.
Optional account
You may create an account with a passkey. The account has no email address and no name. Your device holds the private key.
A signed-in account skips the human check. Your confirmations, reports and votes then carry your account identifier. Nobody else sees it.
After sign-in we set the cookie below. It keeps you signed in.
- __Host-loonaut_session: keeps you signed in. Deleted after 30 days.
On the account page you download your data as a JSON file and delete the account. Deletion removes your passkeys and sessions. Your confirmations, reports and votes stay as anonymous data, because they are facts about toilets.
Legal basis: Article 6 (1) (b) GDPR for the account that you ask for, and section 25 (2) no. 2 TDDDG for the cookie.
Human check
Before we accept a confirmation, a report, a correction or a new account, Cloudflare Turnstile checks that you are a person. Your browser loads a script from challenges.cloudflare.com for this. Cloudflare may process your IP address and browser data.
The script loads only when you send. We check the result on our server.
Legal basis: Article 6 (1) (f) GDPR, our interest in protection against automated abuse.
Map data
Toilet data comes from OpenStreetMap contributors and other open sources. Loonaut loads no map from a third party. A link to OpenStreetMap or to a maps app opens that service. Its own privacy terms then apply.
Business partners
A signed-in account can claim a toilet for a business and buy a Verified Partner listing. You need no account to find a toilet. This section applies only to a claim and a purchase.
A moderator reads each claim. The claim holds the data of the list below. We use it to check that you may act for the business.
- partner_listings: Your claim: the toilet, the business name, your email address, an optional phone number, website and note, the account number, the decision and the time. Deleted with the account.
- partner_billing: The Stripe customer number and subscription number, the tier, the status and the end of the paid period. No card data. No invoice. Deleted with the account.
- partner_profiles: What you enter for visitors: the conditions, the opening hours and the live switch, with the time of the last change. Visitors see it while your plan runs. Deleted with the account.
- stripe_events: The number and the time of each Stripe event that we processed. No personal data. Kept.
When you buy, your browser goes to the Checkout page of Stripe. Loonaut loads no script of Stripe. Stripe collects your payment data, billing address, VAT ID and email address, and it issues the invoice.
Stripe Payments Europe, Ltd. (IE) runs the payment. Stripe may process data in the USA. The transfer rests on the terms of the provider. We receive no card number.
The approved business name and the tier show to every visitor as the label Verified Partner beside the toilet. The conditions, the opening hours and the live switch that you enter show too. Nobody sees your email address, phone number or note.
Invoices stay at Stripe for the period that tax law sets.
Deleting the account removes the claim and the billing data. A running subscription blocks the deletion. Cancel it in the billing portal first.
Legal basis: Article 6 (1) (b) GDPR for the contract, Article 6 (1) (c) GDPR for tax and accounting duties, and Article 6 (1) (f) GDPR for the review of claims and the protection against false claims.
Your rights
You may ask for access, correction, deletion, restriction and transfer of your data. You may object to processing that rests on our interest. You may complain to a data protection authority.