Privacy Policy
Last updated: July 23, 2026
Who operates PocketWorld
PocketWorld is an independent project. In this policy, "PocketWorld", "we" and "our" refer to the PocketWorld project team. A public project email address has not been launched. The current contact channel for privacy questions and deletion requests is the Feedback form in the application footer.
Data used to provide the service
Like every website, our server receives an IP address, request time, requested URL, browser user agent and basic network metadata when it answers a request. We use this information to deliver pages and API responses, protect the service from abuse, diagnose failures and estimate a coarse country or city when a location-aware feature is requested. IP-based location is approximate and is never a substitute for device GPS.
Essential browser storage keeps choices that the user asks PocketWorld to remember, including language, selected mode, favorites, playback state and the consent record. These settings are functional and are not used to build an advertising profile.
OSINT views can be deliberately saved to a local casebook in this browser's IndexedDB. Each entry contains an analyst-written title and note, a permalink, mode, client time, release and build identifiers, record count, completeness and limitations, cryptographic hashes, a public verification key and a signature. The casebook never uploads entries to PocketWorld and never stores raw source records or provider payloads. Its Ed25519 private signing key is non-extractable and remains in this browser. If private browsing or a browser storage policy blocks IndexedDB, the save fails instead of sending the entry elsewhere.
Optional first-party analytics
PocketWorld operates its own analytics endpoint. It is disabled by default and starts only after the user allows analytics in Cookie Settings. When enabled, it can receive a random PocketWorld visitor identifier, a session identifier, page path, referrer, screen size, language, selected mode, interaction names and time on site. We use those records to understand feature reliability, traffic trends and returning use. We do not use Google Analytics.
Rejecting analytics prevents creation of the persistent analytics identifier and prevents analytics requests. Withdrawing consent stops future analytics calls and removes the PocketWorld analytics identifier from browser storage. Cookie Settings remains available from the application footer and the privacy control on mobile.
PocketWorld honors an active Global Privacy Control signal as an opt-out from optional first-party analytics and any future advertising delivery. The browser signal is checked through both the Sec-GPC: 1 request header and navigator.globalPrivacyControl === true. It overrides a previously stored analytics preference, removes the analytics identifier and keeps the analytics control disabled while the signal is active.
Our public analytics APIs expose aggregate counters only. They never return raw IP addresses, visitor or session identifiers, referrer strings, or day-level visitor records. Named source, country, mode and page buckets require at least five recorded events; smaller buckets are merged into an unlabeled other total. This is a publication-minimization threshold, not a claim of k-anonymity.
Messages, donations and affiliate links
When a user deliberately submits feedback, we store the message, submission time, application page, selected mode and interface language so the project administrators can reproduce the report. The form does not request an email address, and its stored feedback record does not contain the visitor's IP address, referrer, screen details or location. A copy may be delivered to the private administrator Telegram bot. Donation interactions store only the action and selected wallet type for aggregate product statistics.
Some flight and travel links may be affiliate links. They are labeled near the action; PocketWorld may receive a commission if a user completes a purchase, without increasing the user's price. Affiliate click notifications contain the requested route or destination, not the visitor's IP address or location.
Service providers and transfers
- IPWho may receive an IP address over HTTPS to return approximate location data. Results are held in a bounded temporary cache.
- Telegram may process feedback text, page, selected mode, interface language and non-personal operational notifications sent to the private administrator bot.
- Public data providers listed in our Methodology supply flight, vessel, weather, disaster, space and media records. PocketWorld normally retrieves and caches these records server-side.
- Google AdSense may be used only after site approval and a compliant consent flow. Publisher ad delivery is currently suspended.
Providers may process data in countries outside the user's residence. Where required, we rely on the safeguards and terms offered by those providers and limit the data sent to what the feature needs.
Advertising cookies
If advertising is enabled in the future, third-party vendors, including Google, may use cookies to serve ads based on a user's prior visits to PocketWorld or other websites. Google's use of advertising cookies enables Google and its partners to serve ads based on those visits. Users can opt out of personalized advertising through Google Ads Settings or use AboutAds choices for participating vendors.
For users in the EEA, the United Kingdom and Switzerland, PocketWorld will use a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework before requesting personalized advertising. The application's first-party analytics choice is not presented as advertising consent.
Legal bases and retention
Essential processing is based on providing the requested service and our legitimate interests in security and reliability. Optional first-party analytics is based on consent. Feedback is processed to review the user's report. Browser preferences remain until the user clears them. Local casebook entries remain until the user deletes them in the casebook or clears this site's browser data; casebook import and export happen only when the user requests them. Analytics records are retained for no longer than 26 months. Website feedback is limited to the most recent 200 records, expires after no more than 180 days, and may be deleted earlier. Temporary IP-location cache entries and operational logs are kept for shorter periods needed for reliability and abuse prevention.
Your choices and rights
Depending on applicable law, users may request access, correction, deletion, restriction or export of personal data, object to processing, or withdraw consent. Withdrawing consent does not affect processing that was lawful before withdrawal. Use Cookie Settings for analytics withdrawal and the Feedback form in the application footer for other requests. Because the form does not collect a reply address, include a non-sensitive way to identify the relevant submission if a response is required.
Children and policy updates
PocketWorld is a general-audience information service and does not knowingly collect personal information from children under 13. If a parent or guardian believes a child submitted personal information, contact us for removal. We may update this policy when features or providers change; the page will show the current revision date.
Data right now
Current API records available to each mode. A globe may render a smaller performance-limited subset and labels that distinction explicitly.