RestopRestop
Open the map

Privacy Policy

Last updated October 10, 2026

Restop is a map of public bathrooms, water fountains and porta potties, with ratings and door codes from the people who use them. It is made by JC Technologies LLC. This page says what we keep about you, what we never keep, who else sees any of it, and how to delete it. The data is yours: we store it to make the app work, we do not sell it, and we do not use it to train AI models.

Browsing needs no account

The map, places, ratings and tags work without signing in, on the web and in the app. A request to our servers carries your IP address, as every request on the internet does. Our host uses it to limit how often one address can call us and keeps it in its request logs for a short time; we do not store IP addresses in our own database. When our servers hit an error, the report records the route and method of the request and nothing else: no body, no position, no token.

When the iPhone app crashes or hits an error it sends a report. The report carries the device model, iOS version, app version, language and time zone settings, memory and connection state, an identifier for the install that is not tied to your account, the names of the screens and buttons used just before, and the code trace. It carries no account, no position and nothing you typed, and the address it was sent from is discarded.

Your location stays on your device

With your permission the app uses your location to show where you are, to sort places by distance and walking time, and to say when you are at a place you are rating. Location is read while the app is open. When the app asks our servers for nearby places it sends the coordinates of that one request, which we answer and do not store or log. A rating, report or answer you post while at a place records only that you were there, never where. Adding a place records the place’s position, which is public map data, not yours.

Your account

You sign in with Apple, Google or an emailed code; there are no passwords. We keep the email address or Apple sign-in identifier that comes with it (Apple’s private relay address, if you chose to hide yours), and the name Apple offers on a first sign-in. On your first contribution you choose a public handle and whether your name shows by default, and you declare your age range; nobody under 13 may create an account.

Your profile is public under your handle: handle, level and badges, points, the number of places you rated, added and confirmed, and the ratings you posted with your name shown. Your email, name and age range are never public. You can leave the weekly city leaderboards in Settings.

What you post

  • Ratings (a word, tags and an optional comment), facts about a place, places you add and “Still there?” answers are public. You choose per post whether your handle shows or the post is name-hidden.
  • Door codes are shown only to signed-in people, one place at a time, and never appear in shared links, previews or the open-data export. A business can have its codes taken down (see Support).
  • Reports you file and contributors you block are private to you and our moderators.
  • Lists are private unless you make one public by link; follows are visible to the people involved.
  • Points are earned for contributions and reversed if moderation removes them.

Facts about places (what and where, hours, access) are shared back to the community under the Open Database License as part of our weekly open-data export, with no account information. Ratings, comments and codes are never exported. See Data and attribution.

Inside other apps

Restop can run inside another app (Athlon, also ours). There your Restop account is linked to that app’s account by its user id only: we never match or link by email, and nothing else from the host app is kept. Signing out of the host signs you out of Restop in it; deleting your account there deletes your Restop account.

Notifications

If you say yes when the app asks, after your first contribution, we keep your device’s push token and send exactly three kinds of notice: your code was confirmed, your place was confirmed, someone followed you. Nothing is sent for marketing or based on your location. Turn them off in iOS Settings at any time, or sign out, and the token is removed.

Keeping the app honest

On iOS, Apple’s App Attest ties your install to a key in your device’s Secure Enclave. We keep that key’s identifier and public key so we can tell a genuine copy of Restop from a script, and every post you make is signed with it. Apple describes this as a device identifier; it does not identify you to anyone else.

We also count how often an account posts, reports and looks up codes, to stop abuse. Those counts are deleted after two days.

Who else is involved

  • Supabase hosts our database and sign-in, and Vercel hosts the website and API, in the United States.
  • Apple provides the map, Look Around, sign-in, notifications and App Attest in the iOS app, under Apple’s own privacy terms.
  • Google provides Street View on the website and, where offered, sign-in; CARTO and MapTiler provide the website’s map tiles, satellite imagery and address search. Loading those sends your IP address and the map area you are looking at to them.
  • Sentry receives the error and crash reports described above.
  • OpenStreetMap is the source of most places; see Data and attribution.

We do not use advertising networks or analytics trackers.

Deleting your account

Delete your account in Settings, in the app or on the website, at any time. That deletes your profile, your ratings and comments, the codes you added, your follows, lists, points, reports, blocks and push tokens, and revokes your Sign in with Apple token. Places you added stay on the map with no link to you, and so do your confirmations of other people’s codes. Anything waiting to send while you were offline stays only on your device until it goes.

Changes and contact

When this page changes we update the date at the top. Questions about your data go to support@restop.app.

CitiesData and attributionPrivacyTermsSupport