Data deletion
Delete your data and your MapMinter account
This page is about MapMinter, the coverage mapping app for MeshCore LoRa networks, and about the MapMinter service at mapminter.com that the app uploads to. If you have used the app and want the data tied to you removed, write to us and we will remove it. This page says exactly how to ask, what goes, what stays, and how long it takes.
Send one email to [email protected]
Write to [email protected] with the subject Data deletion, and name your wallet address or your node. We answer every request within 30 days.
How to ask for deletion
-
Write to [email protected]
Use Data deletion as the subject, so the request is not read as an ordinary question. Any email address works: it does not have to be one you have used with us before, because we have never asked you for one.
-
Say what to delete: your wallet address or your node
Give at least one of these, so we can find your data and delete nobody else's:
- Your wallet address, the one that begins with meshr. You can read it in the app, on the Wallet tab. This is the identity everything of yours hangs off, so it is the most complete way to ask.
- A node identifier, if you are asking about a device rather than about a wallet. That is the short public identifier the app and the map show beside the node name.
-
Say whether you want everything, or one node
Write delete everything for the whole wallet and every device bound to it, or name the single node if that is all you mean. If you write nothing about scope, we will ask before deleting rather than guess.
-
We may write back once, to be sure it is you
A wallet address is public, so an email naming one is not proof that it is yours. If the request is not obviously yours, we will ask you for one signature from that wallet, or for something only its holder could know, before we delete anything. Deleting on the word of a stranger would be the worse failure of the two.
-
Deletion within 30 days, and a note back when it is done
We confirm the request when we read it and we finish it within 30 days of the day you asked. When it is done you get one more email saying what was deleted and what remains, in the terms below.
What gets deleted
On a request for the whole wallet, all of the following goes, permanently, from the service at mapminter.com:
- Your measurements, positions included. Every raw measurement uploaded under your collector: the position where reception happened, the signal metadata, the radio settings, the packet hash, the device model and the time. This is the location data on this service that is tied to you, and it is the point of the whole request.
- Your collector and its profile. The collector record itself, its display name, the name that appears on the contributor board, and its link to your wallet address. Your name comes off the board with it.
- Your message receipts. The record of which operator messages were delivered to you, which you read and when, and which you hid.
- Your device binding records held on the server. The bindings that say a node is yours, the signatures collected during the binding ceremony, and the pending queue entries that had not reached the chain yet.
- Anything else keyed to your wallet address in the service database, such as reward tallies and any moderation notes about your collector.
A request about a single node deletes that node's binding and the measurements attributed to it, and leaves the rest of your wallet alone.
What stays, and why
Two things cannot honestly be promised away, and it is better to read that here than to find it out afterwards.
- Aggregated H3 cells on the public map may remain. The public map serves coverage folded into hexagonal cells: strongest and mean signal, sample count, when the cell was last heard. A cell carries no wallet address, no collector and no raw position, so it is not a record of you by itself. Where your measurements were the only ones in a cell, that cell is a record that somebody was there, and if that is what you are asking about, say so in the email and name the area: we can drop those cells too, we just do not do it silently for every request, because it also removes coverage other people rely on. The reasoning is the same one the privacy page gives: aggregation is not anonymisation.
- On-chain binding records cannot be deleted by anybody. A binding that was already submitted to the MapMinter test chain is written into an append-only ledger. Nobody can remove it, us included: that is what the chain is for. We delete our own copy and the link between that record and everything else about you, and the on-chain entry stays as a public transaction. It contains a wallet address and a node identifier, and no position and no measurement.
The web server also keeps ordinary request logs, which rotate on their own schedule and are not part of the record we can look you up in. Beyond that, the retention of raw measurements in general is not on a fixed window yet, which is why asking is what deletes them today.
There is no delete button in the app yet
Being plain about it: deletion is a manual job done by the operator, on request, by email. There is no self-service button in the app or on this site that does it for you, and we would rather say so than describe a process that does not exist. When there is one, this page changes first.
About the account itself
MapMinter has no account in the usual sense: no username, no password, no email address on file. Your wallet is the whole identity, its private key lives on your phone and we have never had it. So closing the account is two separate things, and you may want both:
- On the server: the request above, which deletes everything held under your wallet address.
- On your phone: uninstalling the app removes the app's own storage, the wallet key included. If you have no backup of the recovery phrase, that key is gone for good and the wallet cannot be brought back, so export the phrase first if there is any chance you want it later.
Self-hosted instances are somebody else's to delete
Everything here describes the instance at mapminter.com. MapMinter is built to be self-hosted, and if you contributed to somebody else's instance, that operator holds that data and is the one to ask.