Project AirTag
PRIVACY
Privacy information
This notice explains in detail how Project AirTag handles personal data, which choices you have, and when an external provider is contacted.
Last updated: 6 August 2026
1. Who is responsible?
Controller
Max Jahn
Sachsdorfer Weg 4
01723 Wilsdruff
Germany
Contact
max-jahn.2210@web.de
+49 176 81201241
The controller decides why and how data are processed for this website. For questions about this notice, your data, a published entry or a request under data-protection law, please use the contact details above.
2. What Project AirTag is
Project AirTag is a public travel archive about three small travelling AirTags. It presents selected journey pings, routes, country names, dates, stories, photos and “moments”. It is not a social network, does not offer visitor accounts, does not accept public comments, does not send newsletters and does not use advertising technology.
Data published in the archive are chosen by the operator. A journey entry can include a location, a time, an associated person’s name if chosen by the operator, a country flag, a short story and/or a photo. The archive may therefore contain personal data if the operator deliberately links an identifiable person to a journey entry. The operator is responsible for ensuring that a publication is permitted before it goes live.
3. Public locations and privacy protection
Exact places are not automatically public. A ping can be marked private in the administration area. For a private ping, the public website does not receive the exact coordinate. Instead, it receives a deliberately altered point and a displayed region of 3 km. The public point is offset from the real coordinate; it is not the centre of the displayed area. This is designed to make reverse-engineering the exact location materially harder.
Only authorised administrators can access the precise coordinate of a private ping. Non-private pings are intentionally presented with their stored exact coordinate. The “latest location” follows the same rule: it is exact only when the operator has not marked that current ping as private.
4. Your map choice: consent before map content
The interactive map is optional external content. The site does not load map tiles until you make a choice in the consent dialog. The dialog is phrased playfully as Taggie asking for a “map cookie”, but the choice is real:
- Only essential crumbs: external map content remains disabled. The map area shows a privacy-friendly placeholder and no map-tile request is made.
- Give Taggie a map cookie: your consent is stored locally in your browser and the interactive map is loaded.
You can revisit the choice through the privacy button in the public site header. If you withdraw consent, the page reloads without the external map. The legal basis for loading map content after approval is consent under Art. 6(1)(a) GDPR. Refusing it has no effect on the rest of the public page beyond the unavailable map interaction.
5. Map providers and data transmitted to them
After consent, the interactive Leaflet map obtains map tiles from OpenStreetMap and, where configured by the operator, MapTiler. To answer a tile request, a provider necessarily receives your IP address, the requested tile address, browser and device information sent with the request, date/time and potentially the referring page. These providers may create server logs under their own responsibility.
Project AirTag does not send the journey’s exact private coordinates to the browser or to a map provider. The map receives only the public data described above. The providers’ own notices apply in addition to this notice:
6. Cookies, local storage and similar technologies
Project AirTag uses no advertising cookies, no marketing pixels, no social-media tracking pixels and no separate visitor analytics service. It uses the following small, functional pieces of storage:
| Storage item | What it does | Basis and duration |
|---|---|---|
journey.mapConsent | Remembers your decision about external map content. | Consent, Art. 6(1)(a) GDPR; stays on your device until you change it or clear browser data. |
| Theme, map view, base layer and playback settings | Keeps the interface comfortable and restores choices such as dark mode and playback speed. | Functional storage / legitimate interest, Art. 6(1)(f) GDPR; stays only on your device until cleared. |
| Admin session and CSRF cookie | Authenticates an authorised administrator and protects changes from forged requests. | Necessary for secure administration, Art. 6(1)(b) and (f) GDPR; session expires after eight hours of inactivity. |
Local storage is controlled by your browser. You can delete it through browser settings. Removing it may reset your choices and cause the map consent dialog to appear again.
7. Hosting, security and access logs
The site is hosted with IONOS. Each request to a website needs technical processing so the server can return a page securely. IONOS may process the requested file or page, referrer, browser type/version, operating system, device type, time of access and an anonymised IP address. The purpose is operating the website, detecting faults, defending against attacks and maintaining stability. The legal basis is the legitimate interest in a secure and technically reliable service (Art. 6(1)(f) GDPR).
For IONOS Webhosting, IONOS states that these visitor access data are retained for up to eight weeks and that the IP address is processed in anonymised form. IONOS processes hosting data as a processor where applicable. More detail is available in the IONOS Webhosting information.
HTTPS is used for the public site and administration area. Access controls, a password-protected administration area, session expiry and CSRF protection are used to reduce the risk of unauthorised modifications. No security measure can guarantee absolute protection; please do not send sensitive data by ordinary email unless necessary.
8. Photos, uploads and EXIF location metadata
Only authorised administrators can upload images. When an administrator explicitly selects and submits a JPEG file in the administration area, the upload workflow may read its embedded GPS/EXIF metadata in order to prefill the coordinates of the linked photo. There is no automatic scanning of a visitor’s device and the feature does not run before a file is submitted.
The uploaded image, the selected public association and any relevant metadata are stored on the web hosting until the administrator deletes the image or the related journey entry. GPS metadata can reveal a sensitive location. Administrators should check an image and its metadata before publishing it, and should only publish images or people’s names where they have an appropriate basis or permission to do so.
9. Administration area
The administration interface is only for the operator and authorised people. It processes the password-protected session, CSRF token and journey data needed to create, edit, delete, export or publish pings, routes, people, photos and moments. The purpose is preventing unauthorised access and maintaining the archive. The legal bases are legitimate interest in secure administration (Art. 6(1)(f) GDPR) and, where relevant, performance of a contractual or organisational relationship with an authorised administrator (Art. 6(1)(b) GDPR).
No public registration, visitor profile, payment information or user database exists. To protect the administration area and the participation form against automated abuse, the server temporarily stores request timestamps under a one-way hash of the connecting IP address. Login limits expire after 15 minutes; participation-form limits expire after one hour. These records are used only for rate limiting and are not combined with visitor profiles. Failed administrative access may also be technically visible in ordinary server logs.
9a. Participation requests (“Join Taggie”)
The “Join Taggie” button opens a voluntary participation-request form. It is intended only for people who would like to take part in the project, for example by receiving, handing over, hosting or otherwise supporting an AirTag journey. Sending the form is optional. Not sending it has no effect on use of the public archive.
The form requests the following data: full name, email address, telephone number, a full shipping address entered as free text, and optionally a Discord tag. The shipping-address field supports multiple lines, for example street and house number, postal/ZIP code and city, and country. It is requested because a possible future handover or shipment cannot be meaningfully assessed without knowing whether, and where, a participant could receive an AirTag. The optional Discord tag is used only if the applicant chooses to provide it.
Before submission, the form requires an explicit confirmation that this privacy information has been read and that the supplied data may be stored to assess and process the participation request. The legal basis is consent under Art. 6(1)(a) GDPR. Insofar as communication is necessary before entering into an arrangement with a prospective participant, Art. 6(1)(b) GDPR may also apply. Consent can be withdrawn at any time with future effect by contacting the controller; this does not affect processing carried out before withdrawal.
Requests are stored in a protected JSON file on the IONOS hosting account and are visible only to authorised Project AirTag administrators in the password-protected Studio. They are not displayed publicly, included in the public journey API, sent to map providers, sold, used for advertising or shared with unrelated third parties. Access is limited to evaluating the request, contacting the applicant and, if appropriate, organising a potential participation or handover.
Participation requests are retained for up to 12 months after the last meaningful contact, or earlier if the request is withdrawn, rejected or no longer required. If a participation arrangement is made, the relevant contact and shipping information may be retained for the duration of that arrangement and for a reasonable follow-up period where necessary to document a handover, respond to questions or meet legal obligations. Requests can be deleted manually in the Studio when no longer needed.
Applicants should provide only their own contact and address data, keep the optional message free of sensitive information, and avoid including special-category personal data, identity documents, passwords or unrelated information about third parties. If an applicant is under the age at which consent is valid in their jurisdiction, they should involve a parent or legal guardian before submitting a request.
Before submitting, applicants must also confirm that they understand the participation concept. If selected, they are expected to receive the AirTag, make a few photographs with it and pass it on responsibly to the next participant according to the operator’s instructions. Project AirTag intends to cover ordinary shipment costs for the planned handover. This acknowledgement is not a contract, a promise of selection, a guarantee of shipment, a guarantee of costs in every circumstance or an entitlement to participate. The order of the journey depends on practical factors such as route planning, availability, safety, customs and the choices of previous participants; a request may therefore take a long time to be answered, may never result in a handover, or may be declined at the operator’s discretion.
10. Recipients, processors and third-country transfers
Personal data are not sold, rented or used for behavioural advertising. Recipients are limited to providers that are technically necessary for the service:
- IONOS, for web hosting, server operation, file storage and related technical logs;
- OpenStreetMap and, where enabled, MapTiler, only after you have consented to the interactive map.
Map providers may use infrastructure outside the European Economic Area. This can involve an international transfer of technical connection data. Their linked privacy information explains their current safeguards and processing locations. No other deliberate transfer is made by Project AirTag.
11. Retention and deletion
Published journey entries, linked photos and moments remain visible until the operator removes or changes them. Exact coordinates for private pings are retained in the restricted administration archive only for as long as they are useful for maintaining the documented journey. Uploaded files remain until deletion by an administrator. Backups may exist briefly as part of hosting and recovery processes before being overwritten according to the provider’s operational cycle.
Hosting access data follow IONOS’s stated retention period. Local preferences remain solely in your browser until you remove them. Administrative session data are deleted or become unusable when the session expires.
12. Your data-protection rights
Where the GDPR applies, you may request information about your personal data (Art. 15), correction of inaccurate data (Art. 16), deletion (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). If processing relies on consent, you may withdraw that consent at any time with effect for the future. You can withdraw map consent directly in the site’s privacy settings.
You also have the right to lodge a complaint with a competent data protection supervisory authority. To exercise a right or ask for the removal of a published item, contact the controller. To protect everyone’s privacy, reasonable identity verification may be required before a request is fulfilled.
13. Automated decisions and children
Project AirTag does not use automated decision-making or profiling within the meaning of Art. 22 GDPR. It is not directed at children and does not knowingly collect personal data from visitors through registration or forms.
14. Updates to this privacy information
This notice will be revised when data processing changes — for example, if the hosting arrangement, map provider, analytics setup, photo workflow or public features change. The date at the top shows the latest revision.
15. Detailed overview of processing activities
For transparency, the following overview separates the main processing activities on Project AirTag. It is intended to make it easy to understand what happens at each stage of using the website. “Processing” includes collecting, viewing, storing, changing, transmitting, restricting and deleting data.
| Activity | Data categories | Purpose | Legal basis | Recipients |
|---|---|---|---|---|
| Opening a page | Connection and log data; requested resource; browser/device information | Delivering, securing and troubleshooting the website | Art. 6(1)(f) GDPR | IONOS |
| Loading the map after approval | IP address, tile request, browser data and timestamp | Showing interactive map tiles and controls | Art. 6(1)(a) GDPR | OpenStreetMap; MapTiler where configured |
| Viewing the archive | No visitor identity data are intentionally collected by the archive itself | Showing intentionally published journey content | Art. 6(1)(f) GDPR | IONOS; map providers only if enabled |
| Administration sign-in | Session data, technical security data and anti-forgery token | Authentication and protection of editorial functions | Art. 6(1)(f) GDPR; where applicable Art. 6(1)(b) | IONOS |
| Editorial upload | Selected image file, file metadata and optional EXIF-GPS coordinates | Adding or maintaining journey material | Art. 6(1)(f) GDPR; where applicable Art. 6(1)(b) | IONOS |
| Email enquiry | Name, email address, message and information supplied voluntarily | Answering and documenting the request where necessary | Art. 6(1)(b), (c) or (f) GDPR, depending on the enquiry | Email/hosting provider as technically necessary |
16. Categories of data in more detail
Technical connection data. Web requests cannot be answered without a connection between your browser and a server. The hosting environment may therefore process protocol information such as the requested address, request method, timestamp, status code, referral source, user agent, browser version, operating system, device category and an anonymised or truncated IP address. Project AirTag does not try to combine this data with visitor profiles.
Published editorial data. The archive may contain place names, country names, dates, routes, travel narratives, photographs, names selected by the operator and approximate or exact public coordinates. This is content of the archive, not data collected from ordinary visitors. Its public visibility is intentional and should be considered before it is submitted to the operator.
Restricted editorial data. Exact coordinates of a ping marked private, unpublished photo metadata and administrative access data are not sent to the public map interface. They are retained only in the restricted management environment and hosting storage required to operate it.
Communication data. If you email the operator, your message and the information you include are processed to respond. Please do not send special-category personal data, passwords, identity documents or sensitive location information by unencrypted email unless this is genuinely required and you accept the associated transmission risk.
17. Why the site uses legitimate interests
Several technical processes are necessary to run a secure, useful and stable website without building a marketing profile of visitors. These include hosting, server security, maintaining the public archive, keeping backups, preventing unauthorised administrative changes and retaining short-lived technical log data. The operator relies on Art. 6(1)(f) GDPR for these purposes after balancing them against visitors’ interests and fundamental rights.
The operator considers the impact on ordinary visitors low because Project AirTag does not require public registration, does not sell visitor data, does not use behavioural advertising, does not create cross-site tracking profiles and offers a real choice before external map content is loaded. You can object to processing based on legitimate interests under Art. 21 GDPR. The operator will assess the request in light of the particular circumstances.
18. Consent: scope, withdrawal and proof
Consent is requested for the optional interactive map because loading map tiles establishes a direct technical connection between your browser and third-party map infrastructure. Consent is voluntary. It is not bundled with a registration or purchase, and the main archive can still be accessed without it.
The browser saves only the result of the choice locally as journey.mapConsent. The website does not transmit a central consent profile to the operator. You can withdraw consent by using Privacy settings in the site header and choosing the essential option, or by clearing local site data in your browser. Withdrawal does not affect processing that already occurred before it was withdrawn.
19. Map-specific privacy explanation
Leaflet is the software library used to present the map in the browser. It runs on the visitor’s device. Leaflet itself does not provide map data. Once consent is granted, it asks the configured tile provider for the small image tiles needed to draw the visible part of the map. Zooming, panning, changing the base layer or returning to the map can create additional tile requests.
A map provider can infer that a device requested particular map tiles. This may reveal an approximate map area being viewed, but does not tell the provider why that area was viewed or who any journey point belongs to. Project AirTag reduces private points before they reach the browser. It does not forward exact private coordinates as map marker data, route-line data, pop-up data or downloadable public GeoJSON data.
The public export contains the same public coordinate representation used on the map. In particular, a private point is exported as approximate and carries an explicit approximate marker. It must not be treated as an authoritative exact location.
20. Personal data in photos and stories
Images and stories can contain personal data, for example a recognisable face, a name, a distinctive setting, a travel date, a vehicle registration or information about a person’s whereabouts. The operator reviews editorial material before publication and may edit, avoid or remove material where it would be inappropriate to publish it. Nevertheless, contributors should assume that content intentionally published in the public archive can be seen, copied or shared by visitors.
If you believe a photo, story, person reference or location in the archive affects your rights or should be corrected or removed, contact the controller with the relevant URL, description and reason for the request. The operator will review it promptly, taking into account legal obligations, freedom of expression and documentation interests where applicable.
21. Data sources
Visitor technical data originate from the visitor’s browser and network connection. Map data requests originate from the browser after consent. Published journey data originate from the operator, authorised editors, the journey materials supplied to them or technical metadata in a file deliberately selected for upload. Project AirTag does not buy personal data, scrape social networks for profile data, use data brokers or enrich visitor data from third-party marketing sources.
21a. Image credits and attribution requests
Project AirTag intentionally does not publish the names of photographers, contributors, rights holders or private handover participants directly next to each photograph. Publishing those details could disclose the identity, location, relationship or travel history of a private person. This restraint is part of the project’s privacy-by-design approach.
Copyright and credit information for a published image can be supplied on request where available and appropriate. Please contact the controller with the relevant image, moment title or page URL. The operator will balance a legitimate attribution request against the privacy, safety and confidentiality interests of the people involved. A credit may therefore be provided directly to the requester, in an appropriately limited form, or not published publicly where doing so would reveal personal data or create a risk for a contributor.
If you are a photographer, rights holder or depicted person and believe that an image is used without the necessary permission, please contact the controller promptly. Include enough information to identify the material and explain your connection to it. Pending review, the operator may temporarily restrict access to the image where appropriate.
22. No analytics, advertising or social-media tracking
There is no Google Analytics, Meta Pixel, TikTok Pixel, advertising retargeting, fingerprinting script, affiliate tracking technology, newsletter tracker or social-login system on Project AirTag. Links to external providers can still be present, for example in legal notices or map attribution. Clicking one is a deliberate navigation to that provider, which then processes data under its own notice.
The site may use basic aggregate counts derived from the journey dataset itself, such as number of pings, countries, kilometres and travellers. These are calculations about the published archive data and do not analyse individual visitors.
23. Data security, confidentiality and access controls
The administration area uses a password-protected session, expiring authorisation and an anti-CSRF token. Exact private coordinates are withheld from the public API. Public pings marked private are transformed before delivery. File uploads are restricted to specified image formats and size limits. These controls are designed to support confidentiality, integrity and availability.
Access to the hosting account and administration functions is restricted to people authorised by the operator. Passwords should be unique and kept confidential. Administrators must log out on shared devices and should not upload files containing unnecessary sensitive information. The operator may update technical controls when a security issue, software change or operational need makes that appropriate.
24. Links, embedded resources and external websites
This website contains links to external websites, including IONOS, OpenStreetMap and MapTiler information. An ordinary hyperlink does not load the destination until you activate it. Project AirTag has no control over external sites and is not responsible for their content or privacy practices. Once you leave this site, please read the privacy information of the destination.
Map tiles are different from a normal hyperlink: they are optional embedded external resources and are therefore not loaded until map consent has been granted.
25. Requests, objections and response time
Please address requests concerning access, correction, deletion, restriction, portability, objection or consent withdrawal to the controller. Describe the requested action as precisely as possible. If an archive entry is involved, include a link or enough details to identify it. The controller will respond within the statutory period, generally one month under Art. 12(3) GDPR, subject to lawful extensions in complex cases.
Some information may need to be retained despite a deletion request where there is a legal obligation, an unresolved legal claim, a security need, an overriding documentation interest or a need to preserve evidence. If that occurs, the controller will explain the applicable reason where legally required.
26. Supervisory authority
You may complain to any data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or alleged infringement. For the controller’s location, the competent authority is generally the Saxon Data Protection and Transparency Commissioner. Contact details and current guidance are available through the authority’s official website. A complaint is available in addition to, not instead of, contacting the controller directly.
A note from Taggie: the map stays asleep until you invite it in. You can always change your mind in privacy settings.
← Back to the journey