Nemo — Last updated September 28, 2026
The short version: Nemo works without an account. If you choose an account, your places sync through our server. Account analytics are enabled by default, including for existing accounts, and you can turn them off at any time without affecting sync. We do not sell your data or use it for advertising or cross-app tracking.
Your saved places are stored on your device or in your browser. Local-only collections are not included in account analytics. Places leave your device when you use sync, sharing or another feature that sends them.
Accounts are optional. You can sign in with Google, Apple, or email and password using our self-hosted sign-in service. We store your sign-in email, account information and your synced places, categories, and shared-map and followed-map definitions. Definitions may contain the private keys your devices need to update or revoke your shared maps; these keys are not included in analytics.
Nemo does not upload your device’s live location or record a location history. Saved coordinates describe places you chose to save, not necessarily somewhere you live or have visited. Your email is used for account operation and sign-in messages, not marketing. Apple’s Hide My Email is supported.
On the web, your browser stores sign-in tokens and synced data to keep you signed in and support offline use. Signing out removes that browser copy. In the native apps, signing out stops syncing and keeps your local places.
Deleting your account: use Account → Delete account, or our account deletion page. Deletion removes your account and synced data from the active service. Limited deletion markers prevent unexpired sign-in tokens from recreating analytics preferences and keep previously attributable maps and follows excluded from analytics. Backup copies expire through our backup rotation and are not used for analytics.
To understand and improve Nemo, we process account-linked usage and synced collections into internal statistics. This is enabled by default for new and existing accounts. It can include collections you already synced, not just places saved after an update.
Statistics include collection sizes, built-in place categories, cities containing saved places, records marked as imported, accepted sync-write activity, device counts and use of sharing and following. Custom category names are grouped as Custom. We do not include private place names, notes, photos, contact details, share-management keys or exact saved coordinates in analytics reports. City assignment happens on our server using local boundary data; we do not send saved coordinates to an external geocoding service. Cities are shown separately from categories, and we do not publish individual venue rankings.
City and category statistics are current snapshots, not a location history. Internal reports may include small groups, even a single contributing account. Aggregation does not guarantee anonymity. Reports are restricted to the operator’s dashboard and authenticated analysis tools. When those tools are used with an AI assistant, report contents may be sent to that assistant’s provider for analysis. Raw synced collections and account identifiers are not supplied through these aggregate-report tools.
To opt out: turn off Account analytics in Account settings in Nemo, or sign in to Account settings on nemo.town. The web setting also works if your installed app does not have the switch yet. The setting applies to your account across devices. A change takes effect when the server confirms it; an offline or failed change is not silently queued.
Opting out stops account-linked product analytics and removes your contribution from rebuildable current reports, including account-level collection and activity rows. Current reports may be temporarily unavailable while they refresh. Sync, shared maps and functional follower counts continue to work. Re-enabling analytics includes your current synced collection again; it does not recreate erased write-activity history.
We retain the minimum preference record needed to honor your choice and count how many eligible accounts have opted out, including accounts with no saved places. Historical totals that no longer retain individual contributions are not retroactively rewritten. Copies of reports already delivered to an analysis provider cannot be withdrawn through this switch. Rebuildable city and category snapshots are excluded from backups; restored data must be refreshed against current preferences before reporting resumes.
The switch does not control identifier-free installation totals, public app-store reports, cookieless website statistics, or service reliability and security measurements. These do not use an account identifier to attribute usage to you.
When you tap the Share button, Nemo uploads the places you selected to a temporary server so they can be opened from a link. This happens only when you actively share.
Shared data is stored in Cloudflare KV (a key-value store) and is automatically and permanently deleted when the link expires: 30 days for a one-off snapshot link, or up to a year for a “keep updated” live map (each update extends it). You can also stop sharing at any time, which deletes it immediately. No personal identifiers are attached to the uploaded data — the server receives only the place data you chose to share.
Anyone with the share link can view your shared places while the link is live. After it expires, or once you stop sharing, the link stops working and the data is gone.
Nemo keeps an anonymous tally of how many times each shared link is opened. This is only a number that counts up — there is no identifier, no cookie, and nothing recorded about who opened it or where. It is used to understand whether the share feature is useful.
A shared map can be a live map that stays up to date — people who open the link can choose to keep following it. So that the map's owner can see how many people follow it, your device is assigned a random, anonymous identifier the first time you follow a map, stored on your device. When your app refreshes a map you follow, it sends that identifier to let the owner's follower count include you.
This identifier is not linked to your name, email, or any other personal data, and it is never shared with other apps or services. The map's owner sees only a number — how many people follow their map — never who those people are. Follower records that go inactive are automatically deleted. This identifier supports functional follower counts; signed-in accounts may also claim devices for account-linked operations. The first-launch message described next carries no identifier at all.
To see how many new installations start using Nemo each day while the app stores’ own reports are delayed, the app sends one message the first time it is launched after installation. It contains only which platform (iPhone, iPad, Mac or Android), which app version, which operating-system version and which device model (for example “iPhone17,1”) — no location, no installation or account identifier, no cookie, nothing that could tie two launches to one device. We keep daily totals per platform, not individual messages. As with any request, our hosting infrastructure processes ordinary connection information such as the IP address to deliver and protect the service; it is used for rate limiting and is not stored with the count.
Our self-hosted, cookieless website analytics measures visits, pages and referrers. Server reliability metrics count sync outcomes and processing time without account identifiers or request contents. Hosting infrastructure processes connection information to deliver and protect the service. Public app-store downloads, ratings and reviews also help us understand Nemo’s use.
You can save a place from an Apple Maps or Google Maps link. Opening a link contacts the map provider that made it, across that provider’s own hosts, and then the place search the app already uses, which is asked for the place by name. This happens only when you choose to open the link.
The website cannot follow another site’s redirects, so it asks a Nemo server function to do that. The function keeps no copy and writes no log line with the link. The link itself is not saved with the place.
Maps and sign-in use the providers relevant to your platform, including Apple, Google and web map providers, under their own privacy policies. Shared links use Cloudflare and the website uses Vercel. The apps contain no advertising SDK or third-party analytics SDK. Internal aggregate analysis may use AI providers as described above.
Nemo is not directed at children under 13. If you believe a child has supplied personal information through an account, contact us so we can address it.
If this policy changes materially, the updated version will be posted at this URL with a new date at the top.
Questions? Reach us at nemo@kardol.us.