Privacy Policy

Last updated: Sep 13, 2026

This policy describes exactly what Tiermaps stores, why, for how long, and who else sees it. It is written against what the site actually does, not from a template.

1. The short version

  • You can build, edit, export and save charts without an account and without giving a name. Publishing is the one thing that needs you to sign in.
  • Drafts and the images you add to them stay in your browser until you confirm Share or Publish. Published charts and their images are public.
  • Deleting your own chart really deletes it. The chart, every version of it we stored, and its hearts are removed from our database rather than hidden, and its images are released for deletion. Two situations are different, and section 9 names them both.
  • Anonymous visitors get one random identifier in a cookie. It is used for hearts, votes, view counting, rate limits, and bans. It is not linked to a name, an email, or an advertising profile.
  • If you vote on a community ranking, we store where you placed each item. Nobody sees your individual votes, only the totals.
  • If you sign in, we store what the provider tells us about your account: your name, your avatar, and an email address where that provider gives one (section 3.2).
  • We count visits two ways: with our own self-hosted, cookie-free analytics, and with Google Analytics, which sets cookies only where you have allowed it (in the EEA, the UK and Switzerland that means after you accept a banner; anywhere, you can switch it off on Your privacy choices). Our ads come from Google, which does set its own cookies; in the EEA and the UK you get a consent choice before personalized ads are used.
  • Anywhere in the world, you can turn personalized advertising off on Your privacy choices, and we honor Global Privacy Control automatically.
  • We never sell your personal information, and we do not use your charts to train AI models. The license you give us over the charts you publish is broad (Terms section 7); the promise about AI is an exception to it that we hold ourselves to.

2. Who we are

The Chart Maker is the trading name of the business that operates Tiermaps (tiermaps.com), and is the data controller for the personal data described here. You can reach us at the address and mailbox below, and we answer privacy requests within 30 days (section 10).

The Chart Maker3115 Lillian Miller Pkwy, Ste 103-269, Denton, TX 76210, United StatesPrivacy contact: [email protected]

3. What we collect and why

3.1 Charts, images, and the things you type

While you are building a chart, the document and the images you add stay in your own browser (see section 5 and Local drafts, sharing and uploads). When you confirm Share or Publish, the chart document is stored on our servers: its type, title, description, the contents you put in it (labels, item names, colors, layout, links to your images), timestamps, and, once published, the public page id, a preview image, a social sharing image, and counters for views, hearts, and remixes. We keep a frozen snapshot of the document each time you publish, which is what other people see and what remixes copy.

Images you add to a chart that is only on this device stay on this device. They are stored in the local draft until you confirm an action whose copy says it will save them to Tiermaps. After that first confirmed Share or Publish, later images added to that same site-backed chart may be stored without repeating the first-upload dialog. If a later upload fails, the local draft remains the copy you can keep editing.

Uploaded images are stored on our image storage (Cloudflare R2) under a key derived from the file contents, and served from img.tiermaps.com. For each upload we record the storage key, the content hash, the file size, the content type, the anonymous identifier below (and your account id as well, if you were signed in), the moderation scan status, and the time. Identical files are stored once and reused, which is why re-uploading a popular image can be instant. An image that no chart ends up using is deleted again by the routine cleanup described in section 9.

Anything you publish is public: the chart, its images, its title and description, the creator name shown on the page, and the fact that it was remixed from, or into, another chart. Do not put private information into a chart you publish.

A chart you saved to the site but have not published is not listed anywhere, is not in our feeds, and is not offered to search engines. It is not secret either: anyone who has its link can open it and read it, which is what makes sending a chart for feedback before publishing work. The link contains a random ten-character id, so it cannot be guessed, but treat it as you would any link you would rather not have forwarded.

3.2 Account data, if you sign in

Signing in is optional for everything except publishing: a chart or a template that goes on a public page needs an account, and nothing else on the site does (Terms section 4).

You sign in with a Google account, and we never see or store a password.

Only Google sign-in is switched on for this deployment. Reddit sign-in is described here because the site supports it, but it is not configured at the moment: no account there can be used to sign in, nothing about your visit reaches Reddit through us, and what is said about it applies from the deploy that switches it on. This notice moves with that deploy, and the "Last updated" date above moves with it.

Here is what a sign-in gives us, provider by provider:

  • Google: we receive and store your name, email address, whether the email is verified, and your profile picture URL.
  • Reddit: we request the "identity" scope only, and receive your Reddit user id, username, and avatar image URL. Reddit does not give us an email address. Our sign-in library requires an email field, so for Reddit accounts we generate a placeholder address at a non-routable internal domain. It is never used to contact you and no mail can reach it.
  • For both: we store the provider name, your account id at that provider, and the access and refresh tokens the provider issues, which is how sign-in stays valid.
  • Sessions: each sign-in creates a session record holding a session token, its expiry, and the IP address and browser user agent of the sign-in, which we keep for security (spotting stolen sessions).
  • Your profile on the site: a public handle, a display name, and an avatar URL. The handle is not taken from your provider account: we generate a neutral one (maker- followed by random characters) and you can choose your own once, on your profile. Your display name stays empty until you do. The avatar URL is the picture the provider gives us. This matters most for Reddit: your Reddit username is never used as your name here and never appears on a public page.

3.3 The anonymous identifier

The first time you do something that needs to be attributed (create, upload, heart, report, or view a chart), the site generates a random identifier and stores it in a first-party cookie named tcm_anon. The cookie is httpOnly (JavaScript on the page cannot read it), SameSite=Lax, and lasts one year.

It is a random string. It is not derived from your device, browser, screen, fonts, or IP address, and it is not shared with anyone. We use it only to:

  • attach the charts and uploads you made without an account to the same visitor, so the work you saved before signing in is still findable and still yours;
  • count one heart per visitor per chart;
  • count one view per visitor per chart per hour, so counters are not trivially inflated;
  • apply rate limits (for example uploads per hour, hearts per hour, reports per day) so one visitor cannot flood the site;
  • enforce a ban when we have had to block a source of abuse;
  • record your votes on a community ranking and keep them to one per person per item (section 3.5);
  • mark who sent an issue report or a piece of feedback, in the same way as a report about a chart, so that several submissions from one person can be recognized as one person (section 3.8).

That is the whole list, and one thing is deliberately not on it any more: this identifier is not what lets a chart be published. Publishing needs an account (Terms section 4), so there is an account behind every public page, including one whose chart was started anonymously and therefore still carries the identifier of the browser that made it. The identifier keeps doing everything above, which is why it does not disappear: hearts, votes, view counting, rate limits, bans, and holding your anonymous work together.

If you clear cookies, you get a new identifier and the old one is orphaned. See section 11 for what that means for your rights.

3.4 Hearts, reports, and views

  • A heart stores the chart, the time, and your anonymous identifier. If you were signed in, your account id is stored on the same row as well: both are written, so that hearting a chart before signing in and after it counts once rather than twice.
  • A report stores the chart, the reason you picked, the optional detail text you write, the time, its status in our moderation queue, and your anonymous identifier, with your account id as well when you are signed in. Both are written for the same reason: the count of different people who reported one chart has to be a count of people. Please do not include personal details in the detail box that we do not need in order to act.
  • Views are counted in aggregate only. We keep a short-lived key ("this visitor has already been counted for this chart this hour") and then increment per-chart totals and a per-chart, per-day number. We do not keep a record of which charts a visitor looked at.

3.5 Votes on community rankings

Some published charts can be opened for voting, so that visitors place the same items themselves and the site shows where everyone put them. If you vote, we store one record per item you place, holding: the ranking and the item, the chart it came from, where you put it (the tier, quadrant, or position) and its rank within that placement, when it was cast and when it last changed, a count of how many times you have changed that particular vote, and the anonymous identifier from section 3.3.

If you are signed in, your account id is written on the vote as well. Both identity columns are filled in, not one or the other, and that is deliberate: it is what lets the site tell that the person who voted anonymously and then signed in is one voter, so the "how many people ranked this" number is a count of people rather than of browsers.

When you vote while signed in, including on a highlighted-item poll attached to a published tier list, we store your current choice with your site account. The same row also keeps this site's anonymous cookie identifier. We keep one current decision per item, not a log of every tap. Those stored choices may later be used for site-wide aggregates or optional personalization of what we show you. This first implementation does not score you, infer traits, predict a future vote, or build a profile from your poll history.

If you vote without signing in, we count the choice against the anonymous cookie this site sets itself. We do not attach that choice to a site account, and we do not provide an account history for those votes.

The count of changes exists so that a vote flipped repeatedly can be recognized as manipulation rather than treated as many opinions, and it is also a cap: after five changes to the same item your placement stays as it is. We keep one record per identity per item, which is what makes changing your mind replace your earlier vote instead of adding a second one.

We deliberately store nothing else about a vote. There is no IP address, no browser or device information, and no identifier from any other platform attached to a vote record. The creator of a ranking is stored against it so they can manage it, and is never displayed.

Your individual votes are not shown to anyone, including the creator of the ranking. What the site publishes is the aggregate: totals, distributions, and the resulting order.

While a ranking is open you can change where you put an item, within the cap above, and the change replaces your earlier answer. There is no button that deletes a vote. If you want your votes removed rather than changed, write to [email protected]: we can delete every vote attached to an identifier once we know which identifier is yours, which for a visitor with no account means telling us the value of your tcm_anon cookie (section 11).

Poll choices

The signed-in and anonymous storage rules for highlighted-item polls are the same as in section 3.5. This first implementation does not predict your votes, does not profile you from them, and does not use them to decide what ads you see.

3.6 Analytics

We use two analytics tools. The first is Umami, which we host ourselves on our own server. Nothing Umami records goes to any outside company, it sets no cookie, and it does not track you across other websites.

Umami records page views and a small set of product events, each with the type of chart involved: starting a chart, publishing, exporting a PNG, copying a share link, remixing, using a template, and hearting. Alongside each event it stores the page URL, the referring URL, and coarse information derived from the request (browser, operating system, device type, country, language). To recognize repeat page views within a visit it uses a rotating hash computed from request data rather than a cookie, and it does not store your IP address.

The second is Google Analytics (Google Analytics 4, run by Google LLC), which we use to count visits in a form that advertising partners can verify. It records page views with the page URL, the referring URL, and the same kind of coarse browser, device, and country information; Google processes that under its own terms and states that Google Analytics 4 does not log or store IP addresses. We keep event data in our Google Analytics property for 14 months. Google's privacy policy is at policies.google.com/privacy.

Google Analytics runs under Google's Consent Mode, and the cookies it sets (_ga and _ga_ followed by our property id, both two years) exist only where analytics storage has been allowed for your browser. The default depends on where you are: denied in the European Economic Area, the United Kingdom, and Switzerland, allowed everywhere else. Advertising storage, ad user data, and ad personalisation are denied everywhere in that same setting, because we do not use Google Ads. To pick the default, the page asks our own server for the country code Cloudflare attached to your request; that lookup returns two letters and stores nothing.

In those three regions, if you have not chosen yet, a small banner asks whether we may use Google Analytics to count visits, with Accept and Decline. Nothing is set until you accept. If you decline, no analytics cookie is set and Google receives no identifier for you; the tag may still send Google a cookieless signal that a page was viewed, with no cookie and no identifier, which Google uses only to estimate totals. Your answer is kept in this browser only, under tcm-analytics-consent, and is never sent to us.

Two more controls apply everywhere. If your browser sends a Global Privacy Control signal, analytics storage is denied in every region and no banner appears. And anyone, in any region, can switch Google Analytics off or on for their browser on Your privacy choices, whether or not they ever saw the banner. Neither tool is used to decide what you see on the site or which ads you are shown.

3.7 Server logs

Our web server and application keep operational logs, which can include the IP address, the time, the URL requested, the response status, and the user agent. We use them to keep the site running, to debug errors, and to investigate abuse. Cloudflare, which sits in front of the site, processes the same request data to provide caching, TLS, and protection against attacks.

3.8 Issue reports and feedback

The editor has a form for reporting that something is broken, and after you publish a chart or save an image the site may ask once how it went. Both are voluntary. Nothing is sent unless you write something or pick a rating and then press send, and closing either one sends us nothing at all.

What a submission sends is what you wrote, plus the little that says where you were: your message, the optional line about what you were doing when it went wrong, a rating from one to five where the ask offers one and you pick it, the page you were on (its path and query, never the part after the #, because an edit token travels there), the chart type and the chart id when the submission came from an editor, and which part of the site the form was opened from. We also store a coarse description of your browser and operating system family, worked out from the request rather than taken from the submission.

The issue form additionally offers a technical details block, which is usually the difference between a report we can act on and one we cannot. It starts ticked, the exact text is printed in full on the form directly below the tick box so you can read every line before deciding, and unticking it sends your report without it. It contains the time, the page address with the part after the # removed, your chart's type, title, and id, the version of the document format, whether the chart was saving, counts describing how large the chart had grown (numbers only), and facts about the browser: the user agent string, the language, the window and screen size, and whether the device is a touch one. It carries no part of the contents of your chart and no edit link.

We do not ask for an email address and we do not collect one here, so a submission is not a message we can reply to. No new identifier is created for it either: it carries your account id if you were signed in, and otherwise the same anonymous identifier from section 3.3 that the rest of the site already uses, which is also what a rate limit counts so that one browser cannot flood the queue. Your IP address is not stored on it. We keep submissions so that we can read them and fix what they describe; they are not shown publicly and they are never used for advertising. Please do not put personal details in the message that we do not need in order to fix the problem.

4. What we do not collect or do

  • We do not store passwords. Sign-in is handled by the provider you choose (section 3.2).
  • We do not take payments, so we hold no payment or card data.
  • We do not collect precise location, contacts, phone numbers, or anything from your device beyond the ordinary contents of a web request. There is one exception and you are the one who decides it: the technical details block on the issue-report form reads your window and screen size and whether your device is a touch one. It is shown to you in full before you send anything and it can be switched off (section 3.8).
  • We do not read your Reddit account beyond the identity scope (id, username, avatar), we do not see your posts or messages, and we never post anything to Reddit for you.
  • We do not sell personal data, and we do not share it with data brokers.
  • We do not use your charts, drafts, or uploaded images to train AI models, and we do not license or sell them to anyone else for that purpose. The license in Terms section 7 is otherwise broad, and this sentence is a deliberate limit on it rather than a description of it.
  • We do not send marketing email. If you gave us an email address through sign-in, we use it for account and service messages only.
  • We do not build advertising profiles ourselves. Advertising cookies come from Google (see section 7).

5. Cookies and storage on your device

The Cookie Policy is the full inventory: every cookie and every browser-storage key by name, what each is for, who sets it, and how long it lasts. It is a separate page so that it stays short enough to actually read. This section covers the parts that change what you should do.

Cookies we set

  • tcm_anon: the anonymous identifier described in section 3.3. First-party, httpOnly, SameSite=Lax, one year. Strictly necessary for hearts, abuse prevention, and keeping anonymous work attached to you.
  • Sign-in cookies: when you sign in, our authentication library sets a first-party session cookie, plus short-lived cookies during the sign-in redirect. Signing out ends the session.

Storage that stays on your device

These are kept by your browser rather than by us, and none of them is sent to us as you browse. A draft and the images inside it reach us only when you confirm Share or Publish. An edit token is sent only when you edit your own site-backed chart. The note of which chart a draft was remixed from is reported once, at the moment you publish that draft.

  • Drafts: every chart you work on is autosaved into an IndexedDB database named tcm-drafts, so a reload or a dropped connection does not lose your work. The draft stays on the device until you save it to the site or delete it. Clearing site data deletes it, and we cannot recover it.
  • Edit tokens: keys beginning tcm-edit-token: in localStorage hold the secret that proves a chart saved without an account is yours. We store only a hash of that token on the server, so the copy in your browser is the one that matters. Treat an edit link like a password.
  • The edit link itself: the cross-device link the site gives you carries that token after the # in the address. That position matters for your privacy: browsers never send the part of a URL after the # to the server, so the token in an edit link does not reach us, does not appear in our request logs, and is not passed to any other site you click through to. It does travel with the link, so anywhere you paste it, you have handed over editing rights.
  • Heart markers: keys beginning tcm-hearted: in localStorage remember which charts you hearted so the button shows the right state immediately.
  • Remix markers: keys beginning tcm-forked-from: in localStorage remember which published chart a draft was started from. The value is reported once, when you publish that draft, so your version can credit the original, and the key is then removed.
  • Already asked: keys beginning tcm.feedback.asked. in localStorage remember that this browser has already been asked how a chart went, so the question does not return after every publish. The value is the word "answered" or "dismissed" and the time, and nothing reads it back out of your browser.
  • Sign-in tab sync: when you sign out, our sign-in library writes a single localStorage value named better-auth.message so that other tabs you have open notice and stop showing you as signed in. It carries no session token.

The Cookie Policy lists all of these by name, with nothing left out.

Third-party cookies

Google's advertising scripts may set cookies and read similar storage on pages that show ads. Where the law requires consent, those cookies are only used for personalized advertising after you have given it (section 7). Ads are not shown on this page or on the other legal pages.

Google Analytics may set its two cookies (_ga and _ga_ followed by our property id) on any page, but only where analytics storage has been allowed for your browser: after you accept the banner in the EEA, the UK, and Switzerland, and unless you have declined elsewhere (section 3.6). Your answer itself is kept in localStorage under tcm-analytics-consent and never sent to us. Our own analytics sets nothing.

You can delete cookies and site data at any time in your browser settings. Deleting tcm_anon resets your anonymous identity; deleting localStorage or IndexedDB data removes your local drafts and your edit tokens.

To refuse advertising storage rather than delete it afterwards, use Your privacy choices, which also shows whether your browser is sending a Global Privacy Control signal (section 13).

Local drafts, sharing and uploads

Building and editing a chart keeps the document and any images you add on this device, in your browser's storage. Reloading, undoing, exporting an image, and canceling Share or Publish do not send the chart or its images to us. We cannot recover a local draft if you clear site data, switch device, or use a private window.

A chart reaches our servers only after you confirm an action whose visible copy says that it will. Those actions are:

  • Sharing an edit link. We store the chart document and its referenced images, then give you a private link. Anyone with the link can edit that same chart. The link is a secret capability, not an access-control list: whoever holds it can overwrite the document. Deleting the chart invalidates the link.
  • Letting people make their own copy. We store a private snapshot of the chart and its referenced images for 90 days. Recipients who confirm make a separate chart. Your working draft stays on this device unless it was already saved to the site. Revoking or expiry stops new copies and does not delete copies already made.
  • Publishing. We store the chart document, its referenced images, and generated preview, thumbnail, and social images, and we create a public page.

Generated preview images are created and uploaded only after you confirm Publish. Exporting an image downloads a file on this device and does not upload the chart.

Once a chart is saved to the site, later edits and new images may be stored without repeating that first confirmation. The editor shows that the chart is saved to the site. Independent-copy snapshots count as live references for image cleanup until they expire or are revoked. See Terms: Shared edit links and copy links.

6. Who else processes your data

We keep the list short on purpose. Each of these acts for us, under contract, and only for the purpose named.

  • Hetzner (hosting): runs the servers holding the application, the database, and our analytics. Everything in section 3 that is stored on our servers sits there. Privacy policy.
  • Cloudflare (CDN, TLS, security, and R2 image storage): processes requests to the site and stores uploaded and generated images. Privacy policy.
  • Google LLC (Google Analytics): counts visits and page views for us as described in section 3.6, only where analytics storage has been allowed for your browser, and only on a deployment where Google Analytics is switched on (the notice in 3.6 says whether it is). Google states that Google Analytics 4 does not log or store IP addresses; we keep event data for 14 months. Privacy policy. Google's separate role as our advertising vendor is described in section 7.
  • Nobody, for image moderation. The automated check described in section 6 runs on our own server, in a separate container with no access to the internet and no access to the database. Your images are not sent to any outside company to be classified, and no third party receives them for that purpose. This used to be Amazon Rekognition; it was replaced in August 2026 and no data has been sent to Amazon Web Services since.
  • Google (AdSense advertising, and Google sign-in if you use it): receives what is described in section 7 for advertising, and, if you sign in with Google, the fact that you signed in. Privacy policy.
  • Reddit (Reddit sign-in, if you use it): receives the fact that you authorised our app and gives us your id, username, and avatar. Privacy policy.

We also disclose data when the law requires it (a valid legal request, or a claim we must answer), when we need it to investigate abuse or protect people, and, if the site is ever sold or transferred, to the buyer, who would be bound by this policy or a successor to it. We would announce that on the site before it took effect.

7. Advertising, personalization, and consent

No advertising is running on this site yet. This section describes what happens once it is. Until then no ad script loads, no advertising cookies are set, and nothing about your visit reaches Google through advertising at all. This notice disappears by itself on the deploy that switches advertising on, and the "Last updated" date above moves with it.

The site is free and is paid for by advertising. We use Google AdSense. Ad units appear on public pages such as the home page, browse pages, and chart pages, and on wide desktop screens beside the editor. There are no ads on this page or on the other legal pages, and there are no ads in the editor on phones and tablets.

Google, as a third-party vendor, uses cookies and similar technologies to serve ads. It may use information about your visits to this and other sites to show ads relevant to you.

Your consent choice in the EEA, the UK, and Switzerland

If you are in a region where consent is required, Google's consent message appears before personalized advertising cookies are used, and you can accept, reject, or configure purposes. We do not run a separate consent script of our own for advertising: the choice you make in that message is what governs the ad stack. (The small analytics banner in section 3.6 is a different question, about Google Analytics, and has no effect on ads.)

You can change your choice later: Your privacy choices reopens the consent message, and clearing the site's cookies makes it appear again on your next visit.

Turning personalization off anywhere in the world

Everyone, in every region, can switch personalised advertising off on Your privacy choices. It sets a flag in your browser that tells Google to serve non-personalised ads on this site. Ads still appear, since they pay for the site, but they are not selected using information about you.

We also honor Global Privacy Control. If your browser or an extension sends a GPC signal, we apply the same opt-out automatically, before any ad is requested, without you having to visit that page. We do not respond to the older Do Not Track header, which was never given an agreed meaning.

Opting out more broadly

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:

  • Performance of a contract (Article 6(1)(b)): running the editor, storing and displaying the charts you save or publish, maintaining your account and sessions.
  • Legitimate interests (Article 6(1)(f)): keeping the site available and secure, preventing abuse and spam (the anonymous identifier, rate limits, bans), moderating published images, counting views and hearts, understanding aggregate usage through our own analytics, acting on the issue reports and feedback people choose to send us (section 3.8), and promoting the service with published charts. We have weighed these against your interests; each one is narrow, uses the least data that works, and none of it builds a profile of you.
  • Consent (Article 6(1)(a)): personalized advertising cookies where consent is required, and Google Analytics cookies in the EEA, the UK, and Switzerland, which are set only after you accept the banner in section 3.6. You can withdraw either at any time (section 7 for advertising; Your privacy choices for analytics).
  • Legal obligation (Article 6(1)(c)): responding to copyright notices and other lawful requests, and keeping the records needed to do so.

9. How long we keep things

  • Drafts in your browser: until you delete them or clear site data. They are on your device, not ours, and we cannot recover them. Images added to a device-only draft stay on the device until you confirm Share or Publish.
  • Charts you saved or published: until you delete them. A published chart stays online indefinitely unless you delete it, we remove it under our Terms, or the site shuts down. When you delete a chart yourself, we delete it. The chart record, every version of it we had stored, the hearts on it, and its per-day view history are removed from our database in one operation, not marked as hidden, and the images it used stop being referenced by anything. It cannot be restored afterwards, by you or by us, and pressing delete a second time cannot reach further than the first. What can survive is a copy in a database backup, until that backup is rotated out (they are taken daily and kept 14 days, and we commit to never keeping one longer than 30), and any remix somebody else already made, which is their chart and stays online (Terms section 8).
  • Published snapshots: kept with the chart, and deleted with it, in the same operation. A remix made from a snapshot is a separate chart and is not affected.
  • Uploaded images: kept while any chart references them. Once nothing references an image, because the chart that used it was deleted outright, or the image was taken out of it, or the draft that used it was never published, it is deleted by a routine cleanup once it is at least 90 days old. That job runs daily and works through a bounded batch each time, so collection can happen later than 90 days but never sooner. An upload that was started and never completed is removed after 24 hours. Because identical files are stored once, an image that another chart also uses stays until no chart uses it.
  • Independent-copy snapshots: kept for 90 days from the moment you confirm the copy link, or until you revoke them. Expiry or revoke stops new copies. Recipient charts already made stay as their own records. Live snapshots pin their referenced images against the cleanup sweep; expired and revoked snapshots do not.
  • Per-day view numbers: deleted after 14 days. The running total per chart is kept as part of the chart.
  • Hearts: until you remove the heart, or until the chart is deleted, which deletes its hearts with it.
  • Votes: kept while the ranking exists, because they are what its published totals are made of. While a ranking is open you can change your own placement, within the cap in section 3.5; there is no self-service delete, and the same section says how to ask us. Closing or removing a poll leaves the votes in place. Unpublishing or moderation-hiding a chart takes its poll and ranking pages off the site without deleting the vote records. We do not hard-delete a chart that other people have voted on (see below). If you ask us to delete your account, we delete every vote that carries that account id and rebuild the totals of the rankings those votes sat in. Votes counted only by the anonymous cookie are not removed unless you also identify that cookie. Items taken out of a chart are retired rather than deleted, so votes already cast on them are not silently rewritten.
  • Reports: kept while the moderation queue needs them, and afterwards as the record of a decision, so that repeat problems can be recognized. A report is attached to the chart it is about, so if the creator deletes that chart after the report has been dealt with, the report goes with it. While a report is still open, the chart is not deleted at all (see below), which is what stops a deletion from erasing an open complaint.
  • Issue reports and feedback: kept while we are dealing with them and afterwards as the record of what was reported and what we did about it, so that a problem reported twice is recognizable as one problem. We do not delete them on a timer, and this page will not pretend otherwise; if you want a submission of yours removed, ask us (sections 10 and 11) and we will delete it. If your account is deleted, its submissions stop being linked to it. The marker that records you have already been asked is on your device, not ours (section 5).
  • Moderation scan status: kept with the upload record for as long as the image exists, including the labels a scan returned if one ran (section 6).
  • Account, sessions, and profile: until you delete your account. A sign-in session expires on its own after a period of inactivity (currently 7 days) or when you sign out.
  • Anonymous identifier: one year in the cookie, renewed as you keep using the site. The copies stored beside your charts, hearts, votes, uploads, and reports live as long as those records do.
  • Server and CDN logs: kept short term for security and debugging, normally no longer than 30 days.
  • Analytics: aggregate page and event statistics in our own analytics, kept without a link to an identifiable person. Event data in our Google Analytics property is kept for 14 months; the two Google Analytics cookies last two years in your browser, where they were allowed at all (section 3.6).

The two cases where we keep a chart you asked us to delete

Deleting your own chart normally means what the bullet above says. There are exactly two situations where it does not, and in both of them the chart still comes off the site (its page and its links stop working) while the record behind it is kept. The site tells you which one applied at the moment you delete, rather than reporting success and doing something else, and a second delete on a chart in that state changes nothing. Because the record we keep is still a chart record, it still references the images that chart used, so those images stay as well rather than being released to the 90-day cleanup described above.

  • While a report about the chart is open. Deleting the chart would delete the complaint with it, and someone could publish something illegal, wait to be reported, delete it, and leave no trace that any of it happened. Our repeat-problem policy (see the Copyright and Takedown Policy) depends on that trace existing. So the chart is taken off the site and the record is kept while the report is being dealt with. Pressing delete again later will not complete it: write to [email protected] once the report has been resolved and we will finish the deletion by hand.
  • Once other people have voted on it. A chart opened for community voting carries other people's votes, and the consensus page built from them may already be linked from elsewhere; deleting the chart would destroy both, because the votes are attached to it. So the chart is taken off the site and the record, with those votes, is kept. If you want it deleted anyway, write to [email protected]: that is a judgement we make case by case, weighed against the people whose votes would go with it, and we tell you what we decided and why.

When we remove a chart under our Terms rather than at your request, it is taken off the site and the record is kept. Moderation needs to know what it acted on, and an enforcement decision is not a privacy request.

10. Your rights and how to use them

Depending on where you live, you have some or all of these rights:

  • access: a copy of the personal data we hold about you;
  • correction of data that is wrong;
  • deletion of your data. What deleting a chart actually does, and the two cases where we keep the record instead, are in section 9; the license consequences are in Terms section 7;
  • portability: your charts in a machine-readable form. You can already export any chart as an image at any time, and we can provide the underlying chart documents on request;
  • objection to processing based on legitimate interests, and restriction of processing while an objection is considered;
  • withdrawal of consent, for anything we do on the basis of consent;
  • a complaint to your data protection authority. In the EEA that is the authority of your country of residence; in the UK it is the Information Commissioner's Office.

To use any of them, write to [email protected] from the email address on your account, or from any address if you tell us which charts or identifiers the request is about. We answer within 30 days. We may ask for enough information to be sure the request really concerns your data, and we will not ask for more than that.

If you have an account, signing in and deleting your charts, or asking us to delete your account, is usually faster than a formal request.

11. Rights when you have no account

Most privacy policies quietly skip this. Here is the honest version.

If you never signed in, we hold no name, no email address, and nothing else that identifies you as a person. What we hold is a random identifier in your cookie, and the hash of the edit token for each chart you made. That has two consequences.

We cannot look you up. There is nothing to search by. A request that says only "delete my data" cannot be matched to any record, and we will not try to identify you from an IP address or anything else in order to answer it, because that would mean collecting more data about you, not less.

The edit link is the proof of ownership. If you send us the edit link (or the chart address plus its edit token) we will treat that as proof and delete or unpublish the chart, on the terms in section 9. If you tell us the value of your tcm_anon cookie (visible in your browser's developer tools under Application, then Cookies, because the cookie is httpOnly and pages cannot read it), we can find and delete the hearts, votes, reports, issue reports, feedback, and upload records tied to it. Removing votes rebuilds the totals of every ranking they were part of, so the published numbers stay correct rather than quietly drifting.

One thing you cannot have done without an account is publish: a chart or a template on a public page has an account behind it (Terms section 4). So if your request is about something public, it is almost certainly account data, and section 10 is the shorter route. What this section is for is everything you did anonymously: the charts you saved without signing in, and the hearts, votes, reports, feedback and uploads tied to your cookie.

If you have cleared cookies and did not keep your edit links, the connection between you and those records no longer exists on either side. We cannot restore it, and we cannot act on a request about them. The practical protection is to save your edit links, or to sign in and claim your charts, which turns them into account data with the full rights in section 10.

Separately from any of this: anyone can ask us to remove content that harms them, whether they created it or not. Use the Report button on the chart, or write to [email protected]. You do not need to prove ownership to report something.

12. Children's privacy

Tiermaps is not directed at children. You must be at least 13 years old to use it, and at least 16 in the European Economic Area and the United Kingdom (Terms, section 2).

We do not knowingly collect personal data from children below those ages. If you are a parent or guardian and believe a child has given us personal data, write to [email protected] and we will delete the account, the charts, and the related records.

13. US state privacy rights

If you live in California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you have rights to know what personal information we collect, to access and delete it, to correct it, to receive a portable copy, and not to be discriminated against for exercising those rights. Use the contact in section 10; the practical limits in section 11 apply to anonymous visitors.

The categories of personal information we collect are described in section 3. Those laws use a fixed list of categories, so here is that list, answered honestly. We collect them for the purposes in section 3 and keep them for the periods in section 9.

California statutory categories of personal information, and whether we collect each one
CategoryCollectedWhat, if so
A. IdentifiersYesA random cookie identifier, an account id, an IP address in logs, and an email address if you signed in with Google
B. California Customer Records categoriesYesName and email address, for account holders only
C. Protected classification characteristicsNoWe never ask your age, sex, race, or anything like them
D. Commercial informationNoWe take no payments, so there is no purchase history
E. Biometric informationNoNo face recognition. Published images are scanned for safety categories only (section 6)
F. Internet or network activityYesPages viewed and product events, through our own analytics and, where you have allowed it, Google Analytics (section 3.6), and your interactions with the site itself: the charts you hearted, the votes you cast on community rankings (section 3.5), anything you reported, and any issue report or feedback you chose to send us (section 3.8)
G. Geolocation dataCountry onlyCountry derived from the request, for analytics and to pick the Google Analytics consent default (section 3.6). No precise or device location, ever
H. Audio, visual, or similar informationYesThe images you upload into your charts. You chose them; we do not analyze them
I. Professional or employment informationNo-
J. Non-public education informationNo-
K. InferencesNoWe build no profile of you and draw no conclusions about your characteristics or preferences
L. Sensitive personal informationNoNo government identifiers, financial accounts, precise location, health, religion, sexual orientation, union membership, or message contents

We do not sell personal information, and we have never received money for anyone's data. Showing advertising through Google may count as "sharing" for cross-context behavioral advertising, or as "targeted advertising", under those laws, so we treat it as if it does.

Your opt-out, and opt-out signals

Your privacy choices is the "Do Not Sell or Share My Personal Information" control for this site, linked from the footer of every page. It works for everyone, not only residents of states that require it, and it needs no account and no request to us.

We honor Global Privacy Control as a valid opt-out of sharing and targeted advertising. The signal is read before any ad is requested and applied for that browser automatically, in every region. You can confirm we received it on the same page.

Sensitive information, and how we use what we hold

We do not collect sensitive personal information as those laws define it: no government identifiers, no precise location, no financial accounts, no health, biometric, racial, religious, sexual-orientation or union data, and no contents of your mail or messages. We do not profile you in furtherance of decisions that produce legal or similarly significant effects, and we do not sell or share the personal information of anyone we know to be under 16.

Appeals

If we refuse a privacy request, we tell you why, and you can appeal by replying to that answer or writing to [email protected] with "Appeal" in the subject. A person reviews it and we respond within 45 days with our decision and our reasons. Colorado, Connecticut, Texas, and Virginia require this; we offer it to everyone. If the appeal fails you can complain to your state Attorney General, and we will tell you how.

Agents, and not being penalised

You can use an authorised agent to make a request, if you send us enough to show they act for you. We never charge for a request, never make the site worse for someone who makes one, and never offer anything in exchange for keeping your data.

California specifics

  • Shine the Light (Civil Code section 1798.83): we do not disclose personal information to third parties for their own direct marketing, so there is nothing to request under it. Ask us anyway at [email protected] and we will confirm that in writing.
  • Under-18 removal (Business and Professions Code section 22581): if you are under 18 and live in California, you can ask us to remove content you published here, and we will. Removal takes it off the public site; it cannot reach copies other people made under Terms section 8, or anything already reposted elsewhere.
  • Consumer complaints about the service itself: Terms section 21.

14. International transfers

Our servers and database are hosted in Europe, and the automated image check runs on that same server rather than at an outside provider. Some of the providers in section 6 (Google, Cloudflare) are US companies that may process data outside your country. Where personal data leaves the EEA or the UK, the transfer relies on the European Commission's standard contractual clauses, the UK addendum, or an adequacy decision such as the EU-US Data Privacy Framework, as applicable to that provider.

15. Security

The site is served over HTTPS. We store no passwords. Edit tokens are stored only as a hash, so a copy of our database does not let anyone edit your anonymous charts. Access to the servers and the database is limited to the people who operate the site, and images are served from a separate domain with immutable caching.

No service can promise perfect security. If we ever discover a breach affecting your personal data, we will notify the relevant authority and, where the law requires it, you.

16. Changes to this policy

When the site changes what it stores, this page changes with it. We update the "Last updated" date at the top, and for significant changes we post a notice on the site. If a change requires your consent, we will ask for it before it takes effect.

17. Contact

Privacy questions and requests: [email protected]. Anything else: [email protected].

The Chart Maker3115 Lillian Miller Pkwy, Ste 103-269, Denton, TX 76210, United States

See also our Terms of Service, our Cookie Policy, our Community Guidelines, our Copyright and Takedown Policy, and Your privacy choices.