Last updated: July 11, 2026
KR Maps Journeys ("the App") is developed by KR Maps ("we," "us"). The App is a companion to KR Maps physical push-pin wall maps: it organizes your travel photos into journeys on a digital map, and it can read the pins on your physical map and place them for you. This policy explains exactly what stays on your device, what leaves it, and why.
The short version
Two promises do most of the work here:
1. The App never silently sends your photos anywhere. It reads the date and location stamps on the photos in your library to sort them into journeys, but it does this entirely on your phone. The pictures themselves are never uploaded to us, to any AI service, or to any server on their own.
2. Images leave your device only when you choose it, in one of three ways. First, the photos you take of your physical wall map are sent to our pin-detection service (and a secondary AI detector we use alongside it) to find your push pins. Second, a journey you actively share with another person is sent directly to their phone, encrypted, over your local network. Third, when you order a printed book, the book you are ordering — including the photos in it — is sent to our print partner to produce and ship it. We ask for your consent before the first wall-map photo is sent and before any book is sent to print; sharing only ever happens when you start it.
Beyond that: there are no accounts, no advertising, and no behavioral tracking. Everything about your journeys lives in a database on your own device.
Your travel photos stay on your device
To build your journeys, the App reads each photo's metadata — GPS coordinates, date taken, and dimensions — directly from your device's photo library. This processing happens entirely on your phone. The photos themselves are never sent to us, to any AI service, or to any server. No person and no server ever sees the contents of your camera roll.
To turn that information into a map, the App does send small pieces of derived data — coordinates and dates, never images — to a few services:
-
Place names: coordinates are passed to your device's built-in geocoding service to turn a latitude and longitude into a name like "Seattle." On most phones this lookup is handled by the operating system (Apple or Google).
-
Weather: a coordinate and date are sent to Open-Meteo to add historical weather to a journey.
These requests carry location and date only. They never include your photos, and there is no account identifier to attach to them.
Wall-map pin scanning
This is the only feature that sends your photos to a service for processing, and it only ever uses photos you take, in the moment, of your physical wall map — never anything from your existing photo library.
When you scan your wall map, or take a close-up of an individual pin, the photo is sent to our pin-detection service. That service analyzes the image, locates your push pins, and returns their positions and colors so the App can place them on your digital map. We ask for your explicit consent before the first image is ever uploaded, and you can cancel a scan at any time — anything not yet sent stays on your device.
Before a scan photo leaves your device, we remove its metadata — including GPS location and other embedded camera data — on-device before it's sent. The two non-identifying camera measurements we keep are the lens's 35 mm-equivalent focal length and whether the flash fired, which we send as separate values because the service needs them to take its measurements. These are always photos of your physical wall map, taken in the moment — never images from your existing library.
How the image is processed: our own computer-vision pin-detection service analyzes the image to locate your push pins. As a secondary detector, the same image is also processed by Roboflow's SAM3 segmentation model to help identify pins more reliably. Roboflow receives the image solely to return the pins it finds to us and does not use it for any other purpose.
Photos sent to our own pin-detection service are used only to detect your pins and are deleted once processing is complete — they are never repurposed for anything else. Because this service runs separately from the App, we can improve how pin detection works without requiring you to update the App.
Camera and photo-library access
The App requests camera access for three things: scanning the QR code that activates the App, photographing your wall map for pin detection, and taking close-up photos of individual pins. It requests photo-library access to read your travel photos as described above. If you export a journey snapshot or a poster, you can optionally save the result to your photo library from your device's own share sheet — the App does not save anything to your library on its own.
What is stored, and where
Everything about your journeys is stored locally on your device, in a SQLite database and your device's standard app-settings storage. This includes your trips and their dates, locations, names, notes and journal entries, saved links and places, bucket-list ("want to go") entries, imported GPS tracks, your home pin, cached weather, your app settings, and which map styles you have activated. We do not keep a copy of any of this on a server. If you delete the App, this data is removed with it.
Sharing journeys
You can share journeys directly with another KR Maps Journeys user over your local Wi-Fi network — for example, importing a friend's or partner's journeys onto your own map. To do this, the two phones discover each other on the same network and connect directly, confirmed by a short pairing code so that only the device you intend can connect.
This transfer is peer-to-peer, over your local network only, and encrypted end-to-end using a fresh, session-specific security certificate generated on your phone for that one transfer — even another device on the same Wi-Fi network cannot read the data in transit. It does not pass through, and is not stored on, any server we operate, and the connection stays open only while you are actively pairing. Whatever you share — including photos — becomes a copy on the other person's device and is then under their control, just as any journey you import becomes a copy on yours. Share, and import, only with people you trust.
You can also export a journey to a file and share it through your device's standard share sheet (email, AirDrop, messaging, and so on); where that file goes from there is up to you.
Ordering a printed book
The App can turn a journey into a printed photo book. This feature is rolling out soon and is not yet available in the App — here is how it will work once it is: if you choose to create a book, the App will upload your selected photos to our book-building service and open our web-based book studio in your browser, where you finish designing the layout. This will be the one case where your travel photos themselves leave your device — it will happen only when you start building a book, and only for the photos in that book; your photo library as a whole is never sent.
We will ask for your explicit consent before any photos are uploaded. Your photos and book layout will be held in storage we operate (Cloudflare R2) while you finish your book. If you place an order, your finished book — along with the shipping address and contact email you provide at checkout — will be sent to our print partner, Prodigi, who manufactures and ships it.
No accounts, no ad tracking
The App does not require an account or a login. Activation happens by scanning the QR code on your map, and is validated entirely on your device — no activation data is sent anywhere. We do not use advertising, attribution, or behavioral-tracking tools, and we do not collect usage analytics beyond the anonymous crash reports described below.
Crash reporting
The App uses Firebase Crashlytics to collect anonymous crash and error reports so we can find and fix bugs. These reports contain diagnostic information — such as the error, the device model, and a random identifier scoped to your installation of the App — but no personal information and none of your journey content. You can turn this off at any time in Settings. See Firebase's privacy documentation.
Third-party services
The App relies on the outside services listed below. Except where noted, none of them ever receive your photos.
-
Our pin-detection service. Receives the wall-map and close-up pin photos you take, and returns the pins it detects. See "Wall-map pin scanning" above.
-
Roboflow (SAM3). Used alongside our own pin-detection service as a secondary AI detector to help locate pins in wall-map and close-up photos. Receives the image solely to return detection results to us. See "Wall-map pin scanning" above.
-
Prodigi (print on demand). When you order a printed book, its photos and layout, along with your shipping address and contact email, are sent to Prodigi to manufacture and ship the book.
-
Cloudflare R2. When you order a printed book, its PDF is briefly stored in storage we operate on Cloudflare R2 so the printer can retrieve it, and is removed after the order is fulfilled.
-
Mapbox. Provides some of the map imagery shown in the App. Loading map tiles sends standard web-request data, including your IP address and the tile coordinates you are viewing. See Mapbox's privacy policy.
-
Amazon Web Services (CloudFront). Delivers the custom-designed map tiles used for KR Maps styles. Loading map tiles sends standard web-request data, including your IP address and the tile coordinates you are viewing.
-
OpenStreetMap and CartoDB. Provide additional map imagery in some views. Loading these tiles sends standard web-request data (IP address, tile coordinates). See the OSMF Privacy Policy.
-
Esri (ArcGIS Online). Provides some of Journey Studio's alternate basemap styles (Terrain, Satellite, Firefly, Hillshade, and Nat Geo). Loading these tiles sends standard web-request data (IP address, tile coordinates).
-
Open-Meteo. Provides historical weather. Receives a coordinate and date; no identifiers and no photos. See Open-Meteo Terms.
-
Device geocoding (Apple / Google). Converts coordinates to place names, and place names to coordinates when you search. On most devices this is handled by the operating system's location framework, which may contact Apple's or Google's servers to complete the lookup. Coordinates or search text are sent; photos are not.
-
Firebase Crashlytics (Google). Anonymous crash reporting, as described above. See Firebase's privacy documentation.
-
Google ML Kit. Powers on-device scanning of the QR code that activates the App. As part of its normal operation it generates a random identifier scoped to this app install; per Google's own disclosure, this data is not shared with third parties. See Google ML Kit's data disclosure.
-
Google Fonts. The App loads its typefaces from Google's font CDN at runtime; standard web-request data may be logged. See Google Privacy Policy.
-
Our proxy infrastructure. Requests to our pin-detection service are routed through a lightweight proxy we operate to keep our API keys secure. The proxy forwards requests and does not retain your photos.
-
Feedback. If you send us feedback from the App, your message and an optional reply-to email address are sent directly to us. We never sell or share this information.
Data retention
Your journey data stays on your device until you delete it — individually, or by deleting the App. Photos you send to our own pin-detection service are kept only as long as needed to detect your pins and are then deleted; Roboflow processes those same photos solely to return detection results and does not retain them for any other purpose. Photos and layout you upload to build a printed book (once that feature is available) are used only to build and print that book. Anonymous crash reports are retained by Firebase according to its own retention schedule, and you can disable crash reporting at any time in Settings.
Requesting deletion
Because the App has no accounts, almost everything about your journeys already lives only on your device — deleting the App, or using "Clear all data" in Settings, removes it completely. If you'd like us to delete any feedback you've sent us, or to disassociate your device from past anonymous crash reports, email us at the address below and we'll take care of it.
Children's privacy
The App is not directed at children under 13, and we do not knowingly collect information from children.
Changes to this policy
We may update this policy from time to time. Changes are reflected by the "Last updated" date above. If we materially change how your images are handled, we will make that clear in the App.
Contact
Questions about this policy? Contact us at kevin.reinhardt@krmaps.com