RabbitMap

Legal

Privacy policy

Last updated August 17, 2026

RabbitMap is an educational archive of disputed narratives — cultural cartography, not a newsroom and not a truth engine. This policy explains what we collect when you browse, ask, take a stand, suggest a hole, or sign in, and what we do with it.

“We,” “us,” and “RabbitMap” mean the operator of the RabbitMap service at rabbitmap.app. If we name a different operator later, that notice replaces this sentence.

What this policy covers

It covers the public site, the map and directory, Ask, Compare / take-a-stand, hole suggestions, accounts, and the admin tools we use to research and publish files. It does not control third-party sites we link to, or players we embed (for example YouTube). Those services have their own policies.

What we are not doing

We do not sell your personal information. We do not run third-party advertising on the pages. We do not score you as right or wrong when you take a stand. Stands and compare answers are a reasoning experiment and, in aggregate, a polarization readout — not a political dossier we market, and not a grade on the file.

Information we collect

How much we hold depends on whether you stay a visitor or create an account.

You give us

  • Email if you sign in. We send a one-time code from noreply@send.rabbitmap.app. There is no password on RabbitMap.
  • Display name if you set one. That name is for you on the account. Public compare answers stay anonymous.
  • Optional security: a passkey on a device you control, and/or an authenticator app (TOTP) as a second step after the email code.
  • Ask text you type into Ask, including suggestions when a hole is not on the map yet.
  • Stands and compare answers — which camp or “not sure” you pick on a dispute, and related case answers. We do not treat these as a public byline.
  • Optional background answers if we later ask for them (for example a coarse age range or country). Those are optional. We do not require them to browse.

We record as you use the site

  • Hole views. Signed-in accounts keep a history of published holes you opened. Visitors get a short recent-view cookie so we can enforce the visitor preview limit (a few holes, then sign-in).
  • Ask searches. Signed-in accounts keep the questions you asked so they show in History and follow you across devices. This browser also keeps a short recent list in local storage for the Ask field.
  • Suggestion trail. If you suggest an uncharted hole before you sign in, we keep a cookie of those suggestion IDs (up to 400 days) so we can attach them to your account when you do.
  • Browser preferences. The map remembers whether you want connection lines shown (local storage). Plan and card-on-file UI may also live in local storage until live billing is wired to a processor.
  • Technical logs. Our host and auth providers see the usual connection data: IP address, user agent, timestamps, and which URLs were requested. We use this to run the service, debug, and stop abuse — not to build an advertising profile.

Cookies, storage, and sign-in

We use first-party cookies and similar storage that the product needs. We do not use them to retarget you on other sites.

  • Auth session cookies from our authentication provider (Supabase Auth), including support for passkeys. These keep you signed in.
  • rm_recent — slugs of holes a visitor recently opened, so the preview limit works.
  • rm_rk — a random respondent key so this browser’s stands can be stored without an account (about 400 days).
  • rm_sg — IDs of hole suggestions filed from this browser, claimed on sign-in (about 400 days).
  • Short-lived sign-in challenge cookies while an email code is outstanding.
  • localStorage for map line visibility, recent Ask searches on this device, and, today, the in-browser billing stub (plan selection / card-on-file UI). When payments go live through a processor, card numbers are handled by that processor, not stored by us as raw PAN data.

You can clear cookies and site data in the browser. You will look like a new visitor. Signed-in history lives on the account until you delete it.

How we use information

  • Run the archive, map, Ask, and accounts.
  • Send sign-in codes and security-related mail only.
  • Remember your trail, stands, and suggestions across devices once you sign in.
  • Enforce visitor limits and plan entitlements (Explorer is free; RabbitMap Pro is the paid Dig deeper membership).
  • Review suggestions and decide what to research. Filing a suggestion does not obligate us to publish a hole.
  • Aggregate stands (after enough answers) into the polarization readout on a file. We wait before we show a number. Nobody gets named.
  • Keep the service secure and investigate abuse.
  • Comply with law and respond to valid legal process.

Who processes data for us

We use vendors to operate RabbitMap. They process data on our instructions, not to advertise RabbitMap users to other companies.

  • Hosting and delivery (currently typical of a Next.js app on a cloud host such as Vercel) — page requests, logs, and cached assets.
  • Authentication and database (Supabase) — accounts, sessions, passkeys, and the application database.
  • Email (Resend) — delivery of one-time sign-in messages.
  • Payments — if and when paid plans charge a card, a processor such as Stripe will receive the payment details you submit to them. We receive tokens, plan status, and limited billing metadata, not your full card number.

Embedded media and outbound links are not our processors for your RabbitMap account. If you play a video or follow a source, that destination may collect its own data.

Sharing

We share personal information only as needed to run the service (the vendors above), to protect RabbitMap or others from harm, or if the law requires it. We may transfer the service to a successor (for example if the project changes operators); this policy would still apply until we post a new one.

Published holes, methodology, and aggregated “where others landed” figures are public by design. They are about the file, not a named user.

Stands, beliefs, and sensitive topics

The archive includes conspiracy claims, crime, war, religion, medicine, and other charged subjects. Taking a stand records how you read a dispute in our file — not a verified biography, and not legal, medical, or financial advice we asked you to rely on.

We treat those answers as account or browser research data. We do not sell them. If you delete your account, we detach your user id from stands and keep the anonymous count so the polarization readout does not break. Suggestion text may remain in the review queue without your account attached.

How long we keep it

  • Account profile, history, and security factors — until you delete the account or we close it for abuse or inactivity we cannot reasonably maintain.
  • Visitor cookies — until they expire (up to about 400 days) or you clear them.
  • Server logs — for a short operational window set by the host, then they roll off.
  • Anonymous stands and queued suggestion text — as long as they are useful to the archive or required for security and bookkeeping.
  • Deactivated or banned accounts — we may retain enough to stop the same email from returning, and to meet legal holds.

Your choices and rights

In Account you can change your display name, manage passkeys and authenticator setup, review history and suggestions, and delete the account. Deletion removes your personal data as described there: the auth user and profile go away; anonymous compare answers stay.

Depending on where you live, you may also have rights to access, correct, delete, or export personal information, to object to or restrict certain processing, and to appeal a refusal. Send the request from the email on the account to privacy@rabbitmap.app. We may need to verify it is you. We will not honor a request that would expose someone else’s account or break a legal hold.

If we rely on consent for an optional field, you can withdraw it by clearing that field or deleting the account. If we rely on legitimate interests (running a secure archive, stopping abuse), you can object; we will stop unless we have a compelling ground or a legal duty.

Children

RabbitMap is not directed at children. The files include adult themes — violence, exploitation, extremist claims, and graphic history. Do not create an account if you are under 16. We do not knowingly collect personal information from anyone under 13. If you believe we have, write to privacy@rabbitmap.app and we will delete it.

International transfers

We and our vendors may process data in the United States and other countries. Those places may not offer the same rights as your home. If you use RabbitMap from elsewhere, you are sending information to us and to those vendors.

Security

We use industry-typical controls: encrypted transport, hashed one-time codes, optional passkeys and TOTP, and access limited to people who operate the archive. No method is perfect. Do not send secrets through Ask. Treat a sign-in email as a key — do not forward the code.

Do Not Track and analytics

We do not currently run a separate product-analytics pixel. The host still sees requests. There is no industry-standard DNT response we implement beyond that. If we add first-party measurement later, we will update this page.

Changes

If we change how we collect or use personal information in a material way, we will post the new policy here and move the “Last updated” date. Continued use after that date is acceptance of the update, except where the law requires a different consent.

Contact

Privacy questions and rights requests: privacy@rabbitmap.app. You can also write from the address on your account. Sign-in mail comes from noreply@send.rabbitmap.app and is not monitored for support.

This page is a site policy, not legal advice. If something here does not match a later notice we publish on RabbitMap, the later notice controls for that subject.