SHITIZENS
PrivacyTermsSupportSafety

PRIVACY NOTICE

Privacy without surprises.

Last updated September 10, 2026.

SHORT VERSION

You can browse without location permission. Posting sends your photo and the precise location captured with it to SHITIZENS for processing. Public pins show an approximate area. The photo can still make a place recognizable, including when someone chooses Show photo. Every install starts with a private anonymous account. Browsing stays anonymous; before a first post, you choose a private name. Saving the account with a password or email is optional and never creates a public profile.

What this notice covers

This notice covers the SHITIZENS mobile app, its website, and the service that publishes and community-manages eligible Toronto street posts. SHITIZENS documents observations; it does not identify a person, promise cleanup, or submit a City of Toronto 311 request.

Information the service handles

Browsing and device choices

Browsing does not require location permission. The app can keep filters, hidden map items, followed areas, and a user-chosen coarse starting area on the device. Those choices are not evidence and are never converted into a route or movement history. The website does not request browser camera or location access; it is a landing and safe-share surface.

Optional product collection

Optional product collection is off unless you turn on Help improve SHITIZENS in Settings. When it is on, the app may send a random event identifier, a fresh session identifier that changes at every app launch, app version, time, a fixed app screen and flow stage, outcome, a coarse error category, and an optional duration. This helps us understand repeated ordered app flows and fix broken steps. It does not include a location, photo, media reference, post identifier, URL, account name, typed text, or arbitrary metadata. The session identifier is not kept as a cross-device identifier. Turning this choice off stops collection on the phone immediately, clears pending local events, and asks the service to remove earlier optional events for that installation. If the phone is offline, collection stays off and the removal request retries when it reconnects. Optional product events are deleted no later than 90 days after they occurred.

Website reactions and photo reveal

When you first react or reveal a screened photo on the website, we create an anonymous browser identity and store its credential in an HTTP-only cookie for up to one year. It remembers your current reaction and helps limit abuse without asking for an email or app install. You can change a reaction or tap it again to remove it. Clearing this cookie removes this browser’s access to that identity. Only emoji reactions are available to guest website visitors; they do not verify a post or control whether it stays on the map. Photos are requested only after you tap Show photo.

Map search

Neighbourhood searches use our local area list. When there is no neighbourhood match, we send the text you typed to the City of Toronto’s address service to find addresses and places. This does not use your device location. Selecting an address centres the map for this session; we do not save it as your preferred area or treat it as posting or verification evidence.

Private source evidence

To submit, the app requires a non-mocked iOS Full Accuracy or Android Fine foreground location inside Toronto, accurate within 25 metres and tied to the photo within 15 seconds. The submission also includes the camera image and capture time. The server validates and normalizes it into a private source copy with embedded metadata removed, stored under a generated private key.

Visual privacy screen

Before a source can supply a public visual, a private self-hosted screen checks for likely identifying visual detail. It holds the source from public processing when it detects a visible person or face, a licence plate, readable address, sign, or text, or another identifying private detail. The result is a generic private hold; it does not record a description of what the screen saw. This is an automated safety filter, not a guarantee, so please do not submit photos with people, plates, addresses, or readable signs.

Nearby presence checks

A nearby check needs a new foreground fix no more than eight seconds old, accurate within 25 metres, non-mocked, inside Toronto, and within 1.5 km of the already-public coarse anchor. The service compares the transient device claim only with that anchor—never the submitted private capture coordinate—and does not retain or publish the checker's exact location. It retains the outcome, timestamp, coarse accuracy band, and pseudonymous installation credential; it never retains the raw check coordinate. A nearby check cannot prove or expose the submitted exact spot.

Private name, password, and optional recovery

Every installation starts with a private anonymous account backed by a persistent pseudonymous installation credential in platform secure storage. It lets you manage your photos in the You tab, change Photo reveal, remove your photos, and follow areas. Map browsing, capture, nearby checks, and sharing do not require an email, password, or saved account. Immediately before a first Post to map, you choose one unique private lowercase name. The name appears only in authenticated You and password sign-in; it never appears in a map, post, share, public DTO, public URL, or public profile. You may add a password to Save account and sign in by name and password on another phone. You may also add an email address for one-time account recovery. In production, Resend delivers that code. The code restores the account; it does not reset or change the password. We use the address only to deliver and verify the recovery code; SHITIZENS persists only an HMAC of the normalized address and one-way code hashes, never a plain-text email address. A forgotten password cannot be used to sign in; without a recovery email, the account is unrecoverable. Saving your account does not change any installation's attestation, public trust, location requirement, reaction eligibility, or rate limit. The website does not collect a waitlist email address.

Support messages

The public Support form sends a private support, privacy, takedown, legal, or access message to the SHITIZENS owner's mailbox. It does not ask for an email address, account, installation credential, post ID, photo, or location. The optional published email route receives the address and message you choose to send; it is not needed to use the form and is not connected to your app identity. Please do not include passwords, exact locations, links, or files. To request deletion of other service data, send a Privacy or removal message through Support.

Optional post notifications

If you turn on post updates in the mobile app, we store a notification token for that installation. Expo and Apple or Google deliver a short update when a new post is ready or needs attention. The payload contains a post identifier, but no photo, precise location, name, or email. Turn these updates off in Settings at any time. Deleting your account deletes its notification registrations. Delivery records are kept for up to seven days.

Owner notifications

When processing stops, an automatic notification or the reporter’s Notify us button can email the owner the receipt number, capture time, area label, processing status, and a secure review link. That link permits viewing the bounded, metadata-free photo and making one review decision. It expires after 24 hours and becomes invalid when the submission changes or a decision is made. Emails contain no photo attachment, precise GPS coordinates, or installation credential.

What can become public

New submissions appear publicly only after automated eligibility, safety, and public-preview processing. The public map receives a stable coarse, city-clipped one-kilometre area anchor and a neighbourhood label—not the capture coordinate. Reports at the same anchor are grouped as a count, not displayed as pretend-exact pins. Eligible community members can choose one of six reversible reactions. Looks real and Looks fake are the only two that affect map visibility; the other four are social only. Active reactions expire after seven days; sending the same choice again does not extend the window. Three active Looks fake reactions with at least a two-reaction margin over Looks real hide the pin from public discovery, and it can return if that balance changes or checks lapse. Two distinct qualified privacy or unsafe-media reports create a faster, reversible safety hide.

A nearby Still there or Gone answer is stored without raw GPS. It contributes to public status only from a server-verified genuine app installation; unsupported, unverified, or revoked installations remain private signals. In each rolling 48-hour window, only the latest eligible answer from each verified installation counts. Still there marks a post Recently reported, including restoring a Gone post. One Gone answer makes a non-Gone post Unconfirmed. Three distinct recent Gone answers with at least a two-signal Gone margin make it Gone. These status changes are automatic for eligible signals. App integrity reduces scripted replay; it does not prove a person, a location claim, or the original report.

Private source copies never appear in maps, Hotspots, owner notifications, public web previews, Open Graph images, social cards, or public lists. The person who posted it and tightly restricted emergency-safety operations can access protected source evidence for withdrawal and emergency-safety work. A separate owner review tool is a loopback-only Basic-Auth relevance dashboard: it contains only terminal unrelated results with separately passed source safety and the current visual-privacy screen, and an owner must explicitly select a case before its bounded metadata-free processing copy loads. Unsafe, manipulated, visual-privacy, uncertain, and blocked results never enter. The dashboard exposes only that bounded copy, never the retained high-resolution original or exact capture location. The secure email review links described above also allow the owner to view a processing copy when a photo needs attention. They never expose the retained high-resolution original or exact capture location. A reporter can separately permit a viewer-controlled screened source-photo view on public post detail only after the automatic media screen passes; the bounded metadata-free processing copy loads only after a viewer taps to reveal it and has no EXIF or exact capture location.

Public detail defaults to a cartoon after the person who posted it chooses Post to map. That affirmative posting action authorizes the self-hosted preview and a viewer-tapped Show photo action. An asynchronous automatic media screen evaluates relevance, safety, and basic plausibility, plus visual privacy, before a public visual is eligible. It does not establish that a photo is true, that the post is current, who caused a condition, or whether anyone is lying. Public visuals become unavailable as soon as the post is no longer publicly eligible.

How information is used and disclosed

We use this information to operate the app, apply automated safety and eligibility safeguards, prevent abuse, provide receipts and area activity, keep voluntarily claimed private activity available when a person changes phones, create safe public map and share views, generate the cartoon authorized by Post to map, or provide the consented screened source-photo view after a deliberate reveal and the automatic media screen. For the narrow terminal-unrelated/source-safety-passed exception, an authenticated owner may select the bounded processing copy in the private loopback dashboard to decide whether to queue private cartoon processing. That decision never directly publishes a post or enables source-photo reveal. Support messages are delivered to the private owner mailbox. Owner notifications contain status details and may include a secure photo-review link. They never contain photo attachments or precise location. We do not sell personal information or use precise location, photos, or pseudonymous installation credentials for cross-app behavioral advertising.

If you choose optional product collection, we use its fixed event vocabulary only for aggregate product analysis of ordered and repeated app flows. It does not change map visibility, posting, account access, safety decisions, advertising, or prices.

Private source evidence is processed by a SHITIZENS-operated, self-hosted model service. We do not send private source evidence or precise coordinates to a third-party AI provider and do not use submissions, cartoons, or location data to train any model. Information is otherwise processed by the service's hosting, storage, database, narrow owner relevance review, and emergency-safety operations. We may disclose information where legally required or needed to protect the service, users, or the public. We do not publish private source evidence or an exact capture coordinate merely because a post is public.

App Store privacy label

The current App Store privacy declaration identifies Precise Location, Photos or Videos, Other User Content, User ID, Product Interaction, Email Address, and Customer Support. Precise Location, Photos or Videos, Other User Content, User ID, and Product Interaction are linked to the private account and installation credential because that link is needed for receipt, withdrawal, abuse prevention, and follow controls. A private lowercase account name is part of the User ID category and is never public. Email Address is collected only when a voluntarily claimed account adds it for account recovery and is retained only as an HMAC hash. Precise location, photos or videos, other submitted content, the installation credential, private name, and email hash are used for app functionality; limited optional product-interaction data is used for aggregate product analytics only after you turn on Help improve SHITIZENS. Customer Support is used for app functionality. The public ticket form itself is unlinked because it accepts no account, installation credential, email, photo, location, or post ID; a direct Support email is linked only to the address a person chooses, never to their app identity. None of these categories are used for cross-app tracking or advertising.

Retention and deletion

A protected draft retains its shutter-bound precise fix only until it is sent or deleted. When you remove your photo, the emergency path removes one, or a serious abuse, safety, legal, or privacy suspension is confirmed, the service immediately makes source evidence and any public cartoon unavailable, clears the exact capture coordinate and public location fields, and queues physical evidence deletion within seven days. A suspension revokes the anonymous installation's current session and applies that same cutoff to all of its posts. Settings > Account data or Device data > Delete account & data permanently removes an anonymous account's installation credential, its owned posts and private receipts, follows, reactions, nearby checks, safety reports, contributor hides, and local draft/settings data. For a saved account, it permanently removes every linked installation and the private name, password credential, and HMAC recovery-email hash too. It immediately removes access to your photos and their cartoons. Other people’s photos and updates stay on shared posts. An HMAC-only completion receipt is retained for up to one year so an offline phone can safely retry a lost deletion response; it contains no installation ID, post, location, media key, or support-message link. If storage is temporarily unavailable, UUID-only cleanup is retried without restoring access. Ordinary activity, canonical engagement, and optional product events attributed to the app identity are removed. If an emergency suspension audit is required for safety or legal accountability, it retains only its constrained reason, emergency actor, and confirmation time after this erasure; its installation and source-post references are cleared. Encrypted backups age out within 35 days.

Optional product events are also removed when you turn off Help improve SHITIZENS. If you leave it on, they are retained for no more than 90 days from their occurrence time, then deleted in bounded maintenance batches.

Source evidence is retained only while the post is active and is deleted or queued for deletion no later than 90 days after it ceases to be active. A public cartoon exists only while the post is publicly eligible, then becomes unavailable immediately and is deleted within seven days. A community-hidden or safety-hidden post is removed from public discovery but its private bytes are retained so a reversible visibility change can restore it. Encrypted backups age out within 35 days. The immediate access cut-off is code-enforced; these physical-deletion and response periods are operating commitments.

Support-form messages are not linked to an installation and do not create an account or ongoing contact record. They are kept only to handle the request, then deleted from the private owner mailbox. If you choose to email Support directly, your message and email address are handled to answer that request and are not connected to your app identity. Support messages are never public map content, so deleting an app identity does not reveal, alter, or attach a message.

Support and reporting

For a public post, use Report post in the app for privacy or unsafe public media. Use Looks fake for a routine wrong-place, duplicate, or misleading pin. For your own photo, use Photo reveal or Remove photo in the You tab. Other people’s photos and updates stay on shared posts. The public Supportpage lets you send SHITIZENS a private message without an account or email address.

Changes to this notice

We will update this page before changing how personal information is materially handled. The launch version also requires Ontario and Canadian privacy review, accessibility review, and applicable App Store and Google Play policy review.

SHITIZENS maps community posts about street waste. It is not a City of Toronto service or a 311 submission.

SupportBack to SHITIZENS