Privacy policy
This policy explains what personal data MosaicEarth processes, why it is needed, who may receive it and how you can exercise your rights.
LAST UPDATED · 24 AUGUST 20261. Controller and scope
MosaicEarth is the controller for the personal data described in this policy and operates the service from Spain. This policy covers mosaicearth.app, app.mosaicearth.app and the related MosaicEarth services.
Privacy questions or rights requests can be sent to privacy@mosaicearth.app. Service identification and contact details are also set out in the legal notice.
2. Information we process
- Account and authentication data: username, email address, account status and the external sign-in provider you choose.
- Project and asset data: uploaded source files, derived web files, coordinates, metadata, descriptions, tags, capture dates, visibility, price and licence choices.
- Public and shared content: creator identity, asset details and saved viewer state where you publish an asset or generate a sharing link.
- Billing and transaction data: Mosaic Credit movements, subscriptions, invoices and payment status. Payment card details are handled by Stripe and are not stored by MosaicEarth.
- Support and communications: messages, completion emails, internal notifications and your communication choices.
- Technical and security data: IP address, browser and device information, request logs, error events, sign-in attempts and fraud or abuse signals.
- Cookies and similar storage: the essential session, security and service data described in our cookie policy.
3. Purposes and legal bases
4. Public assets and sharing links
Publishing a MosaicAsset makes its preview, geographic position, creator, descriptive metadata, price and applicable licence discoverable through the public globe. Acquiring users may obtain the original file under the recorded licence.
A private asset is not listed for public acquisition. However, if you create a sharing link or include it in a shared MyMosaic, anyone who receives that link may be able to view the selected content. Treat private sharing links as confidential and revoke or stop sharing them if access is no longer intended.
5. Service providers and recipients
We use providers only where needed to operate MosaicEarth. Depending on the feature you use, recipients may include:
- Microsoft Azure for application infrastructure, databases, storage, backups and operational services;
- Cloudflare for delivery and hosting of the public landing page;
- Stripe for checkout, payment security, subscriptions and billing;
- the Google or Microsoft authentication service you choose for external sign-in;
- Google reCAPTCHA for automated-abuse prevention on protected forms;
- email delivery providers for account and job-completion messages;
- MosaicEarth-managed or user-configured WebODM/NodeODM services for requested photogrammetry processing; and
- map, terrain and rendering services required by the selected viewer.
We do not sell personal data. Where a provider processes data outside the European Economic Area, we rely on an applicable adequacy decision, standard contractual clauses or another lawful transfer mechanism.
6. Retention
- Account data is normally kept while the account is active and for the limited period needed to resolve closure, fraud, security or legal issues.
- Eligible private project files follow the retention shown in the platform: the standard private period is currently 15 days unless Premium storage is active or another retention rule is displayed.
- Published assets, recorded licence acceptances and acquisition records may need to remain available to preserve the rights of creators and acquiring users.
- Billing, tax and transaction records are kept for the period required by applicable law.
- Security logs and backups are retained only for proportionate operational and recovery periods, after which they are deleted or overwritten.
7. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.
Send requests to privacy@mosaicearth.app from the account email where possible. See the data deletion procedure for account closure. You also have the right to complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
8. Your responsibilities for uploaded data
Geospatial imagery and models may reveal people, homes, vehicles, restricted sites or other personal and sensitive information. Before uploading or publishing, you must have the necessary rights and lawful basis, apply appropriate minimisation or masking, and comply with privacy, intellectual-property, property, aviation and security rules that apply to your capture and use.
9. Security
We use access controls, encrypted transport, restricted administrative permissions, audit records, backups and operational monitoring appropriate to the service. No online system can guarantee absolute security. Contact security@mosaicearth.app if you believe an account or asset has been exposed.
10. Changes and contact
Material changes will be announced in the service or by email when appropriate. The revision date above identifies the current version. Questions can be sent to privacy@mosaicearth.app.