This Privacy Policy explains how BribeMap (“we”, “us”) collects, uses, and shares information when you use bribemap.com and related services (the “Service”). It is written for people signing in with Google, submitting reports, and reading the public record.
Related rules for using the Service are in our Terms of Service.
1. Who we are
BribeMap is a crowd-sourced civic platform for first-person accounts of bribes, refused demands, and honest public service. We operate the website at bribemap.com. For privacy questions, email contact@bribemap.com.
2. Information we collect
Account information from Google
You can create an account by signing in with Google. Google is the identity provider. When you authorize that sign-in, we receive:
- Your Google account email address
- Your Google account name
- Your Google profile photo, if one is available
- A stable Google user identifier used only to recognize your account
We use this information to create and maintain your BribeMap account, show your name and photo on your account page, and (only if you choose) display a public username on reports or comments you publish. We do not read your Gmail, Drive, Contacts, or other Google content. We do not post to your Google account.
Profile information we store
After you sign in, we keep a BribeMap profile linked to that account. It may include a generated username, display name, avatar URL, account creation time, and flags used for moderation (for example, whether an account is banned). Email and phone numbers stay in our authentication provider and are not shown on anonymous reports.
Reports, comments, votes, and flags
If you submit a report, we store the content you provide: title, narrative, incident date, location (country, state/province, district, locality, optional office name), department and service, amounts, payment details you enter, optional evidence files, and whether you want the report shown as anonymous or with your username.
We also store comments, “this happened to me too” votes, and flags you submit, including whether those are anonymous or attributed.
Technical and safety data
- Hashed IP address. We do not store your raw IP. We keep an irreversible hash used only to rate-limit abuse and correlate spam.
- Approximate location on reports. We store the administrative places you select. We do not store exact GPS coordinates of an incident.
- Evidence files. Optional photos or documents you upload. We strip GPS and device EXIF from images where possible.
Information in your browser
- Session cookies from our authentication provider, so you stay signed in.
- A short-lived cookie that remembers where to send you after Google sign-in.
- Local draft storage for an unfinished report, kept in your browser until you publish or clear it. That draft does not leave your device until you submit.
Analytics
We use Vercel Analytics to understand aggregated traffic (for example, which pages are viewed). This is used to operate and improve the Service, not to build advertising profiles.
3. How we use information
We use the information above to:
- Create and authenticate your account
- Publish reports and comments you choose to submit
- Let you upvote, flag, and manage your own activity
- Moderate spam, abuse, and unlawful or unsafe content
- Compute public statistics and maps from published reports
- Protect the Service (rate limits, ban evasion, security)
- Respond to contact and security emails you send us
- Comply with law where we are legally required to do so
We do not sell your personal information. We do not use Google account data to advertise to you.
4. What is public
BribeMap is a public record. Published reports, comments, and aggregate statistics are visible to anyone without an account.
- Anonymous reports (default). We still store that your account authored the report so we can prevent spam and show you your own submissions. The public site does not show your name, email, or username on that report.
- Username reports. If you choose to post with your username, that handle (and related public profile details such as an avatar, if shown) can appear with the report or comment.
Do not put information in a narrative or filename that could identify you, an official by personal name, or another private person. We try to redact some personal data (such as phone numbers, emails, ID numbers, and names after honorifics), but that process is not perfect. You are responsible for what you choose to write.
We do not publish an official’s personal name as a structured field. Designation fields are for role or title only (for example, “clerk” or “inspector”).
5. Who we share information with
We share information with service providers who help us run BribeMap, under contracts that limit how they may use it:
- Google. Sign-in only. Google’s use of data is governed by Google’s privacy policy.
- Supabase. Authentication, database, and related hosting for accounts and report data.
- Hosting and analytics providers (including Vercel) that serve the website and collect aggregated usage metrics.
We may also disclose information if required by law, to protect the rights or safety of users or the public, or in connection with a merger, acquisition, or similar transfer of the Service, with notice where appropriate.
Moderators and operators can see internal fields that the public API does not (for example, authorship of an anonymous report, hashed IPs, and flag notes) in order to keep the Service usable and safe.
6. How long we keep information
Account data is kept while your account exists. Published reports and comments are intended as a lasting public record and may remain after you stop using the Service, including if a report was posted anonymously. Unpublished drafts live in your browser until you clear them. Hashed IPs and moderation logs are kept as long as needed for abuse prevention and audit.
To request deletion of your account or help with a report that identifies you, email contact@bribemap.com. We may retain limited information where we must (for example, to complete a moderation action, resolve a dispute, or meet a legal obligation). Public copies of a report that others have already seen or archived cannot always be fully erased from the internet.
7. Your choices
- Browse reports, statistics, and the map without an account.
- Choose anonymous or username display when you publish.
- Decline Google sign-in; some actions (report, vote, comment) then cannot be used.
- Clear a report draft from your browser.
- Sign out at any time from your account menu.
- Email us to ask what we hold about your account, to correct profile data we control, or to request account deletion.
Name and email shown on your account page come from Google and cannot be edited inside BribeMap. Change them in your Google account if you need to.
8. Security
We use industry-standard measures such as encrypted transport (HTTPS), hashed IPs instead of raw addresses, and access controls for staff tools. No method of transmission or storage is completely secure. If you believe there is a vulnerability, email security@bribemap.com.
9. Children
BribeMap is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
10. International processing
The Service is operated for a worldwide audience. Infrastructure and vendors may process data in other countries. If you access BribeMap from outside those locations, you understand that your information may be transferred and stored there.
11. Changes
We may update this policy as the Service changes. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy. Material changes will be reflected on this page.
12. Contact
Privacy requests: contact@bribemap.com
Security disclosure: security@bribemap.com