Your collection and your privacy

You can use Poké Lid Dex as a guest. Optional accounts add private cloud backups on deployments where accounts are enabled.

Describes guest use and optional accounts · Updated 9 October 2026

This page describes how the current app handles data. External providers have their own privacy policies.

What is saved on your device

Guest use does not upload your collection or photos to an account service. Signing in also does not automatically upload or replace your collection. The app does not send your notes or photos to an AI provider.

Local storage is not encrypted by this app. Someone with access to your browser profile or device may be able to read it. Browser storage can be cleared or evicted; it is not a reliable backup.

There is no automatic cross-device sync. Storage belongs to the website origin and browser profile. A different domain, browser, installed-app context, or device may have a separate collection.

Optional accounts and private cloud backups

Where enabled, accounts use Supabase authentication. Registration, sign-in, email verification, and password recovery send your email and authentication requests to the project's Supabase service over HTTPS. Passwords are handled by the authentication provider; the app does not save your password in its collection or backups. Verification and recovery emails also pass through the configured email provider.

A managed sign-in session, including access and refresh tokens, is stored in this browser so you can stay signed in. Signing out removes this device's session. It does not sign out other devices or clear this browser's collection. On a shared device, export what you want to keep and use Settings → Clear all data before handing the browser to someone else.

Choosing Back up this device uploads a snapshot containing catches, visit dates, photos, notes, saved lids, trips, and the catalogue ID mapping. Backup metadata includes your account ID, a random device ID, the device name you enter, server timestamp, file size, and integrity hashes. Nearby starting coordinates are not included.

Cloud backups are stored in a private bucket with account ownership checks. They are not public share links and are not cached by the offline worker. They are not encrypted end to end: the project operator and service provider may have administrative access. Supabase and the email provider also receive ordinary connection information and may retain operational or security logs under their policies.

There is no automatic cross-device sync or merging. Restoring a selected backup replaces this device's collection after confirmation. Signing into a different account does not switch the local collection; a collection left in this browser can be deliberately backed up to the account currently shown.

Cloud snapshots remain until you delete them or your account, subject to provider backups and retention. Use the account screen to download or delete individual backups. Delete account requires your password and confirmation, removes your cloud backup files and account, and keeps the local collection. If deletion is interrupted, some backups may have been removed before the account deletion finishes; refresh the list and retry.

Clearing local collection data does not delete cloud backups or sign you out. Deleting your account does not remove local collections on other devices, files you downloaded, shares, or provider logs. Provider backup retention and production email configuration must be reviewed by the operator before public account registration is enabled.

Supabase privacy policy

Optional location access

Nearby lids requests your device location only after you choose Use my location. You can instead select an approximate prefecture starting point or enter coordinates yourself. Device permission is controlled by your browser.

The starting coordinates and calculated distances are held in memory for the current session. They are not saved to your journal or backup, and the app does not send them to a project server. Nearby distances are calculated locally. Browser or operating-system location services have their own handling of location data.

Revoke location permission in your browser settings if you no longer want to allow it. Opening an external directions service is a separate action.

Connections to external providers

Cloudflare hosting

Cloudflare Pages serves the website's files. Like other web hosting, this involves receiving requests with information such as your IP address, requested URL, browser headers, and request timing. Cloudflare may process or log this information for delivery and security under its own policies. The project's app code does not control all hosting-level processing or retention.

Cloudflare privacy policy

OpenStreetMap tiles

When the map is displayed, your browser requests background tiles from OpenStreetMap's tile service. The tile URLs identify the viewed map area; the service also receives ordinary request information such as your IP address and browser headers. Map browsing can therefore reveal an area you are looking at. The tracker does not provide offline tile downloads.

OpenStreetMap Foundation privacy policy

Directions and other links

Choosing directions opens Google Maps with the selected lid's public destination coordinates. Google Maps may use your location or account according to its own settings and policies. Links to official Pokémon information or GitHub similarly connect to those sites when you open them.

Google privacy policy · GitHub privacy statement

Fonts and tracking

Fonts, libraries, and app scripts are hosted with the tracker. Fonts do not request Google Fonts. The app does not include an analytics tracker, advertising scripts, or app-set tracking cookies. Local storage is used for the collection, preferences, and an optional managed sign-in session. Hosting providers may use their own security mechanisms; this statement does not cover cookies or tracking on external sites you choose to visit.

Backups, copied links, and shared images

Export backup creates a JSON download containing your collection, including stored photos, dates, notes, and travel lists. It is not encrypted. Keep it in a private location and check a backup before replacing or clearing your collection.

Copying a lid link places its public detail URL on your clipboard. Memory-card download or copy actions can include your personal photo, note, and visit date. Those actions happen when you choose them; the app does not publish a public gallery of your memories.

Downloaded files, clipboard contents, shared images, and copies kept by other apps or people are separate from this browser's collection. The tracker cannot erase those copies. Avoid copying or sharing private details on a shared device.

Changing and deleting your data

Uncatching a lid does not delete its stored note or photo. Clearing collection data does not delete downloads, clipboard copies, external shares, hosting logs, or the browser's public app-file cache. Your browser's site-data controls can remove remaining local storage and caches; export a backup first if you want to keep your collection.

Local records remain until you remove or replace them, or your browser clears them. This app does not promise a fixed retention period for browser storage or external-provider logs.

Questions and changes

You can report a privacy concern through the project's GitHub Issues. Issues are public: do not attach private photos, backups, precise coordinates, or sensitive notes.

If automatic sync, analytics, payments, or other data processing are introduced, this information and the relevant controls will need to be updated before those features are released.