Skip to content
ZeroJumpAppsZeroJumpAppsAPP STUDIO
WorkStudioApproachGet in touch
WorkStudioApproachGet in touch
← HeatZone
HeatZone
Privacy PolicyTerms of ServiceData Deletion

Privacy Policy — HeatZone

LAST UPDATED · 27 SEPTEMBER 2026

1. Who we are

HeatZone is published by Zero Jump Apps LLC. Questions about this policy, or about data we hold, go to the address in section 16.

2. There is no account

You never create one. On first launch the app signs in to Firebase Anonymous Authentication, which issues an anonymous user id. That id exists for three narrow purposes:

  • to rate-limit pin creation (10 per rolling hour) and requests for court and field data,
  • to enforce the one-live-pin-per-person cap that the heat map depends on,
  • to give our security rules a principal to name, so the database is not open to the world.

The anonymous id is not linked to you, to your Google account, to an email address or to any profile. It is not an advertising identifier. Deleting your data (section 9) destroys it and issues a new one.

Crucially, the anonymous id is never attached to a pin that anyone can read. Public pin documents carry no user id, no device id and no owner field at all. This is deliberate: a database cannot hide one field from a read, so anonymity has to be structural rather than a setting. The only places your id touches anything server-side are three records no client can ever read:

  • pin_owners/{pinId} maps a pin to your id and a hashed ownership token. Unreadable and unwritable by every client, in both directions, permanently.
  • reports/{pinId}_{uid} is written when you report a pin. Write-only; no client can read it.
  • rate_limits/{uid} holds two rolling-hour counters: pins created, and map tiles of courts and fields requested (60 per hour). Each is a list of timestamps and nothing else; which tiles you asked for is not recorded. Server bookkeeping only.

3. Location

Permissions requested: approximate location (ACCESS_COARSE_LOCATION) and precise location (ACCESS_FINE_LOCATION).

Background location (ACCESS_BACKGROUND_LOCATION) is deliberately absent from the app and will stay absent. HeatZone cannot read your position while it is closed or in the background, because Android will not let it: the permission is not declared.

The app is fully usable without location permission. Browsing the heat map, opening zones and reading activity all work with location switched off. Location is needed only to place a pin accurately and to centre the map on you.

What leaves your device

Before a coordinate is transmitted it is snapped to a 25-metre grid on the device. The server snaps it again on arrival, as defence in depth. The raw GPS fix is never transmitted at all, to us or to anyone. What we receive is a grid intersection, which is the same value for everybody standing anywhere within that 25-metre square.

Your own position marker, the dot showing where you are on the map, is drawn locally and is never uploaded.

When you create a pin, the accuracy of your fix, in metres, is sent alongside it. It is used once, to reject fixes worse than 100 metres, and is not stored on the pin.

What browsing the map reveals

Showing you a part of the map means asking the server for that part of the map, with or without location permission. The app requests pins and heat cells by map area, and courts and fields by tile, each tile being a tenth of a degree on a side, roughly 11 km. Those requests say which area is on your screen. They do not say where you are standing, and they are not stored against your anonymous id or kept as a history of where you have looked.

Courts and fields are being added one region at a time, and where they are not available yet the map says so and offers “Notify me”. Tapping it saves that area’s tile on your device, and nowhere else. About once a day, until the area is covered, the app asks the server about that tile in exactly the way it asks when you look at the map, even when the app is closed. The request says nothing more than that one tile, and it is not recorded. Once the area is covered, the app notifies you and stops asking. No email address or account is involved.

Like any internet service, the servers that answer these requests necessarily see the IP address they came from. That is handled by Google’s infrastructure (section 10), appears in its operational logs for a limited time, and is not something HeatZone reads, stores in its own database or attaches to a pin.

4. What a pin contains

Every field of a public pin document, in full:

Field Contents
geohash derived from the snapped coordinate, for map queries
lat, lng the snapped coordinate
sport one of eleven sport categories
createdAt server timestamp
expiresAt server timestamp
durationMinutes 30, 60 or 120
cellId the ~174 m aggregation cell it falls in
extended whether its one extension has been used
hidden whether reports have hidden it

There is no name, no id, no device information and no owner. Two pins dropped by the same person in different places are not linkable by anyone reading the database.

A pin lives 30, 60 or 120 minutes. It can be extended once by up to 60 minutes, to a hard ceiling of 180 minutes in total. Then it is gone: clients stop showing it the second it expires, every query filters on expiry, and a server task deletes expired pins every two minutes.

At city-wide zoom the map reads aggregated counts instead of individual pins, one number per ~174-metre cell per sport. These carry no identity and no timing information.

5. Ownership of your own pins

When you create a pin the server returns a one-time ownership token. Only a SHA-256 hash of it is kept server-side; the token itself is stored only on your device, and it is the only thing that proves a pin is yours.

The consequence is deliberate and worth stating plainly: if you clear the app’s data, reinstall, or move to a new device, you can no longer delete or extend pins you created earlier. Nothing is stranded, because they expire on their own within at most three hours, but there is no recovery path either, since there is no account to recover them against.

6. Reporting a pin

Reporting writes a record containing the pin id, the reason you chose, your anonymous id and timestamps. The record is write-only: no client, including the reporter’s own, can read it back. Three reports from three distinct people hide a pin. Report records are deleted after 30 days.

7. What is stored on your device

  • Your onboarding flag and your sport filter selection.
  • Ownership tokens for pins you created (section 5).
  • A cache of recently seen pins, heat cells and venues, so the map still shows something when you are offline. Pin and cell rows are discarded after 10 minutes.
  • The areas you asked to be notified about (section 11), at most ten, each as a map tile and the point the map was centred on. Each is removed once you have been notified.

Android’s automatic backup is enabled for HeatZone for part of this data. Your settings (the onboarding flag, sport filter and other preferences) and the areas you asked to be notified about may be included in your device’s backup to your own Google account, under Google’s terms rather than ours, so that a new phone picks up where the old one left off. The ownership tokens and the cache are excluded, and are never part of that backup. Android’s per-app backup settings control this if you would rather nothing were backed up.

8. How long we keep things

Data Retention
Pins deleted at expiry, so at most 3 hours
Ownership records 30 days, then deleted automatically
Report records 30 days, then deleted automatically
Rate-limit counters rolling one-hour window, timestamps only
Aggregate counts counts only, carrying no identity
On-device cache 10 minutes for pins and heat cells

9. Deleting your data

Settings has a “Delete my data” action. It does all of the following, in this order:

  1. deletes every pin you currently have live, so they leave the map immediately,
  2. clears the local cache,
  3. clears your ownership tokens,
  4. deletes the anonymous account itself,
  5. forgets the areas you asked to be notified about, and stops checking on them.

The order matters: the tokens that authorise deleting your pins are destroyed only after the pins are gone. Each step runs even if an earlier one failed, so a network problem cannot leave the deletion half done. A fresh anonymous id is issued the next time the app needs one.

Pins that had already expired are gone before you ask. There is nothing left to delete.

The same steps, written out tap by tap, are published at https://zerojumpapps.com/legal/heatzone/deletion/.

Because the app holds no identifier for you, we cannot look up “your” data on request, and neither can anyone else. The in-app action is the complete mechanism.

10. Third parties

Google Firebase (Authentication, Firestore, Cloud Functions, App Check). Hosts the backend. Data is processed in Google’s us-east1 region. Subject to Google’s privacy policy.

Google Play Integrity, via Firebase App Check. Attests that requests come from a genuine, unmodified copy of the app rather than from a script. Google receives device and app integrity signals as part of this.

Google Maps SDK for Android. Renders the map. Google receives the map requests your device makes. Subject to Google’s privacy policy.

Google AdMob. A single banner above the bottom navigation. There is no ad on the onboarding screen and none on the pin-creation flow. This is the one part of HeatZone that does involve an identifier, and it is Google’s rather than ours: to select, deliver and measure ads, AdMob may collect your device’s advertising ID, your IP address and the approximate location it implies, device and app information, and how you interact with an ad. HeatZone does not pass your location, your pins or your anonymous id to AdMob, and never receives the advertising ID itself.

You control this in Android, under Settings > Google > Ads (or Settings > Privacy > Ads): you can reset or delete the advertising ID, after which ads are no longer personalised with it. How Google uses this data is described at https://policies.google.com/technologies/partner-sites.

If you buy “Remove ads” (below), none of this applies to you any longer: the banner is not loaded, the advertising SDK is not started, and you are not asked for advertising consent.

Google Play Billing. HeatZone offers one optional purchase, “Remove ads”, which removes the banner for good. The purchase is made with Google Play, in Google’s own window, and is attached to the Google account on your device. Google handles the payment and holds the record of it; we never see your name, your email address, your payment method or your Google account.

What the app learns from Google Play is a yes or no: whether the Google account on this device owns the purchase. It keeps that answer on your device, so that the banner does not flash up while Google Play is being asked, and it asks again each time the app starts. The answer is not sent to our servers and is not linked to your anonymous id, so we cannot tell who has bought it, or that you have. Refunds are handled by Google Play, under Google Play’s refund policy.

GeoNames. The names of towns and cities the app shows for an area come from a list built into the app, from GeoNames (https://www.geonames.org/), under the Creative Commons Attribution 4.0 licence. Looking a name up happens on your device and sends nothing to anyone.

OpenStreetMap / Overpass API. Supplies the catalogue of courts and fields. Your device never contacts OpenStreetMap: our server holds a copy built from OpenStreetMap’s published data, so no request of yours is visible to them. Court and field locations are © OpenStreetMap contributors, available under the Open Database License (ODbL) 1.0.

We do not sell your data and we do not share it with data brokers. There is nothing identifying to sell.

11. Notifications

If you allow notifications, HeatZone warns you five minutes before your pin expires. The alarm is scheduled locally on your device and re-created after a reboot. No push service is involved and nothing is transmitted to deliver it. Declining the permission costs you only the warning.

If you tap “Notify me” where courts and fields are not on the map yet, HeatZone also tells you once they are. That notification comes from the daily check described in section 3, made by your own device. No push service is involved here either, and there is no list of people waiting on our side. Declining the permission costs you only that message.

12. Your rights, and our legal bases

Depending on where you live, the law may give you rights over personal data: to know what is held, to have it corrected or deleted, to object to or restrict its use, to receive a copy, and to complain to your data protection authority. Residents of the EEA, the UK and Switzerland have these under the GDPR and its equivalents; residents of California and several other US states have comparable rights, including the right not to be discriminated against for using them. We do not sell personal data and do not share it for cross-context behavioural advertising ourselves; the advertising in section 10 is Google’s, under the controls described there.

In practice HeatZone can honour most of these only through the app, for the reason given in section 9: there is no name, email or account to find you by. “Delete my data” is the deletion right. For anything else, write to us (section 16) and we will tell you plainly what we can and cannot do.

Where the GDPR applies, we rely on these legal bases:

  • Performing the service you asked for: showing the map, and publishing, extending and removing the pins you create.
  • Our legitimate interest in keeping the service usable and honest: the anonymous id, rate limits, the one-live-pin cap, report handling and app attestation.
  • Your consent, given through Android’s permission dialogs and withdrawn the same way, for location and notifications; and, where the law requires it, for advertising identifiers.

13. Where data is processed

The backend runs in Google’s us-east1 region, in the United States. If you use HeatZone from elsewhere, the limited data described here is transferred to and processed in the United States, under Google’s standard data-processing terms.

14. Children

HeatZone is not directed to children under 13, and we do not knowingly collect information from them. Since the app collects no identifying information from anyone, there is nothing to return; if you believe a child has used the app and you want the associated pins removed, the in-app deletion in section 9 removes them, or write to us.

15. Changes

If this policy changes materially we will update the date at the top and note the change in the app’s release notes. Continuing to use HeatZone after a change means you accept the updated policy.

16. Contact

Zero Jump Apps LLC
support@zerojumpapps.com

ZeroJumpApps, LLC
© 2026 · All rights reserved
Privacy PolicyTerms of ServiceSupport