The design decision everything follows from
Reports are public. That is deliberate and it is what makes the network function: a map only works if people can see what is on it, confirm it, and act on it.
Personal data is not public. Account details, email, location history and a resident's own activity trail are not exposed to other users, are not sold, and are not shared with third parties for advertising. There is no advertising in the product at all, which removes an entire category of data-sharing question.
So the honest summary is: the litter is public, the person is not. Anyone evaluating this should hold us to that line and check it.
What is visible on a public report
- The location of the report: necessarily, since that is the point of it
- The photos submitted with it
- Title, description, type and severity
- The reporter's display name and avatar, as they chose them
- Its lifecycle: when it was reported, cleaned, or reopened
What is not
- Email address and account credentials
- The resident's location history: the app knows where a report was made, not where the person has been
- Any device or advertising identifier used for tracking; there is no ad tech in the product
- Private groups and private events, which are visible only to their members
Hosting and location
Data is hosted in the EU. For most municipal procurement that is the question behind the question, so it is worth stating plainly rather than burying in a sub-clause.
If your process requires specifics, the sub-processors involved, the exact region, transfer mechanisms, ask and we will put them in writing. We would rather answer that in week one of an evaluation than in month three of a legal review.
Erasure, and what survives it
A resident can delete their account and the personal data associated with it, from inside the app. This is worth understanding, because "delete everything" is not quite what happens and a procurement officer will spot the gap if we gloss it.
What is deleted is the person: account, personal details, the link between them and their contributions. What remains is the public content they created, reported spots, cleanup records, comments, events, but anonymised, no longer attached to their name or profile.
The reasoning is that the shared map and the community history are collective records that other people also rely on. Erasing a cleanup from three years ago would rewrite the history of a location for everyone who contributed to it. If your legal position requires different behaviour, that is a conversation to have before a pilot, not after.
What municipal staff can see
Access is scoped to your territory. Staff see reports inside your boundary and nothing outside it. A neighbouring council's reports are not visible to your team, and yours are not visible to theirs.
Within your organisation, permissions are capability-based rather than three fixed job titles, so you grant triage, assignment, reporting or settings access to the roles you actually have. Internal notes on a report are visible to your staff, not to the resident who reported it.
External contractors can be given access to the work assigned to them without that implying access to everything else.
Controller, processor, and the honest answer
For the citizen app, residents use a public service and CleanSpot determines the purposes of the processing.
For the municipal dashboard, the split depends on the arrangement: what your authority does with reports in your territory, and under what legal basis, is a matter for your DPO and our agreement, not something a marketing page should assert.
We would rather write "that depends, here is who decides it" than publish a confident answer that turns out to be wrong for your specific setup.
Moderation and photographs
Photos are user-submitted, which creates an obvious risk: someone photographs a person, a number plate, or a private interior along with the rubbish.
There is a moderation path for removing content, and removal propagates: a removed photo stops being served and stops counting toward public figures. If your authority needs a defined route for takedown requests from residents, ask; it is a reasonable thing to want written into an agreement.
Is data hosted in the EU?
Yes. If you need the specific region, sub-processors and transfer mechanisms documented, ask and we will provide them in writing.
Can a resident have everything deleted?
They can delete their account and personal data from the app. Public content they created stays on the map but is anonymised and no longer linked to them. If your legal position requires full erasure of the content too, raise it before a pilot.
Do you sell data or run advertising?
No to both. There is no advertising in the product and personal data is not sold or shared for advertising purposes.
Can our staff see reports outside our municipality?
No. Access is scoped to your territory.
Do you hold ISO 27001 or similar certification?
No, and we are not going to imply otherwise. If a certification is a hard requirement in your procurement, tell us early so nobody wastes time.