Stomp!

Privacy Policy

Last updated September 24, 2026. Draft — pending legal review.

Who we are

Stomp! is made and run by Lyle Sanders and Jeremy Labelle ("we", "us"). This policy explains what the app collects, why, who can see it, and how to delete it. Questions or requests: support@thestomp.net.

Privacy at a glance

A quick summary — the sections below go into full detail.

Email address

Linked to you • Used to sign in and reset your password

Collected

Precise location

Linked to you • Only when you log a kill, never in the background, and optional

Collected

What you log and share

Linked to you • Kills, display name, profile icon, friends, featured badges

Collected

Feedback you send

Linked to you • What you type, plus your phone's model, system version and screen size, and the app's version

Collected

Identifiers

Linked to you • Your account ID, used to tie your data to your account

Collected

Analytics, ads and cookies

No analytics tools, no ad networks, no cookies

None

Sold or used to track you

Never sold, never shared for advertising or cross-app tracking

None

What we collect

Your email address and password when you make an account. Your password is never stored in readable form. Each kill you log: how many, when, and — if you allow location — where, as coordinates plus the town, state and country your phone works out from them. Your display name, profile icon, featured badges, friend requests, and the date you took the honesty pledge. Anything you send through the feedback form, and with it your phone's model, system version and screen size and the app's version — sent so a bug can be reproduced on the right kind of device, and only when you send feedback. Nothing else: no contacts, photos, microphone, or background location.

How it's used

Only to run the app: your stats, history, streaks and badges; the Friends, Regional (same state) and National leaderboards; the community total and challenge; and the community map. Feedback is read by us to fix bugs and improve the app. We don't use your data for advertising, and we don't sell it.

Who can see what

Other signed-in users can see your display name, profile icon, kill totals and featured badges, and which state you log in, because that is how the leaderboards and friends work. Your email address is never shown to anyone. Your exact coordinates stay on our servers: the community map only ever receives kills rounded to roughly 100 metres and added together, with no name attached.

Services we rely on

Your account and data are stored with Supabase, our database provider, which holds it on our behalf and doesn't use it for its own purposes. To turn coordinates into a town name, your phone's built-in location service is used (provided by Google on Android and by Apple on iPhone). The community map loads its map pictures from OpenStreetMap and its map code from unpkg, which, like any website, see your device's internet address when they send them. None of these receive your name or email from us.

What's stored on your phone

The app doesn't use cookies. It keeps a sign-in token in your phone's encrypted storage, only if you choose "Remember me", so you stay signed in. It also remembers small settings such as your theme, your display name and profile icon for a faster start, and a copy of what your account has unlocked, so the Store opens quickly. These stay on your phone and are removed when you uninstall the app; the unlocks themselves are kept with your account, which is why they come back when you sign in on a new phone.

Your choices and deleting your data

Location is optional: turn it off in your phone's settings at any time and kills still log, just without a place. In Settings, "Reset kill data" permanently deletes every kill you've logged, along with the badges earned from them; your account, friends, purchases and other badges stay. "Delete my account" permanently deletes your account straight away — your login and email, profile, kills, friends and unlocks. Two things outlive both: feedback you've sent, with your name removed from it, and anonymous sighting records, described below. To ask what we hold about you, or to delete your account without the app, write to support@thestomp.net.

How long we keep it

For as long as you have an account, until you delete it as described above.

Anonymous sighting records

When you reset your kill data or delete your account, one thing is kept: a record that lanternfly were seen. It holds a rough area, the date, and how many — nothing else. There is no name, no account, no email, no exact location and no time of day, and nothing that could be used to link one record to another or back to you. We keep these because the point of the app is knowing where the invasion is and how hard it's being pushed back, and that picture shouldn't develop holes whenever somebody leaves. Because they can't be traced to a person, they aren't deleted on request — there is nothing in them to find you by.

Children

Stomp! is for people aged 13 and over. We don't knowingly collect data from anyone younger. If you believe a child under 13 has made an account, contact us and we will delete it.

Changes to this policy

If what we collect or who can see it changes — for example, if ads are ever added — this policy will be updated first and the date at the top will change. Anything beyond what the app strictly needs will ask for your permission before it is switched on.

Contact

Lyle Sanders and Jeremy Labelle — support@thestomp.net