Last updated: 26 July 2026
Biome Atlas (“the app”, “we”, “us”) is an interactive map of the world’s biomes, operated as a personal, non-commercial project by Jan Wohlfahrt-Laymann from Germany. For any privacy question or request, contact us at [email protected]. For the purposes of the EU/UK General Data Protection Regulation (GDPR), we are the “data controller” for the limited personal data described below.
We only collect what the app needs to sign you in and save your progress:
| Data | Where it comes from | Why |
|---|---|---|
| Your email address, and your basic Google profile (name, profile picture) and Google account ID | Provided by Google when you choose “Sign in with Google” | To identify your account and show who’s signed in |
| Your exploration progress — places marked seen, your wishlist, and experiences you log | Created by you as you use the app | To save your progress and sync it across your devices |
| Technical data such as your IP address and browser type | Automatically, in the server logs of our hosting/content providers (see §6) | To deliver the site securely and prevent abuse |
We do not collect a password (Google handles sign-in), and we
request only the minimum Google scopes: your email address and basic profile
(email, profile, openid). We do not access your
Gmail, contacts, files, or anything else in your Google account.
Your data is used solely to:
We do not use your data for advertising, profiling, analytics, or any automated decision-making, and we do not sell, rent, or trade it.
Where GDPR applies, we process your data on the basis of your consent (which you give by choosing to sign in) and to perform the service you requested (saving and syncing your progress). You can withdraw consent at any time by signing out and deleting your data (see §9).
Biome Atlas does not use advertising or tracking cookies. To work, it stores a
small amount of data in your browser’s localStorage: your exploration
progress (so the app works offline) and your Supabase login session (so you stay
signed in). Some third-party resources listed in §6 may set their own cookies as a
normal part of delivering content (for example, map tiles or CDN files).
We rely on the following providers. Signing in and saving progress involves the first group; the second group are content sources your browser loads directly, which therefore receive your IP address in order to serve that content.
Core infrastructure:
| Provider | Role |
|---|---|
| Google LLC | Sign-in (Google OAuth). Governed by the Google Privacy Policy. |
| Supabase, Inc. | Authentication service and the managed PostgreSQL database that stores your account and progress. |
| Cloudflare, Inc. | Website hosting (Cloudflare Pages), content delivery (CDN), and DNS for the site. |
Third-party content loaded in your browser:
| Provider | What it serves |
|---|---|
| Wikimedia Foundation | Place photos and image galleries (Wikipedia / Wikimedia Commons) |
| OpenStreetMap Foundation & CARTO | Map tiles |
| Freesound (Universitat Pompeu Fabra) | Optional soundscape audio previews |
| unpkg & jsDelivr | Open-source JavaScript libraries (map and Supabase client) |
| Perplexity AI | Only if you tap the optional “Ask AI” button on a place — this opens Perplexity in a new tab with a pre-filled question. No account data is sent. |
These providers act as our processors or independent controllers for the technical data (such as IP address) they necessarily receive. We do not send them your account data or progress.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google-provided data only to authenticate you and label your account, we never transfer it to others except as needed to run the service (our database provider above), and we never use it for advertising.
Your account and progress are stored in Supabase’s managed database. Our providers (Google, Supabase, Cloudflare) may process data on servers located outside your country, including in the United States. Where required, such transfers are covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
We keep your account and progress until you delete them. Because your progress is stored under your account ID and protected by database row-level security, only you (when signed in) and the operator can access your row.
You have the right to access, correct, export, or delete your data, and to withdraw consent. To do so:
You also have the right to lodge a complaint with your local data protection authority.
Sign-in is handled by Google, so we never see or store a password. Data is transmitted over HTTPS, and access to your stored progress is enforced at the database level by row-level security so that each signed-in user can only read and write their own record.
Biome Atlas is not directed at children and we do not knowingly collect data from children under the age where consent is required in their country. If you believe a child has provided us data, contact us and we will delete it.
If we change how the app handles data, we’ll update this page and the “Last updated” date above. Material changes affecting signed-in users will be reflected here.
Questions or requests: [email protected].