Logo
← Back to Home

Privacy Policy

Last updated: September 4, 2026

This policy covers the Littr website (littr.info) and the Littr apps for iOS and Android.

In short

  • Littr is a community project. We do not sell your data, we do not show ads, and there is nothing in our apps that tracks you across other apps or websites.
  • To use the app you need an account: a username, a password and an email address.
  • When you mark litter, the photo, the GPS location, the litter details and your username are visible to other Littr users. Your username, level and score also appear on the leaderboard. Please keep people, faces, vehicle number plates and home addresses out of your photos.
  • We use error reporting (on by default) and usage analytics (off unless you turn it on). Both are controlled by you under Account → Privacy, and neither ever receives your location, photos, notes or contact details.
  • The website counts page views without cookies, using Vercel and Google Analytics. Nothing on it tracks you across other sites.
  • Photos are screened automatically before anyone sees them, and a person decides on anything flagged. A small number of Littr volunteers can see account and submission data through a moderation dashboard, and everything they change is logged.
  • Your account and content are stored in the UK and the EU. You can download a copy of your data or delete your account at any time — from this website or from inside the app.

Who is responsible for your data

Littr (“Littr,” “we,” “our,” or “us”) is a community-run litter picking project based in Berlin, Germany, operated by an individual rather than a registered company. For the purposes of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG), we are the data controller for the personal data described in this policy.

You can reach us about anything in this policy at contact@littr.info. We have not appointed a Data Protection Officer, as we are not required to.

Information we collect

Website (littr.info)

  • Nothing you have to give us. You can browse the whole site, including our collection statistics, without an account and without submitting any personal information.
  • Email correspondence: if you email us, we receive your email address and whatever you write to us.
  • Technical data: our hosting provider records standard server logs (IP address, browser user agent, requested page, timestamp) to serve the site and protect it from abuse.
  • Aggregate usage measurement: we measure page views and page load performance using Vercel's built-in analytics and Google Analytics. Both are cookieless. We run Google Analytics in its consent-denied mode on every visit, so it stores no cookies or identifiers on your device and cannot link one visit to the next. It receives the page you viewed, the site that referred you, your browser type and your approximate location; it uses your IP address only to work out that location and does not store it. We have all advertising features switched off. Neither service builds a profile of you or follows you across other websites. If you would rather not be counted at all, a content blocker or Google's Analytics opt-out browser add-on stops these requests.

The litter collection totals shown on our home page and stats page come from a spreadsheet of event weights. It contains collection dates and kilogram totals, not personal information about participants.

Littr app — account information

  • Username (required) — chosen by you and shown publicly next to litter you mark and on the leaderboard. You do not have to use your real name.
  • Password (required) — we never store your password itself. We store a one-way bcrypt hash of it, which cannot be reversed back into your password.
  • Email address (required) — it is the only way we can verify your account and help you recover it, so we ask for it at registration. To verify it we send a six-digit code and store only a hashed, short-lived copy of that code. We do not send marketing email.
  • Profile photo (optional).
  • Age confirmation: when you register you confirm you are 16 or older (or have a parent's consent). We record the date you confirmed this, not your date of birth.
  • Score data: your XP total and level, a record of each individual XP award, your day streak, the badges you have earned, and counts of your marks and cleanups. These are all calculated on our server, never by the app.
  • Account timestamps: when your account was created and last updated.

We do not ask for your phone number, your real name, your date of birth or your address.

Littr app — the litter you mark

  • Photos: the photo of the litter you take with the camera, or choose from your photo library. The app re-encodes every photo on your device before uploading it, which strips the embedded metadata — including any GPS coordinates, capture time and camera details the original file carried.
  • Precise location: the GPS latitude and longitude of the mark, which you can adjust on a map before submitting. The app also uses your device location while you have it open to centre the map and find marks near you.
  • Litter details: the quantity band (small, medium, large), the litter types you select (plastics, toxic, commercial, industrial, glass, general public waste, paper and cardboard) and any free-text notes you add.
  • Cleanups: when you mark something as cleaned, we record that you did so, when, and any optional proof photo.
  • Timestamps: when each mark and cleanup was created.

If you mark litter while offline, the mark and its photo are held in a queue on your device only and uploaded when you are back online. Nothing leaves your phone until then.

What the apps do not collect

To be explicit: the Littr apps contain no advertising software, no session recording or screen replay, no social login, and nothing that tracks you across other apps or websites. We do not collect your contacts, your calendar, your health data, your device advertising identifier, or your location while the app is closed or in the background.

What other people can see

Littr works because the community can see where litter is. When you submit a mark, the following becomes visible to other signed in Littr users on the map and in the app's feeds:

  • Your username
  • The photo you submitted
  • The precise GPS location of the mark, shown as a pin on a map
  • The litter quantity, types and any notes you wrote
  • When you submitted it, and whether it has been cleaned

The leaderboard shows your username, level, the XP you earned in the selected period, and how many marks and cleanups you have recorded, ranked against other users for the week, the month or all time. Everyone signed in to Littr can see it. Taking part is automatic — if you would rather not appear, contact us.

Please think before you submit. Do not photograph people, faces, number plates, house numbers, letters or documents, and avoid marking litter at a location you would not want associated with you, such as directly outside your own home. Anything visible in a photo is published along with it.

Your email address and password are never shown to other users.

Photo rules and moderation

What you may upload

Photos must be JPEG, PNG, HEIC or WebP, and up to 10 MB. A photo attached to a mark should show litter — not people, faces, number plates, house numbers, letters, documents or anything else that identifies somebody. Sexual content, gore and hateful material are not allowed anywhere on Littr. If you send us feedback from the app you can attach a screenshot or a short screen recording; those go only to us and are never shown to other users.

Automated screening

Because a photo you upload can appear on other people's screens within seconds, uploads are screened automatically before anyone sees them. The image is sent to a specialist content moderation provider, which classifies it for sexual content, violence and self-harm and returns a verdict. Nothing else about you goes with it — not your name, your email address or the location of the mark.

Your photos are not stored by that provider, and are never used to train anyone's AI models. The moderation service we use keeps nothing from these checks: the image is classified in the moment and discarded. It is a content check, not a contribution to a training set.

If the screen flags a photo, the mark is hidden from everybody, including you, and waits for a person to look at it. The automated step never has the last word: a moderator makes the decision, and if they disagree with the screen they restore the mark. Equally, a photo passing the screen is not approval — it only means the classifier saw nothing, and anyone can still report it.

If the provider can't be reached, your upload is allowed through rather than blocked, and the fact that it went unchecked is recorded so it can be screened later.

Reporting something

You can report any mark from the app — as not litter, inappropriate, a privacy problem, or spam — and add a note. A moderator reviews it and either removes the mark or restores it. If a photo shows you or your property, reporting it is the fastest route; you can also email us.

When flagged content is kept

This is the one exception to everything else in this policy about deletion, so it is worth stating plainly. When a photo is flagged, we freeze a record of it — the photo itself, the username, email address and account creation date of whoever uploaded it, and where and when it was taken. That record survives deletion of the account, and is removed only once a moderator has ruled on it.

We do this because some of what an automated screen catches is the kind of material that has to be reportable to the authorities, and someone who has just uploaded it has an obvious reason to delete their account before anyone looks. Our legal basis is our legitimate interest in the safety of the people who use Littr and in being able to establish or defend legal claims (Art. 6(1)(f) and Art. 17(3)(e) GDPR). It applies only to content the screen flagged or a moderator hid — nothing else you upload is held back this way.

Who at Littr can see your data

We run a moderation dashboard, used by a small number of trusted Littr volunteers, so that we can answer support requests, remove content that shouldn't be there, and correct mistakes. Through it they can see your username, email address, whether your email is verified, when you joined, your score and badges, and the marks, cleanups and photos you have submitted.

Access is limited by role. Most accounts are read-only. A smaller number can edit or remove users, marks and cleanups, adjust scores and award or remove badges. A single senior role can additionally manage the other dashboard accounts and export data in bulk. Dashboard accounts are entirely separate from app accounts — no app login can reach the dashboard — they require a longer password and support two-factor authentication, and their sessions are short-lived and individually revocable.

Every change is recorded. Any action that modifies data writes an entry naming who did it, what they changed, before and after, the reason they gave, and the time. Deletions and bulk exports require a written reason. We keep this record so that access to your data is accountable, and we retain it even after the account or mark it refers to is gone.

Error reporting and usage analytics

Both of the following are controlled by you, in the app, under Account → Privacy. Neither ever receives your location, photos, notes, username or email address. Both are handled by specialist providers on our behalf, on their European infrastructure, so the data stays in the EU. They are named in the service providers table below.

Error reporting — on by default, switchable off

When the app or our servers hit an unexpected error, we send a technical report so that we can find and fix it. The report contains the error and its stack trace, your device model, operating system version and app version, and — if you are signed in — your Littr account ID, which is a random identifier. We switch off the features that would otherwise capture screenshots, your screen layout, or the web addresses our app requests (those can contain map coordinates). Expected errors, such as a wrong password or a validation message, are never reported.

Reports are kept for 90 days and then deleted. Legal basis: our legitimate interest in keeping Littr working (Art. 6(1)(f) GDPR). Switch it off under Account → Privacy → Send crash reports and it stops immediately.

Usage analytics — off unless you opt in

If — and only if — you turn on Account → Privacy → Share anonymous usage data, the app sends a small, fixed set of events so we can see which features are actually used. Until you turn it on, the analytics software is never even started.

The complete list of events we may send is: app opened, login, registration, mark submitted (with the size band, how many litter types were ticked, and whether it had been queued offline), mark queued offline, cleanup recorded, leaderboard viewed (with which period), badges viewed, and account deleted. Alongside them we send your device model, operating system and app version, screen size, locale, timezone and network type, plus your Littr account ID. We do not record your screen, your taps, or which pages you look at.

Events are kept for 12 months and then deleted. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by switching the toggle off — the app stops sending immediately and forgets its analytics identity. Deleting your account also breaks the link between your account ID and any past events.

How we use your information, and our legal basis

Under the GDPR we must have a lawful basis for each thing we do with your data. Ours are:

What we do Data used Legal basis
Create and run your account, sign you in, keep you signed in Username, password hash, email address, session token Performance of a contract (Art. 6(1)(b))
Verify your email address and let you recover your account Email address, hashed verification code Performance of a contract (Art. 6(1)(b))
Publish your marks to the community map and feeds Photo, location, litter details, username, timestamp Performance of a contract (Art. 6(1)(b)) — this is the service you signed up for
Access your camera, photo library and location Photos, precise device location Your consent, given through the operating system's permission prompts (Art. 6(1)(a)) — withdrawable at any time in your device settings
Award XP, levels, streaks and badges, and rank the leaderboard Username, XP award history, mark and cleanup counts Performance of a contract (Art. 6(1)(b))
Confirm you are old enough to use Littr Your 16+ confirmation and its date Legal obligation (Art. 6(1)(c)), read with Art. 8 GDPR
Moderate content, answer support requests, and keep a record of what our moderators do Account and submission data, moderator actions and reasons Legitimate interests (Art. 6(1)(f)) — a safe community and accountable access to your data
Screen uploaded photos automatically before other users see them The photo itself Legitimate interests (Art. 6(1)(f)) — nobody should be shown illegal or abusive imagery
Hold a record of flagged content pending review, and report it where we must The flagged photo, uploader username and email, account creation date, location and time Legitimate interests and legal claims (Art. 6(1)(f), Art. 17(3)(e))
Produce aggregate statistics and litter maps for the website and for community campaigns Aggregated and anonymised mark data Legitimate interests (Art. 6(1)(f)) — documenting the community's environmental impact
Diagnose crashes and unexpected errors Error reports, device and app version, account ID Legitimate interests (Art. 6(1)(f)) — switchable off in the app
Understand which features are used, to improve Littr The usage events listed above, account ID Your consent (Art. 6(1)(a)) — off unless you opt in
Keep the service secure, rate-limit abuse and fake submissions Server logs, IP address, account and submission activity Legitimate interests (Art. 6(1)(f)) — running a safe, working service
Measure website traffic and page performance Cookieless, aggregated page view data (Vercel and Google Analytics) Legitimate interests (Art. 6(1)(f)) — no cookies are set and no profile is built
Reply to you, and comply with legal obligations Your correspondence and account data Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects. XP, levels, streaks, badges and leaderboard rank follow simple published point rules, not a profiling system.

Permissions the app asks for

  • Camera — to photograph the litter you mark.
  • Photo library — only if you choose to attach an existing photo instead of taking one.
  • Location, while using the app — to place your mark accurately and to show marks near you. Littr does not request background or “always” location access and cannot track you when the app is closed.

You can grant or withdraw any of these at any time in your device settings — on iOS under Settings → Privacy & Security or Settings → Littr, on Android under Settings → Apps → Littr → Permissions. Withdrawing location or camera access means you will not be able to create new marks, but the rest of the app keeps working.

Who we share information with

We do not sell, rent or trade your personal information, and we do not share it with advertisers or data brokers. We share data only with the service providers we need in order to run Littr. Each of them acts as our processor — they may only use the data to provide the service to us, under a contract requiring protection equivalent to this policy. The categories are:

  • Hosting and database providers — run our servers and store your account, marks, cleanups and scores.
  • Object storage providers — store the photos you upload.
  • Email delivery providers — send your verification email.
  • Error reporting and usage analytics providers — as described above.
  • Content moderation providers — receive the photos you upload, and only the photos, in order to screen them for prohibited content.
  • Map providers — supply the map you see. To draw it, their servers receive your IP address and the area of the map you are looking at.
  • Push notification gateways — Apple's and Google's notification services are the only way to deliver a notification to a phone. They receive your device's notification token and the text of the notification itself.
  • Weather providers — receive an approximate location so we can show the forecast for an event. No account details go with it.
  • App store and mobile platform providers — distribute the apps and supply device location services.

Our service providers

For transparency, these are the providers we currently use. If we change one we will update this list.

Provider What they do for us
DigitalOcean Hosts our API, moderation dashboard and database (United Kingdom)
Amazon Web Services Stores uploaded photos and sends verification email (EU)
Sentry Error reporting (EU region)
PostHog Usage analytics, only if you opt in (EU region)
OpenAI Automated screening of uploaded photos for prohibited content
Vercel Hosts littr.info and measures page views without cookies
Apple iOS app distribution, map tiles, and push notifications to iPhones
Google Android app distribution, device location services, push notifications to Android phones, cookieless page view measurement on littr.info (Google Analytics), and the spreadsheet holding our aggregate collection weights
OpenStreetMap Foundation Map tiles in the Android app
Open-Meteo Weather forecasts for event locations

We may also disclose information where we are legally required to, where it is necessary to protect the rights, property or safety of Littr or our community, or with your explicit consent.

Platforms we link to, but do not control

Our website links to our WhatsApp community group, our Instagram page, our Reddit community and our donation page. If you follow those links and take part, those services collect your data under their own privacy policies, not this one. We can see what any other group member can see — for example your WhatsApp display name and phone number in the group — but we do not export or store that information.

Cookies

The Littr website does not set advertising or tracking cookies, and our page view measurement is cookieless. That includes Google Analytics, which we run in its consent-denied mode so that it never sets a cookie. The apps do not use cookies; they store your sign-in token in the device's secure storage — the iOS Keychain, or encrypted preferences on Android — so you do not have to log in every time. Signing out or deleting the app clears it.

Our moderation dashboard, which only Littr volunteers can sign in to, sets a single strictly necessary session cookie. It is not used for tracking and it is never set on littr.info or in the apps.

How long we keep things

  • Account data — for as long as your account exists. Deleted immediately when you delete your account in the app.
  • Marks, photos and cleanups — kept while they are useful to the community. When you delete your account we delete your photos outright and detach your username from your marks, keeping only the anonymised location, litter type and date so the community map and historical statistics stay intact.
  • Verification codes — hashed, valid for minutes, and deleted once used or expired.
  • Sign-in tokens — expire after 7 days.
  • Error reports — 90 days, then deleted.
  • Usage analytics — 12 months, then deleted. Only exists if you opted in.
  • Flagged or hidden photos — the photo and its frozen record are kept until a moderator rules on them, even if the account is deleted first, then removed.
  • Moderation records — kept indefinitely, so that there is a lasting account of who accessed or changed what. They identify the moderator, not you, beyond the identifier of the record they acted on.
  • Server logs — retained for a short period (typically up to 30 days) for security and fault diagnosis.
  • Website page view data — Google Analytics keeps individual, cookieless page view events for two months, its shortest setting. Aggregated totals, such as page views per day, are kept for longer because they contain nothing about you personally.
  • Email correspondence — kept while the conversation is relevant, and deleted on request.
  • Aggregated, anonymised statistics — kept indefinitely. These cannot be traced back to you.

Getting a copy of your data, and deleting your account

There are two ways to do this, and you do not need our help with either.

  • On this website — enter your email address and we'll send you a six-digit code. With that code you can download everything we hold about you as a file, delete your account, or both. You don't need to be signed in, or to still have the app installed.
  • In the app, under Account → Delete account. You will be asked to re-enter your password, so that a lost or stolen phone can't be used to wipe your account.

Deletion is immediate and cannot be undone, so if you want a copy of your data, download it first.

Deletion removes your username, email address, password hash, profile photo, XP history, streak and badges, and erases every photo you uploaded from our storage. The underlying litter records are anonymised rather than removed — they show as reported by a deleted user — so that the community map does not develop holes and cleaned-up sites do not reappear as unreported. Once the link to you is severed and the photographs are destroyed, what remains is a coordinate, a litter type and a date, which is no longer personal data.

One exception: if a photo of yours was flagged by our automated screening or hidden by a moderator and hasn't been ruled on yet, that photo and the record attached to it — including your username and email address — are kept until a moderator decides. See Photo rules and moderation above for why.

If you want your marks removed entirely rather than anonymised — for example because a photo shows someone identifiable — ask us and we will do that instead.

If either route doesn't work for you, email us at contact@littr.info and we will action it within 30 days.

How we protect your data

  • Passwords are stored only as bcrypt hashes and are never returned to any client, including our own apps.
  • Sign-in tokens are stored in your device's encrypted secure storage (iOS Keychain, Android encrypted preferences).
  • Transport — all traffic between the apps, our servers and our storage runs over encrypted HTTPS connections.
  • Photos are not publicly listable. They are served through short-lived signed links that expire, rather than from an open bucket.
  • Database access is restricted to a single dedicated application role per environment; the database is not exposed to the public internet.
  • Separated credentials — photo storage and email sending use different, narrowly scoped provider accounts, so a problem with one cannot reach the other.
  • Moderation access is a separate system with its own credentials and signing keys, two-factor authentication, short sessions that can be revoked individually, and a permanent log of every change.
  • Rate limiting and hardened headers protect our servers against brute-force sign-in attempts and abuse.
  • Score integrity — XP, levels and badges are calculated on our servers and can never be set by a client.

No system is perfectly secure. If we ever become aware of a breach affecting your personal data, we will notify the competent supervisory authority within 72 hours where required, and tell you directly where the risk to you is high.

Your rights

You can exercise two of these yourself, straight away and without asking us: download a copy of your data, or delete your account. For anything else, email us.

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy (Art. 15)
  • Correct data that is wrong or incomplete (Art. 16)
  • Erase your data (Art. 17)
  • Restrict how we process it (Art. 18)
  • Portability — receive your data in a machine-readable format, or have it sent to another controller (Art. 20)
  • Object to processing we base on legitimate interests (Art. 21)
  • Withdraw consent at any time, for anything we do on the basis of consent — including camera, photo library and location access, and usage analytics. This does not affect processing carried out before you withdrew (Art. 7(3))

To exercise any of these, email contact@littr.info. We will respond within one month. We do not charge for this, and we will not ask you for more identifying information than we need to be sure it is really your account. If you ask, we will also tell you the specific providers your data has been shared with.

Complaining to a regulator

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to lodge a complaint with a data protection supervisory authority — in our case the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), or with the authority where you live or work.

Children

The Littr app is not intended for children under 16. In Germany, the digital age of consent under Art. 8 GDPR is 16, so users under that age may only use the app with the consent of a person holding parental responsibility. Registration requires you to confirm that you meet this condition. We do not knowingly collect personal data from children under 16 without that consent. If you believe a child has created an account, contact us and we will delete it.

Children are very welcome at our in-person litter picking events when accompanied and supervised by an adult — that does not require a Littr account.

International data transfers

Your photos are stored in the European Union, verification email is sent from the EU, and error reports and usage analytics are stored in the EU. Your account, marks and scores are stored in the United Kingdom. The European Commission has decided that the UK provides an adequate level of data protection, so data may flow there from the EEA without additional safeguards; that decision was renewed in March 2026 and runs until 27 December 2031.

Some of our providers are US-headquartered and may access data from outside the EEA for support and operations. Cookieless page view data from Google Analytics is processed by Google on the same basis. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses and, where applicable, the provider's certification under the EU–US Data Privacy Framework.

Changes to this policy

We will update this policy when what we do with your data changes — for example if we add a new provider, or start collecting something new. We will change the “Last updated” date above, and for significant changes we will tell you in the app before they take effect.

Contact us

Questions about this policy, or about your data:

*Approximately, some data may have been missed and averaged at times.
View our stats here


Copyright © 2025 Littr | Privacy Policy