Darly/ elevation · STAC
ExplorerDocsPricing
▸ Legal

Privacy policy.

Effective September 7, 2026

Darly provides an API for public lidar and elevation data. The datasets we serve are public geospatial data and contain no personal information — this policy is about the data we hold on you: your account, your API usage, and the emails you send us. We collect as little as we can, and this page lists all of it.

What we collect

Account data. When you create an account we store your name, email address, and a hash of your password. If you sign in with Google we store your name, email, and avatar image URL as provided by Google instead of a password.

Sign-in sessions. For security, each active session records the IP address and browser user-agent it was created from. You can review and revoke sessions in your dashboard settings.

API usage records. Each API request is logged with the endpoint path, response status, timing, response size, and the API key and account it was made with. We use these records for quota enforcement, billing, and aggregate statistics. Request coordinates and query parameters are not stored. Unauthenticated requests are recorded against a truncated hash derived from the IP address and user-agent, used only for rate limiting and abuse prevention.

Support email. If you email us, we keep the correspondence so we can help you.

Audience measurement. On our public pages we count page views and clicks on a few buttons (sign up, docs, pricing, copy-example) with PostHog, hosted in the EU. It runs in cookieless mode: nothing is stored on your device, and visits are grouped by a hash of your IP address and browser that changes every day and cannot be reversed. Your IP address is discarded on arrival. Query strings are stripped, so nothing you type into a form is ever included. There is no cross-site tracking, no session recording, and no advertising. If your browser sends a “Do Not Track” signal we honor it.

Product usage for account holders. Once you have an account, our servers record a handful of milestones — account created, API key created, first API call, a request for a dataset or endpoint outside your plan, a quota reached, a plan change, account deleted — keyed by your internal account id, never your name or email. We use them to understand where people get stuck and which datasets are in demand. Individual API requests are not mirrored there; they stay in the usage records described above.

What we don't do

No advertising, no cross-site tracking, no session recording, no sale or sharing of personal data, no third-party fonts or embeds. Map fonts and basemap tiles are self-hosted. We set two cookies: the session cookie that keeps you signed in, and darly_attr, which for one hour remembers how you arrived (the referring site and any campaign parameters in the link) so that, if you sign up, we can tell which channel brought you. It contains no identifier.

Why we process it

We process account and usage data because it is necessary to provide the service you signed up for (contract). We process session and rate-limiting data to keep the service secure and fair (legitimate interest). We measure our audience and record product milestones to understand and improve the service (legitimate interest); the browser-side measurement stores nothing on your device, and you can object to either at any time by email.

Where your data lives

Darly is operated from France. Our database (accounts, sessions, usage records) is hosted with Neon in the EU (Frankfurt), and our services run on Google Cloud in the EU (Belgium). These providers process data on our behalf:

  • Neon — database and authentication hosting (EU).
  • Google Cloud — application hosting and file storage (EU). When you download data or load map tiles, your browser fetches them directly from Google Cloud Storage, so Google receives your IP address for those requests.
  • Cloudflare — DNS and network proxy in front of our domains.
  • Proton — inbound support mailboxes.
  • PostHog — audience measurement and product milestones, hosted in the EU (Frankfurt).

Where a provider processes data outside the EU/EEA, transfers are covered by the EU–US Data Privacy Framework or standard contractual clauses.

How long we keep it

Account data is kept until you delete your account. API usage records are kept for up to 24 months for billing history and aggregate statistics. Short-lived operational server logs are retained for roughly 30 days.

Deleting your data and your rights

You can delete your account yourself from the dashboard settings. Deletion is immediate: your account, sessions, and API keys are removed, and retained usage records are stripped of every identifier linking them to you.

You can also ask us for a copy of your data, ask us to correct it, or object to processing by emailing [email protected]. If you are in the EU/EEA or UK, you additionally have the right to lodge a complaint with a data-protection authority — for Darly, the lead authority is France's CNIL.

Changes and contact

If this policy changes materially, we will note it here and email account holders. Questions go to [email protected].

See also the terms of service and the mentions légales, which identify the operator of Darly.

Darly
Lidar elevation data, served as a service.
© 2026 Darly
Product
Coverage mapData specsPricingDashboard
Developers
DocumentationQuickstartOpenAPI specllms.txtSTAC Browser ↗STAC Map ↗
Company
ContactWhy DarlyPrivacyTermsMentions légales