Privacy and Transparency
As a project built for the community, your privacy comes first.
1. Personal Data
"LA MAPPA UNIPI" does not require registration, does not use profiling cookies and does not sell any personal data. We do not have a user database or an account system. All interaction with the app takes place without authentication.
2. Local Storage (LocalStorage)
To provide you with a smooth experience, we save some preferences directly on your device through the browser's LocalStorage. In particular:
- Accessibility settings (dyslexia-friendly font, text size)
- Order and visibility of the categories on the MAP
- State of the special layers (bike lanes, city walls)
- Courses followed for the class timetable (course code, course name, lecturer)
None of this is sent to our servers or analyzed. You can delete this data at any time from your browser settings.
3. Network Connections and External Services
When you open "LA MAPPA UNIPI", your browser establishes connections with several third-party services. For transparency, here is the complete list.
A) CDNs and Libraries (direct connection)
Most frontend resources (Nunito font, FontAwesome icons, the MapLibre GL map engine and the SortableJS drag-and-drop handling) are downloaded and hosted on our servers to maximize your privacy and the speed of the app. However, the only script that is still downloaded directly by the browser from an external CDN is:
cdnjs.cloudflare.com— OpenSeaDragon library (interactive indoor building floor plans)
B) Data Services (direct connection)
Some services are contacted directly by your browser. These can see your IP address:
basemaps.cartocdn.com— Background map graphic tiles (CARTO)routing.openstreetmap.de— Walking route calculation (OSRM). Activated only when you use the "Directions" feature. Your start and end coordinates are sent to this open-source server.apache.prod.up.cineca.it— University classroom occupancy (Cineca). Your browser sends a POST request directly to this server.unipi.coursecatalogue.cineca.it— Course search, class timetables and professors' calendars (Cineca Course Catalogue). Your browser sends GET and POST requests to this server to search for courses and retrieve timetables.unipi.prod.up.cineca.it— Public calendars and detailed class timetables (Cineca UP). Your browser sends POST requests to retrieve the events (classes, classrooms, lecturers) of the selected calendars.
C) Data Services (via our Proxy)
To work around browser CORS restrictions and to reduce the load on the sources, many requests go through a proxy server of ours (lamappa.org/api/proxy). In this case, the third-party platforms do not see your IP address, but only that of our Cloudflare server:
api.citybik.es— Real-time CicloPi bike availabilitywww.viaggiatreno.it— Real-time train departures and arrivalswww.sba.unipi.it— University library opening hourseventi.pisamo.it— Pisamo events and mobilityradio-eco.it— Radio Eco articles and podcastswww.regione.toscana.it— Regional train notices and newswww.arsenalecinema.com— Cinema Arsenale showtimeswww.multisalaisolaverde.it— Cinema Isola Verde showtimeswww.multisalaodeon.com— Cinema Odeon showtimes
Our proxy does not maintain any database or log of requests. It only implements a temporary cache (from a few seconds for live data, up to 30 minutes for static data) to reduce the load on the sources and speed up response times.
D) Class Calendar (via our Server)
If you use the "Sync Timetable" feature to add your classes to your calendar (Apple Calendar, Google Calendar, etc.), your device subscribes to a URL of the type lamappa.org/api/calendar.ics.
When your calendar refreshes the subscription, our Cloudflare Worker server contacts the Cineca APIs (unipi.prod.up.cineca.it) to retrieve the updated timetables of the courses you have selected, and generates a standard iCalendar (.ics) file.
In this case:
- The codes of the selected courses are included in the URL parameter (
?c=...) — this allows the server to know which courses to retrieve without requiring authentication. - Our server acts as an intermediary: it is the one contacting Cineca, not your device. Cineca only sees the IP address of our Cloudflare server.
- The results are stored in a temporary cache on the Cloudflare Edge (approximately 1-4 hours) to avoid repeated requests and speed up the update.
- We do not record or monitor which courses you follow or how many times the calendar is refreshed.
4. Geolocation
The application includes a "Find my location" button (in Settings) and a "Directions" feature to calculate walking routes. The GPS position is requested through the browser APIs and requires your explicit consent.
The coordinates are used locally to center the map and calculate distances. The only case in which your location leaves your device is when you use the "Directions" feature: in that case, the start and end coordinates are sent to the OSRM server (routing.openstreetmap.de) to calculate the route. We do not store or monitor your location.
5. Infrastructure and Hosting
The entire site is hosted on Cloudflare Pages, with a Worker proxy for API requests. Cloudflare, as a hosting and CDN provider, processes all HTTP requests to lamappa.org and consequently sees your IP address.
Cloudflare generates temporary network logs for security reasons (DDoS protection, firewall) in accordance with its own Privacy Policy. We do not have access to logs containing individual IP addresses and we do not use analytics or tracking tools.
6. What We Do NOT Do
- We do not use Google Analytics or any other analytics tool
- We do not use profiling or third-party cookies
- We do not have a user database
- We do not sell, share or process personal data
- We do not display advertising
Last updated: August 2026
Questions or concerns?
For any clarification on how the service works, on data or on privacy, you can write to us directly.