Terdaq

Terdaq Privacy Policy

Effective date: September 25, 2026

Terdaq is built and operated by GraniteCore Technologies, 330 2nd Avenue South, Suite 200 #1487, Minneapolis, MN 55401 ("GraniteCore", "we", "us"). This policy covers the Terdaq mobile app for iOS and Android and the website at www.terdaq.app. It describes what Terdaq actually collects, why, where it goes and how long we keep it, in plain language and matched to what the app really does.

The short version

Information we collect and why

Using Terdaq without an account

To show you a property, a search result or the map, the app sends requests to Terdaq's servers. Each request includes what you asked for (for example the property, the map area on screen, or the words you typed into search) and three technical headers: the app version, the app build number and the platform (iOS or Android). We use these to answer the request and to keep older versions of the app working correctly. Like any internet service, our servers and hosting provider also receive your device's IP address with each request.

We do not store your search text in our database. Search text travels in the request address, so it can appear in the operational logs described under "Server and hosting logs" below.

Your account

An account is optional. You need one only to subscribe to Terdaq+ or restore a purchase. Sign-in takes place on a Microsoft-hosted page for GraniteCore's Microsoft Entra External ID directory, using an email address and password, Sign in with Apple, or Google. Your password, and your Apple or Google credentials, go only to Microsoft, Apple or Google, never to Terdaq. The sign-in directory is operated by GraniteCore and is shared with GraniteCore's other apps (such as Sondaq), each with its own sign-in flow; the directory itself keeps the details you give it when you sign up, under Microsoft's terms.

When you sign in, the app sends Terdaq's servers a signed sign-in token, which we verify. From it we store:

The sign-in token can also contain your name. We do not store it.

Your sign-in token is stored in your phone's secure storage (the iOS Keychain, or Android's encrypted storage) so you stay signed in. It is sent with your requests to Terdaq's servers so we can tell which plan you are on.

Subscriptions and purchases (Terdaq+)

Terdaq+ is sold as an Apple App Store or Google Play subscription. Apple or Google takes the payment and holds your payment details; we never receive your card number or billing information. We use RevenueCat to keep your subscription status in sync. When you are signed in, the app identifies you to RevenueCat by your internal Terdaq account ID, not by your email address. RevenueCat receives your purchase and receipt information from the store, and its software in the app processes technical information about your device and app as described in RevenueCat's privacy policy.

On our servers we store, tied to your account ID: your plan (for example Terdaq+), where it came from (a store purchase or a complimentary grant), the store product, whether the purchase was a live or test purchase, when it expires, and the time of the last subscription event we processed. RevenueCat notifies our servers when a subscription starts, renews, changes, is cancelled or expires, and our servers can also ask RevenueCat for your current status right after a purchase. We keep a list of the notification IDs we have already processed, which contains no personal information.

Usage limits

If you are signed in, some searches count toward a monthly allowance that depends on your plan. For each month we store how many of those searches your account has used. To avoid counting the same search twice when you scroll through more results, we also keep a shortened one-way code of your last 20 counted searches (the search text and county), made with a secret key only our server holds, not the text itself. We also keep short-lived rate-limit counters keyed to your account ID to prevent abuse.

Feedback and bug reports

When you send feedback from the app, we receive:

The form shows you these details before you send. The report is not linked to your Terdaq account.

So that you can come back and see the status of your reports under "My reports", the app creates a random identifier on your phone, keeps it in your phone's secure storage and sends it only with feedback requests. It is not linked to your account or to any advertising identifier. We store only a one-way hash of it with each report.

To prevent spam and abuse, we rate-limit feedback using a one-way hash of your IP address together with the app version, build and platform. We do not store your IP address with your report.

Reports are stored in our database, screenshots in our cloud storage, and our replies and triage notes in GraniteCore's internal support tools. We do not write the text of your message or your contact details to our logs.

Tester access codes

A small number of people receive access codes from us for testing. If you enter one, it is stored in your phone's secure storage and sent with your requests to Terdaq's servers. We store only a one-way hash of the code, a note of whom we issued it to, when it was last used and how many times.

Location

With your permission, Terdaq uses your phone's location while the app is open, to centre the map on where you are and to highlight the property you are standing on. Terdaq does not request background location. The location is used on your phone and Terdaq does not send your GPS coordinates to our servers.

Once the map is centred on you, the app loads the map, the property boundaries and the details of the property you are standing on in the same way as for any other place, so our servers and the map providers listed below receive requests for that map area and that property, as they would if you had scrolled there yourself.

You can turn location access off at any time in your phone's settings. The rest of Terdaq works without it.

Photos

If you attach a screenshot to a bug report, the app opens your phone's photo picker and reads only the image you pick. Terdaq does not use the camera.

Information stored only on your phone

The following stays on your phone and is not sent to our servers: your saved properties, any properties you download for offline use, cached map and property data, your map, theme and display settings, a remembered feedback contact detail, and a local copy of your "My reports" list and any reports waiting to be sent while you are offline. Because saved properties are not backed up to your account, uninstalling the app or moving to a new phone removes them.

Server and hosting logs

Terdaq runs on Microsoft Azure in the United States. Our servers write operational logs to diagnose errors and keep the service healthy. These can include your Terdaq account ID (for example when an account is created or deleted, or when a limit is reached), feedback report IDs, and error details. Microsoft Azure, as our hosting provider, also processes technical request data such as IP addresses and request addresses to deliver and protect the service. We use these logs for operations and security only, not to build a profile of you.

Public property records shown in Terdaq

Terdaq displays public property records published by government sources, such as Minnesota county and state GIS and property-tax data (including MnGeo), and US federal sources. These records can include the names of property owners and taxpayers and their mailing addresses, because the government sources publish them. Terdaq shows each fact with its source. Finding properties by owner or taxpayer name is available only with a paid plan such as Terdaq+, and counts toward that plan's monthly allowance.

If a record about you is wrong, the government office that publishes it is the place to correct it, and Terdaq picks up the correction when it next refreshes that source. When a county withholds or replaces a name (for example under Minnesota's Safe at Home program), Terdaq shows what the current source shows and does not restore the name from older copies. You can also contact us about a record Terdaq displays.

Services the app and our servers use

Terdaq relies on the following organisations. When the app contacts one of them directly, that organisation receives your IP address and the technical details any app or browser sends, and handles them under its own privacy policy.

Terdaq sends its version, build and platform headers only to Terdaq's own servers, never to these map providers.

How we use information

We use the information above to provide Terdaq: to show properties and maps, to run searches, to sign you in, to apply the plan you have paid for or been given, to enforce usage limits and prevent abuse, to answer and act on your feedback, to fix problems, and to keep the service secure. We use your contact detail from a feedback report only to follow up on that report.

We do not sell your personal information, share it for targeted advertising, or use it to profile you. Terdaq has no advertising, and no analytics or cross-app tracking tools. We share information with the service providers listed above only as needed to run Terdaq, and we may disclose information if the law requires it or to protect the rights and safety of our users or others.

Cookies and the website

The www.terdaq.app website and the Terdaq servers set no cookies and run no analytics.

How long we keep information

Your choices and rights

We aim to respond to requests within 7 days, and we will complete your request within 30 days. Depending on where you live, you may have additional rights under the law; contact us to exercise them.

Security

Connections between the app and our servers use HTTPS. Sign-in tokens, the feedback identifier and access codes are kept in your phone's secure storage. On our servers, access codes and the feedback identifier are stored only as one-way hashes, our database accepts sign-in only through Microsoft Entra identities rather than passwords, and the app's database access is limited to what each feature needs. No system is perfectly secure, and we cannot guarantee the security of information sent over the internet.

Children

Terdaq is a general-audience app for property research and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us and we will delete it.

Where your information is processed

Terdaq is operated from the United States and currently covers Minnesota. Our servers and data are hosted on Microsoft Azure in the United States. The service providers listed above may process information in the United States and other countries.

Changes to this policy

If we change this policy, we will post the new version at www.terdaq.app/privacy and update the effective date above.

Contact

Questions about this policy or your information, and requests to access, correct or delete it:

GraniteCore Technologies, 330 2nd Avenue South, Suite 200 #1487, Minneapolis, MN 55401

contact@granitecoretech.com