Terdaq Privacy Policy
Effective date: September 25, 2026
Terdaq is built and operated by GraniteCore Technologies, 330 2nd Avenue South, Suite 200 #1487, Minneapolis, MN 55401 ("GraniteCore", "we", "us"). This policy covers the Terdaq mobile app for iOS and Android and the website at www.terdaq.app. It describes what Terdaq actually collects, why, where it goes and how long we keep it, in plain language and matched to what the app really does.
The short version
- You can look up properties, browse the map and save properties without an account. We do not ask who you are for any of that.
- Sign-in is handled by Microsoft Entra External ID, with email, Sign in with Apple or Google. We never see or store your password.
- If you create an account, we store an internal account ID, your sign-in identifiers, your email address (if your sign-in provides one), your plan and your monthly usage counts.
- Your location, if you allow it, is used on your phone to centre the map on you. Terdaq does not send your GPS coordinates to our servers.
- Terdaq+ subscriptions are billed by Apple or Google and managed through RevenueCat. We never see your card or payment details.
- Feedback you send is stored with the app details listed on the form before you send it. It is not linked to your account.
- We do not run ads, we do not include analytics or advertising SDKs, we do not track you across other apps or websites, and we do not sell your personal information.
- You can delete your account from inside the app at any time.
Information we collect and why
Using Terdaq without an account
To show you a property, a search result or the map, the app sends requests to Terdaq's servers. Each request includes what you asked for (for example the property, the map area on screen, or the words you typed into search) and three technical headers: the app version, the app build number and the platform (iOS or Android). We use these to answer the request and to keep older versions of the app working correctly. Like any internet service, our servers and hosting provider also receive your device's IP address with each request.
We do not store your search text in our database. Search text travels in the request address, so it can appear in the operational logs described under "Server and hosting logs" below.
Your account
An account is optional. You need one only to subscribe to Terdaq+ or restore a purchase. Sign-in takes place on a Microsoft-hosted page for GraniteCore's Microsoft Entra External ID directory, using an email address and password, Sign in with Apple, or Google. Your password, and your Apple or Google credentials, go only to Microsoft, Apple or Google, never to Terdaq. The sign-in directory is operated by GraniteCore and is shared with GraniteCore's other apps (such as Sondaq), each with its own sign-in flow; the directory itself keeps the details you give it when you sign up, under Microsoft's terms.
When you sign in, the app sends Terdaq's servers a signed sign-in token, which we verify. From it we store:
- An internal Terdaq account ID, a random identifier we create for you.
- Your sign-in identifiers from Microsoft (the token's subject identifier and, where present, your directory object ID), so we can recognise you next time.
- Your email address, if the sign-in provides one, and whether the provider says it is verified. If you use Sign in with Apple and choose to hide your email, this is the relay address Apple gives us. We use it to identify your account and to apply any complimentary access we have granted to that address.
- When the account was created and when you last signed in.
The sign-in token can also contain your name. We do not store it.
Your sign-in token is stored in your phone's secure storage (the iOS Keychain, or Android's encrypted storage) so you stay signed in. It is sent with your requests to Terdaq's servers so we can tell which plan you are on.
Subscriptions and purchases (Terdaq+)
Terdaq+ is sold as an Apple App Store or Google Play subscription. Apple or Google takes the payment and holds your payment details; we never receive your card number or billing information. We use RevenueCat to keep your subscription status in sync. When you are signed in, the app identifies you to RevenueCat by your internal Terdaq account ID, not by your email address. RevenueCat receives your purchase and receipt information from the store, and its software in the app processes technical information about your device and app as described in RevenueCat's privacy policy.
On our servers we store, tied to your account ID: your plan (for example Terdaq+), where it came from (a store purchase or a complimentary grant), the store product, whether the purchase was a live or test purchase, when it expires, and the time of the last subscription event we processed. RevenueCat notifies our servers when a subscription starts, renews, changes, is cancelled or expires, and our servers can also ask RevenueCat for your current status right after a purchase. We keep a list of the notification IDs we have already processed, which contains no personal information.
Usage limits
If you are signed in, some searches count toward a monthly allowance that depends on your plan. For each month we store how many of those searches your account has used. To avoid counting the same search twice when you scroll through more results, we also keep a shortened one-way code of your last 20 counted searches (the search text and county), made with a secret key only our server holds, not the text itself. We also keep short-lived rate-limit counters keyed to your account ID to prevent abuse.
Feedback and bug reports
When you send feedback from the app, we receive:
- the kind of report (bug, feature idea or other) and the message you write;
- a contact email or other contact detail, only if you choose to enter one;
- a screenshot, only if you choose to attach one;
- details about the app and where you were in it: app version, build number, over-the-air update ID, platform, operating-system version, your plan, the screen you were on, the property you were viewing and the search you had typed, when those apply.
The form shows you these details before you send. The report is not linked to your Terdaq account.
So that you can come back and see the status of your reports under "My reports", the app creates a random identifier on your phone, keeps it in your phone's secure storage and sends it only with feedback requests. It is not linked to your account or to any advertising identifier. We store only a one-way hash of it with each report.
To prevent spam and abuse, we rate-limit feedback using a one-way hash of your IP address together with the app version, build and platform. We do not store your IP address with your report.
Reports are stored in our database, screenshots in our cloud storage, and our replies and triage notes in GraniteCore's internal support tools. We do not write the text of your message or your contact details to our logs.
Tester access codes
A small number of people receive access codes from us for testing. If you enter one, it is stored in your phone's secure storage and sent with your requests to Terdaq's servers. We store only a one-way hash of the code, a note of whom we issued it to, when it was last used and how many times.
Location
With your permission, Terdaq uses your phone's location while the app is open, to centre the map on where you are and to highlight the property you are standing on. Terdaq does not request background location. The location is used on your phone and Terdaq does not send your GPS coordinates to our servers.
Once the map is centred on you, the app loads the map, the property boundaries and the details of the property you are standing on in the same way as for any other place, so our servers and the map providers listed below receive requests for that map area and that property, as they would if you had scrolled there yourself.
You can turn location access off at any time in your phone's settings. The rest of Terdaq works without it.
Photos
If you attach a screenshot to a bug report, the app opens your phone's photo picker and reads only the image you pick. Terdaq does not use the camera.
Information stored only on your phone
The following stays on your phone and is not sent to our servers: your saved properties, any properties you download for offline use, cached map and property data, your map, theme and display settings, a remembered feedback contact detail, and a local copy of your "My reports" list and any reports waiting to be sent while you are offline. Because saved properties are not backed up to your account, uninstalling the app or moving to a new phone removes them.
Server and hosting logs
Terdaq runs on Microsoft Azure in the United States. Our servers write operational logs to diagnose errors and keep the service healthy. These can include your Terdaq account ID (for example when an account is created or deleted, or when a limit is reached), feedback report IDs, and error details. Microsoft Azure, as our hosting provider, also processes technical request data such as IP addresses and request addresses to deliver and protect the service. We use these logs for operations and security only, not to build a profile of you.
Public property records shown in Terdaq
Terdaq displays public property records published by government sources, such as Minnesota county and state GIS and property-tax data (including MnGeo), and US federal sources. These records can include the names of property owners and taxpayers and their mailing addresses, because the government sources publish them. Terdaq shows each fact with its source. Finding properties by owner or taxpayer name is available only with a paid plan such as Terdaq+, and counts toward that plan's monthly allowance.
If a record about you is wrong, the government office that publishes it is the place to correct it, and Terdaq picks up the correction when it next refreshes that source. When a county withholds or replaces a name (for example under Minnesota's Safe at Home program), Terdaq shows what the current source shows and does not restore the name from older copies. You can also contact us about a record Terdaq displays.
Services the app and our servers use
Terdaq relies on the following organisations. When the app contacts one of them directly, that organisation receives your IP address and the technical details any app or browser sends, and handles them under its own privacy policy.
- Microsoft: Entra External ID for sign-in, and Azure for hosting our servers, database, file storage and logs.
- Apple and Google: Sign in with Apple and Google sign-in if you use them; App Store and Google Play for downloads, subscriptions and payments.
- RevenueCat: subscription management, as described above.
- Expo (EAS Update): when the app starts, it checks Expo's update service for app updates. That request includes technical details about the installed app, such as its version and platform, and may include a random installation identifier created by the update software.
- OpenStreetMap: the street basemap tiles.
- USGS (The National Map): shaded-relief terrain tiles.
- jsDelivr: the 3D property view loads its mapping library from the jsDelivr content-delivery network.
- GraniteCore map storage: aerial imagery and the fonts used for map labels, hosted by GraniteCore on Microsoft Azure.
- Esri: Esri World Imagery aerial tiles, only when the aerial basemap feature is enabled for you. Today it is limited to internal testing.
Terdaq sends its version, build and platform headers only to Terdaq's own servers, never to these map providers.
How we use information
We use the information above to provide Terdaq: to show properties and maps, to run searches, to sign you in, to apply the plan you have paid for or been given, to enforce usage limits and prevent abuse, to answer and act on your feedback, to fix problems, and to keep the service secure. We use your contact detail from a feedback report only to follow up on that report.
We do not sell your personal information, share it for targeted advertising, or use it to profile you. Terdaq has no advertising, and no analytics or cross-app tracking tools. We share information with the service providers listed above only as needed to run Terdaq, and we may disclose information if the law requires it or to protect the rights and safety of our users or others.
Cookies and the website
The www.terdaq.app website and the Terdaq servers set no cookies and run no analytics.
How long we keep information
- Account information, plan and usage counts: until you delete your account. Monthly usage rows are kept while the account exists.
- After you delete your account: we keep only a count of how many searches and analyses you used in the current calendar month, stored under a one-way keyed code derived from your sign-in identity (not your email or any other contact details), solely to stop deleted-and-recreated accounts from resetting the free monthly allowance, and we erase it automatically at the end of that month.
- Short-lived rate-limit counters: these hold a count and a time keyed to your account ID or a hash, and are overwritten as you use Terdaq. Counters keyed to your account ID are deleted when you delete your account.
- Feedback reports and screenshots: kept until they are no longer needed to support Terdaq and fix the problems you report. They are not linked to your account, so deleting your account does not delete them; see "Your choices and rights" to ask us to delete them.
- Operational logs: up to 90 days.
- Backups: our database backups are kept for 7 days, so deleted information can remain in a backup for up to 7 days before it expires.
Your choices and rights
- Access and correction: you can see your email address and plan on the Account screen in the app. To ask for a copy of the information we hold about your account, or to correct it, contact us at the address below.
- Deleting your account: open Account in the app and choose Delete account. This permanently deletes your Terdaq account record, your email address and sign-in identifiers, your plan and purchase records, and your usage counts from our database straight away. It is not a "soft" delete.
- What account deletion does not do: it does not cancel an App Store or Google Play subscription (only you can cancel it, in your store account settings, and you should do that before or after deleting); it does not delete your sign-in in GraniteCore's Microsoft Entra directory, which other GraniteCore apps may also use; it does not delete RevenueCat's record of your purchases; and it does not delete feedback reports, which are not linked to your account.
- If you cannot use the app, or want more deleted: contact us to delete your account, your sign-in directory entry or your feedback reports. Because feedback reports are not linked to your account, tell us roughly when you sent them and what they said so we can find them.
- On your phone: you can remove saved properties and offline downloads in the app, turn off location or photo access in your phone's settings, and remove everything stored on the phone by uninstalling Terdaq.
We aim to respond to requests within 7 days, and we will complete your request within 30 days. Depending on where you live, you may have additional rights under the law; contact us to exercise them.
Security
Connections between the app and our servers use HTTPS. Sign-in tokens, the feedback identifier and access codes are kept in your phone's secure storage. On our servers, access codes and the feedback identifier are stored only as one-way hashes, our database accepts sign-in only through Microsoft Entra identities rather than passwords, and the app's database access is limited to what each feature needs. No system is perfectly secure, and we cannot guarantee the security of information sent over the internet.
Children
Terdaq is a general-audience app for property research and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us and we will delete it.
Where your information is processed
Terdaq is operated from the United States and currently covers Minnesota. Our servers and data are hosted on Microsoft Azure in the United States. The service providers listed above may process information in the United States and other countries.
Changes to this policy
If we change this policy, we will post the new version at www.terdaq.app/privacy and update the effective date above.
Contact
Questions about this policy or your information, and requests to access, correct or delete it:
GraniteCore Technologies, 330 2nd Avenue South, Suite 200 #1487, Minneapolis, MN 55401
contact@granitecoretech.com