The googlymaps manual
Everything the app does, in one place. If you only want the short version, read how it works instead. This is the full reference.
This manual is kept current. If something here doesn't match the app, that's
a bug worth reporting to [email protected].
Anything described here that is decided but not yet built is marked (not built yet) where it appears, and listed again in What isn't built yet at the end. We'd rather say "designed, coming" than let you assume something is protecting you today when it isn't. That list used to be long. As of 25 August 2026 it has one item left on it, because the rest shipped.
What googlymaps is
A world map of googly eyes.
People stick googly eyes on things (postboxes, parking meters, bins, statues, the family dog) and other people find them. This is the map of where they are. You photograph one, the app records exactly where you're standing, and once it's checked, a pin appears for everyone.
That's the whole app. A photo and a place.
A pin has no title and no description. There is nowhere to type anything at all. That isn't an oversight. Every word a user could write would be a word nobody had checked, sitting on a public map, and the automatic checker only ever looks at pictures. Take the box away and the problem goes with it. The photo says what it needs to say. The fields don't exist behind the scenes either: they were removed from the database, not just hidden.
Getting started
Signing in
Browsing the map needs no account at all. Posting does.
You can sign in with Google, Apple, or an email address and password. Whichever you choose, we get almost nothing: an account identifier and, for email sign-ups, your email address. We don't ask for your name, and we don't store a profile picture even if your provider offers one.
Your account carries a name, purely so our own records make sense. It is never published: not on a pin, not on the chart, not anywhere another user can see it.
Where that name comes from is worth being exact about, because the obvious
answer is the wrong one. Google and Apple do hand us the name on your account,
usually your real one. We throw it away and generate one instead: googly_
and a few characters. Nothing in this app ever asked for your real name, and
picking it up as a side effect of which sign-in button you tapped would be
collecting it by accident, which is the kind of thing that is easy to do and hard
to undo. If you signed up on our own form and typed a name in, that's the name
you have. Either way you can change it in your account, and nothing anyone else
sees depends on it.
Your age
You need to be 16 or older to post. You can browse at any age.
We ask for your date of birth the first time you try to post, not when you sign up. We check it, record the moment you were confirmed old enough, and then discard the date. We never write your birthday to the database and we don't keep it. There is no column for it to go in: the check runs on the value you typed and the value is gone by the time the answer is stored.
Why the check happens at posting rather than at signup: Apple and Google don't tell us your date of birth when you sign in with them, so refusing to create the account would simply have broken those buttons. The account can exist; it can't post until the age check passes.
The 16 is enforced in the database itself, not in the app on your phone, so there's no version of the app that can be talked out of it. There is no parental-consent route.
We ask once, and the answer sticks to that account. If the date you give is under 16, we record that it happened and the account can't post from then on. You don't get a second go with a different date. That's the only thing that makes asking worth anything: a question you can answer again until you get the answer you want isn't a check, it's a formality.
What we record is simply that it happened, and when. Not the date you typed, and not anything the date could be worked back out from.
We know an honest person can mistype a year, and that somebody who was 15 will eventually be 16. Both cases are a real email to [email protected] and a human sorting it out, rather than an automatic second chance that would defeat the point.
And to be straight with you: none of this proves anything. Somebody determined to lie about their age can. The check is here so that we asked, so that the answer is recorded, and so that we aren't knowingly running a service for children. Actually verifying age would mean asking you for ID or a card, which would mean collecting exactly the personal information the rest of this manual explains we go out of our way not to hold.
Posting a googly eye
1. Take the photo
The app opens the camera. Get close enough that the eyes are clearly visible, with enough of the object in frame that people can tell what they're stuck to. Daylight helps. That's it.
You take the photo there and then. You can't upload one you already had, and that's deliberate rather than us being awkward.
The place on a pin comes from your phone at the moment you post, not from the photo. Phones and browsers strip location out of saved pictures anyway, so if you uploaded a photo from a trip last week while sitting at home, we'd have no honest way to know where it was taken, and the pin would land on your house. A pin in the wrong place is worse than no pin at all, because the whole point is that somebody else can go and look.
What counts: real, physical googly eyes, the plastic kind with a pupil that rattles, attached to something. On a bin, a tree, a car, a shop sign, a rock, your dog. Animals and pets are fine.
What doesn't:
- Eyes drawn on, added with a filter, or edited in afterwards. They have to be real and actually there.
- Anything explicit, sexual, gory, or vulgar.
- Photos where a person is the subject, or where a recognisable face is the point of the picture.
- Anything that pinpoints where somebody lives.
2. Location
A pin needs a precise location, and there's no way around it. The app reads your device's GPS at the moment you photograph. GPS is the only way a pin gets a location. You can't tap the map, drag a pin, or type in coordinates. A googly eye is at one specific spot, and half the point is that someone else can go and find it. The manual-placement route isn't hidden, it's gone: the database accepts exactly one kind of location, a device fix, and refuses everything else.
How precise is precise enough? We accept a fix accurate to 50 metres or better. That's the floor, not the target: while you're framing the shot the app keeps asking for a better fix and keeps the best one it gets, and it only settles for 50m if the phone genuinely can't do better. Anything worse than 50m is refused.
Every pin shows how accurate it is. We store the accuracy your phone reported and we show it: a circle around the pin on the map, and a line on the pin's detail page reading something like "accurate to about 40m". A 6-metre pin and a 48-metre pin look different, because they are different, and someone walking out to find the eyes deserves to know which one they're chasing.
The published number is rounded up to the nearest 5 metres, so it's one of ten values between 5 and 50 rather than whatever your phone said to two decimal places. Partly because nobody needs "accurate to 37.42 metres". Mostly because an exact per-device accuracy figure, sitting next to an exact coordinate and a timestamp, is a faint fingerprint of your handset, and ten shared values are not. You still see the precise figure on your own pins.
If the fix isn't good enough yet, you'll see "getting a precise location…" while it settles. GPS usually sharpens within a few seconds. If it can't get there, stepping outside or away from tall buildings almost always fixes it.
If location is switched off entirely, the app will tell you exactly where to turn it on for your device. One thing that catches people out on iPhone: you can grant location access while Precise Location stays off, which gives a deliberately fuzzy position that will never be good enough. The app will say so if that's what's happening.
3. What happens next
Your photo is checked automatically for two things: that it really shows googly eyes, and that it contains nothing explicit.
Most photos clear in seconds and the pin goes live immediately. Occasionally one is borderline and waits for a person to look at it. That's normal and usually quick.
Borderline is never auto-rejected. Googly eyes on the backside of a classical statue is the obvious case: public art, centuries old, nobody's idea of explicit, and exactly the sort of thing an automatic checker gets wrong. Anything in that grey zone goes to a human instead of being turned down by a machine.
If it's rejected, you'll be told why, and you can appeal. A human reads appeals. You get three goes at it on the same pin, not one, and then the decision stands.
Appeals, warnings, and bans
This is the part most apps are vague about, so here it is straight.
Appealing is safe
An honest appeal is never punished. Not if you win, not if you lose. If you genuinely thought your photo was fine and we disagree, that is the end of it, with no warning, no strike, no mark on your account.
We are explicit about this because the alternative is worse for everyone. If appealing carried any risk at all, honest people would stop appealing, and every mistake the automatic checker made would quietly become a lost user. We'd rather read a hundred appeals that go nowhere than lose one person who was right.
The appeal screen actively invites you to explain yourself, including the awkward part: tell us why this might look borderline. Saying "it's a statue, and yes, it's a bare backside, but it's a 400-year-old one in a public square" is exactly the right thing to write. That's not a confession. That's the appeal working.
What actually gets you in trouble
The penalty is for lying, not for being wrong.
| What happened | What we do |
|---|---|
| Photo rejected for content | Rejected, and a warning. No ban. |
| You appeal a genuine grey area, and win | Nothing. Pin goes up. |
| You appeal a genuine grey area, and lose | Nothing at all. No penalty, ever. |
| You appeal something clearly prohibited, in bad faith | Permanent ban. |
| Explicit content, posted with evident intent | Permanent ban, no warning. |
The gap between rows three and four is the whole system. Row three is a person who was wrong. Row four is a person who knew and argued anyway.
A ban is permanent, and it survives deleting your account
If you are banned, you are banned. Not for 30 days, but permanently.
And it has to outlast your account, or it means nothing: delete, re-register, and you'd be back in five minutes. So:
We keep a one-way hash of the sign-in identifier you were banned under, for ever. When anybody signs up, we hash the new identifier the same way and check it against that list. A match doesn't create an account you then can't use: the sign-up is refused outright.
Two details, because they're the ones that decide whether this works at all. Changing your email address while banned doesn't shake it off, it adds the new address to the list. And deleting your account doesn't clear it either, which is the entire point.
Being plain about the trade-off, because it is a real one:
- A one-way hash can't be turned back into your email address. We can't read the list, we can't sell it, and it doesn't tell us who you were.
- To make the lookup work at all, the hashing uses one fixed value across the whole app. That means the same email always produces the same hash, which is precisely what lets us recognise a returning banned user, and also means the list isn't as unreadable as a per-user salt would make it. We chose the version that works. It's a deliberate trade, and pretending otherwise would be worse.
- Nothing else survives. The ban record and the hash are all that's left; your pins, your photos and your account data go.
- This is the one thing a deletion request does not erase, and the privacy policy says so in the same words.
Points and the chart
Every new googly eye you post is worth 10 points.
Emphasis on new. Photographing the same pair of eyes from five angles is one googly eye, not five. The app compares each accepted photo against the ones you have already had accepted, using a perceptual hash, a fingerprint of what the image looks like rather than of the file, so a rotated, re-cropped, or recompressed copy of the same eyes is recognised as the same eyes and scores once. The comparison is against your own accepted photos and nobody else's.
What's public and what isn't
Public: your rank, your points, and an opaque handle, a short code we generate, not a name you chose and not anything you can be looked up by. That's the chart. Anyone can see it.
The chart is rebuilt on a schedule rather than live, about once a day. Your points land on your account the instant a photo is accepted; the public chart catches up on its next refresh. Nothing is lost in the gap. The delay is also doing a job: a rank that ticked upward the second a new pin appeared on the map would quietly tie that pin to that handle, and a chart that updates once a day can't.
Private: where you've been. Nobody but you can list your pins. Not by handle, not by rank, not by clicking your score, not through any part of the app or the website.
That split is the entire design. Points are a game and games want a scoreboard. Pin lists are a movement history with timestamps, and handing one to a stranger would be handing them the answer to "where does this person spend their evenings". So the score is public, and the trail is not.
You are anonymous
Nothing on a public pin says who posted it. No name, no picture, no account ID, no handle, no badge, no colour, no per-user code of any kind. Someone browsing the map sees a photo and a place. The opaque handle from the chart doesn't appear here either. It lives on the chart and nowhere else, and there's no route from it to a pin. There is no profile page anywhere in the app.
You'll see your own pins marked as yours when you're signed in. That marking is computed for you and shown to nobody else.
Why this matters more than it sounds: pins carry precise coordinates. If strangers could list every pin by one person, they could map that person's movements, and the place someone posts from most often in the evening is usually their home. Keeping pins unlinkable is what makes the map safe to use.
Blocking used to be a hole in this, and isn't any more. Blocking hides exactly the photo you blocked and nothing else. The same person's other photos stay on your map, and the reason is the whole of this section: if blocking made someone's entire footprint vanish, the act of blocking would tell you which pins share an owner. Block one pin, see what else disappears, unblock, repeat, and you could sort a neighbourhood by author in an afternoon. Nothing fixes that except not doing it: rate limits only price it, making blocks permanent only stops you reusing an account, and hiding a few random extra pins as cover is defeated by trying twice. So the block acts on the photo you named. You'd already been shown that photo and already picked it out, so watching it go tells you nothing you didn't know.
Earlier versions of this manual described the leak as current and said we hadn't decided what to do. It's decided and it's built. The cost landed on you and we'll say so plainly: hiding a second photo by the same person is a second tap.
The one thing that's still true and can't be fixed here: when somebody deletes their account, everything they posted goes at the same moment, so a few of your hidden photos can leave that list together. Anyone who writes down pin identifiers off the public map and watches sees exactly the same thing, with no block involved, so this is a fact about deleting things rather than about blocking. We run deletions in batches to smudge it, which works better the more people are using the app, and is therefore weakest right now.
The other honest exception: we can see who posted what. We have to, to deal with abuse, respond to reports, and meet legal obligations. Anonymous means anonymous to other users, not to the people running the service. We'd rather say that plainly than imply something we can't deliver.
Sponsored pins are the last exception, and those are labelled with the business that paid for them, which is the point of paying.
Finding and getting there
Tap any pin for the photo, the location, and how accurate that location is, then open it in your usual map app for walking directions. Google Maps, Apple Maps, whatever your phone defaults to.
You can also export pins as KML (for Google My Maps or Google Earth) or GPX (for GPS units and hiking apps): either your own pins, or whatever's in view. Handy for planning a walking route. See maps and export for the details, including how to import a KML into Google My Maps if you want your own layer.
Ads, and getting rid of them
The app is free, and ads pay for it.
Nothing ever covers the map. No banner sits on top of the thing you came to look at. You'll see an ad after you successfully post a pin, at most once in a while, and there are optional ads you can choose to watch in exchange for things.
Or pay US$3, once, and they're gone forever. Not a subscription, but one payment, ad-free permanently, on every device you sign in on. Local prices apply elsewhere.
Reporting and blocking
Every pin has a report button, and you don't need an account to use it. If something shouldn't be on the map, use it. You'll get an acknowledgement straight away, and if you're signed in, or you leave us an email address, we'll tell you what we decided.
Reporting while signed out has some small print, so here it is. That button is reachable by anyone on the internet, so it's behind a captcha and capped at five anonymous reports an hour from one source. We don't keep the address it came from: we keep a one-way hash of it with a counter, and that's deleted after 24 hours. It's the shortest-lived thing in the whole service, deliberately.
Two consequences you should know before you rely on it:
- The confirmation says the same thing whatever we find. It won't tell you whether that pin exists, whether it's still up, or what's happening to it. Pin identifiers are public, so a reply that varied would let anybody use the report button to work out what we'd taken down. That's a privacy control for whoever posted the pin, not us being unhelpful to you.
- An anonymous report gives us nothing to reply to. We review it on the same
timescale either way. If you want the outcome, leave an email address in the
form or write to
[email protected].
You can block from a pin. There's no profile page to block from: pins don't carry one, and there is no profile to visit. It hides that photo, and only that photo. See the note above for why, because the reason is the interesting part. Blocking is private, the other person is never told, and it never tells you who anybody is. Your hidden photos are listed in your settings and you can unhide any of them whenever you like.
Your data
We keep as little as possible, and not forever.
| What | How long |
|---|---|
| The photo that appears on the map | Stripped of hidden data (EXIF), resized and re-encoded before it is written. The same stripped copy is what the automatic checker sees. Nothing unstripped is ever published or sent outside |
| Your original camera file | Uploaded over an encrypted connection and kept privately, EXIF and all, for as long as the pin lives. Not published, not served to anyone browsing: you can see yours, a moderator can see one they're reviewing, nobody else can. It's what an appeal is judged against and what the published copy is made from. Deleted with the pin or your account. (not built yet: doing the strip on your phone, so the untouched file never leaves it at all.) |
| A rejected photo, including that original | 14 days |
| The window to appeal | 7 days, and the photo always outlives it, so there's something for the moderator to look at |
| Verification verdicts (what the checker decided, and how confident it was) | 6 months |
| Reports and moderation records | 6 months after they're resolved |
| Server logs | 7 days |
| The counter behind the anonymous-report rate limit (a one-way hash of the source, an hour, a count: no address, no pin, no text) | 24 hours |
| Your account after you delete it | Purged within 7 days |
| Your pins | Until you delete them, or delete your account |
| Ban records, and the one-way hash of a banned sign-in identifier | Kept indefinitely, which is what makes a ban permanent |
| Records of a supporter payment | 5 years, because Australian tax law requires it |
Two rows we can't shorten, and it would be dishonest not to point at them.
Ban records are forever. A ban that expires when you delete your account is not a ban. See above.
Supporter payments last five years. If you buy the ad-free upgrade, the record of that transaction has to survive even a deletion request, because Australian tax law requires the operator to keep business records for five years. That is not our policy and we can't waive it. What we keep is the bare transaction (date, amount, currency, a transaction identifier) and it is never public and never used to restore anything. Everything else goes.
Photos are checked by an AI service (Anthropic's Claude) to confirm they show googly eyes and nothing explicit. That means your photo is sent there to be looked at. It isn't used to train anything.
Deleting your account removes your profile, your pins and your access. Your ad-free purchase does not survive it, because restoring that would mean keeping the payment identifiers that link you to it, which is exactly what deleting your data is supposed to prevent. We chose deletion.
The full detail is in the privacy policy, and the rules you're agreeing to are in the terms.
What isn't built yet
One thing. It's decided and being built, and until it ships the app does the older thing, which this manual would rather tell you than let you assume.
- Stripping the photo on your phone. Today your camera file travels to us intact, over an encrypted connection, and the copy we publish is stripped and re-encoded here. The original is kept privately and deleted with the pin (see Your data). Once this ships, the untouched file won't leave your phone at all.
What used to be on this list, and shipped on 25 August 2026
Recorded because a manual that quietly deletes its own caveats isn't worth trusting. Every one of these is now enforced by the database itself, not by the app on your phone, which means there's no version of the app that can be talked out of any of them:
- Discarding the date of birth. There is no column for a birthday any more.
- GPS-only placement. Manual placement isn't disabled, it's impossible: only a device fix is accepted.
- The pin title and description fields, removed rather than hidden.
- The 50-metre accuracy floor, and showing the accuracy on every pin.
- Duplicate detection by perceptual hash, so the same eyes score once.
- The public chart: rank, points, opaque handle.
- The permanent blocklist, the one-way hash that makes a ban survive account deletion, including when the banned account changes its address first.
- Reporting without an account, captcha-gated and rate limited.
- Per-photo blocking, which replaced the version that hid everything an account had ever posted and told you, by doing so, which pins were theirs.
Getting help
[email protected], for anything: a bug, a rejected photo you think was
wrong, a privacy request, or a pin that shouldn't be there.
Nothing is sent from or received at an @googlymaps.net address. If you get mail
claiming to be from us at one, it isn't.
Last update: 2026-08-25 AWST