The googlymaps manual

Everything the app does, in one place. If you only want the short version, read how it works instead. This is the full reference.

This manual is kept current. If something here doesn't match the app, that's a bug worth reporting to [email protected].

Anything described here that is decided but not yet built is marked (not built yet) where it appears, and listed again in What isn't built yet at the end. We'd rather say "designed, coming" than let you assume something is protecting you today when it isn't. That list used to be long. As of 25 August 2026 it has nothing left on it: everything that was designed and promised has shipped.


What googlymaps is

A world map of googly eyes.

People stick googly eyes on things (postboxes, parking meters, bins, statues, the family dog) and other people find them. This is the map of where they are. You photograph one, the app records exactly where you're standing, and once it's checked, a pin appears for everyone.

That's the whole app. A photo and a place.

A pin has no title and no description. There is nowhere to type anything at all. That isn't an oversight. Every word a user could write would be a word nobody had checked, sitting on a public map, and the automatic checker only ever looks at pictures. Take the box away and the problem goes with it. The photo says what it needs to say. The fields don't exist behind the scenes either: they were removed from the database, not just hidden.


Getting started

Signing in

Browsing the map needs no account at all. Posting does.

You can sign in with Google, Apple, or your email address. There is no password to choose: the email option sends you a link that signs you straight in, so there's nothing to forget and nothing to steal. Whichever you choose, we get almost nothing: an account identifier and, for email sign-ups, your email address. We don't ask for your name, and we don't store a profile picture even if your provider offers one.

Using more than one sign-in button

They usually land on the same account. If your Google and Apple accounts use the same email address, signing in with either one gets you the same pins, the same points, the same everything. You don't have to do anything for that to happen.

Sometimes they can't, and it's worth knowing when, because we can't fix it afterwards. We match you up by email address. If your Apple ID and your Google account use different addresses, there's nothing linking them, and the second one you use starts a new, separate account. The commonest way to hit this is Apple's "Hide My Email" option: take it, and Apple gives us a random @privaterelay.appleid.com address instead of yours, which matches nothing.

So if you want more than one way in, add it deliberately: sign in, open Account → Ways to sign in, and press Add. That attaches it to the account you're already using, whatever address it reports. It takes a few seconds and it's the difference between one account and two.

If you've already ended up with two, email [email protected]. We'd rather sort it out by hand than pretend it can't happen.

Your account carries a name, purely so our own records make sense. It is never published: not on a pin, not on the chart, not anywhere another user can see it.

Where that name comes from is worth being exact about, because the obvious answer is the wrong one. Google and Apple do hand us the name on your account, usually your real one. We throw it away and generate one instead: googly_ and a few characters. Nothing in this app ever asked for your real name, and picking it up as a side effect of which sign-in button you tapped would be collecting it by accident, which is the kind of thing that is easy to do and hard to undo. If you signed up on our own form and typed a name in, that's the name you have. Either way you can change it in your account, and nothing anyone else sees depends on it.

Your age

You need to be 16 or older to post. You can browse at any age.

We ask for your date of birth the first time you try to post, not when you sign up. We check it, record the moment you were confirmed old enough, and then discard the date. We never write your birthday to the database and we don't keep it. There is no column for it to go in: the check runs on the value you typed and the value is gone by the time the answer is stored.

Why the check happens at posting rather than at signup: Apple and Google don't tell us your date of birth when you sign in with them, so refusing to create the account would simply have broken those buttons. The account can exist; it can't post until the age check passes.

The 16 is enforced in the database itself, not in the app on your phone, so there's no version of the app that can be talked out of it. There is no parental-consent route.

We ask once, and the answer sticks to that account. If the date you give is under 16, we record that it happened and the account can't post from then on. You don't get a second go with a different date. That's the only thing that makes asking worth anything: a question you can answer again until you get the answer you want isn't a check, it's a formality.

What we record is simply that it happened, and when. Not the date you typed, and not anything the date could be worked back out from.

We know an honest person can mistype a year, and that somebody who was 15 will eventually be 16. Both cases are a real email to [email protected] and a human sorting it out, rather than an automatic second chance that would defeat the point.

And to be straight with you: none of this proves anything. Somebody determined to lie about their age can. The check is here so that we asked, so that the answer is recorded, and so that we aren't knowingly running a service for children. Actually verifying age would mean asking you for ID or a card, which would mean collecting exactly the personal information the rest of this manual explains we go out of our way not to hold.

Accepting the rules

Browsing needs nothing from you: no account, and nothing to agree to. You can look at the whole map, every pin on it, without ever seeing a terms screen.

Posting a pin, or reporting one, does. Before your first pin, and before your first report of somebody else's, we ask you to accept the current Terms of Use and the current privacy policy. It's one tap, and it sticks, unless something changes (below). This applies even if you're reporting without an account: reporting has never needed one, but it does need this.

Both documents now carry a version number and an effective date at the top, and that isn't decoration: it's exactly what you're agreeing to, and exactly what gets recorded against you.

When something in either document changes enough to matter, you're asked again. We call that a material change: a new version is published, and you can't post or report under it until you've accepted it. A typo fix, a clarified sentence, anything that doesn't actually change what you're agreeing to, doesn't trigger this, on purpose. Asking you to re-agree over a typo would teach you to stop reading the screen, which is worse than the typo.

What's recorded is small and exact: which document, which version, and when. Nothing else rides along with it. It's kept as evidence that you agreed, not deleted on a schedule the way most things in this app are (see your data).

If you delete your account, the record of your acceptance stays, but the link to you doesn't. What's left afterwards is a document, a version number and a timestamp: no name, no account, nothing that leads back to you. It's one of a short list of things a deletion request doesn't erase; see your data for the others.

If you accepted while reporting anonymously, there was never a link to remove. You're asked to accept the same two documents at the report form even with no account behind you, and because there's no account to tie the record to, it's anonymous from the moment it's made.


Posting a googly eye

1. Take the photo

The app opens the camera. Get close enough that the eyes are clearly visible, with enough of the object in frame that people can tell what they're stuck to. Daylight helps. That's it.

You take the photo there and then. You can't upload one you already had, and that's deliberate rather than us being awkward.

Before anything is sent, your phone turns the photo the right way up, strips the hidden data your camera wrote into it, and resizes it. This happens on your device: the camera file your phone actually produced never leaves it. If your phone can't open a photo to do this, the photo is refused rather than sent as it is: you'll be asked to take the shot again, and nothing is uploaded.

The place on a pin comes from your phone at the moment you post, not from the photo. Phones and browsers strip location out of saved pictures anyway, so if you uploaded a photo from a trip last week while sitting at home, we'd have no honest way to know where it was taken, and the pin would land on your house. A pin in the wrong place is worse than no pin at all, because the whole point is that somebody else can go and look.

What counts: real, physical googly eyes, the plastic kind with a pupil that rattles, attached to something. On a bin, a tree, a car, a shop sign, a rock, your dog. Animals and pets are fine.

What doesn't:

2. Location

A pin needs a precise location, and there's no way around it. The app reads your device's GPS at the moment you photograph. GPS is the only way a pin gets a location. You can't tap the map, drag a pin, or type in coordinates. A googly eye is at one specific spot, and half the point is that someone else can go and find it. The manual-placement route isn't hidden, it's gone: the database accepts exactly one kind of location, a device fix, and refuses everything else.

How precise is precise enough? We accept a fix accurate to 50 metres or better. That's the floor, not the target: while you're framing the shot the app keeps asking for a better fix and keeps the best one it gets, and it only settles for 50m if the phone genuinely can't do better. Anything worse than 50m is refused.

Every pin shows how accurate it is. We store the accuracy your phone reported and we show it: a circle around the pin on the map, and a line on the pin's detail page reading something like "accurate to about 40m". A 6-metre pin and a 48-metre pin look different, because they are different, and someone walking out to find the eyes deserves to know which one they're chasing.

The published number is rounded up to the nearest 5 metres, so it's one of ten values between 5 and 50 rather than whatever your phone said to two decimal places. Partly because nobody needs "accurate to 37.42 metres". Mostly because an exact per-device accuracy figure, sitting next to an exact coordinate and a timestamp, is a faint fingerprint of your handset, and ten shared values are not. You still see the precise figure on your own pins.

If the fix isn't good enough yet, you'll see "getting a precise location…" while it settles. GPS usually sharpens within a few seconds. If it can't get there, stepping outside or away from tall buildings almost always fixes it.

If location is switched off entirely, the app will tell you exactly where to turn it on for your device. One thing that catches people out on iPhone: you can grant location access while Precise Location stays off, which gives a deliberately fuzzy position that will never be good enough. The app will say so if that's what's happening.

3. What happens next

Your photo is checked automatically for two things: that it really shows googly eyes, and that it contains nothing explicit.

Most photos clear in seconds and the pin goes live immediately. Occasionally one is borderline and waits for a person to look at it. That's normal and usually quick. When a person does say yes, the pin appears a minute or so later rather than instantly: your photo has to be copied into the public half of the app first, where it's stripped and resized again, independently, on our own servers, rather than us simply trusting that your phone did it correctly. Nothing is wrong if you refresh and don't see it for a moment.

Borderline is never auto-rejected. Googly eyes on the backside of a classical statue is the obvious case: public art, centuries old, nobody's idea of explicit, and exactly the sort of thing an automatic checker gets wrong. Anything in that grey zone goes to a human instead of being turned down by a machine.

If it's rejected, you'll be told why, and you can appeal. A human reads appeals. You get three goes at it on the same pin, not one, and then the decision stands.

How many you can post

Up to 10 pins in any rolling 24 hours, per account. Not a calendar day: it's always whatever happened in the 24 hours right before your next attempt, so there's no trick where you post 10 right before midnight and 10 more right after. Every submission counts, whatever became of it afterwards: one that got rejected still counts, and so does one you later deleted yourself. Deleting a pin frees up nothing.

You'll always be able to see how many you've got left, and exactly when your next slot opens up.

Why the limit exists, plainly: every photo you submit, accepted or not, is checked twice: once by an AI classifier that costs real money every time it runs, and again by a human moderator whenever the automatic check can't be sure. Both of those cost something, per photo, whatever the outcome turns out to be. Ten a day, per account, is plenty for anyone genuinely out finding googly eyes, and it stops one account from being able to run either check into the ground.


Appeals, warnings, and bans

This is the part most apps are vague about, so here it is straight.

Appealing is safe

An honest appeal is never punished. Not if you win, not if you lose. If you genuinely thought your photo was fine and we disagree, that is the end of it, with no warning, no strike, no mark on your account.

We are explicit about this because the alternative is worse for everyone. If appealing carried any risk at all, honest people would stop appealing, and every mistake the automatic checker made would quietly become a lost user. We'd rather read a hundred appeals that go nowhere than lose one person who was right.

The appeal screen actively invites you to explain yourself, including the awkward part: tell us why this might look borderline. Saying "it's a statue, and yes, it's a bare backside, but it's a 400-year-old one in a public square" is exactly the right thing to write. That's not a confession. That's the appeal working.

What actually gets you in trouble

The penalty is for lying, not for being wrong.

What happened What we do
Photo rejected for content Rejected, and a warning. No ban.
You appeal a genuine grey area, and win Nothing. Pin goes up.
You appeal a genuine grey area, and lose Nothing at all. No penalty, ever.
You appeal something clearly prohibited, in bad faith Permanent ban.
Explicit content, posted with evident intent Permanent ban, no warning.

The gap between rows three and four is the whole system. Row three is a person who was wrong. Row four is a person who knew and argued anyway.

A ban is permanent, and it survives deleting your account

If you are banned, you are banned. Not for 30 days, but permanently.

And it has to outlast your account, or it means nothing: delete, re-register, and you'd be back in five minutes. So:

We keep a one-way hash of the sign-in identifier you were banned under, for ever. When anybody signs up, we hash the new identifier the same way and check it against that list. A match doesn't create an account you then can't use: the sign-up is refused outright.

Two details, because they're the ones that decide whether this works at all. Changing your email address while banned doesn't shake it off, it adds the new address to the list. And deleting your account doesn't clear it either, which is the entire point.

Being plain about the trade-off, because it is a real one:


Points and the chart

Every new googly eye you post is worth 10 points.

Emphasis on new. Photographing the same pair of eyes from five angles is one googly eye, not five. The app compares each accepted photo against the ones you have already had accepted, using a perceptual hash, a fingerprint of what the image looks like rather than of the file, so a rotated, re-cropped, or recompressed copy of the same eyes is recognised as the same eyes and scores once. The comparison is against your own accepted photos and nobody else's.

A discarded photo costs you a point. If a photo is rejected, or a pin that had already gone up is later taken down for breaking the rules, that's minus 1. Your score can go negative, and that's deliberate: it costs something to keep pushing photos that don't belong on the map, in a way a score stuck at zero never would. None of this touches a photo while its fate is still open: a pin waiting on its first check, or a rejected photo you're appealing, costs nothing until the decision is final. You're never charged for a decision that hasn't been made yet, and never charged twice over for the same photo.

Deleting your own pin is a different thing again, with a different cost. See Deleting your own pin below.

What's public and what isn't

Public: your rank, your points, your country flags (see below), and an account number: a plain number, not a made-up code. Numbers start at 0 for the very first account ever created and count up in the order accounts joined, so yours is simply your place in the queue. If an account is deleted, its number goes with it and is never handed to anyone else, so the numbers on the chart aren't a live headcount of who's using the app today, but the highest number in use is a rough sense of how many accounts have ever existed, and a lower number always joined before a higher one. That's the honest trade of a plain number instead of an opaque code, and we'd rather say so than pretend the chart tells a stranger nothing about the rest of us. See your data and the privacy policy for the full picture.

The chart is rebuilt on a schedule rather than live, about once a day. Your points land on your account the instant a photo is accepted; the public chart catches up on its next refresh. Nothing is lost in the gap. The delay is also doing a job: a rank that ticked upward the second a new pin appeared on the map would quietly tie that pin to that account number, and a chart that updates once a day can't.

Private: where you've been. Nobody but you can list your pins. Not by account number, not by rank, not by clicking your score, not through any part of the app or the website.

That split is the entire design. Points are a game and games want a scoreboard. Pin lists are a movement history with timestamps, and handing one to a stranger would be handing them the answer to "where does this person spend their evenings". So the score is public, and the trail is not.

Country flags

Every accepted photo also earns you the flag of the country it was taken in, shown next to your account number, including on the public chart. Flags never appear on a pin: like everything else on the chart, they sit next to your account number and nowhere else, so seeing a flag tells nobody which pin it came from.

Flags don't repeat. Your first accepted photo in Australia earns you an Australian flag. Your hundredth accepted photo in Australia earns you nothing new: you already have that one. Post from a different country and you earn a new flag for it, so your set of flags is the story of where your googly eyes have actually been, not a count of how many you've posted.

A rejected photo earns no flag. Neither does a duplicate: a second photo of eyes you've already photographed is published normally but scores no points (see above), and it earns no flag either, for the same reason. Posting from somewhere the app can't place, such as well out at sea, simply earns no flag. None of this ever stops the photo publishing: a flag is a bonus on top of a successful pin, never a condition of one.

How we work out the country, and why this doesn't change what we collect: we look at the same coordinate your pin already publishes, and work out the country on our own servers. No outside mapping or geocoding service is called, and no new information about you is gathered to do it: the flag is entirely derived from a location that was already going to be public on the map. The boundary data is Natural Earth, a public domain map of the world at a resolution good enough to tell which country you're in, not which side of the street.

Worth knowing: there's a 12 km allowance along coastlines. At the resolution we use, a coastline is a simplified line, and real places, a spot in Manhattan, a canal in Venice, a street in Hong Kong, can technically fall just outside their own country's shape on the map. Rather than hand out no flag to someone standing exactly where they say they are, we count a photo as being in a country if it's within 12 km of that country's coastline. One side effect worth being upfront about: someone taking a photo from a ferry within 12 km of a coast can earn that country's flag too.

A flag is a rough badge, not a political statement, and we know it isn't perfect. A couple of things are worth knowing about before you email us confused:

If a flag looks wrong to you, or you'd like to tell us it should be different, email [email protected]. We'd rather hear about it than have you wonder.


Deleting your own pin

You can delete a pin you posted, and only one you posted: there's no way to delete anyone else's.

It costs you the 10 points that pin earned. Deleting a pin isn't a punishment, so it isn't the same minus-1 that a discarded photo costs (see Points and the chart); it simply gives back what the pin gained, because the pin isn't on the map earning its keep any more.

Three things you can't delete, and why:

The pin comes off the map immediately. Nobody sees it again, not even you. But the photo itself is kept for 14 days before it's deleted from storage, the same 14 days a rejected photo gets, for legal and safety reasons: it needs to still exist in case something comes up in that window. It isn't visible to anyone during that time, not even to you. The app asks you to confirm before you delete a pin, and tells you about the 14 days before you agree, because this is one of those things you should know before you tap, not after.


You are anonymous

Nothing on a public pin says who posted it. No name, no picture, no account ID, no badge, no colour, no per-user code of any kind. Someone browsing the map sees a photo and a place. Your account number from the chart doesn't appear here either. It lives on the chart and nowhere else, and there's no route from it to a pin. There is no profile page anywhere in the app.

You'll see your own pins marked as yours when you're signed in. That marking is computed for you and shown to nobody else.

Why this matters more than it sounds: pins carry precise coordinates. If strangers could list every pin by one person, they could map that person's movements, and the place someone posts from most often in the evening is usually their home. Keeping pins unlinkable is what makes the map safe to use.

Blocking used to be a hole in this, and isn't any more. Blocking hides exactly the photo you blocked and nothing else. The same person's other photos stay on your map, and the reason is the whole of this section: if blocking made someone's entire footprint vanish, the act of blocking would tell you which pins share an owner. Block one pin, see what else disappears, unblock, repeat, and you could sort a neighbourhood by author in an afternoon. Nothing fixes that except not doing it: rate limits only price it, making blocks permanent only stops you reusing an account, and hiding a few random extra pins as cover is defeated by trying twice. So the block acts on the photo you named. You'd already been shown that photo and already picked it out, so watching it go tells you nothing you didn't know.

Earlier versions of this manual described the leak as current and said we hadn't decided what to do. It's decided and it's built. The cost landed on you and we'll say so plainly: hiding a second photo by the same person is a second tap.

The one thing that's still true and can't be fixed here: when somebody deletes their account, everything they posted goes at the same moment, so a few of your hidden photos can leave that list together. Anyone who writes down pin identifiers off the public map and watches sees exactly the same thing, with no block involved, so this is a fact about deleting things rather than about blocking. We run deletions in batches to smudge it, which works better the more people are using the app, and is therefore weakest right now.

The other honest exception: we can see who posted what. We have to, to deal with abuse, respond to reports, and meet legal obligations. Anonymous means anonymous to other users, not to the people running the service. We'd rather say that plainly than imply something we can't deliver.

Sponsored pins are the last exception, and those are labelled with the business that paid for them, which is the point of paying.


Finding and getting there

Tap any pin for the photo, the location, and how accurate that location is, then open it in your usual map app for walking directions. Google Maps, Apple Maps, whatever your phone defaults to.

You can also export pins as KML (for Google My Maps or Google Earth) or GPX (for GPS units and hiking apps): either your own pins, or whatever's in view. Handy for planning a walking route. See maps and export for the details, including how to import a KML into Google My Maps if you want your own layer.


Ads, and getting rid of them

The app is free, and ads pay for it.

Nothing ever covers the map. No banner sits on top of the thing you came to look at. You'll see an ad after you successfully post a pin, at most once in a while, and there are optional ads you can choose to watch in exchange for things.

Or pay US$3, once, and they're gone forever. Not a subscription, but one payment, ad-free permanently, on every device you sign in on. Local prices apply elsewhere.


Reporting and blocking

Every pin has a report button, and you don't need an account to use it. If something shouldn't be on the map, use it. You'll get an acknowledgement straight away, and if you're signed in, or you leave us an email address, we'll tell you what we decided.

You do need to accept the current terms and privacy policy first, the same one-tap agreement posting asks for. See Accepting the rules above for exactly what that means and what gets recorded. Not needing an account and needing to accept those two documents are different things, and both are true at once.

Reporting while signed out has some small print, so here it is. That button is reachable by anyone on the internet, so it's behind a captcha and capped at five anonymous reports an hour from one source. We don't keep the address it came from: we keep a one-way hash of it with a counter, and that's deleted after 24 hours. It's the shortest-lived thing in the whole service, deliberately.

Two consequences you should know before you rely on it:

You can block from a pin. There's no profile page to block from: pins don't carry one, and there is no profile to visit. It hides that photo, and only that photo. See the note above for why, because the reason is the interesting part. Blocking is private, the other person is never told, and it never tells you who anybody is. Your hidden photos are listed in your settings and you can unhide any of them whenever you like.


Your data

We keep as little as possible, and not forever.

What How long
The photo that appears on the map Stripped of hidden data (EXIF), resized and re-encoded before it is written. The same stripped copy is what the automatic checker sees. Nothing unstripped is ever published or sent outside
Your original-of-record Your phone strips, straightens and resizes the photo before anything is sent, so the file your camera actually made never leaves it. What's uploaded, over an encrypted connection, is that stripped copy at up to 2560 pixels on its long edge, and it's that stripped copy that's kept privately, for as long as the pin lives. Not published, not served to anyone browsing: you can see yours, a moderator can see one they're reviewing, nobody else can. It's what an appeal is judged against and what the published copy is made from, kept a little larger than the published copy so a moderator can look closely. Deleted with the pin or your account
A rejected photo, including that original 14 days
A pin you deleted yourself, including its photo 14 days, the same as a rejected photo (see Deleting your own pin)
The window to appeal 7 days, and the photo always outlives it, so there's something for the moderator to look at
Verification verdicts (what the checker decided, and how confident it was) 6 months
Reports and moderation records 6 months after they're resolved
Server logs 7 days
The counter behind the anonymous-report rate limit (a one-way hash of the source, an hour, a count: no address, no pin, no text) 24 hours
Your account after you delete it Purged within 7 days
Your pins Until you delete them (which costs the 10 points that pin earned), or delete your account
Ban records, and the one-way hash of a banned sign-in identifier Kept indefinitely, which is what makes a ban permanent
Records of a supporter payment 5 years, because Australian tax law requires it
The record that you accepted a Terms of Use or privacy policy version (which document, which version, when) Kept indefinitely, as evidence. Deleting your account removes the link between this record and you, not the record itself

Two rows we can't shorten, and it would be dishonest not to point at them.

Ban records are forever. A ban that expires when you delete your account is not a ban. See above.

Supporter payments last five years. If you buy the ad-free upgrade, the record of that transaction has to survive even a deletion request, because Australian tax law requires the operator to keep business records for five years. That is not our policy and we can't waive it. What we keep is the bare transaction (date, amount, currency, a transaction identifier) and it is never public and never used to restore anything. Everything else goes.

A third thing survives too, but in a different way. Accepting a Terms of Use or privacy policy version (see Accepting the rules) is recorded, and that record isn't deleted with your account either. Unlike the two above, though, nothing is being kept about you: deleting your account removes the link between the record and you, so what's left is a document, a version number and a timestamp, and nobody's name attached to any of them.

Photos are checked by an AI service (Anthropic's Claude) to confirm they show googly eyes and nothing explicit. That means your photo is sent there to be looked at. It isn't used to train anything.

Deleting your account removes your profile, your pins and your access. Your ad-free purchase does not survive it, because restoring that would mean keeping the payment identifiers that link you to it, which is exactly what deleting your data is supposed to prevent. We chose deletion.

The full detail is in the privacy policy, and the rules you're agreeing to are in the terms.


What isn't built yet

Nothing. Everything that was once designed but not yet shipped has now shipped; see the list below. This section stays in the manual, empty, rather than disappearing, so that if it ever gains an item again, you'll know this is where to look.

What used to be on this list, and shipped on 25 August 2026

Recorded because a manual that quietly deletes its own caveats isn't worth trusting. Every one of these is now enforced by the database itself, not by the app on your phone, which means there's no version of the app that can be talked out of any of them, with one exception noted where it applies:


Getting help

[email protected], for anything: a bug, a rejected photo you think was wrong, a privacy request, or a pin that shouldn't be there.

Nothing is sent from or received at an @googlymaps.net address. If you get mail claiming to be from us at one, it isn't.

Last update: 2026-08-25 AWST