Aethrio
  1. Aethrio
  2. Privacy

Privacy Policy

What Aethrio collects, why, who else can see it, and what you can ask us to do about it.

Effective July 29, 2026·Last updated July 29, 2026

The short version

Aethrio is run by one person and collects as little as it can. This summary is here so you can get the shape of it in thirty seconds. It is not a substitute for the sections below, which are what actually applies.

Signing in needs an email address. We send a one-time code instead of using a password, so there is no password for us to store or lose.

Anything you post about a park is public: your review, your rating, your photos, and the display name attached to them. Your email address never is.

Your location never leaves your browser. When you tap the locate button, the coordinates sort the map on your device. They are not sent to us and not stored anywhere.

We do not sell personal information and there are no advertising trackers on the site.

You can delete anything you posted, whenever you like. To delete the whole account, email hey@aethrio.co and it is done within 30 days.

Contents

  1. 1.Who we are
  2. 2.Information you give us
  3. 3.Information collected automatically
  4. 4.Location
  5. 5.Cookies and local storage
  6. 6.What is public, and what is not
  7. 7.How we use information
  8. 8.What we never do
  9. 9.Who else processes it
  10. 10.How long it is kept
  11. 11.Your rights, and how to use them
  12. 12.Security
  13. 13.Children
  14. 14.If you are outside the United States
  15. 15.Changes to this policy
  16. 16.Contact

1.Who we are

Aethrio is a directory of public parks, beaches and recreation areas, published at aethrio.co and operated by Val Aristides, an individual doing business as Aethrio. The older address grillable.app redirects here and is covered by this policy.

This policy covers the website and the interactive map. It does not cover the third-party sites we link to, including the park authorities' own pages, which have their own policies. Questions about anything here go to hey@aethrio.co.

2.Information you give us

You can browse the entire site without an account and without giving us anything. The following is collected only when you choose to do something that needs it.

Account

  • Email address. Required to sign in, and used to send you the one-time sign-in code. We use codes rather than passwords, so we never receive or store a password.
  • If you sign in with Google or Apple instead, that provider tells us your email address and, where it offers one, your name and profile picture address. Nothing else: not your contacts, not your calendar, not your files. You enter your Google or Apple password on their site, never on ours, and we never see it. Apple's Hide My Email gives us a relay address rather than your real one, and everything here works the same way with it.
  • Display name, avatar image address, and home region. All optional. The display name is shown next to anything you post publicly.

Things you post

  • Reviews and ratings.
  • Photos you attach to a review, and their captions.
  • Saved parks, and lists you create. A list is private unless you make it public.
  • Gatherings you host: the park, title, time and note.
  • RSVPs: the name you give, your response and your party size.
  • Condition reports and re-verification reports, for example that a park is closed or that a fire ban is in effect.
  • Corrections to park information, and requests to add a park we do not have.

Messages

  • Anything you send us by email, including the address you send it from.

3.Information collected automatically

Visiting any website leaves a trace. Here is the whole of ours.

  • Delivery logs. Our host records the IP address, browser user agent, requested address and timestamp of requests, for security and reliability. We do not use these logs to build a profile of you.
  • Analytics. Google Analytics records page views, referring page, device and browser type, and an approximate region derived from your IP address. It is configured for measurement. We do not run advertising, do not use it for ad targeting, and do not merge it with your account.
  • Error reports. When something breaks, Sentry receives what broke, on which page, and in which browser. It is deliberately configured not to attach IP address, email address or account identity to that report.
  • Performance. Vercel Speed Insights records anonymous page timings.
  • Bot protection. Cloudflare Turnstile runs on the sign-in form to keep automated systems from creating accounts. It sees the request, not your account.

4.Location

Two different things get confused here, so both are stated plainly.

Your location stays on your device. Tapping the locate button asks your browser for your coordinates. They sort the list, center the map and compute distances, all inside the page you have open. They are not written to our database, not attached to your account, not sent to any analytics tool, and they are gone when you close the tab. Granting the permission is always your choice, and every part of the site works without it.

The other location data that moves, and where it goes:

  • ZIP code search. The ZIP you type is sent to zippopotam.us to look up its center point. That request carries the ZIP, not your identity.
  • Weather and fire alerts. We send the park's coordinates, not yours, to Open-Meteo and the National Weather Service.
  • Map tiles. Your browser requests map images directly from CARTO, so your IP address is visible to them, as it is to any image host.
  • Photos. Photos are re-encoded in your browser before they are uploaded. That removes the metadata a camera writes into a file, including the GPS coordinates of where the photo was taken.

5.Cookies and local storage

Short enough to list in full.

NameWhat it doesKept
themeRemembers whether you chose light or dark.Until you clear it
Sign-in sessionKeeps you signed in. Clearing it signs you out.Until sign-out or expiry
_ga, _ga_*Google Analytics measurement.Up to 2 years
Turnstile tokenCloudflare bot check during sign-in.Minutes

There are no advertising cookies, no cross-site tracking pixels and no data broker tags. Blocking analytics in your browser does not break anything on the site.

6.What is public, and what is not

This is the section worth reading twice, because it is the one that surprises people.

Anyone can see

  • Reviews, ratings, and the photos attached to them.
  • The display name you chose, next to each of those.
  • Gatherings you host, including the park, title, time and note, and the names and party sizes of everyone who has RSVPed. Anyone with the link can see a gathering, so treat the link as public.
  • Lists you have marked public.

Only you can see

  • Your email address.
  • Your saved parks.
  • Lists you have kept private.
  • Corrections, park requests and feedback you send us.
  • Your home region.

Do not put anything in a review, a photo or a gathering note that you would not want a stranger to read, including your own phone number, home address or vehicle. Once something is published, other people and search engines can copy it, and we cannot pull those copies back.

Content can also be hidden by moderation. Hidden content disappears from the site for everyone, including the person who posted it.

7.How we use information

  • To run accounts and keep you signed in.
  • To show you your saved parks, lists and posted content.
  • To publish reviews, ratings, photos and gatherings, as described above.
  • To answer your messages and to correct park information you tell us is wrong.
  • To keep the service working: fixing errors, measuring which pages are used, and blocking abuse.
  • To send transactional email, meaning sign-in codes and replies to you. We send no marketing email today. If that ever changes it will be opt-in, and never a consequence of having signed in.

8.What we never do

  • We do not sell or rent personal information.
  • We do not share it with advertising networks or data brokers.
  • We do not use your content to target advertising, because there is none.
  • We do not read your private lists or saved parks for any purpose other than showing them back to you.
  • We do not use your email address for anything except sign-in and support.

One clarification, since the site does use AI tooling: we use a language model to read official park pages and pull facts out of them, and to draft the descriptive summary on a park page from those published sources. Your reviews, photos and messages are not part of that pipeline and are not used to train models.

9.Who else processes it

We use these companies to run the site. Each one only receives what its job needs.

ProviderWhat it handles
SupabaseAccounts, database, and photo storage
VercelHosting, delivery, request logs, page timings
Google AnalyticsUsage measurement
Google, AppleSign-in, only if you choose to use their account for it
SentryError reports, with IP and identity switched off
CloudflareSign-in bot check, and email routing for our address
CARTO and OpenStreetMapMap tiles requested by your browser
Open-Meteo, National Weather ServiceForecasts and fire alerts, by park coordinates
zippopotam.usZIP code center lookup
AnthropicReading official park pages. No user content is sent

These providers process data in the United States. We may also disclose information if the law requires it, or to protect the safety of a person or the integrity of the service. If that ever happens, we will tell you unless we are legally prohibited from doing so.

10.How long it is kept

  • Account and profile: until you ask us to delete the account.
  • Reviews, photos, lists, gatherings and RSVPs: until you delete them, or until the account is deleted, whichever comes first.
  • Corrections and park requests: while we work through them, and afterwards as the record of why a park's information changed. Ask us and we will delete yours.
  • Delivery logs and analytics: kept by our host and by Google under their own retention windows, which are short by comparison.
  • Backups: deleted content can persist in routine backups for a short period before those rotate out.

11.Your rights, and how to use them

These rights are offered to everyone who uses the site, wherever you live. We would rather grant one clear set of rights to all of you than sort visitors by jurisdiction.

  • See what we hold about you.
  • Get a copy of it in a portable form.
  • Correct anything wrong.
  • Delete it. Reviews, photos, lists, saved parks, gatherings and RSVPs can be deleted by you at any time, directly in the app. Deleting the account itself is done by email, because there is deliberately no way for a browser to reach the account records directly, and that same restriction is part of what keeps other people out of your account.
  • Object to a use, or ask us to restrict one.
  • Opt out of analytics, either with a browser setting or blocker, or by asking us.
  • Not be treated differently for exercising any of the above.

To use any of them, email hey@aethrio.co. We answer within 30 days. We may ask you to confirm you control the email address on the account, which is the only way we can tell it is you.

If you are a California resident, the rights above are the ones the CCPA and CPRA give you, granted here without you having to invoke them. We do not sell or share personal information as those laws define those terms, and we have not in the past 12 months.

One honest limit: deleting your account removes your published reviews and photos from the site going forward, but copies already made by search engines, archives or other visitors are outside our control.

12.Security

  • Everything is served over HTTPS.
  • Sign-in is passwordless, so a password of yours cannot leak from us.
  • The database enforces access at the row level: the rules that decide you can only read and write your own records live in the database itself, not in the app, so a modified or hostile browser cannot talk its way past them.
  • Uploaded photos are re-encoded and size-capped before they are stored.

No system is perfectly secure, and we will not pretend otherwise. If you find a vulnerability, email hey@aethrio.co and we will work with you on it. We will not pursue anyone who reports a flaw in good faith.

13.Children

Aethrio is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has created an account, email hey@aethrio.co and we will delete the account and its content.

14.If you are outside the United States

The catalogue covers parks in the United States and the service is hosted there. If you use it from another country, your information is transferred to and processed in the United States, where privacy law may differ from your own. The rights described above are granted to you regardless.

15.Changes to this policy

We will update the date at the top of this page whenever it changes, and we will say what changed on the site itself when the change is significant. Continuing to use the site after a change means you accept the updated policy.

16.Contact

Val Aristides, operating Aethrio. Email hey@aethrio.co for anything in this policy, including a request to see, export or delete your information. A postal address is available on request. These terms are governed by the law of New York, as set out in the Terms of Use.

Terms of Use · Browse by region · Browse by amenity · All parks

Last updated July 29, 2026.