MahoniaLegal

Legal

Last updated 5 September 2026

How Mahonia handles your data, and the terms for using it. Jump to Privacy or Terms.

Mahonia is made by one person. No advertising, and I don’t sell your data. Lists need no account; “My Gear” does, and the account holds your email and nothing else. If anything here is unclear, email hello@mahonia.app.

Where your data lives

Your list titles, folders, items, notes and weights are saved in your browser, and synced to the server once a list has real content. An empty draft you never add anything to is never sent anywhere.

A synced list is private: unlisted, not indexed, and openable only by someone you give the link to. There is no publish step; nothing you make appears anywhere except at its own links.

Body weight is treated differently from everything else here, and more carefully. Planning a trip lets you enter it so the calorie estimates mean something; it is optional, and the rest of the planning view works without it. It is saved on this device only: it is never sent to the server, so it cannot appear on a share link, a published list, the public feed, or a JSON backup, and it does not follow you to another device. Clear the field and the estimates fall back to a stated assumption.

Your route gets the same care. Importing a map file stores the line the trail follows, and that is the only geography Mahonia keeps; a recorded track often starts where you parked, which is sometimes where you live. So it is yours alone: it never appears on a share link, a published list or the public feed, not even in the page’s hidden data. Anyone you share with sees the distance, the climb and the shape of the elevation, which carry no coordinates at all. Your own JSON backup does include it, because that file is yours and the route is the one thing you couldn’t type again from memory.

My Gear, your saved gear, is the one part that needs an account. It holds names, brands and weights, and belongs to you rather than to a browser, so signing in on another device brings it with you, and clearing this one doesn’t lose it. Gear reaches it when you add something to a list yourself, or import or copy a list. Opening a list someone shared with you doesn’t put their gear into yours.

What Mahonia collects in the background

  • Request data. Your IP address and basic request details, processed briefly to serve pages, apply rate limits, and stop abuse. The host keeps standard short-lived logs.
  • Analytics. Cookieless, aggregate counts of page views, a handful of in-app actions (making a list, importing one, copying a share link, opening Packing or Trip, signing in), and performance. No advertising cookies, no cross-site tracking, no profile.

An account holds an email address, an optional display name, and the public half of any passkey you add. There is no password to store, because there are no passwords: you sign in with a passkey or with a link sent to that address. Mahonia never asks for your real name, payment details, or location, and a display name is shown only if you set one. The one thing it asks about you (optionally, for trip planning) is your body weight, and that never leaves your device; see above.

What you type can improve the shared catalog

When you type a piece of gear that isn’t already in Mahonia’s catalog, the brand, name and weight are noted. If the same item is typed on three or more different lists, it’s added to the public catalog with the median weight, so everyone gets a suggestion instead of typing it again. Only branded products qualify; generic words like “tent” or “snacks” never make it in.

Nothing that identifies you goes with it: not your list, not your account, not your email. What travels is the product and the weight, and the result is a catalog entry indistinguishable from any other.

The services Mahonia relies on

Four US-based providers run the plumbing, so your data may be processed there: Vercel (hosting, delivery, analytics), Neon (the database), Upstash (rate limiting, and the short-lived challenge a passkey needs), Resend (sending sign-in links, so it handles your email address).

One more, and only on one screen. When a list has a route, the planning view draws it on a topographic map, and those map images come from OpenTopoMap, a volunteer project built on OpenStreetMap data. Loading an image tells that server your rough map position and that the request came from mahonia.app, never which list you’re looking at, because the browser is told to send the site’s address and nothing further. It’s the only request Mahonia makes to anyone else, it only happens on a list that has a route, and the map’s code isn’t even downloaded otherwise.

Keeping and deleting your data

Removing things is mostly in your hands:

  • “Your lists” shows every list saved on this device. “Remove from device” takes one off this browser (it stays online for anyone with the link); “Delete” removes it from the server for everyone.
  • In “My Gear”, “Remove” takes a piece of gear out and keeps it out. Signing out leaves your gear where it is, ready for the next time you sign in. “Sign out everywhere” ends every session on every device, if you ever need it.
  • “Delete account” on your account page removes your email, display name, passkeys and your saved gear, straight away and without asking me. It asks separately whether to delete your lists; by default they stay, because they belong to their edit links rather than to your account.
  • For anything else, including a copy or deletion of a shared list, email hello@mahonia.app.

Some things are also cleaned up automatically, and the timings are exact rather than vague. A list that never got past a single item and hasn’t been edited for 30 days is marked for removal; saved gear untouched for 180 days is treated the same way. Either is then held for 90 days before it’s deleted for good, and using it again during that window brings it straight back; for your gear, signing in is enough. If you’ve lost something, email me and I’ll see what can be recovered.

No system is perfectly secure. Please don’t put sensitive personal information into a list.

What Mahonia does not do

  • No passwords, no advertising. Lists need no account at all.
  • No selling your data and no cross-site tracking.
  • No advertising cookies, tracking pixels, or third-party trackers. The map tiles above are the only thing loaded from another company, and they’re pictures of terrain, not trackers.
  • No asking where you are. The map shows your route, never you; there is no “find me” button, and Mahonia never requests location permission.

Children

Mahonia isn’t directed at children under 13 and doesn’t knowingly collect data from them. If you believe a child has provided data through Mahonia, email me and I’ll remove it.

Changes to this policy

Material changes will be reflected here with an updated date.

By using Mahonia you agree to what’s below. If you don’t agree, don’t use it.

What Mahonia is

A free tool for making and sharing packing lists. A list’s private edit link is the only key to changing it; a separate read-only link lets others view it; publishing puts it in a public feed.

The edit link is your responsibility

Anyone who has a list’s edit link can change that list. Keep it private and save it somewhere safe. If you lose it, I can’t recover edit access for you.

Your content is yours

You keep ownership of the lists you create. Sharing or publishing one gives me permission to store and display it so the feature works, and that permission ends when you remove the content. You’re responsible for what you put in your lists and for having the right to share it. Public means public, so don’t share anything you wouldn’t want out in the open.

Fair use of Mahonia

Please don’t use Mahonia to break the law, infringe others’ rights, post abusive or deceptive content, impersonate people, or attack, overload, or scrape the service. Public lists can be flagged with “Report list” in the ⋯ menu; to report a problem or request a takedown, email hello@mahonia.app with enough detail to find the content. I may remove content or limit access, including pulling lists off the public feed.

It’s free and provided “as is”

Mahonia may change, pause, or shut down at any time, and isn’t guaranteed to keep your data forever. Keep your own backups of anything important; the editor can export your list. It’s provided as is and as available, with no warranties of any kind and no guarantee of availability, accuracy, or fitness for any particular purpose, to the fullest extent the law allows. Weights, the catalog, and totals may be wrong or out of date. Don’t rely on Mahonia for anything safety-critical, and verify your own kit before you head out.

Limitation of liability

To the fullest extent permitted by law, I’m not liable for any indirect, incidental, or consequential damages, or for any loss of data, arising from your use of (or inability to use) Mahonia.

Changes to these terms

These terms may change. Material changes will be reflected here with a new date, and continuing to use Mahonia after a change means you accept the updated terms.

Governing law

These terms are governed by the laws of the State of Oregon, United States, without regard to its conflict-of-laws rules. Nothing here limits any rights you have under the mandatory laws of the place you live.

Open source, and the code Mahonia borrows

Mahonia’s own code is open source under the MIT license. It also ships a handful of libraries other people wrote (the map, the framework it’s built on) and their licenses ask for credit where the code goes. That credit is at /licenses.txt, along with the map data’s.

Anything about your privacy or these terms: hello@mahonia.app. See also About.