Privacy Policy
Last updated: August 17, 2026
FrightMaps (“we”, “us”) operates the FrightMaps mobile app and frightmaps.com (the “Service”), which helps people discover haunted houses and Halloween displays, plan routes, design haunts with AI-powered tools, buy and sell event tickets, enter contests, and control compatible decorations. This policy explains what we collect and why.
1. Information we collect
Account information
When you sign in with Google, Apple, or email, we receive your name, email address, and (if provided) profile photo. You may browse much of the Service without an account.
Profile & activity
- Username, profile photo, and reward balance (“FrightCoins”), rank, and streaks.
- Houses and displays you like, save, visit, subscribe to, or list, including photos you upload.
- Your general location and/or ZIP code, used to show haunts near you and relevant content.
Location
With your permission, we use your device location to show nearby haunts and build routes. You can disable location access at any time in your device settings.
Ticketing information
If you buy tickets, we collect your name, email, the order and ticket details, and your selected event date/time. If you sell tickets, we collect your business details, events, and payout configuration. Card payments are processed by Stripe — we do not store full card numbers.
AI features
If you use FrightLabs, our AI haunt planner, we process the prompts you enter and the plan content generated for you in order to produce your designs. A plan can include your property’s dimensions, the positions you place for features such as the house, door, driveway, porch, pool, shed, street, and sidewalk, the guest route, zone and element names, and free-text notes you write about the space. You may attach photos — such as an aerial or satellite view of your property — to help build a layout; those photos are processed to generate the layout and are stored with your plans.
If you mark a plan as a paid attraction, FrightLabs also processes the ticketing and cost assumptions you provide — opening and closing times, number of nights, occupancy limit, expected attendance, tickets sold, ticket price, per-guest variable cost, labor cost, fixed cost, and fee and tax percentages — and calculates projected attendance, capacity, gross revenue, and projected profit from them. Those figures are stored with the plan and shown back to you. Plans that are not marked as paid carry no forecast.
If you import a prop from a product link, we fetch the URL you supplied and keep that URL with the prop as its source. If you use AI Skelly, voice lines are generated by AI, and we store your audio settings and usage metering with your account so we can apply your plan’s voice limits. Section 6 describes what changes when you reach FrightLabs through ChatGPT.
Usage & device data
We collect analytics about how the Service is used (events such as views, likes, and purchases), along with app version, device model, operating system, and language. When you contact support, we include diagnostic details (account type, app/OS version, and a short recent-activity log) to help resolve your issue.
Push tokens
If you enable notifications, we store a push token to send you alerts you’ve opted into.
2. How we use your information
- Operate and personalize the Service (show nearby haunts, save your activity, run contests).
- Process ticket purchases and subscriptions and deliver tickets.
- Generate the AI content you request (FrightLabs plans and layouts, AI Skelly voice lines) and meter usage of those features.
- Calculate the capacity and profitability forecasts you ask for on paid-attraction plans.
- Publish a plan or listing to a public link when you ask us to, and remove it when you revoke.
- Send notifications and support responses you request.
- Measure and improve performance, reliability, and features.
- Detect, prevent, and address fraud, abuse, and technical issues.
3. Payments & subscriptions
Ticket and advertising payments are handled by Stripe. Pro and other subscriptions are handled through the Apple App Store, Google Play, RevenueCat, and/or Stripe depending on where you purchase. These providers process your payment information under their own privacy policies; we receive confirmation and limited transaction details, not your full card data.
4. Service providers we share data with
We use trusted providers to run the Service, each acting as a processor on our behalf:
- Google Firebase — authentication, database, storage, analytics, and notifications.
- Supabase — ticketing data (events, orders, tickets).
- Stripe — payment processing and payouts.
- RevenueCat — subscription management.
- Google Maps — maps and location features.
- OpenStreetMap (Nominatim) — converting a ZIP code you search into map coordinates so we can sort haunts by distance.
- Branch — deep links and attribution.
5. When we share with others
When you purchase tickets, we share the information needed to fulfill your order (such as your name and email) with the haunt/event operator you bought from, who is the merchant of record for that sale. We do not sell your personal information. We may disclose information if required by law or to protect the rights, safety, and security of users and the Service.
Haunt Clubs. If you request to join a Haunt Club from your haunt listing, we share that listing’s public information (haunt name, location, cover image, and membership status) with that club’s owner and co-administrators so they can review and approve your membership, and — once approved — display your haunt on the club’s public page and map and in member exports. Club owners and co-administrators can see member haunts’ public listing details and membership status — never account passwords — and club admins do not receive member email addresses through club tools. Membership can be revoked by either side: you can withdraw a request or leave a club at any time from your listing, and a club may remove your haunt from its roster.
AI assistant discovery. So people can find haunts inside AI assistants such as ChatGPT and Claude, we serve public haunt listing data — name, city/state-level location, photos, descriptions, likes, hours, badges, and links — to third-party AI platforms through our public discovery API. Only information that is already public on the listing is shared. For a free home display, location is returned at city level only; the postcode, coordinates, and any phone number are withheld. For a ticketed attraction, which is a business, the listing’s published postcode and phone number are included. Account emails and private account data are never included, and these discovery tools never read or write a FrightMaps account. We keep an anonymous daily count of how often each tool is called, and a tally of searches that returned nothing, neither tied to any person.
Directory listings & claims. FrightMaps publishes directory listings of publicly-advertised haunted attractions compiled from public sources. If a listing describes an attraction you operate, you can claim it; if a listing is inaccurate, you can flag it (“this isn’t here”), and repeated flags hide a listing pending review.
6. Using FrightMaps inside ChatGPT
We publish two apps for ChatGPT: FrightLabs, the haunt planner, andFrightMaps Discovery, which finds haunts and ticketed events. They run on our servers and are reached by ChatGPT over the Model Context Protocol (MCP). This section describes that surface specifically, because the data flow differs from using our app or website directly.
What the tools can do
So you can see exactly what is reachable from a chat, these are the actions our tools perform:
- Plan without an account. create_frightlabs_plan, revise_frightlabs_plan, and review_frightlabs_plan build, edit, and critique a plan from what is in the conversation. review_frightlabs_plan stores nothing at all; the other two also produce the temporary link described under “Editor and download links” below.
- Work on a plan in your FrightMaps account. When you supply an AI Sync code (below), read_frightlabs_live_plan, revise_frightlabs_live_plan, list_frightlabs_saved_plans, open_frightlabs_saved_plan, and save_frightlabs_live_plan can read the plan you have open, change it, list the names of every plan saved in your account, open a different saved plan into your editor — replacing what was open — and save, which overwrites the current record unless you ask for a new copy.
- Publish and un-publish. share_frightlabs_live_plan creates a public read-only link to the plan; revoke_frightlabs_share removes it.
- Import a prop. add_prop_from_product_url fetches a product link you supply and stores the extracted image, optionally placing it in a connected plan.
- Reference and product information. list_frightlabs_elements and automate_props return a fixed catalog and fixed product copy, and involve no personal data.
- Discovery. find_haunts, get_haunt_details, find_ticketed_events, trending_haunts, and about_frightmaps read public listing data only, exactly as described in section 5. They never touch a FrightMaps account, never accept an AI Sync code, and write nothing to your account.
What we receive
We receive only the arguments ChatGPT sends with a tool call. For planning, that is the plan itself — its name, whether the venue is a home or a professional attraction, property dimensions, the positions of elements such as the house, door, driveway, porch, pool, and shed, the guest route, zone and element names, free-text notes, image links, and, for a paid attraction, the ticketing and cost figures listed in section 1: ticket price, per-guest variable cost, labor cost, fixed cost, fee and tax percentages, tickets sold, number of nights, occupancy limit, and your opening and closing times. For a prop import it is the product URL you supply, which we keep as the prop’s source and store in the saved image’s file metadata. For discovery it is a search location — typically a city, state, or ZIP — and simple filters. If you have connected a plan, it also includes your AI Sync code.
ChatGPT does not send us your conversation history, your OpenAI account identity, your OpenAI email address, or any message you did not direct at one of our tools. FrightMaps Discovery requires no account at all and receives nothing that identifies you.
Connecting a plan with an AI Sync code
FrightLabs can work directly on a plan in your FrightMaps account. To allow that, you sign in to the FrightLabs editor on our website, generate an AI Sync code, and paste that code into ChatGPT. The code is a random secret that stands in for your account for this purpose. We store it only as a one-way hash, together with your FrightMaps account identifier, the email address on that account, and your display name, so we know whose plan to open. None of those three values is ever returned to ChatGPT — the tools return plan contents, not your identity.
Treat the code like a password. Anyone who holds it can, through our tools, read the connected plan, list the names of every plan saved in your account, open a different saved plan into your editor, change and overwrite the plan, and create or revoke a public link to it. A code stops working four hours after it is created, and you can end it sooner from the editor.
What we do with it
Planning arguments are used to generate, revise, and store your haunt plan so you can return to it, and to calculate the forecast figures on paid-attraction plans. Search arguments are used to query our public haunt and event listings and are not attached to an identity. If you ask FrightLabs to import a prop from a product link, our server fetches the URL you supplied, extracts the product image, and stores the cut-out image so it can be placed in your layout; we do not fetch anything you have not explicitly given us. We do not sell this data, do not use it for advertising, and do not use it to train AI models.
What goes back to ChatGPT
Tool results are returned into your ChatGPT conversation, which means they reach OpenAI. That matters most for images: when ChatGPT reads a connected plan it requests the plan’s pictures by default, and we return up to six of them — including the aerial or site photo of your property, along with prop images — up to five megabytes each and twelve megabytes in total. A prop import likewise returns the cut-out image itself. Text results include the plan contents and, for a paid attraction, the projected attendance, gross revenue, and projected profit; when a plan is connected, the AI Sync code is echoed back in the result as well. Once returned, that content is part of your ChatGPT conversation and is handled under OpenAI’s privacy policy, not this one. If you would rather a property photo not leave FrightMaps, ask ChatGPT to read the plan without images, or remove the photo from the plan before connecting.
Editor and download links
Every tool that returns a plan also stores a copy of that plan and gives ChatGPT a link so you can open it in the FrightLabs editor or download it as a file. The link contains a long random token and requires no sign-in: anyone holding the link can open or download the full plan, including any property photo embedded in it, until the link expires roughly thirty minutes after it is created. Because the link is placed in your ChatGPT conversation, treat it as you would any other private link and do not forward it to someone you do not want to have the plan.
Sharing a plan publicly
If you ask to share, FrightLabs publishes a read-only copy of the plan at a public link. There is no sign-in on that link: anyone who has the URL can view the plan, including its dimensions and layout, the guest route, your notes, any attached site or aerial imagery, and the ticketing and cost figures if it is a paid attraction. The published copy also carries your FrightMaps display name, if you have set one, and an internal account identifier; if you have not set a display name, the share is credited to “a FrightMaps haunter” and your email address is never used in its place. The link is unlisted rather than indexed, but it is public to anyone who holds it.
You can un-publish at any time by asking FrightLabs to revoke the share, by using “Revoke share link” in the editor, or by deleting the plan — each of which removes the public copy. Revoking stops future access; it cannot recall a copy someone already opened, downloaded, or saved.
Who it reaches
- OpenAI, as the operator of ChatGPT, receives everything our tools return into your conversation, as described above.
- The processors listed in section 4, principally Google Firebase, which stores the plans and images. A ZIP you search through FrightMaps Discovery is also sent to our geocoding provider.
- The public, for the two link types above — a temporary editor and download link, and a share link you ask us to create.
- The website you point us at, when you supply a product link for a prop import: that site sees the request our server makes for the image.
We do not sell this data, do not use it for advertising, and do not use it to train AI models. Your use of ChatGPT itself is governed by OpenAI’s privacy policy, not this one; we are the recipient of a tool call, not a party to your ChatGPT session.
How long we keep it
- Plans saved to your account — until you delete them or ask us to delete your account.
- An AI Sync connection — four hours, or until you end it from the editor.
- An editor or download link — about thirty minutes from the moment it is created.
- A public share — until you revoke it or delete the plan.
- Imported prop images — kept indefinitely. These are stored in a shared cache keyed by the product link rather than by user, so two people importing the same store item share one stored image. The stored files hold the retailer’s product picture and that product URL, and nothing that identifies you. Because they are not filed under your account, deleting a plan or your account removes the plan and its reference to the image but does not by itself remove the cached image; email us if you want a specific cached image taken down.
- Tool-call arguments that do not produce a saved plan — such as a haunt search — are retained only in short-lived operational logs and are not stored as a profile of you. We do keep three anonymous aggregates that are tied to no person and no account: a daily count of how many times each tool was called, recording tool names only and no arguments; a tally of the ZIP or city searched when a search returns nothing; and the map coordinates of any ZIP we have geocoded, so we need not ask our geocoding provider about that ZIP again.
Your controls
- End an AI Sync connection from the FrightLabs editor, which immediately stops any code you shared from working.
- Revoke a public share link from the editor, or by asking FrightLabs to revoke it.
- Delete a plan from within FrightLabs, which also removes that plan’s public share.
- Ask ChatGPT to read a plan without images, or remove a property photo from the plan, if you do not want that photo returned into the conversation.
- Save as a new copy rather than saving over an existing plan, if you want to keep the earlier version.
- Disconnect the app in ChatGPT at any time.
- Email contact@frightmaps.com to request deletion of anything we hold, including a cached prop image.
The rights described in section 9 apply equally to data received through ChatGPT.
7. Cookies & analytics
The website uses essential cookies and privacy-respecting analytics to understand usage and improve the Service. You can control cookies through your browser settings.
8. Data retention
We keep your information for as long as your account is active or as needed to provide the Service and meet legal, tax, and accounting obligations (for example, ticket and payment records). You can request deletion of your account and associated data (see “Your rights”). Retention periods specific to plans, sync connections, share links, and links created through our ChatGPT apps are set out in section 6.
9. Your rights & choices
- Access, correct, or delete your account data — contact us or use in-app account controls.
- Disable location and notifications in your device settings at any time.
- Manage or cancel subscriptions through the store where you purchased them.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
11. Security
We use industry-standard safeguards (encryption in transit, access controls, and reputable infrastructure providers) to protect your information. No system is perfectly secure, but we work to protect your data.
12. Changes to this policy
We may update this policy; we’ll revise the “Last updated” date and, for material changes, provide notice.
13. Contact
Questions? Email contact@frightmaps.com.