Skip to main content
Natural Disaster Map

Privacy

Natural Disaster Map has no accounts and no sign-in. This page explains what it sends, to whom, and what it keeps on your device; the last section names every item it stores.

Updated October 9, 2026

In short

No accounts, no advertising, nothing to sign up for.

Two tools count visits: Google Analytics, inside a sealed-off frame that stores no cookies, and Cloudflare Web Analytics, which also measures how fast pages load.

Cloudflare, the network that delivers the site, runs a bot check on the main pages. It sets a cookie called cf_clearance that lasts up to a year.

Your searches, saved places and position on the map are never sent to Google Analytics, and saved places never leave your device.

The details, and every item the site stores on your device, are below.

Location

Place search uses an index that runs in your browser, so what you type stays there. The exception is pressing Enter before the page has finished loading, or with JavaScript off: the search then becomes the page’s address (/?q=…), which reaches this site’s hosting like any address you open.

The “my location” button asks your device for permission. Your position then centres the map, becomes part of the map’s address in this tab, and can set the displayed timezone. Links shared from that view use an approximate area unless you choose to include the precise location.

When a place card shows a U.S. place, the site checks for National Weather Service warnings there: the place goes to this site’s server, which asks the NWS, about once a minute while the card is open. For a point you picked on the map, that happens only when you ask, and the point’s coordinates are what is sent.

Approximate location

This site is served by a Cloudflare Worker. Cloudflare works out an approximate city from your IP address on each request. After the page loads, the globe and the events page ask for a private answer naming that city and any reports within 500 km; it is never cached or stored. The estimate can be wrong, especially with a VPN or on a mobile network, which is why the line always names the city it used.

Cloudflare processes your IP address and request details to deliver and protect the site. Its operational logs can include requested addresses, including search text or map coordinates in a query string. The private nearby response is separate from those request logs. Cloudflare also asks your browser to report requests to this site that fail, for up to 7 days (Network Error Logging); such a report can include the address that failed.

Optional beach-camera video

The temporary storm-watch page checks fixed beach-camera broadcasts through this site’s server. The server reads public live-status metadata from YouTube’s privacy-enhanced embeds and Explore.org, and checks the approved camera, creator and video identities. No API key is needed, and these checks do not send your map location or search text.

YouTube’s player loads only after you choose to watch a verified live camera. It connects your browser to Google and YouTube, which receive your IP address and browser information and may use cookies or show ads under their own policies. Privacy-enhanced playback is used, but this does not make the player anonymous. No video player loads on the globe or inside the embeddable globe.

Analytics

This site uses Google Analytics to count visits and a few control actions. It runs in a sandboxed frame that cannot see this page, its address or anything this site stores on your device, with cookie storage disabled. The page passes it only these events: opening a page; which map layer you switched on or off; the motion setting you chose; the time window you chose; sharing a view of the globe; opening a report, with its hazard type; and opening a highlighted report, with its hazard type. Each carries the kind of page it happened on (for example “/event” for any event page, never which event) and the referring website’s origin. Google’s own enhanced measurement also records a “scroll” event when the frame loads, with the same page kind.

Google receives them with your IP address and browser details, under Google’s terms. The site does not send Google map coordinates, search text, event IDs, place names, saved places, Future Moon activity or full referrer addresses. Google signals and ad personalization are off, and the site runs no advertising or remarketing. The embeddable globe loads no analytics.

Cloudflare Web Analytics also runs on the main pages to measure page visits and performance. Its beacon receives browser information, page paths (including event and place paths) and loading or interaction timings, and sends measurements through this site’s /cdn-cgi/rum endpoint. Cloudflare says Web Analytics does not log query strings. That statement is about Web Analytics, not the operational request logs described above. The embeddable globe and the isolated Google frame exclude this beacon.

Error reports

If something on a page breaks, your browser sends a short report to this site’s own server at /api/client-error, never to a third party. It contains the error message (up to 500 characters); its stack trace, which names the code files involved (up to 2,000 characters); the page’s path, such as /event/… (never its query or map position); which part of the site caught the error; and your browser’s user-agent string. After a graphics failure, the report also says how many times the globe has restarted its graphics, which the server discards.

Failures that stop the globe or a whole page are always reported; other errors about one time in ten, and each distinct message at most once per page load. The server writes the other fields as one line to its log and keeps nothing else from the report. So that one visitor cannot crowd out the rest, it counts each connecting IP address’s reports for one minute, in memory only; the address is never written to the log. Cloudflare’s Workers Logs keep that line and operational request logs.

Scripts from elsewhere

The main pages allow script files from this site and static.cloudflareinsights.com for Cloudflare Web Analytics. Cloudflare’s network also adds its bot-detection script to the main pages, served from this site’s /cdn-cgi/ path; it sets the cf_clearance cookie listed below. Google’s script runs only in the separate sandboxed analytics frame. The optional storm-watch page additionally permits YouTube’s player script after you choose to watch a live camera. Other external script origins are blocked by the site’s security policy. The embeddable globe allows only this site’s scripts.

Data you look at

Every hazard on the map is public scientific data from the agencies named on the about page. Your browser fetches map tiles, satellite imagery and some reports directly from those providers and from the services that host them: map labels and symbols from GitHub Pages, and NIFC’s wildfire records from Esri’s ArcGIS Online. Each receives your IP address and, for tiles and imagery, which areas you view, under its own terms.

On your device

Nothing syncs between devices. Your saved-places list, the names you give places and your Future Moon colony are never added to shared links or analytics. Below is every name stored on your device by the site, the libraries it runs on and its hosting network, grouped by where it is kept.

Saved in this browser

Local storage, kept until you or your browser clear it. “Clear this site’s data” removes them.

NameWhat it’s for
ndm.detail-modeYour motion setting for the globe: Cinematic, Simple, or automatic (follows your device’s reduced-motion setting).
ndm.timezoneYour timezone choice, or automatic, for the times the site shows, including in snapshots and summaries you share. “My location” can set it to that place’s zone; only the zone’s name is saved.
ndm.last-visitWhen you last had the globe open, updated every few minutes while you look, so a return visit can show what is new since then.
ndm.current-visit.v1When this visit began and which earlier visit it is compared with, so “since your last visit” stays the same across reloads and tabs.
ndm.saved-places.v1My Places: the places you saved and the names shown for them, which you can change.
ndm.featured-dismissed.v1Remembers which featured report you closed, so it stays closed until a different report leads.
ndm-earth-panel-position-v1Where you moved the Imagery panel. “Reset position” removes it.
ndm.moon-colony.v2Your Future Moon colony: buildings, missions, upgrades and discoveries.
ndm.moon-colony.before-import.v2Your previous Future Moon colony, kept when you restore a backup so you can still download it.
ndm.moon-colony.v1A colony saved by an earlier version of Future Moon. It is only read, to carry that colony forward, and left in place as a recovery copy.
ndm.moon-soundWhether Future Moon’s sound effects are on.

Kept for this tab

Session storage, cleared when you close the tab. “Clear this site’s data” removes them.

NameWhat it’s for
ndm.map-return-v1The address of the map view you were on, which can include the map’s centre and zoom, so closing a report returns you to that view.
ndm.map-return-history-v1The same address with its place in this tab’s history, so closing a report can use the browser’s own Back step.
ndm:satellite:v1Which satellite images are available and when that list was fetched (never the images), reused for up to 15 minutes so imagery opens faster.
ndm.chunk-reload-v1Written only if part of the site fails to load, usually just after the site updates: the time the page reloaded to fetch the new version, so it reloads at most once a minute and never in a loop.
tsr-scroll-restoration-v1_3Scroll positions of the pages you visited in this tab, so Back returns you to the same place. Written by the site’s routing library.
tanstack_router_reload:…Written only if part of a page fails to load, usually just after the site updates: it marks that the page reloaded once, so it cannot reload in a loop. The name ends with the error message.

Kept in this tab’s history

Saved in the tab’s Back and Forward history rather than in site storage, so it lasts as long as that history does. “Clear this site’s data” does not remove them.

NameWhat it’s for
ndmReportsOpenWhether the Reports panel was open, so Back and reload bring it back.
ndmNearbyDismissedWhich place card you closed, so Back and reload keep it closed.
ndmNearbyCollapsedWhich place card you folded to its “Nearby:” line, so a reload shows it as you left it.
ndmSheetOn a phone, that this Back step is an open sheet (Reports, Layers or My Places) and which one, so Back closes the sheet instead of leaving the map.
ndmSheetBelowThe address of the step before an open sheet (the map view it showed), so closing the sheet with Back keeps changes made while it was open.
ndmNearbyReadingYour place in a place card’s nearby reports: the place, how many reports were showing, whether older records were open and how far you had scrolled.
ndmPopupReportWhich report you opened from a map popup, so Back to the map rings it again. Cleared when the map reads it.
ndmBriefingOpenWhether the briefing’s highlights were open in the Reports panel (true or false only), so Back keeps them as you left them.
ndmBriefingScopeWhether the briefing was showing reports near the selected place or worldwide.
ndmSearchReportWhether a search result opened a report from this map view (true or false only), so closing the report returns keyboard focus to the map.
ndmReportRowWhich report a list on this map view opened (the report page's path on this site and the kind of row), so Back returns keyboard focus to that row.
ndmEventMapContextThe map view a report was opened from, so the report’s “Live map” link returns to it.
ndmDeviceLocationViewWhether the map view came from your device’s location (true or false only), so shared links use an approximate area unless you choose the precise one.
__TSR_indexThis page’s position in the tab’s history, used for Back and Forward.
__TSR_keyA random ID for this history entry, used to restore its scroll position.
keyThe same random ID again: the routing library writes it under both names.

Cached files

Cache storage and a service worker. “Clear this site’s data” removes them.

NameWhat it’s for
ndm-assets-v1Copies of the site’s own code and style files, whose names change with every release, so repeat visits start faster. Never pages, reports, map tiles or anything about you.
/sw.jsThe service worker that keeps those copies. It caches only the site’s own /assets/ files. When a page cannot load at all, it shows a short notice of its own, never an old copy of a page.

Cookies

The site’s own code sets no cookies. Cloudflare’s network sets the one below, and your browser sends it back with each request to the site. “Clear this site’s data” removes them.

NameWhat it’s for
__cf_bmSet by Cloudflare, the network in front of the site’s host, for its bot protection. It expires 30 minutes after your last request, and the site’s code never reads it.
cf_clearanceSet by Cloudflare’s bot-detection script, which its network adds to the main pages but not the embed. It lasts up to a year, and the site’s code never reads it.