Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README states that geocoding uses OpenStreetMap Nominatim and RIDB queries are sent to ridb.recreation.gov, but it does not clearly warn users that their entered locations or coordinates will be transmitted to third-party services. This can expose sensitive travel plans, precise locations, or operational context if users assume searches are local-only, making it a real privacy and data-handling issue rather than a false positive.
