01What we collect
In shortYour account details, the content you post, your settings, and a small amount of technical data for security.
Account information
- Username and email address — to create and secure your account.
- Password — stored only as a salted bcrypt hash. We never see or store your actual password.
- Date of birth — collected once, used solely for age gating (see Minors). It is never shown to other users.
Profile & settings
- Avatar, banner, bio, custom status, and the colors and font you choose for your name and profile — these are visible to other users wherever your name appears.
- Client settings (theme, fonts, UI and notification preferences) synced to your account so they follow you across devices. Hardware device identifiers (like your microphone or camera selection) stay on your device only.
Content you create
- Messages in servers and direct messages, including edits, replies, reactions, pins, and checklists.
- Files and images you upload as attachments, avatars, banners, or server emoji.
- Reports and suggestions you submit.
Technical data
- Push subscriptions — if you enable notifications, your browser gives us a push endpoint, or the mobile app gives us a device push token, so we can deliver them.
- IP address and browser user-agent — recorded in our internal audit log alongside administrative and security-relevant actions. We do not use them for profiling or analytics.
- Read states, mutes, per-channel notification levels, and which threads you follow — so unread badges and notifications work.
- Precise location — only if you switch on Location sharing in the mobile app, and only while it is on. See Location sharing for exactly what this means.
We do not run advertising, third-party analytics, or tracking pixels — not on this website, and not in the app.
02How we use it
We use your data for exactly four things:
- Running the Service — delivering messages, calls, files, and notifications to the right people in real time.
- Keeping you signed in and safe — authentication, age gating, and account security.
- Moderation and safety — handling user reports, enforcing our Terms of Service, and preventing abuse.
- Talking to you — service emails and, if you opted in, push notifications. No marketing spam.
We never sell your personal data, and we never share it with advertisers.
03Voice, video & screenshare
In shortCalls are live-only. We don't record them, and nothing is stored.
Voice, video, and screenshare streams are routed in real time through Cloudflare's Realtime infrastructure (an SFU — a relay that forwards streams between call participants). Streams exist only for the duration of the call: we do not record, store, or transcribe calls, and neither does the relay. The Service knows who is in which voice channel (that's visible to other members) but keeps no history of what was said or shown.
To keep calls working, the app reports technical call diagnostics to us during a call: connection states, track/codec names, packet counters, and error messages. This is metadata about the connection only — it never includes audio, video, or screen content — and is used solely to debug call problems.
04Who can see your content
In shortServer messages are visible to that server's members. DMs are private between you two — staff can access them only for moderation, and every access is logged.
- Server messages are visible to the members of that server, subject to channel permissions its moderators set.
- Direct messages are visible only to you and the other participant.
- Your profile (username, avatar, bio, status) is visible to users you share a server or DM with.
- Platform staff can access content — including direct messages — only when investigating a report or suspected abuse. Every staff access of this kind is recorded in an immutable audit log.
- Uploaded files are served from our storage via unguessable links; anyone with a file's link can fetch that file, so treat attachments like anything else you share in a chat.
We disclose personal data to third parties only if required by law (for example, a valid legal request), or to protect the safety of our users or the Service.
05Location sharing
In shortOff by default, 18+ only, and only the specific people you pick can see you. Turn it off and we stop collecting it.
The mobile app has an optional feature that shares your location with friends you choose. It is off unless you turn it on, and while it is off we collect no location data at all.
- Who can use it — members aged 18 and over only. If your date of birth puts you under 18, the feature is unavailable and any sharing you had is switched off automatically.
- Who can see you — only people you have specifically granted access to: an individual friend, a circle you have switched sharing on for, or (if you switch it on) your friends generally, minus any exceptions you set. It is never visible to a server, a channel, or anyone you are not friends with. There is no public map.
- Circles — a circle is a group whose members can see each other, but each member decides for themselves whether the rest of it can see them, at what precision, and whether it gets their history. Being added to a circle never starts you sharing: your sharing with it is off until you turn it on, and that applies to the person who created the circle too. Its owner controls who is in it — not whether anyone in it is visible.
- Exact or approximate — each grant is either your exact position or an approximate area of roughly one kilometre, your choice, per person and per circle.
- Time limits and pause — a grant can expire automatically after a period you choose, and "Pause" hides you from everyone instantly while keeping your settings.
- What we store — your most recent position, and a location history (a trail) kept for up to 30 days. Your history is visible only to you unless you explicitly switch history on for a specific person or circle.
- Places — you can name an area ("Home", "School"). When you enter or leave one, the people who can see that place are told, and your position reads as “at Home” instead of coordinates. A place you make on your own is visible to everyone you share your location with. A place attached to a circle belongs to that circle: everyone in it sees it, it applies to every member, and the circle's owner and anyone they mark as an admin can rename or delete it. Nobody outside the circle can see it or is told it exists. You can switch off arrival and departure alerts for a circle without switching off sharing with it.
- What we collect it with — while sharing is on, the app reports your position in the background as you move, at your phone's high-accuracy setting (roughly 10 metres, rather than the ~100 metres it used before). It also reports every few minutes while you are not moving, so the people you share with can tell a phone that is still at the same place from one that has stopped reporting — and if your phone has been silent for about twenty minutes, our server asks it to report once, using the same silent request described under "Ringing and locating a phone" below. A report that shows you have not moved is not added to your trail; it only refreshes the time you were last seen and how long you have been at that spot, both of which the people you share with can see. Android shows a permanent notification for the whole time any of this is happening.
- Movement and drives — the position your phone reports includes its own accuracy estimate and, while you are moving, your speed. People you share with see both, and if you have also given someone access to your history, the app groups your saved trail into drives (start, end, distance, duration, top speed). This is worked out from the trail already described above — we do not record anything extra to produce it, and someone who can see only your current location never sees your drives.
- Ringing and locating a phone — anyone who can currently see your location can also make your phone ring (it sounds even if nobody picks it up, and on Android it is designed to sound through a silenced ringer), and can ask your phone to report its position straight away rather than wait for you to move. Both work without anyone touching the phone. The request to report a position happens silently: your phone is not notified and you are not shown a record of it. Neither action reveals anything the person could not already see — the position they receive is the same one they were already entitled to, at the same precision, so someone with an approximate share still only ever sees an approximate area. Both are limited to a few attempts every few minutes per person. If you do not want someone to be able to do this, stop sharing your location with them, pause sharing, or block them — any of those removes the ability immediately.
- Turning it off — switching sharing off stops collection immediately and deletes your last position. You can delete your entire location history at any time from the app, and it is deleted with your account.
- Blocking — blocking someone immediately ends any location sharing between the two of you, in both directions: direct grants are deleted, they are removed from your circles and you from theirs, and neither of you can re-share until the block is lifted. Unblocking does not restore what was revoked; it only allows contact again.
We do not use your location for advertising, profiling, or analytics, we do not sell it, and we do not share it with third parties.
Maps are provided by Google. When you open the map, the Google Maps service receives the map area being displayed and standard technical request data, under Google's privacy policy. Your friends' positions and your own stored location history are held by us and are not sent to Google; but be aware that viewing a map centred on a location does disclose that map area to them. Place names shown as “near…” are resolved on our own servers. If you tap a business or landmark on the map to get directions or send it to a friend, that one place is looked up from Google.
06Services we rely on
In shortCloudflare carries traffic, stores uploads, and relays calls. Giphy powers GIF search. Google Fonts serves fonts on this website.
- Cloudflare — sits in front of the Service (CDN/proxy), stores uploaded files (R2), and relays voice/video/screenshare (Realtime & TURN). Traffic and files pass through Cloudflare's infrastructure under their privacy terms.
- Google Maps — renders the map in the Nearby feature (web and mobile). Opening a map sends the displayed map area to Google. We do not send them your account, your friends' positions, or your location history.
- Giphy — powers the GIF picker. Your GIF search terms are forwarded to Giphy through our server; your identity, IP address, and account details are not sent to them.
- Google Fonts — this website (not the app itself) loads fonts from Google's servers, which means your browser makes a request to Google when you visit these pages.
- Your browser's or device's push service — if you enable notifications, delivery goes through the push service built into your browser or OS (e.g. Mozilla, Google, or Apple's). Web notification payloads are encrypted end-to-end between our server and your device. For the mobile app, notifications are delivered via the Expo push service (our mobile push delivery provider) and then Google or Apple; the notification title and preview text pass through those providers.
07Cookies & local storage
We use browser storage for one purpose: keeping you signed in and remembering device-local preferences (like which microphone you picked). There are no advertising cookies and no cross-site tracking of any kind.
08Retention & deletion
In shortYour data lives as long as your account does. A few safety records outlive deletion — with your name detached where possible.
- Deleting a message hides it from everyone immediately. A copy is retained internally so moderators can still act on reports about it (e.g. someone deleting harassment right after sending it).
- Editing a message keeps its earlier versions internally for the same moderation reason (e.g. editing abusive content after it's seen). Prior versions are visible only to platform administrators, never to other members.
- Reported messages are snapshotted, along with surrounding conversation, at the moment of the report. That snapshot is kept as evidence even if the original messages are edited or deleted.
- Location data — your current position is deleted as soon as you stop sharing. Your location history is kept for up to 30 days and then deleted automatically; you can delete all of it yourself at any time.
- Deleting your account removes your profile, memberships, messages, DMs, settings, push subscriptions, friendships, and all location data.
- What survives account deletion: moderation records (reports, warnings, bans) and audit-log entries, which keep a snapshot of the username involved but are detached from the deleted account. If your account was blocked for being under 16, we retain the email address to prevent re-registration until eligibility.
09Security
All traffic to the Service is encrypted in transit (HTTPS/WSS). Passwords are hashed with bcrypt and never stored in plain text. Administrative access is restricted to designated staff and every administrative action is recorded in an audit log that cannot be edited. No system is perfectly secure — if we ever discover a breach affecting your personal data, we will notify you as required by law.
10Minors
Translocate is not for children under 16. We collect your date of birth at signup to enforce this: accounts under 16 are fully blocked from the Service, and users aged 16–17 are automatically prevented from joining or viewing communities and channels marked 18+. Location sharing is restricted further still: it is available only to members aged 18 and over, and the daily age check switches it off for anyone who is not. If you believe a child under 16 is using Translocate, email [email protected] and we will act on it.
11Your rights
Wherever you live, we extend the same rights to everyone:
- Access & portability — ask us what data we hold about you and get a copy.
- Correction — fix inaccurate account data (most of it you can edit yourself in User Settings).
- Deletion — delete your account and data yourself, from Settings → Account in the app; it takes effect immediately (see Retention for the narrow exceptions).
- Objection — object to a use of your data you think is improper.
To exercise any of these, email [email protected] from the address on your account. We'll respond within 30 days. Depending on where you live (e.g. the EU/EEA, UK, or California), you may also have the right to complain to your local data-protection authority.
12EU, EEA & UK: the formal bits
If you're in the EU, EEA or UK, the GDPR applies to us and this section spells out what it requires. It doesn't change what we do — section 11 already gives everyone those rights — it just states it in the vocabulary the law uses.
Who is the controller. Sterango, operator of Translocate, is the data controller for your account and everything described in this policy. Our legal identity, postal address and contact details are on our legal notice page. You can reach us about any data-protection matter at [email protected]; we have not appointed a data protection officer, as we are not required to.
Why we're allowed to process your data. Our legal bases are:
- Performance of a contract — running your account and delivering messages, calls and files. Without this data there is no service to provide.
- Consent — location sharing, and push notifications. Both are off until you switch them on, and withdrawing consent is instant and as easy as giving it (turn sharing off in the app; withdrawal doesn't affect what happened before it).
- Legal obligation — reporting apparent child sexual abuse material to NCMEC, and responding to lawful orders.
- Legitimate interests — keeping the platform safe and abuse-free, moderation records, security logging, and preventing ban evasion. We've weighed these against your rights and kept the data narrow and the retention short.
Your rights, named. In addition to access, portability, correction, deletion and objection in section 11, you have the right to restriction of processing, the right to withdraw consent at any time, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we don't make any such decisions; moderation that affects your account is reviewed by a person.
Where your data goes. We are based in the United States, so using Translocate means your data is transferred outside the EEA and UK, to us and to the providers listed in section 06. Where a provider processes personal data on our behalf, that transfer relies on the European Commission's Standard Contractual Clauses (plus the UK Addendum) or, where applicable, the provider's certification under the EU–US Data Privacy Framework.
Complaints. You can complain to your national data protection authority — in the UK, the Information Commissioner's Office. We'd rather you told us first at [email protected] so we can fix it, but you don't have to.
13Changes to this policy
If we change what we collect or how we use it, we'll update this page and its "Effective" date, and give notice in the app or by email for anything material. We won't quietly start doing something this policy says we don't do.
14Contact
Translocate is operated by Sterango, based in the United States. For anything privacy-related, email [email protected]. Our full operator identity and postal address are on our legal notice page.
Translocate.