01What we collect
In shortYour account details, the content you post, your settings, and a small amount of technical data for security.
Account information
- Username and email address — to create and secure your account.
- Password — stored only as a salted bcrypt hash. We never see or store your actual password.
- Date of birth — collected once, used solely for age gating (see Minors). It is never shown to other users.
Profile & settings
- Avatar, banner, bio, custom status, and the colors and font you choose for your name and profile — these are visible to other users wherever your name appears.
- Client settings (theme, fonts, UI and notification preferences) synced to your account so they follow you across devices. Hardware device identifiers (like your microphone or camera selection) stay on your device only.
Content you create
- Messages in servers and direct messages, including edits, replies, reactions, pins, and checklists.
- Files and images you upload as attachments, avatars, banners, or server emoji.
- Reports and suggestions you submit.
Technical data
- Push subscriptions — if you enable notifications, your browser gives us a push endpoint, or the mobile app gives us a device push token, so we can deliver them.
- IP address and browser user-agent — recorded in our internal audit log alongside administrative and security-relevant actions. We do not use them for profiling or analytics.
- Read states, mutes, and per-channel notification levels — so unread badges and notifications work.
- Precise location — only if you switch on Location sharing in the mobile app, and only while it is on. See Location sharing for exactly what this means.
We do not run advertising, third-party analytics, or tracking pixels — not on this website, and not in the app.
02How we use it
We use your data for exactly four things:
- Running the Service — delivering messages, calls, files, and notifications to the right people in real time.
- Keeping you signed in and safe — authentication, age gating, and account security.
- Moderation and safety — handling user reports, enforcing our Terms of Service, and preventing abuse.
- Talking to you — service emails and, if you opted in, push notifications. No marketing spam.
We never sell your personal data, and we never share it with advertisers.
03Voice, video & screenshare
In shortCalls are live-only. We don't record them, and nothing is stored.
Voice, video, and screenshare streams are routed in real time through Cloudflare's Realtime infrastructure (an SFU — a relay that forwards streams between call participants). Streams exist only for the duration of the call: we do not record, store, or transcribe calls, and neither does the relay. The Service knows who is in which voice channel (that's visible to other members) but keeps no history of what was said or shown.
To keep calls working, the app reports technical call diagnostics to us during a call: connection states, track/codec names, packet counters, and error messages. This is metadata about the connection only — it never includes audio, video, or screen content — and is used solely to debug call problems.
04Who can see your content
In shortServer messages are visible to that server's members. DMs are private between you two — staff can access them only for moderation, and every access is logged.
- Server messages are visible to the members of that server, subject to channel permissions its moderators set.
- Direct messages are visible only to you and the other participant.
- Your profile (username, avatar, bio, status) is visible to users you share a server or DM with.
- Platform staff can access content — including direct messages — only when investigating a report or suspected abuse. Every staff access of this kind is recorded in an immutable audit log.
- Uploaded files are served from our storage via unguessable links; anyone with a file's link can fetch that file, so treat attachments like anything else you share in a chat.
We disclose personal data to third parties only if required by law (for example, a valid legal request), or to protect the safety of our users or the Service.
05Location sharing
In shortOff by default, 18+ only, and only the specific people you pick can see you. Turn it off and we stop collecting it.
The mobile app has an optional feature that shares your location with friends you choose. It is off unless you turn it on, and while it is off we collect no location data at all.
- Who can use it — members aged 18 and over only. If your date of birth puts you under 18, the feature is unavailable and any sharing you had is switched off automatically.
- Who can see you — only people you have specifically granted access to: an individual friend, a circle you have switched sharing on for, or (if you switch it on) your friends generally, minus any exceptions you set. It is never visible to a server, a channel, or anyone you are not friends with. There is no public map.
- Circles — a circle is a group whose members can see each other, but each member decides for themselves whether the rest of it can see them, at what precision, and whether it gets their history. Being added to a circle never starts you sharing: your sharing with it is off until you turn it on, and that applies to the person who created the circle too. Its owner controls who is in it — not whether anyone in it is visible.
- Exact or approximate — each grant is either your exact position or an approximate area of roughly one kilometre, your choice, per person and per circle.
- Time limits and pause — a grant can expire automatically after a period you choose, and "Pause" hides you from everyone instantly while keeping your settings.
- What we store — your most recent position, and a location history (a trail) kept for up to 30 days. Your history is visible only to you unless you explicitly switch history on for a specific person or circle.
- Places — you can name an area ("Home", "School"). When you enter or leave one, the people who can see that place are told, and your position reads as “at Home” instead of coordinates. A place you make on your own is visible to everyone you share your location with. A place attached to a circle belongs to that circle: everyone in it sees it, it applies to every member, and the circle's owner and anyone they mark as an admin can rename or delete it. Nobody outside the circle can see it or is told it exists. You can switch off arrival and departure alerts for a circle without switching off sharing with it.
- What we collect it with — while sharing is on, the app reports your position in the background as you move, at your phone's high-accuracy setting (roughly 10 metres, rather than the ~100 metres it used before). Android shows a permanent notification for the whole time this is happening.
- Movement and drives — the position your phone reports includes its own accuracy estimate and, while you are moving, your speed. People you share with see both, and if you have also given someone access to your history, the app groups your saved trail into drives (start, end, distance, duration, top speed). This is worked out from the trail already described above — we do not record anything extra to produce it, and someone who can see only your current location never sees your drives.
- Turning it off — switching sharing off stops collection immediately and deletes your last position. You can delete your entire location history at any time from the app, and it is deleted with your account.
- Blocking — blocking someone immediately ends any location sharing between the two of you, in both directions: direct grants are deleted, they are removed from your circles and you from theirs, and neither of you can re-share until the block is lifted. Unblocking does not restore what was revoked; it only allows contact again.
We do not use your location for advertising, profiling, or analytics, we do not sell it, and we do not share it with third parties.
Maps are provided by Google. When you open the map, the Google Maps service receives the map area being displayed and standard technical request data, under Google's privacy policy. Your friends' positions and your own stored location history are held by us and are not sent to Google; but be aware that viewing a map centred on a location does disclose that map area to them. Place names shown as “near…” are resolved on our own servers. If you tap a business or landmark on the map to get directions or send it to a friend, that one place is looked up from Google.
06Services we rely on
In shortCloudflare carries traffic, stores uploads, and relays calls. Giphy powers GIF search. Google Fonts serves fonts on this website.
- Cloudflare — sits in front of the Service (CDN/proxy), stores uploaded files (R2), and relays voice/video/screenshare (Realtime & TURN). Traffic and files pass through Cloudflare's infrastructure under their privacy terms.
- Google Maps — renders the map in the Nearby feature (web and mobile). Opening a map sends the displayed map area to Google. We do not send them your account, your friends' positions, or your location history.
- Giphy — powers the GIF picker. Your GIF search terms are forwarded to Giphy through our server; your identity, IP address, and account details are not sent to them.
- Google Fonts — this website (not the app itself) loads fonts from Google's servers, which means your browser makes a request to Google when you visit these pages.
- Your browser's or device's push service — if you enable notifications, delivery goes through the push service built into your browser or OS (e.g. Mozilla, Google, or Apple's). Web notification payloads are encrypted end-to-end between our server and your device. For the mobile app, notifications are delivered via the Expo push service (our mobile push delivery provider) and then Google or Apple; the notification title and preview text pass through those providers.
07Cookies & local storage
We use browser storage for one purpose: keeping you signed in and remembering device-local preferences (like which microphone you picked). There are no advertising cookies and no cross-site tracking of any kind.
08Retention & deletion
In shortYour data lives as long as your account does. A few safety records outlive deletion — with your name detached where possible.
- Deleting a message hides it from everyone immediately. A copy is retained internally so moderators can still act on reports about it (e.g. someone deleting harassment right after sending it).
- Editing a message keeps its earlier versions internally for the same moderation reason (e.g. editing abusive content after it's seen). Prior versions are visible only to platform administrators, never to other members.
- Reported messages are snapshotted, along with surrounding conversation, at the moment of the report. That snapshot is kept as evidence even if the original messages are edited or deleted.
- Location data — your current position is deleted as soon as you stop sharing. Your location history is kept for up to 30 days and then deleted automatically; you can delete all of it yourself at any time.
- Deleting your account removes your profile, memberships, messages, DMs, settings, push subscriptions, friendships, and all location data.
- What survives account deletion: moderation records (reports, warnings, bans) and audit-log entries, which keep a snapshot of the username involved but are detached from the deleted account. If your account was blocked for being under 16, we retain the email address to prevent re-registration until eligibility.
09Security
All traffic to the Service is encrypted in transit (HTTPS/WSS). Passwords are hashed with bcrypt and never stored in plain text. Administrative access is restricted to designated staff and every administrative action is recorded in an audit log that cannot be edited. No system is perfectly secure — if we ever discover a breach affecting your personal data, we will notify you as required by law.
10Minors
Translocate is not for children under 16. We collect your date of birth at signup to enforce this: accounts under 16 are fully blocked from the Service, and users aged 16–17 are automatically prevented from joining or viewing communities and channels marked 18+. Location sharing is restricted further still: it is available only to members aged 18 and over, and the daily age check switches it off for anyone who is not. If you believe a child under 16 is using Translocate, email [email protected] and we will act on it.
11Your rights
Wherever you live, we extend the same rights to everyone:
- Access & portability — ask us what data we hold about you and get a copy.
- Correction — fix inaccurate account data (most of it you can edit yourself in User Settings).
- Deletion — request deletion of your account and data (see Retention for the narrow exceptions).
- Objection — object to a use of your data you think is improper.
To exercise any of these, email [email protected] from the address on your account. We'll respond within 30 days. Depending on where you live (e.g. the EU/EEA, UK, or California), you may also have the right to complain to your local data-protection authority.
12Changes to this policy
If we change what we collect or how we use it, we'll update this page and its "Effective" date, and give notice in the app or by email for anything material. We won't quietly start doing something this policy says we don't do.
13Contact
Translocate is operated by Sterango, based in the United States. For anything privacy-related, email [email protected].
Translocate.