1. Information We Collect
- Access logs: a hash of a device-generated identifier, source IP address, timestamp, and sector number. Retained for 180 days.
- Location: your latitude and longitude are sent to the server during the entrance procedure only. See section 5.
- Push notification token: only if you enable notifications.
- Encrypted posts: end-to-end encrypted; we cannot decrypt them. Permanently deleted 24 hours after posting.
2. Why We Retain Access Logs
For the operator's legal defense. Retention is 180 days. Access logs are retained for this period even after you delete your data.
3. What We Do Not Collect
We do not collect your name, email address, phone number, or contact list. There is no account registration. We use only a randomly generated device identifier.
4. Posts
Posts are end-to-end encrypted with MLS; the server relays ciphertext only. The operator cannot decrypt them. They are physically deleted from server and device 24 hours after posting.
5. Location
Joining a sector requires confirming that the person inviting and the people joining are physically near each other. Solely for that confirmation, your latitude and longitude are sent to the server during the entrance procedure.
- The inviting device's coordinates are stored as part of the entrance record for 5 minutes, then discarded automatically.
- The joining devices' coordinates are used only to compute the distance and are not stored. Only the resulting distance (in meters) and the ultra-wideband (UWB) distance reported by the device (in centimeters) are kept.
We never use location to show you on a map, build a movement history, or target advertising. Location is not accessed outside the entrance procedure.
6. Reporting
When you report a sector, the conversation for that sector stored on your device — including posts written by other participants — is sealed and sent to the developer for review. The sealing uses public-key encryption; the server cannot read the contents. Only the developer can decrypt it locally. Reports are anonymous to other participants.
Reported data is retained as a record of the moderation decision. It is not deleted automatically, so no maximum retention period is set.
7. Deleting Your Data
You can delete this device's data from the app's settings screen. This deletes all data on the device (posts, encryption keys, identifier) and, on the server, your KeyPackages and push notification registration. Access logs are retained as described in section 2, and reported data as described in section 6.
8. Third Parties
We do not share your data with third parties except as required by law.