Privacy Policy
Overview
Opaloc is built on a single principle: your location data never reaches our servers. Not encrypted. Not anonymised. Not temporarily. Never.
This policy explains what information Opaloc does collect (which is very little), how it is used, and who it is shared with.
Opaloc is a peer-to-peer location sharing application for Android. Location data is exchanged directly between the devices of connected users โ via Bluetooth when nearby, or via an encrypted WebRTC channel when apart. At no point does location data pass through or reside on Opaloc infrastructure.
What we collect
Opaloc collects and stores the following information:
Display name and profile photo (optional)
Stored exclusively on your device using encrypted local storage. Never transmitted to Opaloc servers. Shared with your connected peers directly, device-to-device, so they can identify you on the map.
A locally generated anonymous user ID
A random identifier created on your device the first time you open the app. Used to derive Bluetooth service identifiers and WebRTC session tokens. Never linked to your identity, email, or any external account. Never transmitted to Opaloc servers in a personally identifiable form.
Subscription and purchase data
Managed by RevenueCat on our behalf. See Third-party services below.
Opaloc does not collect:
- Email address
- Phone number
- Location data of any kind on any server
- Your list of connections or groups
- Usage analytics or behavioral telemetry
- Advertising identifiers
- Device model, OS version, or crash reports
Location data
Your device's GPS location is accessed by the app while you are sharing your location with connected peers. This data:
- Is transmitted directly to connected devices โ not through Opaloc servers
- Is encrypted in transit using standard WebRTC DTLS or Bluetooth GATT encryption
- Is stored only on the receiving device, in local app storage, for up to 24 hours
- Is never logged, retained, or viewable by Opaloc
When a connection is removed, the associated location history is deleted from both devices. Opaloc has no copy to delete because it was never stored on our systems.
The app accesses location in the background to keep your position updated for people you are sharing with. You control this permission through your device's system settings. Revoking background location access pauses sharing; it does not affect stored data.
Third-party services
Opaloc uses the following third-party services, each of which operates under its own privacy policy:
RevenueCat
Manages in-app subscriptions and purchase verification. RevenueCat receives your app store transaction data (purchase history, subscription status, and a pseudonymous app user ID). RevenueCat does not receive your location data, display name, photo, or connection list. See RevenueCat's Privacy Policy.
Stadia Maps
Provides map tiles displayed inside the app. When the map is visible, your device fetches tiles from Stadia Maps' servers. Stadia Maps does not log IP addresses and does not use tile requests for tracking or advertising. See Stadia Maps' Privacy Policy.
Opaloc signaling server
When establishing a long-range connection with a peer, both devices exchange encrypted WebRTC handshake messages through an Opaloc-operated signaling server. This server:
- Stores only a short-lived random session token (an opaque string with no personal data), deleted within 48 hours
- Never receives, processes, or stores location data
- Does not log IP addresses beyond what standard server infrastructure requires for security purposes
Once a WebRTC connection is established, all location data flows directly between devices and the signaling server is no longer involved.
Data retention
Because Opaloc stores almost nothing on our servers, most data retention decisions are yours to make.
On-device data (display name, photo, connection list, location history) is held until you remove a connection, clear app data, or uninstall the app. Signaling tokens expire after 48 hours regardless of whether a connection was established.
RevenueCat retains purchase records in accordance with their own retention policy and applicable financial regulations.
You can delete all data associated with your Opaloc account by removing the app. Because no personal data is held on Opaloc's servers, there is nothing on our side to delete.
Children
Opaloc is rated 17+ / Mature on app stores. We do not knowingly collect information from children under 13. If a parent or guardian believes their child has used the app, contact us at the address below and we will assist with removal of any locally stored data.
Family plans support supervised accounts for minors. A parent or account owner has administrative visibility over connections for supervised users on their plan.
Your rights
Depending on where you live, you may have rights including access to, correction of, or deletion of personal data. Because Opaloc holds almost no personal data on its servers, most of these rights are exercised directly on your device.
For subscription and purchase data held by RevenueCat, contact them directly or reach out to us and we will assist.
For questions about any data Opaloc may hold, contact us at our contact page.
Changes to this policy
If this policy changes in a material way, we will update the effective date at the top and note the changes in the app. Continued use of Opaloc after a policy update constitutes acceptance of the revised terms.
Contact us
Privacy questions and requests can be sent through our contact page. We aim to respond within 5 business days.