Transponder Privacy Policy

Last updated: January 12, 2026

Transponder is a location sharing app designed with privacy as a core principle. This policy explains what data we collect, how it's protected, and your rights.

Summary

Data We Collect

Location Data

How it's used: Shared with friends you choose, displayed on the map.

How it's protected: Encrypted on your device using AES-256-GCM before transmission. The server only stores encrypted data it cannot decrypt.

Identity Information

How it's used: Your display name is shared with friends via friend links. Your public key identifies you in the system.

How it's protected: Display name is stored locally. Cryptographic keys are stored in secure device storage (iOS Keychain / Android Keystore).

Friend List

How it's used: Determines who can see your location and whose location you can see.

How it's protected: Stored locally on your device only.

Data We Do NOT Collect

How Encryption Works

Transponder uses end-to-end encryption, meaning your location is encrypted on your device before it ever leaves your phone.

  1. Key Generation: When you create your identity, cryptographic keys (Ed25519 and X25519) are generated on your device
  2. Encryption: Your location is encrypted with AES-256-GCM using keys derived from your friends' public keys
  3. Transmission: Only encrypted data is sent to the server
  4. Decryption: Only friends with the matching private keys can decrypt your location

The server never has access to your unencrypted location data.

Data Storage

On Your Device

DataStorage Method
Private keysiOS Keychain / Android Keystore (hardware-backed when available)
Display nameiOS UserDefaults / Android SharedPreferences
Friends listLocal JSON file
Cached friend locationsLocal storage

On Servers

Third-Party Services

Maps

Maps are display-only. Your location data is not sent to mapping services.

No Other Third Parties

We do not use analytics services, crash reporting, advertising networks, or social media SDKs.

Data Sharing

Your location is only shared with:

We do not sell, rent, or share your data with any third parties for marketing or advertising purposes.

Data Retention

On Device

On Server

Your Rights

Access & Deletion

Opt-Out

Background Location

If you enable "Always Allow" location permission:

Background location is optional and only used if you enable automatic sharing.

Security

Self-Hosting

Transponder supports self-hosted servers. If you run your own server, you control all server-side data and retention policies.

Children's Privacy

Transponder is not intended for children under 13. We do not knowingly collect data from children.

Changes to This Policy

We may update this policy from time to time. Significant changes will be noted in app updates.

Contact

For privacy questions or data requests, contact: privacy@bentley.sh

Open Source

Transponder is open source software. The source code for the iOS app, Android app, and server is available upon request. Contact us if you'd like to review or audit the code.