Privacy
A marketing-level explanation of how Signal handles your data. The full Privacy Policy is the binding legal document.
Privacy Policy
Last updated: 6 September 2026
This revision records the product decision (Variant A of the 2026-09-06 privacy review): nearby observers see the post owner's display_name + avatar_url + a 15°-quantized direction + a whole-meter distance + the post text + the time until expiration. Precise coordinates, exact azimuth, and background location remain unshared. See § 1.7 and § 2.1.
This Privacy Policy explains what data we collect when you use Status, why we need it, how we use it, who we may share it with, and what rights you have.
1. What data we collect
1.1 Profile
We may collect and process:
- display name;
- profile image URL;
- short bio;
- user identifier;
- data required for authentication and account operation.
If you sign in with Google, some profile data may be provided to us by Google according to your selected settings and permissions.
1.2 Geolocation
Status uses geolocation for the radar to work.
When you create an active post, the app receives data about your current location, including:
- coordinates;
- location accuracy;
- timestamp of the location fix.
Status does not track your location in the background.
Geolocation is used to operate features related to displaying users near you.
We do not show your precise coordinates to other users. Other users only see derived data — an approximate direction and the distance in whole meters.
1.3 Posts
If you create a post on the radar, we process:
- the post text;
- the time of creation;
- the expiration time;
- the post's visibility parameters;
- technical data required to display it and to operate Status features.
The post may be visible to other users according to the radar's settings and operation rules.
1.4 Reactions
If you send a 👋 reaction to another user, we store the fact of the reaction and the information needed to deliver the notification to the recipient.
The recipient can see your profile in connection with this reaction.
The recipient does not receive your precise coordinates through the reaction.
1.5 Blocks and reports
If you block a user or report a violation, we may store the information needed to:
- apply the block;
- prevent unwanted contact;
- review the report;
- ensure user safety;
- prevent abuse and circumventing restrictions.
1.6 Push notifications
If you have allowed push notifications, we may store the device push token and related technical data needed to deliver notifications.
Push notifications are used, in particular, to notify about reactions and other supported Status features.
You can disable push notifications in your device settings.
1.7 What other users see on the radar
When you publish a post, nearby users within the radar's 1 km radius see:
- your display name;
- your profile picture (or the initial circle if you have no avatar);
- the post text you chose to publish;
- the approximate direction to you, rounded to a 15° sector (a 24-sector compass);
- the distance to you, shown in whole meters;
- the time remaining until your post expires.
Other users never see:
- your precise coordinates;
- your exact bearing (a 15° sector is the most precise direction we expose);
- your background location (Status does not collect it);
- any data tied to a deleted or stopped post (the radar stops showing your post and your identity the moment you stop it or it expires).
The identity surface (display name + profile picture) is shown only while your post is active. As soon as you stop the post or it expires, your name and picture disappear from every nearby radar within one refresh cycle.
If you block another user, or they block you, neither of you sees the other on the radar. If you report a post, that post is hidden from your nearby list on the next refresh. See § 1.5.
1.8 Local cache of nearby radar posts
To show nearby radar activity when your device is offline or the network is slow, the app may store a small, short-lived cache of nearby radar posts on your device. The cache:
- is per-user (each sign-in uses its own cache);
- lives only on your device and is not synced to the server;
- contains only the minimum fields needed for offline display: the post identifier, its expiration time, the post text, the distance to you (whole meters), the approximate direction (rounded to a 15° sector), and the time the entry was fetched;
- does NOT contain your precise coordinates, the post author's precise coordinates, the post author's display name, profile picture, or user identifier;
- expires automatically no later than 24 hours after the entry was cached, and is removed immediately if the underlying post has expired;
- is cleared when you sign out and when you delete your account.
The cache is read-only stale data. Posts from the cache are labelled as potentially outdated in the interface and cannot be used as proof that a post is currently active.
2. How we use the data
We use the data only to the extent necessary to operate Status, ensure safety, and meet our legal obligations.
2.1 For the radar
Geolocation is used to determine which users and posts are in the relevant area around you.
Your raw coordinates are not shared with other users.
Instead, the server may provide the data needed for visual display on the radar, for example:
- your display name and profile picture (so other users can recognize you while your post is active);
- approximate direction;
- distance;
- post text and time until expiration.
Direction is shown approximately, and distance is shown in whole meters.
2.2 For displaying your profile
Profile data is used to display your profile in the relevant Status interfaces.
2.3 For posts
Your posts are used to display them to other users according to Status's mechanics and the selected post parameters.
2.4 For reactions and notifications
We use reaction data to process the reaction and deliver the corresponding notification to the recipient.
2.5 For safety
We may use data to:
- detect abuse;
- prevent spam;
- apply blocks;
- investigate reports;
- protect users;
- ensure service safety and stability;
- prevent fraud and circumventing restrictions.
2.6 For legal compliance
We may process and retain certain data when necessary to meet legal obligations, protect our rights, or prevent abuse.
3. Precise location data
Geolocation is an important part of how Status works.
We aim to minimize its use:
- geolocation is used only for the Status features that require it;
- background location tracking is not used;
- your precise coordinates are not shown to other users;
- derived data, such as direction and distance, is used to display users;
- after an active post ends, its display stops according to Status's mechanics.
Do not post through Status information that reveals your exact home address or other sensitive location.
4. Who we may share data with
We do not sell your personal data.
We also do not share it with third parties for their own advertising or data sales.
However, for Status to operate, certain data may be processed by service providers acting within the services they provide to us.
4.1 Supabase
We use Supabase for infrastructure, including authentication, the database, and related server-side functions.
4.2 Google
If you use Google sign-in, Google processes the relevant data according to its own privacy policy.
4.3 Push notification services
To deliver push notifications, the relevant infrastructure services may be used, including Expo and Apple/Google system services such as APNs and FCM.
4.4 As required by law
We may disclose data to government authorities, courts, or other authorized parties when such disclosure is required by law or necessary to protect the rights, safety of users, or the service.
5. International data transfer
Some infrastructure and service providers may process data outside your country or region.
If such transfer falls under applicable data protection law requirements, we use the safeguards provided by law.
6. Where the data is stored
Status's main data is stored in the infrastructure of the cloud service providers we use.
In addition, a short-lived local cache of nearby radar posts is stored on your device (see § 1.8). The cache lives in the app's local storage on your device. Whether the cache is included in your device's automatic backups (such as Android Auto Backup or iCloud / iTunes backups) depends on your operating system and device settings; Status verifies this behaviour on each release.
If specific regional storage restrictions apply to a particular type of data or service, we aim to comply with the relevant contractual and technical requirements.
The specific storage region may depend on the infrastructure used and the service configuration.
7. How long we keep the data
We keep personal data no longer than necessary for the relevant purpose, unless a longer period is required by law or needed to protect our legitimate interests.
7.1 Active posts
An active post exists until the selected expiration time, or until you stop it earlier.
7.2 Reactions and notifications
Reactions and notification data may be kept for a limited period required for the corresponding features to operate, after which it is deleted or anonymized according to the established retention schedule.
7.3 Blocks
Block information may be kept until you lift the block, or longer if necessary for safety, preventing abuse, or meeting legal obligations.
7.4 Account data
Account data is kept until you delete your account, unless longer retention is required or permitted by law.
Some technical data may be kept in backups or system logs for a limited period after deletion and then removed as part of the standard retention cycle.
7.5 Local cache of nearby radar posts
Each cache entry expires no later than 24 hours after it was stored. Entries whose underlying post has expired are removed at the next read regardless of how much of the 24-hour window remains. The cache is also cleared when you sign out and when you delete your account.
8. Account deletion
You can delete your account via:
Profile → Delete account
After deletion is confirmed, we delete or anonymize the data associated with the account in accordance with our deletion procedure.
Local cache of nearby radar posts (see § 1.8) is cleared as part of the deletion. Cache entries that the deleted account had written about other users are removed at the same time, because they are keyed by the deleted account's identifier.
Account deletion may be irreversible.
Some data may be retained after deletion when necessary:
- to meet legal requirements;
- to prevent fraud and abuse;
- to resolve disputes;
- to protect rights and safety;
- in backups until the end of their standard retention period.
9. Your rights
Depending on your country or region of residence, you may have the right to:
- request access to your personal data;
- request correction of inaccurate data;
- request deletion of data;
- request restriction of processing;
- object to certain types of processing;
- receive a copy of certain data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with the competent data protection authority.
The scope of these rights depends on the applicable law.
9.1 Geolocation
You can limit or revoke Status's access to geolocation through your operating system settings.
If you disable the permission, features that require location may stop working.
Disabling the location permission does not by itself delete the local cache of nearby radar posts (see § 1.8). Cached entries remain on the device until the 24-hour TTL expires, until you sign out, or until you delete your account. While location is disabled, cached posts are not re-rendered as active; they remain on disk but are filtered out at the moment the app would hydrate them, because there is no current observer location to match against.
9.2 Push notifications
Push notifications can be disabled in your device settings.
9.3 Account
You can delete your account directly in the app.
To exercise other rights, contact us using the details in the "Contact" section.
10. Children
Status is intended for users 18 and older only.
We do not allow Status to be used by anyone under 18 and do not knowingly collect personal data from minors.
If you believe a minor has created an account or provided us with personal data, contact us.
11. Security
We apply reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.
However, no method of storage or transmission over the internet can guarantee absolute security.
12. Changes to this Privacy Policy
We may periodically update this Privacy Policy.
For significant changes, we may notify you through the app or by other appropriate means.
The date of the last update is shown at the top of this page.
13. Contact
For questions about privacy and personal data processing, see the operator contact details listed in the app’s account settings under Help → About this app → Legal.
Operator contact details (legal entity name, privacy email, postal address) are pending operator input. The contact section is rendered without those fields until the operator fills them in. See AGENTS.md §«Legal documents — operator contact fields».
If a Data Protection Officer (DPO) is appointed, their contact details will be added to the same Help section.