Account privacy
Lotra
Effective June 22, 2026
Privacy Policy
This Privacy Policy explains how Lotra collects, uses, shares, retains, and deletes data for account, group, live location, messaging, and SOS features.
Data we collect
We collect account information such as your email address, display name, Firebase user ID, profile details, group memberships, group roles, preferences, and account deletion request metadata.
When Live Location is enabled, Lotra collects precise location coordinates, accuracy, heading, timestamps, and related live location status so active group members can see your current or last known location. Background location may be used only after you grant the required device permission and enable Live Location.
We collect messages you send, chat participation metadata, group activity, SOS events, notification records, Expo push tokens, and operational data needed to provide safety, messaging, group, and notification features.
We may collect crash reports, diagnostic logs, sanitized map telemetry, app version, build/runtime tags, platform, and error details to keep the app reliable. Sentry is configured not to send default personal information, screenshots, view hierarchy, automatic network breadcrumbs, or session replay.
Data we do not collect
Lotra does not collect contacts, microphone recordings, stored QR camera images or videos, advertising identifiers for tracking, or payment data. Camera access is used to scan group invitation QR codes and is not used to store photos or videos.
How we use data
We use data to authenticate accounts, show profile names, manage groups, share live location with active group members when enabled, send SOS and notification updates, deliver chat messages, process account deletion requests, prevent abuse, troubleshoot errors, and maintain service reliability.
How data is shared
Live Location, group membership, display names, SOS records, and messages are shared with active members of the relevant group or chat as needed for app functionality. We do not sell personal data or use it for cross-app advertising tracking.
We use service providers to operate the app: Firebase and Google Cloud for authentication, database, functions, hosting, storage, and push-related infrastructure; Google Maps and Directions for map and routing features; Sentry for diagnostics; and Resend for account deletion emails. These providers process data for app functionality, security, diagnostics, or communications.
Location controls
Live Location is optional and can be paused from Settings. If Live Location is paused, the app stops writing shared coordinates and group members can no longer access new live updates from you. Device-level location permissions can also be changed in system settings.
Account deletion
You can delete your account in the app from Settings > Danger Zone > Delete Account, or use the public deletion page if you no longer have the app installed. The public page is available at /delete-account.
Account deletion removes or anonymizes your account, profile, public profile, group memberships, live location records, notification data, push tokens, and user-attributed SOS references where applicable. Groups you own may be transferred to another active member or deleted if no other active member exists.
Messages sent by a deleted account are replaced with the tombstone text "Message deleted" and shown as coming from "Deleted user" so remaining chat participants keep conversation continuity without retaining the deleted account's message text or identity.
Retention
We retain data while your account is active and as needed to provide the app. After deletion, some limited records may be retained only where required for security, fraud prevention, operational logs, legal compliance, or to prove that a deletion request was processed.
| Data category | Retention default |
|---|---|
| Account, profile, group membership, and location data | Deleted on account deletion where applicable. |
| Deleted-user messages | Sender is anonymized and message text is replaced with "Message deleted". |
| External deletion requests | Unverified, expired, no-account, rate-limited, and failed records are retained up to 30 days. Processed scrubbed audit records are retained up to 90 days. |
| SOS precise location | Stripped after 24 hours; non-location SOS metadata is retained up to 30 days. |
| In-app notifications | Retained up to 90 days. |
| Push tokens | Deleted on account deletion, invalid-token detection, or after 180 days without refresh. |
| Operational logs and diagnostics | Cloud Logging default logs target 30 days or less; required Google Cloud audit logs may be retained by Google Cloud for 400 days. Sentry retention follows the active Sentry plan. |
Security
Data is transmitted using encrypted connections. Access to app data is restricted through Firebase Authentication, Firestore Security Rules, and trusted backend Cloud Functions for sensitive actions such as account deletion and group administration.
Contact
For privacy or support questions, contact support@lotra.app.