Privacy Policy

Last updated: 21 July 2026

Trunex is built on trust. We collect only what is necessary to operate the network. We do not sell your data, we show no advertising, we use no advertising identifier and no third-party analytics SDK, and we do not share your information with anyone for commercial purposes.

1. Who we are

Trunex is a private, invitation-only network that connects trusted people worldwide. The service, the mobile apps and trunex.app are operated by:

SC Trunex SRL is the data controller for all personal data described in this policy, within the meaning of the EU General Data Protection Regulation (GDPR) and Romanian Law 190/2018.

For any privacy request — access, correction, deletion, portability, objection — write to privacy@trunex.app. We answer within 30 days. We have not appointed a Data Protection Officer; the address above reaches the person responsible for data protection.

2. What data we collect

2.1 Account and identity

2.2 Location

Location fuzzing. Your exact coordinates are never shown to another member. Before any position leaves our servers for the map, it is displaced by a pseudo-random offset of roughly 200–300 metres. The offset is deterministic for a given member and a given day, so your pin does not jitter while you are being looked at, and it changes direction every day so that repeated observation cannot average the noise away. Anonymous visitors who have no account see the same fuzzed pins and nothing else — no name, email, phone or exact position.

2.3 Emergency (SOS)

When you trigger an SOS, and only then, we transmit your precise, unfuzzed coordinates and your phone number to the members alerted to help you, and we make them visible to our safety team. That is the entire point of the feature. An SOS also creates a group conversation with the responders. Nothing in the SOS path runs unless you deliberately trigger it. SOS is unavailable to visitors without an account.

2.4 Content you create

2.5 Contact discovery (opt-in, hashed)

If you want to check whether people you know are on Trunex, you type or paste phone numbers into the app. The app has no access to your address book — no contacts permission is requested and no contacts plugin is installed. The numbers you type are converted into irreversible SHA-256 hashes on your device and only the hashes are sent to us, compared against hashes of registered numbers, and discarded. We never store your typed list.

2.6 Notifications

To send you push notifications we store a push registration for each device you allow. In the mobile apps this is a device token issued by Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS). In the web app it is a Web Push subscription (endpoint plus encryption keys) issued by your browser vendor. A push registration identifies a device installation, not a person, and we delete it when you sign out, revoke the permission or delete your account.

2.7 Technical and security data

We use no advertising identifier (no Android Advertising ID, no Apple IDFA), no advertising SDK, and no third-party analytics or tracking SDK. We do not track you across other companies' apps or websites.

3. Why we use it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Create and run your account; show your profile to other membersName, email, profile, activityContract — 6(1)(b)
Verify that a new member is a real, unique personPhone number, SMS codeContract — 6(1)(b); legitimate interest in preventing fraud — 6(1)(f)
Show you on the map and show you nearby membersFuzzed location, statusConsent for the device permission — 6(1)(a); contract for the feature — 6(1)(b)
Emergency assistance (SOS)Precise location, phone numberVital interests — 6(1)(d); consent by triggering — 6(1)(a)
Deliver messages and notificationsMessage content, push registrationContract — 6(1)(b)
Record and store your ridesGPS track, ride photosConsent — 6(1)(a); you start each recording
Contact discoveryPhone-number hashesConsent — 6(1)(a)
Transactional email and, if you opt in, the weekly digestEmail, activityContract — 6(1)(b); consent for the digest — 6(1)(a)
Take payment and grant what you boughtPurchase record, receipt idContract — 6(1)(b); legal obligation for accounting — 6(1)(c)
Detect and stop abuse, spam and fraud; handle reports and blocksSecurity logs, reportsLegitimate interest — 6(1)(f)
Keep the app stable — diagnose and fix crashes and errorsDiagnostic and crash dataLegitimate interest — 6(1)(f)

Where the basis is consent you may withdraw it at any time — revoke the permission in your device settings, or turn the feature off in the app — without affecting anything we did before you withdrew it.

We do not use your data for advertising, for profiling with legal effect, or for sale to third parties. Messages and content are screened automatically for fraud, scam and abuse (using Anthropic's Claude as our processor — see §4); this screening only flags content for a person to review. We take no automated decision that produces a legal effect on you; suspensions after a report are reviewed by a person.

4. Who we share your data with

We share the minimum necessary with the processors that make the service work. Each acts on our instructions under a data-processing agreement, or as an independent controller where indicated.

ProviderWhat it processesWhere
CloudflareHosting, application logic, database (Workers + KV), backup storage, DDoS protection. All account data lives here.Global edge, EU included
ResendTransactional email delivery — your email address and the message body.US / EU
TwilioSMS delivery for phone verification and invitation texts — the destination number and the message.US / EU
StripeCard payment for donations and purchases made on the website. Stripe is an independent controller for payment data. Purchases made inside the mobile apps do not go through Stripe.US / EU
Apple (App Store, APNs)In-app purchases and subscriptions on iOS, purchase receipt validation, and delivery of push notifications to your iPhone. Apple issues and holds the device push token.US / EU
Google (Google Play, Firebase Cloud Messaging)In-app purchases and subscriptions on Android, purchase receipt validation, and delivery of push notifications to your Android device. Google issues and holds the device push token.US / EU
MapboxMap tiles, map styles and fonts. When the map is on screen your device requests tiles directly from Mapbox, so Mapbox receives your device's IP address and the area of the map you are looking at. It does not receive your account, your name or your precise position.US
OpenStreetMap Foundation (Nominatim)Converting a typed place name into coordinates, and coordinates into a place name for a shared location. It receives the place name or the coordinate, nothing about you.EU
Anthropic (Claude)Automated safety screening of messages and content for fraud, scam and abuse detection. Message content is sent transiently for classification and is not used to train models. Acts as our processor under a data-processing agreement.US

Transfers outside the European Economic Area are covered by the European Commission's Standard Contractual Clauses or by an adequacy decision, as applicable to each provider.

We also disclose data when we are legally obliged to — a valid order from a competent authority — or when it is strictly necessary to protect someone's life or safety.

5. How long we keep it

DataRetention
Account and profileWhile the account exists. Deleted when you delete the account.
Direct messagesDeleted automatically 72 hours after the last message in the conversation. A background job runs every hour and enforces this; you and the other person are warned by notification about an hour before. Either of you can raise or lower the window for that conversation in its settings — the shorter of the two choices always wins. Either of you can also delete the conversation immediately, which removes it for both. If either account is suspended, the conversation is deleted at once.
SOS group conversations72 hours after the SOS was triggered, then deleted automatically by the same job.
Rides (tracks and ride photos)Until you delete the ride or your account. Rides are not auto-deleted.
Stories, comments, ratings, business listingsUntil you delete them or your account.
Push registrationsUntil you sign out, revoke the permission, uninstall, or delete your account.
Pending invitations you sentUntil used or expired; deleted with your account.
Security and audit logs, security alerts, blocked-invite attempt records, moderation reports90 days.
Record that an account was deleted2 years, as an irreversible hash of the email address and nothing else. It stops a removed invitation being recycled and proves the deletion was carried out.
Payment and accounting recordsAs required by Romanian accounting and tax law.

6. Deleting your account and your data

You can delete your account yourself, and you do not need to contact us:

Deletion removes your profile and photo, every location we hold for you, your conversations and your messages inside other people's threads, your rides and their photos, your stories and comments, your business listing and recommendations, your ratings, your invitations, your group memberships, your notifications, your push registrations and your sessions on every device. It is immediate and it cannot be undone.

Three things survive, for the reasons given in §5: the hashed record that the account was deleted, anything a safety or moderation decision rests on (reports about you, and SOS records other people were part of), and payment records held as accounting documents by us, our accountant, and Apple, Google or Stripe.

You do not have to delete the whole account to delete something. In the app you can remove a single conversation, ride, story, rating, business listing or your stored position, and each removal is immediate on our servers.

7. Your rights

If you are in the European Union or the United Kingdom you have the right to:

Write to privacy@trunex.app from your account address. We respond within 30 days. If you believe we have handled your data badly you may complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority in your own country.

8. Browsing without an account

You can install the app and look around as a guest without creating an account. A guest sees heavily approximated map pins with no identity attached, public stories and the business directory. A guest cannot message anyone, cannot trigger an SOS, does not appear on the map and has no profile. We store no account for a guest; we log only the technical request data described in §2.7 for rate limiting and abuse prevention.

9. Security

Data is stored on Cloudflare's infrastructure with encryption in transit (TLS) and at rest. Phone numbers are additionally encrypted with a key held only by the application. Sessions are bearer tokens with a limited lifetime; sign-in is rate-limited and unusual activity raises an internal security alert. Access to member data by our team is restricted, authenticated and logged. Payments are handled entirely by Apple, Google or Stripe — Trunex never stores card numbers or payment credentials.

No system is perfect. If a breach is likely to put you at risk, we will notify the supervisory authority within 72 hours and tell you directly.

10. Children

Trunex is for adults. It is not intended for anyone under 18 and we do not knowingly collect personal data from children. If you believe a minor has registered, write to privacy@trunex.app and we will remove the account.

11. Changes to this policy

We may update this policy. When we do we update the "Last updated" date above, and for any change that materially affects you we notify active members by email or in-app notification before it takes effect.

12. Contact