Last updated: 21 July 2026
Trunex is built on trust. We collect only what is necessary to operate the network. We do not sell your data, we show no advertising, we use no advertising identifier and no third-party analytics SDK, and we do not share your information with anyone for commercial purposes.
Trunex is a private, invitation-only network that connects trusted people worldwide. The service, the mobile apps and trunex.app are operated by:
SC Trunex SRL is the data controller for all personal data described in this policy, within the meaning of the EU General Data Protection Regulation (GDPR) and Romanian Law 190/2018.
For any privacy request — access, correction, deletion, portability, objection — write to privacy@trunex.app. We answer within 30 days. We have not appointed a Data Protection Officer; the address above reaches the person responsible for data protection.
Location fuzzing. Your exact coordinates are never shown to another member. Before any position leaves our servers for the map, it is displaced by a pseudo-random offset of roughly 200–300 metres. The offset is deterministic for a given member and a given day, so your pin does not jitter while you are being looked at, and it changes direction every day so that repeated observation cannot average the noise away. Anonymous visitors who have no account see the same fuzzed pins and nothing else — no name, email, phone or exact position.
When you trigger an SOS, and only then, we transmit your precise, unfuzzed coordinates and your phone number to the members alerted to help you, and we make them visible to our safety team. That is the entire point of the feature. An SOS also creates a group conversation with the responders. Nothing in the SOS path runs unless you deliberately trigger it. SOS is unavailable to visitors without an account.
If you want to check whether people you know are on Trunex, you type or paste phone numbers into the app. The app has no access to your address book — no contacts permission is requested and no contacts plugin is installed. The numbers you type are converted into irreversible SHA-256 hashes on your device and only the hashes are sent to us, compared against hashes of registered numbers, and discarded. We never store your typed list.
To send you push notifications we store a push registration for each device you allow. In the mobile apps this is a device token issued by Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS). In the web app it is a Web Push subscription (endpoint plus encryption keys) issued by your browser vendor. A push registration identifies a device installation, not a person, and we delete it when you sign out, revoke the permission or delete your account.
We use no advertising identifier (no Android Advertising ID, no Apple IDFA), no advertising SDK, and no third-party analytics or tracking SDK. We do not track you across other companies' apps or websites.
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account; show your profile to other members | Name, email, profile, activity | Contract — 6(1)(b) |
| Verify that a new member is a real, unique person | Phone number, SMS code | Contract — 6(1)(b); legitimate interest in preventing fraud — 6(1)(f) |
| Show you on the map and show you nearby members | Fuzzed location, status | Consent for the device permission — 6(1)(a); contract for the feature — 6(1)(b) |
| Emergency assistance (SOS) | Precise location, phone number | Vital interests — 6(1)(d); consent by triggering — 6(1)(a) |
| Deliver messages and notifications | Message content, push registration | Contract — 6(1)(b) |
| Record and store your rides | GPS track, ride photos | Consent — 6(1)(a); you start each recording |
| Contact discovery | Phone-number hashes | Consent — 6(1)(a) |
| Transactional email and, if you opt in, the weekly digest | Email, activity | Contract — 6(1)(b); consent for the digest — 6(1)(a) |
| Take payment and grant what you bought | Purchase record, receipt id | Contract — 6(1)(b); legal obligation for accounting — 6(1)(c) |
| Detect and stop abuse, spam and fraud; handle reports and blocks | Security logs, reports | Legitimate interest — 6(1)(f) |
| Keep the app stable — diagnose and fix crashes and errors | Diagnostic and crash data | Legitimate interest — 6(1)(f) |
Where the basis is consent you may withdraw it at any time — revoke the permission in your device settings, or turn the feature off in the app — without affecting anything we did before you withdrew it.
We do not use your data for advertising, for profiling with legal effect, or for sale to third parties. Messages and content are screened automatically for fraud, scam and abuse (using Anthropic's Claude as our processor — see §4); this screening only flags content for a person to review. We take no automated decision that produces a legal effect on you; suspensions after a report are reviewed by a person.
We share the minimum necessary with the processors that make the service work. Each acts on our instructions under a data-processing agreement, or as an independent controller where indicated.
| Provider | What it processes | Where |
|---|---|---|
| Cloudflare | Hosting, application logic, database (Workers + KV), backup storage, DDoS protection. All account data lives here. | Global edge, EU included |
| Resend | Transactional email delivery — your email address and the message body. | US / EU |
| Twilio | SMS delivery for phone verification and invitation texts — the destination number and the message. | US / EU |
| Stripe | Card payment for donations and purchases made on the website. Stripe is an independent controller for payment data. Purchases made inside the mobile apps do not go through Stripe. | US / EU |
| Apple (App Store, APNs) | In-app purchases and subscriptions on iOS, purchase receipt validation, and delivery of push notifications to your iPhone. Apple issues and holds the device push token. | US / EU |
| Google (Google Play, Firebase Cloud Messaging) | In-app purchases and subscriptions on Android, purchase receipt validation, and delivery of push notifications to your Android device. Google issues and holds the device push token. | US / EU |
| Mapbox | Map tiles, map styles and fonts. When the map is on screen your device requests tiles directly from Mapbox, so Mapbox receives your device's IP address and the area of the map you are looking at. It does not receive your account, your name or your precise position. | US |
| OpenStreetMap Foundation (Nominatim) | Converting a typed place name into coordinates, and coordinates into a place name for a shared location. It receives the place name or the coordinate, nothing about you. | EU |
| Anthropic (Claude) | Automated safety screening of messages and content for fraud, scam and abuse detection. Message content is sent transiently for classification and is not used to train models. Acts as our processor under a data-processing agreement. | US |
Transfers outside the European Economic Area are covered by the European Commission's Standard Contractual Clauses or by an adequacy decision, as applicable to each provider.
We also disclose data when we are legally obliged to — a valid order from a competent authority — or when it is strictly necessary to protect someone's life or safety.
| Data | Retention |
|---|---|
| Account and profile | While the account exists. Deleted when you delete the account. |
| Direct messages | Deleted automatically 72 hours after the last message in the conversation. A background job runs every hour and enforces this; you and the other person are warned by notification about an hour before. Either of you can raise or lower the window for that conversation in its settings — the shorter of the two choices always wins. Either of you can also delete the conversation immediately, which removes it for both. If either account is suspended, the conversation is deleted at once. |
| SOS group conversations | 72 hours after the SOS was triggered, then deleted automatically by the same job. |
| Rides (tracks and ride photos) | Until you delete the ride or your account. Rides are not auto-deleted. |
| Stories, comments, ratings, business listings | Until you delete them or your account. |
| Push registrations | Until you sign out, revoke the permission, uninstall, or delete your account. |
| Pending invitations you sent | Until used or expired; deleted with your account. |
| Security and audit logs, security alerts, blocked-invite attempt records, moderation reports | 90 days. |
| Record that an account was deleted | 2 years, as an irreversible hash of the email address and nothing else. It stops a removed invitation being recycled and proves the deletion was carried out. |
| Payment and accounting records | As required by Romanian accounting and tax law. |
You can delete your account yourself, and you do not need to contact us:
Deletion removes your profile and photo, every location we hold for you, your conversations and your messages inside other people's threads, your rides and their photos, your stories and comments, your business listing and recommendations, your ratings, your invitations, your group memberships, your notifications, your push registrations and your sessions on every device. It is immediate and it cannot be undone.
Three things survive, for the reasons given in §5: the hashed record that the account was deleted, anything a safety or moderation decision rests on (reports about you, and SOS records other people were part of), and payment records held as accounting documents by us, our accountant, and Apple, Google or Stripe.
You do not have to delete the whole account to delete something. In the app you can remove a single conversation, ride, story, rating, business listing or your stored position, and each removal is immediate on our servers.
If you are in the European Union or the United Kingdom you have the right to:
Write to privacy@trunex.app from your account address. We respond within 30 days. If you believe we have handled your data badly you may complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority in your own country.
You can install the app and look around as a guest without creating an account. A guest sees heavily approximated map pins with no identity attached, public stories and the business directory. A guest cannot message anyone, cannot trigger an SOS, does not appear on the map and has no profile. We store no account for a guest; we log only the technical request data described in §2.7 for rate limiting and abuse prevention.
Data is stored on Cloudflare's infrastructure with encryption in transit (TLS) and at rest. Phone numbers are additionally encrypted with a key held only by the application. Sessions are bearer tokens with a limited lifetime; sign-in is rate-limited and unusual activity raises an internal security alert. Access to member data by our team is restricted, authenticated and logged. Payments are handled entirely by Apple, Google or Stripe — Trunex never stores card numbers or payment credentials.
No system is perfect. If a breach is likely to put you at risk, we will notify the supervisory authority within 72 hours and tell you directly.
Trunex is for adults. It is not intended for anyone under 18 and we do not knowingly collect personal data from children. If you believe a minor has registered, write to privacy@trunex.app and we will remove the account.
We may update this policy. When we do we update the "Last updated" date above, and for any change that materially affects you we notify active members by email or in-app notification before it takes effect.