Effective date: September 1, 2026
App name: Lociro
Data controller/service provider: Ashlee Heiston, an individual developer
Ashlee Heiston, an individual developer (“Lociro,” “we,” “us,” or “our”), respects your privacy. This Lociro Privacy Policy (the “Policy”) explains how we collect, use, disclose, retain, and protect personal information when you use the Lociro mobile application, related websites, and services (collectively, the “Service”), and how you may exercise your privacy rights.
The Service’s core features involve ongoing, precise location data. Please read this Policy carefully before granting location permission, adding a friend, or accepting an invitation, particularly the sections titled “How Location Sharing and Place Alerts Work,” “Information We Process,” “Data Retention and Deletion,” and “Your Choices and Rights.”
1. Key Points
• No secret tracking. We provide new location information to a friend only when the device has granted location permission, the users have established a friend relationship, and the applicable sharing settings are enabled.
• Default effect of becoming friends. After you generate and share a valid Friend Code or accept a friend invitation, location sharing between you and that friend is enabled by default. The friend may create arrival or departure alerts associated with you, and you may not receive a new notice each time that friend later creates or edits an individual alert.
• You can stop at any time. You may pause all sharing, pause sharing with a specific friend, remove a friend, turn off iOS location permission, or delete your account.
• Up to 30 days of history. Location history includes only information generated while the sharing conditions were satisfied and is retained on a rolling basis for no longer than the most recent 30 days. The Service does not reconstruct a route for periods when sharing was paused or the required permission was unavailable.
• We do not sell location information. We do not sell personal information, use precise location for cross-context behavioral advertising, or provide location data to data brokers.
• An anonymous account is not anonymous data. Even though registration does not require a phone number or email address, the anonymous account ID, device credential, friend relationships, and location may still relate to you or your device and therefore constitute personal information.
• The Service is not for emergencies. Location information and arrival or departure alerts may be delayed, unavailable, or inaccurate and must not be the sole basis for an emergency, rescue, or personal-safety decision.
This summary does not replace the full Policy.
2. Scope of This Policy
This Policy applies to the Lociro Service that we control. Lociro is initially offered only in the United States and is not initially directed to the European Economic Area, the United Kingdom, or other markets outside the United States. Apple or any third-party service that you access independently may process information under its own privacy policy.
This Policy continues to apply when we display your location and related status to friends you designate. If a friend independently copies, screenshots, exports, or discloses information visible to them, we may not be able to control that person’s subsequent conduct.
3. Information We Process
The categories below describe the information involved in the current product design. Before release, this description must be compared with the final application code, SDKs, vendors, and actual data flows. Listing information here does not authorize us to collect information that the Service does not actually need.
3.1 Anonymous account and profile
• Information: Internal user ID, account status, Keychain recovery credential or the corresponding server-side identifier, default or custom nickname, and avatar or emoji.
• Main source: You, your device, and information we generate.
3.2 Precise location and movement status
• Information: Latitude and longitude, collection time, location accuracy, speed and direction if actually collected, source or permission status, last location, and sharing or pause time.
• Main source: Device Location Services after you grant permission.
3.3 Location history and routes
• Information: Location points generated during up to the most recent 30 days of active sharing, routes, starting and ending points, stays, data gaps, and display time in the viewer’s time zone.
• Main source: Derived from location records.
3.4 Friends and invitations
• Information: Friend Code, invitation link, generation, revocation, and expiration times, usage count, inviter and recipient profiles, friend-relationship ID, shared-space ID, friendship creation and deletion times, and global or friend-specific sharing status.
• Main source: You, your friends, and information we generate.
3.5 Places and alerts
• Information: Place name, searched or selected address, center coordinates, geofence radius, selected friend, arrival or departure rule, candidate and confirmed geofence status, and event type and time.
• Main source: Your input, Apple Maps/MapKit, and calculations based on location data.
3.6 Notifications
• Information: APNs device token, notification permission or preferences, notification type, delivery, failure, or open status if actually recorded, and notification destination.
• Main source: Your device, Apple, and information we generate.
3.7 Purchases and entitlements
• Information: Apple product ID, plan type, transaction or original transaction identifier, purchase, renewal, grace-period, expiration, refund, or revocation status, entitlement status, and price and currency if Apple provides them.
• Main source: Apple and you.
3.8 Device and technical data
• Information: IP address, device type, operating system, App version, language, time zone, network status, request time, logs, errors, crashes, and performance data.
• Main source: Your device, our servers, and diagnostic services.
3.9 Usage and analytics data
• Information: Impressions, taps, successes, failures, and duration events involving onboarding, invitations, maps, places, history, paywalls, and purchases, together with internal object IDs that do not directly identify you.
• Main source: Generated when you use the Service.
3.10 Support, safety, and rights requests
• Information: Name, email address, communications, screenshots, issue records, identity-verification information, complaints, and outcomes that you choose to provide.
• Main source: You and our support or safety process.
We do not place precise location, Friend Codes, or nicknames into a general-purpose product analytics platform. Analytics events involving friends and places should use internal relationship, shared-space, or place IDs, with appropriate access controls and deidentification.
The Service does not require access to your contacts or microphone and does not provide a chat feature. If we later add photo uploads, contact-based invitations, advertising tracking, or another feature not currently described, we will update the relevant disclosures before collection and obtain permission or consent where required.
4. How and Why We Use Information
Our principal purposes and legal grounds are described below. Depending on the circumstances and applicable law, more than one ground may apply.
• Creating, restoring, and maintaining an anonymous account. We use the account ID, Keychain-related credential, profile, and device information to perform our agreement and provide a service you request.
• Collecting precise location with your permission and sharing it with designated friends. We use precise location, permission and sharing status, friend ID, and shared-space ID based on your consent and to perform the location-sharing service you request.
• Generating location history, routes, and stays. We use location records, time, and sharing status based on your consent and to perform our agreement.
• Providing place search, geofencing, and arrival or departure alerts. We use places, location, friend relationships, and notification tokens based on your consent and to perform our agreement.
• Creating and managing friend relationships and invitations. We use profiles, Friend Codes or links, relationships, and status to perform our agreement and for our legitimate interest in preventing abuse.
• Sending service notifications. We use APNs tokens, nicknames, place names, events, and times to perform our agreement, in accordance with your notification permission, and for our legitimate interest in operating the Service.
• Processing purchases and membership entitlements. We use Apple transaction and entitlement data and account IDs to perform our agreement and comply with financial and consumer-protection obligations.
• Operating, troubleshooting, and improving the Service. We use device, log, crash, performance, and usage-event information for our legitimate interest in maintaining a secure and reliable Service and obtain consent where required.
• Preventing fraud, Friend Code enumeration, unauthorized access, and abuse. We use IP addresses, device information, invitations, relationships, and access and security logs for our legitimate interest in protecting users and the Service and to comply with legal obligations.
• Responding to support, complaints, and privacy requests. We use contact, verification, communication, and account information to perform our agreement, comply with legal obligations, and establish or defend legal claims.
• Complying with law, enforcing our Terms, and protecting rights. We use information relevant to the particular request or incident to comply with legal obligations, pursue legitimate interests, and establish or defend legal claims.
4.1 Location consent
You may decline iOS location permission. If you do, you may still be able to establish friend relationships and use limited features that do not depend on location, but you cannot upload or share your location in real time. You may withdraw location permission at any time through the sharing controls in the App or iOS Settings. Withdrawal does not affect processing that was lawful before withdrawal and does not automatically delete information that was lawfully created and remains within an applicable retention period.
If the Service uses background location, we will explain why in the operating-system permission notice and in the relevant in-App context. We do not repurpose location collected for friend sharing for advertising, data sales, or incompatible profiling unless we have another lawful basis and obtain new consent where required.
4.2 Legitimate interests
When we rely on a legitimate interest, we assess whether the processing is necessary and balance that interest against your rights, considering the sensitivity of the information, your reasonable expectations, and available safeguards. You may object as described in Section 11.
5. How Location Sharing and Place Alerts Work
5.1 Who can see your information
Only a user who has a valid friend relationship with you and passes the server-side authorization check for the corresponding two-person shared space may view the location that you share with that user through the Service. If multiple people use the same Friend Code to add you, those people do not automatically become friends with one another and do not gain access to one another’s locations merely because they used the same code.
5.2 Consent when a friend relationship is created
When you generate or share a Friend Code, the App explains that a person holding a valid code may directly become your friend and view the location you share. When you accept an invitation, the App explains the effect of establishing the friend relationship and sharing location, including that the other person may create arrival or departure alerts associated with you.
After a friend relationship is established, location sharing between the two users is enabled by default. Your authorization for place alerts continues after the friendship is established. You may not receive a new notice each time the other person later creates or edits a specific place rule, and you may not be able to disable only one alert created by that person. You can stop future location and place events by pausing all sharing, pausing sharing only with that friend, removing that friend, or turning off system-level location permission.
5.3 Pausing, deleting, and stale locations
• When you pause all sharing, no friend receives your new location.
• When you pause sharing with a specific friend, only that friend stops receiving your new location.
• After sharing is paused, the other person may continue to see the last location collected before the pause, its last-updated time, and the paused status until that information reaches the end of its retention period or the friend relationship is deleted.
• After you remove a friend or delete your account, the relevant users immediately lose access through the former relationship to your new location and history.
• Re-establishing a friend relationship creates a new relationship and shared space and does not restore or combine history from the former relationship.
• If a device is offline, permission is unavailable, or a location is stale, the App will use reasonable efforts to display the corresponding status rather than represent an old location as current.
5.4 Information in push notifications
A place-event notification may include a friend’s nickname, an arrival or departure status, a place name, and the event time. We design the Service not to display a precise street address in a lock-screen notification, but a user-defined place name may itself be sensitive. Use iOS notification settings to select a preview option appropriate for you.
6. How We Disclose Information
We do not sell personal information or share personal information for cross-context behavioral advertising. We disclose information only as described below.
6.1 Friends you designate
Depending on your sharing status, we may display your nickname, avatar, location, last-updated time, sharing or permission status, up to the most recent 30 days of history that the particular friend is authorized to access, and place events to a friend you designate. A friend may take a screenshot or otherwise retain information they can see. Establish friend relationships only with people you trust.
6.2 Service providers and platforms
Our currently identified service providers and platforms are:
Amazon Web Services, Inc. (AWS)
• Services and purposes: Cloud hosting, servers, databases, storage, content delivery, and security.
• Information it may process: Account information, friend relationships, precise location, places and alerts, purchase entitlements, logs, and other information needed to operate the Service.
• Processing location and rules: Primary storage is in AWS US East (N. Virginia), us-east-1, and processing is governed by applicable AWS data-protection and privacy terms.
Apple Inc. and relevant Apple entities
• Services and purposes: Apple Maps/MapKit map display, place search, and geocoding; App Store and StoreKit purchases; APNs; iOS Location Services; Keychain; and system sharing.
• Information Apple may independently process: Information necessary to provide its services, including map requests, searches, location, device and network information, Apple Account or transaction-related information, and push-notification information. Apple processes complete payment-card information; we do not receive it.
• Processing rules: Apple processes this information under its terms and privacy notices. For mapping information, see Apple Maps & Privacy (https://www.apple.com/legal/privacy/data/en/apple-maps/).
The Service uses only Apple Maps/MapKit for mapping and does not integrate Amap or another third-party mapping SDK. Apple states that Apple Maps usage data sent to Apple generally is associated with randomized, rotating identifiers rather than an Apple Account. Apple processes information it independently collects under its own privacy policies. We remain responsible under this Policy for location, place, and history information collected and stored by Lociro’s own servers.
If we later add product analytics, crash reporting, log monitoring, customer support, email, subscription validation, or another third-party service, we will assess the data flow before integration and update this Policy and obtain consent where required. A provider that processes information for us may process only the information necessary for the contracted purpose and in accordance with our instructions and must provide safeguards appropriate to the risk. A third party acting independently is responsible for its own processing under its own policy.
6.3 Legal, safety, and rights protection
We may disclose information to courts, law-enforcement or regulatory authorities, professional advisers, insurers, or other relevant parties when we believe in good faith that disclosure is necessary and legally justified to comply with legal process, protect users or the public, investigate fraud or abuse, enforce our Terms, or establish, exercise, or defend legal claims. We assess the legal basis for a request and, where permitted by law, seek to limit its scope and notify the affected user.
6.4 Business transactions
If we are involved in a merger, financing, reorganization, bankruptcy, sale of assets, or transfer of the business, personal information may be provided to transaction participants to the extent reasonably necessary. We will require a recipient to continue protecting the information in accordance with this Policy and applicable law and will provide notice where legally required.
6.5 Aggregated or deidentified information
We may use and disclose aggregated or deidentified information that cannot reasonably be linked to an individual or device. We do not attempt to reidentify information that has been deidentified and require recipients to observe the same restriction. Merely replacing a name with an internal ID does not necessarily make information deidentified.
7. Data Retention and Deletion
We retain personal information only for as long as necessary to fulfill the purposes in this Policy, meet security and audit needs, comply with legal obligations, or resolve disputes. The proposed pre-launch periods are listed below. Every period marked “confirmation required” must be verified against the server, backup, log, and vendor configurations before this Policy is published.
• Precise location and accessible history: Retained on a rolling basis for no more than the most recent 30 days and recorded only while sharing is active. Target for deletion or deidentification from the online production environment after account deletion: 30 days — engineering confirmation required.
• Friend relationships and shared spaces: Retained while the relationship remains active. Access by both users ends immediately when a friend is removed. Prior relationship records and associated alerts are deleted or deidentified from the online production environment within 30 days — confirmation required, except for minimum records needed for security audits.
• Places and alert rules: Retained while the place or rule is active and deleted or deidentified from the online production environment within 30 days — confirmation required after the user deletes the place, removes the friend, or deletes the account.
• Anonymous account and profile: Retained while the account is active. Upon confirmed account deletion, the account is immediately disabled and no longer visible to friends, with cleanup from the online environment completed within 30 days — confirmation required.
• Friend Codes and invitation links: Usable for no more than 30 minutes, or until earlier revocation, regeneration, or use-limit exhaustion. Anti-abuse logs are retained for 180 days — confirmation required.
• Notification tokens: Retained while the account and device are in use and deleted within 30 days — confirmation required after the token becomes invalid, the user leaves the Service, or the account is deleted.
• Purchase and entitlement records: Retained as necessary to fulfill and restore purchases, conduct financial audits, and resolve disputes, ordinarily for 7 years after the transaction — confirm under the law applicable to the service provider.
• Security, access, and server logs: Ordinarily retained for 180 days — confirmation required. Records needed for a material security incident or legal claim may be retained until the incident is resolved and the applicable limitation period expires.
• Product analytics, crash, and performance data: Ordinarily retained for 24 months — confirmation required, then deleted or aggregated.
• Support and privacy-request records: Retained for 3 years after the request is closed — confirmation required, or longer where necessary to demonstrate compliance or resolve a dispute.
• Backups: After deletion from the online environment, information may remain in isolated backups for up to 90 days — confirmation required. During that period, it is not used for ordinary business purposes, and deletion instructions are reapplied if a backup is restored.
Where the law requires us to retain particular information, or where limited retention is necessary to prevent fraud, protect user safety, process refunds, or resolve disputes, we may retain it longer with strictly limited access. When the applicable period ends, we delete or irreversibly deidentify the information.
Deleting the App does not automatically delete server-side data or cancel an Apple subscription. Use “Delete Account” in the App and separately manage subscriptions through Apple.
8. International Processing
We and our service providers may process personal information outside the country or region where you are located. Privacy laws in those jurisdictions may differ from the laws where you live.
Our primary business data is stored in the AWS US East (N. Virginia) region. Map display, place search, and geocoding use only Apple Maps/MapKit. Apple may process information necessary to provide those services in facilities operated by Apple or its service providers under Apple’s privacy policies.
Current information and matters that still require verification before launch include:
• Primary business-data storage country and region: United States, AWS US East (N. Virginia);
• Countries or regions from which business data may be accessed remotely: confirmation required; and
• Initial market: United States only. Before officially offering the Service in another country or region, we will assess and implement any locally required transfer mechanism, representative, or other safeguard and update this Policy before launch in that market.
The server region and principal service providers have been identified, but the countries of remote access and Apple-related data flows must still be verified against the final build. This section does not mean that all data-flow verification is complete.
9. Information Security
We use administrative, technical, and organizational measures appropriate to the risks associated with precise location information. These may include encryption in transit, access controls, least-privilege access, environment separation, audit logging, credential protection, security testing, vulnerability management, and confidentiality obligations. We also require service providers that process personal information for us to provide appropriate safeguards.
No system can guarantee absolute security. If a personal-information security incident occurs that may create a risk to your rights, we will take steps to contain, investigate, and remediate it and will notify you and regulators as required by applicable law.
Before launch, the engineering and security owner must verify that the measures described in this section have actually been implemented. A measure that has not been implemented must be removed from the public Policy or completed before publication.
10. Children and Teenagers
The Service is intended for adults. It is not directed to anyone under 18, and we do not knowingly collect precise location information from anyone under 18. Users must be at least 18 years old and have reached the legal age of majority where they live.
If you believe that a minor has provided personal information to us or that a minor’s location is being improperly shared through the Service, contact us at 18101026917@163.com. We will assess the report and, as required by applicable law, stop processing, delete information, or take other protective steps. If there is an immediate safety risk while we investigate, also contact local law enforcement or child-protection services.
11. Your Choices and Rights
11.1 App and device controls
Regardless of whether you have made a purchase, you may:
• Pause or resume all location sharing in the App;
• Pause or resume sharing with a specific friend;
• Remove a friend, which immediately ends both users’ access through the former relationship to each other’s location and history;
• Delete a place or alert rule;
• Turn off location or notification permission in iOS Settings;
• Edit your nickname and avatar in the App;
• Delete your account in the App; and
• Cancel a subscription through Apple settings.
11.2 Privacy rights
Depending on the law where you live, you may have the right to:
• Know whether we process your personal information and obtain access to or a copy of it;
• Correct inaccurate or incomplete information;
• Request deletion of personal information;
• Restrict certain processing;
• Receive information you provided in a structured, commonly used, machine-readable format and request a technically feasible transfer;
• Withdraw consent-based processing;
• Object to processing based on legitimate interests or to direct marketing;
• Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects;
• Lodge a complaint with a competent privacy authority;
• Appeal our denial of certain requests; and
• Exercise applicable privacy rights without discrimination.
We do not currently use location information to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.
11.3 How to submit a request
You may submit a request through the privacy section of the App or by emailing 18101026917@163.com. Describe the type of request and information associated with the anonymous account. To avoid disclosing location or relationship information to another person, we may verify your identity through possession of the relevant device, account credentials, Apple transaction information, or another method proportionate to the risk.
We ordinarily respond within the period required by applicable law. For example, a California privacy request generally receives a response within 45 days, subject to a legally permitted extension for a complex request. If we extend the period, we will explain why. Exercising a right ordinarily is free, except where applicable law permits a charge for repeated, manifestly unfounded, or excessive requests.
Where permitted by law, you may appoint an authorized agent to submit a request. We may require proof of the agent’s authority and may directly verify your identity or confirm the authorization. If we deny a request, we will explain the reason and any available appeal or complaint procedure.
11.4 Withdrawal and limits on deletion
Withdrawing consent does not affect processing that was lawful before the withdrawal. We may be unable to delete certain information immediately when limited retention is required for transaction records, fraud prevention, security incidents, legal obligations, or the establishment, exercise, or defense of legal claims. We restrict the use of such information and delete it when the applicable period ends.
12. United States State Privacy Notice
This section applies where Lociro is subject to an applicable U.S. state privacy law or where we voluntarily extend the corresponding rights.
12.1 Categories, sources, and purposes
During the preceding 12 months, we may have processed identifiers, including internal user IDs, IP addresses, and device or transaction identifiers; customer-record information; commercial information; internet or electronic-network activity; precise geolocation; content you submit; routes or stays inferred from the preceding information; and credentials used for security or account access. Sections 3, 4, and 6 describe the sources, purposes, and recipients of these categories.
Precise geolocation is sensitive personal information. We use it only to provide the location sharing, history, place alerts, security, and related services that you actively request, and not to infer sensitive characteristics unrelated to the Service.
12.2 Sale, sharing, and targeted advertising
We do not sell personal information for money or other valuable consideration, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising. Accordingly, we do not currently provide a “Do Not Sell or Share” control. If our practices change, we will update this Policy before the change and provide any choice mechanism required by law. Where applicable, we recognize and honor legally binding opt-out preference signals such as Global Privacy Control.
12.3 Rights of U.S. state residents
Depending on applicable law, you may have the right to confirm processing; access, delete, or correct personal information; obtain a portable copy; opt out of a sale, sharing, targeted advertising, or certain profiling; and limit certain uses of sensitive personal information. You may submit a request as described in Section 11.3 and appeal a denial where applicable. We will not discriminate against you for exercising an applicable right.
12.4 California “Shine the Light”
We do not disclose personal information to third parties for their own direct-marketing purposes. If this practice changes, we will provide the information and choices required by applicable law.
13. Third-Party Links and Apple Services
The Service may contain links to third-party pages and uses services and technologies provided by Apple, including Apple Maps/MapKit, the App Store, StoreKit, APNs, iOS Location Services, Keychain, and system sharing. Apple may act as an independent controller and process Apple Account, payment, device, mapping, or system-service information under its own policies. We do not receive your complete payment-card information.
Before following a third-party link, review that third party’s privacy policy. We do not control the privacy practices of independent third parties, but we assess and contractually manage processors that we select as required by applicable law.
14. Changes to This Policy
We may update this Policy because of changes to product features, service providers, processing activities, or law. Before a material change takes effect, we will provide notice through the App, by email if we have collected one, or by another reasonable means. We will obtain consent where legally required and will identify the current version and date at the top of the Policy.
If an update would use precise location for a new and incompatible purpose, we will not rely solely on your continued use of the Service. We will provide a clear explanation and choice to the extent required by law.
15. Contact Us and Complaints
Data controller/service provider: Ashlee Heiston, an individual developer
Mailing address: 303 Lantz Ave, Salisbury, North Carolina 28144-2327, United States
Privacy, data-rights, security, and safety-reporting email: 18101026917@163.com
Privacy contact, where applicable: Ashlee Heiston, using the contact details above
U.S. state privacy-request address: 18101026917@163.com
You may submit a complaint to a state or federal privacy, consumer-protection, or other regulatory authority having jurisdiction. We encourage you to contact us first so that we have an opportunity to address the matter, but doing so does not affect your right to complain directly.
If you believe that you or another person is in immediate danger, contact local police, emergency medical services, child-protection services, or another emergency service. Do not rely solely on our privacy or support channels.