Privacy Policy.

Draft prepared for professional legal review. Not yet in force.

Last updated: 2026-07-02 (draft)

1. Who we are and what this policy covers

Trancr is operated by [Operator legal name] ("Trancr," "we," "us"), based in Alberta, Canada. This policy explains what personal information we collect through the Trancr website and progressive web application (the "Service"), why we collect it, how it is protected, who it is shared with, and the rights you have. We handle personal information in accordance with Alberta's Personal Information Protection Act (PIPA) and, where it applies, the federal Personal Information Protection and Electronic Documents Act (PIPEDA).

We have designated a Privacy Officer who is responsible for our compliance with PIPA. You can reach the Privacy Officer through the contact page.

2. Privacy by design: what we deliberately do not collect

Trancr serves a privacy-sensitive community, and the Service is built to hold as little identifying information as possible:

  • No email address and no legal name. Accounts are a pseudonymous username and password. Account recovery uses a recovery key you hold, not an email reset.
  • No device location. We never read GPS, browser geolocation, or IP-based location. The only location data we hold is a city name you type in yourself.
  • No photographs of you. Profiles use persona images and artwork. Every uploaded image is re-encoded and stripped of all embedded metadata (including any GPS data) before it is stored.
  • No advertising, no analytics trackers, no third-party marketing cookies.
  • We do not sell personal information and have no intention of doing so.

3. Information we collect

Account information. Your username, a hash of your password, hashes of your recovery key and backup codes, and optional authenticator-app second-factor enrolment. If you sign in through a third-party provider (Google, Microsoft, Facebook, X/Twitter, or Bluesky), we receive a provider identifier used only to recognize your sign-in; any email address the provider offers is discarded and never stored.

Profile information you choose to provide. Your handle, bio, roles and experience levels, interest tags, modalities and platform handles (such as a Discord or Telegram handle, revealed to another member only after a mutual match), hard limits and comfort boundaries, wake word and session preferences, languages, timezone, typed home-base and current-location city names, persona images, profile prompts, custom tags, hardware ownership, and optional personality-quiz answers (private by default, with a visibility setting you control; raw answers are never shown to anyone).

Attestations. Timestamps of your 18+ age attestation, your acceptance of the SFW covenant (with the covenant version), and, if applicable, the practitioner disclaimer acknowledgement.

Activity and content. Match interactions (like or pass), matches, messages, pre-session consent agreements (stored and timestamped for both parties), session feedback, vouches, onboarding questionnaire answers, event RSVPs, meetup and session records, shared audio files, in-app notifications, invite attribution (which member's invite link brought you in, if any), and a last-seen timestamp.

Trusted-contact information. If you use the trusted-contact safety feature, you provide a label and contact details for a person you choose. This is personal information about a third party: provide it only with that person's knowledge, and we use it solely to support the safety feature on your behalf.

Reports and moderation records. Reports you make or that are made about you, the reported content (preserved even if the reporter unmatches or the content is otherwise deleted), automated screening flags, and the history of moderation actions on your account.

Technical information. Cookies and similar storage described in section 10, and standard web-server and application error logs kept for security and troubleshooting. Error records can include the page being accessed and technical context, and are used only for diagnosing and fixing faults.

4. Why we collect and use this information

Under PIPA we collect, use, and disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances. Ours are:

  • operating the Service: accounts, matching and discovery, messaging, meetups, and the map;
  • safety and consent: consent agreements, the trusted-contact and check-in features, blocking, reporting, and moderation;
  • enforcing the SFW covenant and our Terms of Use, including automated screening reviewed by human moderators;
  • maintaining, securing, and improving the Service, including diagnosing errors; and
  • complying with legal obligations.

We do not use your personal information for advertising, profiling unrelated to matching, or any purpose incompatible with the ones above without seeking your consent.

5. Automated screening and translation

To keep the Service SFW, uploaded images and message text may be screened automatically using Microsoft Azure AI Content Safety. Content that exceeds a severity threshold is rejected or flagged for review by a human moderator. No automated decision bans an account; automated flags only queue content for human judgment.

If you turn on inline translation in a conversation, the other member's messages in that thread are sent to Microsoft Azure AI Translator to produce the translation you see. Your own messages are not translated. This feature runs only when you use it.

6. The map and your typed city

Appearing on the member map is opt-in and off by default. If you opt in, the city name you typed as your home base is sent to Microsoft Azure Maps to resolve the city's centre coordinates, which we cache. Your pin is placed at city-level precision only, never at an address, and never from your device's location. Opting out removes your pin. If you never opt in, your typed city is used only as profile text and for distance bands in discovery.

7. Who can see your information, and who we share it with

Other members. Your profile (handle, bio, roles, tags, images, city, and similar profile fields) is visible to signed-in members in discovery, subject to your quiet-mode and visibility settings. Platform handles you enter as modality details are revealed only after a mutual match. Messages and consent agreements are visible to the other party to the conversation or agreement. Feedback ratings are aggregated and never shown verbatim.

Service providers. We use a small number of providers to run the Service, each receiving only what the function requires: Microsoft Azure for database hosting and for the Content Safety, Translator, and Maps services described above, and our web-hosting infrastructure. Providers act on our instructions under contractual safeguards.

Legal and safety disclosures. We may disclose personal information where required or authorized by law, such as in response to a valid court order or where necessary to respond to a genuine emergency threatening life or safety. Because accounts hold no email, legal name, or device location, the identifying information we could disclose is inherently limited.

Business transitions. If the Service is reorganized or transferred, personal information may be transferred with it under PIPA's business-transaction provisions, with the recipient bound to use it consistently with this policy.

We do not sell, rent, or trade personal information, and there are no advertising or analytics partners.

8. Service providers outside Canada

Some of our service providers process information outside Canada. In particular, Microsoft Azure services (database hosting, content screening, translation, and geocoding) may store or process data in Microsoft data centres located outside Canada, including in the United States. Information processed outside Canada is subject to the laws of those jurisdictions, which may permit access by their courts, law enforcement, and national-security authorities. Questions about our use of service providers outside Canada, including written information about our policies and practices, can be directed to our Privacy Officer through the contact page.

9. How long we keep information

We keep personal information only as long as reasonably needed for the purposes above or as the law requires, and we destroy or anonymize it when it is no longer needed.

  • Account deletion. When you delete your account it is deactivated immediately: your profile disappears from discovery, the map, and matching. Content and records associated with the account are then removed or anonymized on a scheduled basis, subject to the retention needs below.
  • Safety records. Consent agreements, reports, reported content, and moderation records are retained after deletion or unmatching for as long as reasonably needed to investigate violations, protect members, and meet legal obligations, and are then destroyed.
  • Error logs. Application error records are rotated and deleted on a schedule.

10. Cookies and local storage

The Service uses no advertising or analytics cookies. What it does use:

  • Authentication cookie - keeps you signed in.
  • Anti-forgery tokens - protect forms against cross-site request forgery.
  • Bluesky session cookie - only if you sign in with Bluesky, to maintain that session.
  • Maintenance-bypass cookie - only used by administrators during maintenance windows.
  • Browser local storage - remembers on-device preferences such as your chosen text size, and the offline shell cached by the progressive web app's service worker. Pages containing your personal data are never cached for offline use.

Blocking these cookies in your browser will prevent sign-in from working.

11. How we protect information

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information: passwords, recovery keys, and backup codes are stored only as salted hashes; connections are encrypted in transit; uploaded images are re-encoded and stripped of metadata before storage; access to production data is restricted; and the minimal-collection design in section 2 limits what could be exposed in the first place. No system is perfectly secure. If a security breach creates a real risk of significant harm to individuals, we will notify the Information and Privacy Commissioner of Alberta and affected individuals as PIPA requires.

12. Your choices and your rights

You can act directly in the Service at any time:

  • edit or remove profile fields, images, tags, and quiz answers;
  • opt in or out of the map pin;
  • enable quiet mode to hide your profile and pause matching;
  • control notification and visibility settings;
  • regenerate your recovery key; and
  • delete your account.

Under PIPA you also have the right to request access to the personal information we hold about you and an explanation of how it has been used and disclosed, and to request correction of errors. Send requests to our Privacy Officer through the contact page. We will respond within 45 days as PIPA requires, subject to the limited extensions and exceptions PIPA permits. Because accounts are pseudonymous, we will verify requests against control of the account rather than legal identity.

You may withdraw consent to collection, use, or disclosure at any time on reasonable notice, subject to legal or contractual restrictions. Withdrawing consent for information the Service needs to function (such as account data) means we may no longer be able to provide the Service, in which case account deletion is the practical effect.

13. Complaints

If you have a concern about our handling of your personal information, contact our Privacy Officer first and give us the chance to resolve it. If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner of Alberta (OIPC): www.oipc.ab.ca, toll-free 1-888-878-4044.

14. Age

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18, and accounts found to belong to minors are removed and their information deleted.

15. Changes to this policy

We may update this policy from time to time. For material changes we will give notice within the Service before the changes take effect, and the "last updated" date above will change. We will not use previously collected information for a materially different purpose without seeking consent.

16. Contact

Privacy questions and requests should be directed to our Privacy Officer through the contact page.