Privacy Policy.
Draft prepared for professional legal review. Not yet in force.
Last updated: 2026-07-02 (draft)
1. Who we are and what this policy covers
Trancr is operated by [Operator legal name] ("Trancr," "we," "us"), based in Alberta, Canada.
This policy explains what personal information we collect through the Trancr website and
progressive web application (the "Service"), why we collect it, how it is protected, who it
is shared with, and the rights you have. We handle personal information in accordance with
Alberta's Personal Information Protection Act (PIPA) and, where it applies, the federal
Personal Information Protection and Electronic Documents Act (PIPEDA).
We have designated a Privacy Officer who is responsible for our compliance with PIPA. You can
reach the Privacy Officer through
the contact page.
2. Privacy by design: what we deliberately do not collect
Trancr serves a privacy-sensitive community, and the Service is built to hold as little
identifying information as possible:
- No email address and no legal name. Accounts are a pseudonymous username
and password. Account recovery uses a recovery key you hold, not an email reset.
- No device location. We never read GPS, browser geolocation, or IP-based
location. The only location data we hold is a city name you type in yourself.
- No photographs of you. Profiles use persona images and artwork. Every
uploaded image is re-encoded and stripped of all embedded metadata (including any GPS
data) before it is stored.
- No advertising, no analytics trackers, no third-party marketing cookies.
- We do not sell personal information and have no intention of doing so.
3. Information we collect
Account information. Your username, a hash of your password, hashes of your
recovery key and backup codes, and optional authenticator-app second-factor enrolment. If you
sign in through a third-party provider (Google, Microsoft, Facebook, X/Twitter, or Bluesky),
we receive a provider identifier used only to recognize your sign-in; any email address the
provider offers is discarded and never stored.
Profile information you choose to provide. Your handle, bio, roles and
experience levels, interest tags, modalities and platform handles (such as a Discord or
Telegram handle, revealed to another member only after a mutual match), hard limits and
comfort boundaries, wake word and session preferences, languages, timezone, typed home-base
and current-location city names, persona images, profile prompts, custom tags, hardware
ownership, and optional personality-quiz answers (private by default, with a visibility
setting you control; raw answers are never shown to anyone).
Attestations. Timestamps of your 18+ age attestation, your acceptance of the
SFW covenant (with the covenant version), and, if applicable, the practitioner disclaimer
acknowledgement.
Activity and content. Match interactions (like or pass), matches, messages,
pre-session consent agreements (stored and timestamped for both parties), session feedback,
vouches, onboarding questionnaire answers, event RSVPs, meetup and session records, shared
audio files, in-app notifications, invite attribution (which member's invite link brought you
in, if any), and a last-seen timestamp.
Trusted-contact information. If you use the trusted-contact safety feature,
you provide a label and contact details for a person you choose. This is personal information
about a third party: provide it only with that person's knowledge, and we use it solely to
support the safety feature on your behalf.
Reports and moderation records. Reports you make or that are made about you,
the reported content (preserved even if the reporter unmatches or the content is otherwise
deleted), automated screening flags, and the history of moderation actions on your account.
Technical information. Cookies and similar storage described in section 10,
and standard web-server and application error logs kept for security and troubleshooting.
Error records can include the page being accessed and technical context, and are used only
for diagnosing and fixing faults.
4. Why we collect and use this information
Under PIPA we collect, use, and disclose personal information only for purposes a reasonable
person would consider appropriate in the circumstances. Ours are:
- operating the Service: accounts, matching and discovery, messaging, meetups, and the map;
- safety and consent: consent agreements, the trusted-contact and check-in features,
blocking, reporting, and moderation;
- enforcing the SFW covenant and our Terms of Use, including automated screening reviewed
by human moderators;
- maintaining, securing, and improving the Service, including diagnosing errors; and
- complying with legal obligations.
We do not use your personal information for advertising, profiling unrelated to matching, or
any purpose incompatible with the ones above without seeking your consent.
5. Automated screening and translation
To keep the Service SFW, uploaded images and message text may be screened automatically using
Microsoft Azure AI Content Safety. Content that exceeds a severity threshold is rejected or
flagged for review by a human moderator. No automated decision bans an account;
automated flags only queue content for human judgment.
If you turn on inline translation in a conversation, the other member's messages in that
thread are sent to Microsoft Azure AI Translator to produce the translation you see. Your own
messages are not translated. This feature runs only when you use it.
6. The map and your typed city
Appearing on the member map is opt-in and off by default. If you opt in, the
city name you typed as your home base is sent to Microsoft Azure Maps to resolve the city's
centre coordinates, which we cache. Your pin is placed at city-level precision only, never at
an address, and never from your device's location. Opting out removes your pin. If you never
opt in, your typed city is used only as profile text and for distance bands in discovery.
7. Who can see your information, and who we share it with
Other members. Your profile (handle, bio, roles, tags, images, city, and
similar profile fields) is visible to signed-in members in discovery, subject to your
quiet-mode and visibility settings. Platform handles you enter as modality details are
revealed only after a mutual match. Messages and consent agreements are visible to the other
party to the conversation or agreement. Feedback ratings are aggregated and never shown
verbatim.
Service providers. We use a small number of providers to run the Service,
each receiving only what the function requires: Microsoft Azure for database hosting and for
the Content Safety, Translator, and Maps services described above, and our web-hosting
infrastructure. Providers act on our instructions under contractual safeguards.
Legal and safety disclosures. We may disclose personal information where
required or authorized by law, such as in response to a valid court order or where necessary
to respond to a genuine emergency threatening life or safety. Because accounts hold no email,
legal name, or device location, the identifying information we could disclose is inherently
limited.
Business transitions. If the Service is reorganized or transferred, personal
information may be transferred with it under PIPA's business-transaction provisions, with the
recipient bound to use it consistently with this policy.
We do not sell, rent, or trade personal information, and there are no advertising or analytics
partners.
8. Service providers outside Canada
Some of our service providers process information outside Canada. In particular, Microsoft
Azure services (database hosting, content screening, translation, and geocoding) may store or
process data in Microsoft data centres located outside Canada, including in the United
States. Information processed outside Canada is subject to the laws of those jurisdictions,
which may permit access by their courts, law enforcement, and national-security authorities.
Questions about our use of service providers outside Canada, including written information
about our policies and practices, can be directed to our Privacy Officer through
the contact page.
9. How long we keep information
We keep personal information only as long as reasonably needed for the purposes above or as
the law requires, and we destroy or anonymize it when it is no longer needed.
- Account deletion. When you delete your account it is deactivated
immediately: your profile disappears from discovery, the map, and matching. Content and
records associated with the account are then removed or anonymized on a scheduled basis,
subject to the retention needs below.
- Safety records. Consent agreements, reports, reported content, and
moderation records are retained after deletion or unmatching for as long as reasonably
needed to investigate violations, protect members, and meet legal obligations, and are
then destroyed.
- Error logs. Application error records are rotated and deleted on a
schedule.
10. Cookies and local storage
The Service uses no advertising or analytics cookies. What it does use:
- Authentication cookie - keeps you signed in.
- Anti-forgery tokens - protect forms against cross-site request forgery.
- Bluesky session cookie - only if you sign in with Bluesky, to maintain
that session.
- Maintenance-bypass cookie - only used by administrators during
maintenance windows.
- Browser local storage - remembers on-device preferences such as your
chosen text size, and the offline shell cached by the progressive web app's service
worker. Pages containing your personal data are never cached for offline use.
Blocking these cookies in your browser will prevent sign-in from working.
11. How we protect information
We use administrative, technical, and physical safeguards appropriate to the sensitivity of
the information: passwords, recovery keys, and backup codes are stored only as salted hashes;
connections are encrypted in transit; uploaded images are re-encoded and stripped of metadata
before storage; access to production data is restricted; and the minimal-collection design in
section 2 limits what could be exposed in the first place. No system is perfectly secure. If
a security breach creates a real risk of significant harm to individuals, we will notify the
Information and Privacy Commissioner of Alberta and affected individuals as PIPA requires.
12. Your choices and your rights
You can act directly in the Service at any time:
- edit or remove profile fields, images, tags, and quiz answers;
- opt in or out of the map pin;
- enable quiet mode to hide your profile and pause matching;
- control notification and visibility settings;
- regenerate your recovery key; and
- delete your account.
Under PIPA you also have the right to request access to the personal information we hold
about you and an explanation of how it has been used and disclosed, and to request correction
of errors. Send requests to our Privacy Officer through
the contact page.
We will respond within 45 days as PIPA requires, subject to the limited extensions and
exceptions PIPA permits. Because accounts are pseudonymous, we will verify requests against
control of the account rather than legal identity.
You may withdraw consent to collection, use, or disclosure at any time on reasonable notice,
subject to legal or contractual restrictions. Withdrawing consent for information the Service
needs to function (such as account data) means we may no longer be able to provide the
Service, in which case account deletion is the practical effect.
13. Complaints
If you have a concern about our handling of your personal information, contact our Privacy
Officer first and give us the chance to resolve it. If you are not satisfied with our
response, you may complain to the Office of the Information and Privacy Commissioner of
Alberta (OIPC): www.oipc.ab.ca, toll-free 1-888-878-4044.
14. Age
The Service is for adults 18 and older. We do not knowingly collect personal information from
anyone under 18, and accounts found to belong to minors are removed and their information
deleted.
15. Changes to this policy
We may update this policy from time to time. For material changes we will give notice within
the Service before the changes take effect, and the "last updated" date above will change. We
will not use previously collected information for a materially different purpose without
seeking consent.
16. Contact
Privacy questions and requests should be directed to our Privacy Officer through
the contact page.