← Topo

Privacy Policy for topo

Last updated: 14 September 2026

topo maps how the people you know are connected to each other. This policy describes exactly what the app collects, why, and what it never does. It was written against the code rather than from a template, so where it makes a specific claim — that contacts are hashed on your device, that your surname is never displayed — that claim is checkable in the app's behaviour.

If you have a question this does not answer, contact us at the address at the bottom.

Who is responsible

topo is operated by the developer of the topo app ("we", "us"). Data is stored with Supabase, which hosts our database and file storage.

When someone adds an interest nobody has used before, the wording alone (for example "powerlifting") is sent to Anthropic, whose Claude model sorts it into a group such as Fitness or Climbing. Nothing else about you is sent with it, not even which account it came from.

What we collect, and why

Things you enter

What Why Shown to others
First name Identifies you on the map Yes
Last name Distinguishes people with the same first name Only the first letter. Stored in full, displayed as an initial
Username How people look you up Yes
Email address Signing in, and account recovery No
Password Signing in No — stored only as a hash, by Supabase Auth
Date of birth Age-appropriate defaults No
Phone number So people who already have your number can find you No
Photo Your node on the map Yes
Interests Finding people you have things in common with Yes
Bio Your profile Yes
Social links Your profile Yes
Messages Delivering them To the people in that conversation

Things the app derives

or received. Other people can see connections you have in common with them. - Events you host or attend, and who else is attending. - Suggestions — the app works out when it might be worth messaging someone (for example, that you have not spoken in several months). This is computed on your device from data already there. Nothing about who you know is sent anywhere to produce it, and it is not shared with anyone.

Location

Only while Nearby is switched on, and only then. Your approximate location is used to show other people who have Nearby on at the same time. It is not kept as a history, and Nearby turns itself off after three hours.

Contacts

Only if you ask the app to check them.

Your contacts never leave your device. Each email address and phone number is hashed on your phone with SHA-256, and only those hashes are sent, to be compared against hashes of accounts that already exist. A hash cannot be turned back into an address. We do not store your contact list, and we never contact anyone in it.

Camera

Used only to scan QR codes, when you open the scanner. No image is stored or transmitted.

Technical data

Standard server logs from our hosting provider, including IP address and timestamps, kept for security and debugging.

What we do not do

number to other users.

Notifications

Some notifications are sent by our server rather than your phone: a weekly summary (someone you haven't talked to in a while, two of your connections who share an interest, an event your connections are going to), a reminder the day before an event you joined, and a note after an event about people you met there through Nearby. These are built from your connections, events and the dates of your messages. Message text is never read for them.

We also record which days you open the app, only to count how many people come back. Reports you file are sent to the topo team for review.

If you allow them, the app may remind you about someone worth messaging or an event coming up. These reminders are scheduled by your own device from information already on it. If you turn notifications off, in the app or in your phone's settings, they stop.

Who can see what

interests — is visible to people you are connected to, and to people who look up your username or scan your code. - Nearby shows your first name and last initial and your photo to others with Nearby on. Your username is hidden until you have connected. - Messages are visible only to the people in that conversation. They are not end-to-end encrypted: they are encrypted in transit and at rest, and are technically readable by us on the server. We do not read them. - Blocking someone removes you from each other's view.

How long we keep it

Until you delete it. Deleting your account removes your profile photo, your connections, the events you created, and every message you have sent — including from the conversations of the people you sent them to. Nothing of yours is kept behind.

You can delete your account in the app: Settings → Delete account. It takes effect immediately and is not reversible.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your data, and to object to processing. Most of this is available in the app directly; for anything else, contact us and we will respond within 30 days.

Children

topo is not intended for anyone under 13, and we do not knowingly collect data from children under 13. If you believe a child has an account, contact us and we will remove it.

International transfers

Our database is hosted by Supabase. Depending on the region of that instance, your data may be processed outside your own country, under appropriate safeguards.

Security

Passwords are hashed by Supabase Auth and never stored by us in a readable form. Access to your data is enforced at the database level by row-level security policies, so one account cannot read another's data even if the app were tampered with. Data is encrypted in transit.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and any regulator we are required to.

Changes

If this policy changes materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.

Contact

Email: support@jointopo.app