Vapio

Privacy Policy

Version 2.4 · Effective 22 September 2026
Applies to the Vapio mobile application and to vapio pages served from unmappedpeoples.org

The short version

This summary is not the whole policy, but nothing below contradicts it.

Where you are going never leaves your phone. Vapio plans journeys on the device. There is no journey-planning endpoint on our server, so your origin and destination cannot reach us.

No advertising, no analytics, no trackers, no data sales. The app ships 27 third-party packages and not one of them is an analytics, advertising or crash-reporting SDK.

You do not need an account. Everything except feedback replies and cross-device favourites works without signing in.

You can erase everything. Settings → Delete account removes your account, your conversations and your attachments immediately — see section 13.

Who we are

Vapio is a public-transport application for İstanbul, built and run by an independent developer. There is no company behind it, no investors, no advertising business and no data business — which is most of the reason this policy has so little to disclose.

That also means one person decides what happens to the data described here, and the same person answers when you ask about it: contact@unmappedpeoples.org, or the Feedback screen inside the app.

Scope of this policy

This policy covers the Vapio mobile application on Android and iOS, and the Vapio web pages served from unmappedpeoples.org and api.unmappedpeoples.org. Both hostnames serve the same pages.

It does not cover:

  • Other sites reachable from the same domain that are not part of Vapio.
  • The services of İETT and İBB, İstanbul’s transport authorities, whose open data Vapio consumes. Vapio sends them nothing about you (section 15).
  • Google, Apple, or your network operator, each of whom has its own policy governing what it does with data you give it directly.

Terms used

  • Install identifier. A random value the app generates the first time it runs. It is not derived from your phone, your account, or anything about you, and it changes if you uninstall and reinstall on Android.
  • Device identifier. The value the operating system gives us for the physical device — ANDROID_ID on Android, identifierForVendor on iOS. Unlike the install identifier, it survives a reinstall.
  • Account. The record created when you sign in with Apple or Google, or verify an email address. Using Vapio without one is fully supported.
  • Processor. A company that handles data on our instructions and may not use it for its own purposes. Section 15 lists them.

What never reaches us

Vapio carries İstanbul’s entire transit network — every stop, line, route shape and timetable — inside the application itself. That architecture, not a promise, is why the following cannot reach our servers:

  • Your journeys. Origin, destination and every route suggested are computed on your device. There is no endpoint on our server that accepts a journey request, so there is nothing for us to log even accidentally.
  • Your saved places — unless you sign in. Home, Work, recent destinations and saved trips live in the app’s own files on your phone. If you sign in, a copy is stored with your account on our server; that is what carries them to a new phone, and it is the only reason we hold them. Deleting your account deletes that copy. Signed out, none of it leaves the device.
  • A location trail. We never receive a continuous record of where you have been. Section 6 describes the one location-derived thing we do receive.
  • Your contacts, calendar, photos library, microphone or call history. Vapio does not request access to any of them. It can read a photo you choose to attach to a feedback message, and nothing else.

Data collected without an account

Vapio works without signing in. In that state, requests to our server carry:

WhatWhyKept?
Map area requested (a bounding box), and sometimes a single reference pointTo return the live vehicles inside the area you are looking at, and to sort them by distanceNot stored in our database; present in short-lived server request logs
Install identifierTo attach settings to this install and to apply per-install limitsYes, while the install exists
Device identifierAbuse prevention only — see section 12Yes
Platform, app version, interface languageTo tell which build a fault belongs to and to serve the right languageYes
IP addressUnavoidable in any internet request; used for rate limiting and diagnosticsIn request logs, and against verification-email records (section 9)

Location data

If you grant the location permission, your position is used on the device to centre the map, to find stops near you and to start a journey from where you are.

What reaches our server is not your position but the area of the map you are viewing — and, when you open a stop or follow a route, a single reference point so that vehicles can be ordered by distance. These are request parameters. They are not written to our database and are not joined to your account; they appear only in server request logs, which rotate automatically (section 17).

You can refuse or withdraw the location permission at any time in your device settings. Vapio continues to work: you type a starting point instead of using “Current location”.

Finding a place by name. Two features send a place to an outside service rather than to us. When you type a destination, the text you type is sent to Nominatim, the geocoder run by the OpenStreetMap Foundation, which returns matching places; the query is restricted to İstanbul. When you pick a point on the map, those coordinates are sent to the same service so that the point can be given a name. In both cases Nominatim receives the query and your IP address, as it would for any web request. We send it no account identifier, no installation identifier and nothing else about you, and it is not told who is asking. Neither request reaches our own server, and neither is stored by us.

Data collected if you sign in

Signing in is optional. Its only purposes are to carry your favourites to a new phone and to let us reply to your feedback.

Sign in with Apple

We receive the account identifier Apple assigns you and, if you allow it, your email address. Your name reaches us only if you choose to share it, and only on the first sign-in — Apple never sends it again.

If you pick Hide My Email, what we receive is a relay address ending in @privaterelay.appleid.com. We never see the address behind it, and we treat that relay address as a different account from any other address you may have used here — because from where we stand, it is one.

The identifier Apple gives us is specific to our developer account. No other developer receives it, so it cannot be used to recognise you in anyone else’s app. Were we ever to publish a second app, that app would see the same identifier — Apple issues it per developer, not per app.

Google sign-in

Vapio requests three scopes and no others: openid, userinfo.profile and userinfo.email. From them we receive your name, email address, profile picture URL and the account identifier Google assigns you. We request no access to your contacts, calendar, files, photos or any other Google service.

Email sign-in

We receive the address only. There is no password: we email a six-digit code and you enter it. Section 9 describes how that code is handled.

Also stored on the account

  • Your favourite lines, so they follow you to a new device.
  • Interface language and app version, for support.
  • The date the account was created and the date it was last seen.

An account can be signed in on one device at a time. When you sign in on a new phone, the previous device is signed out and told why.

Feedback and attachments

If you write to us from inside the app, we store the conversation so that we can answer it and find the fault you are describing:

  • The subject and the text of every message, yours and ours.
  • Any photos you choose to attach. Photos are stored as files on our server and are visible to the people who answer feedback.
  • The platform and app version of the device you wrote from.

You can remove a conversation from the app at any time. Deleting your account (section 13) erases the conversations and the attached files themselves.

Please do not send us documents or photographs containing other people’s personal data — identity papers, tickets with names on them, screenshots of private messages. We do not need them to fix a bus route, and once sent they are on our server until the conversation is deleted.

Email verification

When you verify an email address we record the address, the time, the install it came from, the IP address of the request, and a salted hash of the code — never the code itself. The hash exists so that a copy of our database is not a way into anyone’s account.

A code expires after ten minutes, is invalidated once used, and is destroyed after five wrong attempts. We also keep a short delivery log — which address we sent to and whether the provider accepted it — so that “I never received the code” is a question we can actually answer.

Notifications

If you enable notifications, your operating system gives us a push token. It is a delivery address for that one install, not an identity, and it changes when you reinstall. We use it to send service alerts for your favourite lines and replies to your feedback.

Turning notifications off in your device settings stops us using it. Deleting your account removes it.

Identifiers, and why there are two

Vapio holds two identifiers for a phone, and the difference matters enough to explain rather than bury:

  • The install identifier changes when the app is removed and reinstalled. It is what settings and feedback are attached to.
  • The device identifier does not change on reinstall. It exists for one purpose: so that a block imposed for abuse cannot be undone by reinstalling. It is not used for advertising, profiling, measurement or cross-app tracking, and it is never shared with anyone.

Abuse prevention and app integrity

We record the package name, the signing certificate fingerprint and the installer of the application that is talking to our server, so that repackaged copies of Vapio are visible to us.

We can also see that two accounts have signed in on one install, or that one device has installed the app many times. These observations are listed for a person to review. Nothing is blocked automatically. When a block is imposed, it is imposed by a human and recorded with a reason.

Deleting your data

In the app: Settings → Delete account. This removes, immediately and without a recovery period:

  • your account and everything on it — email address, name, profile picture, favourites, push token;
  • your feedback conversations and every message in them;
  • your attachments, including the files themselves on our disk;
  • your inbox, your notification history, and the verification-email records tied to your address.

The app keeps working afterwards; it starts again as a new, anonymous install. Your favourites and saved places remain on your phone, because they were never on ours.

You can also write to contact@unmappedpeoples.org and we will do it for you. Uninstalling the app removes what is on the phone but not what is on our server; the button above does that.

One exception, stated plainly rather than hidden: if your account is blocked for abuse, deleting it erases your personal details but the block itself remains. Otherwise “delete account” would simply be a way to undo a block, and a block would stop meaning anything.

Legal bases for each purpose

Where the GDPR applies, we rely on the following bases. Where Türkiye’s KVKK applies, the corresponding grounds in Article 5 are relied on.

PurposeDataBasis
Showing live vehicles and arrivalsMap area, reference point, IP Performance of a contract — it is the service you asked for
Running an accountEmail, name, picture, account identifier, favourites, saved places, recent destinations, saved trips Performance of a contract
Answering feedbackMessages, attachments, device details Performance of a contract
Sending a verification codeEmail address, IP, hashed code Performance of a contract, and legitimate interest in preventing abuse of the email channel
NotificationsPush tokenConsent — given by enabling notifications, withdrawn by disabling them
Location on the deviceYour positionConsent — the operating system permission, withdrawable at any time
Abuse prevention, blocks, integrity checksDevice identifier, package signature, IPLegitimate interest in keeping the service usable and available to everyone
Diagnosing faultsServer request logsLegitimate interest

Who else processes your data

WhoWhat they receiveWhen
CloudflareAll traffic between your phone and our server passes through itAlways
AppleThe sign-in exchangeOnly if you choose Sign in with Apple
GoogleThe sign-in exchangeOnly if you choose Google sign-in
BrevoYour email address and the message containing your codeOnly when a verification email is sent
Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS)The push token and the notification textOnly if you enable notifications
OpenStreetMap Foundation (Nominatim)The place name you type, or the coordinates of a point you pick on the map, plus your IP address — never an account or installation identifierOnly when you search for a place or pick a point on the map
Alibaba CloudHosts the server; holds the database and attachment filesAlways

We do not sell personal data, and we do not share it for anyone else’s purposes. No advertising network, data broker or analytics provider receives anything from Vapio, because the app contains no such component.

Vapio reads live vehicle positions and service announcements from İETT and İBB. That traffic goes one way: nothing about you is sent to them.

Where your data is held

Our server is in Frankfurt, Germany. For users in Türkiye this means the data described in this policy is held in the European Union rather than locally.

Cloudflare, Google, Brevo and Apple operate globally, so the parts of your data that reach them (section 15) may be processed outside your country, each under its own published terms.

How long we keep things

DataRetention
Account, favourites, conversations, attachmentsUntil you delete the account, or ask us to
Verification codesTen minutes; destroyed on use or after five wrong attempts
Verification-email delivery logDeleted with the account
Server request logs (including map areas requested)Rotated automatically by size; kept only for diagnosing faults, never analysed, joined to accounts, or exported
Block recordsFor as long as the block applies — that is what makes a block a block
App integrity records (package signatures seen)Aggregated counts, not tied to an identity

Security

  • All traffic between the app and our server is encrypted in transit (HTTPS).
  • Verification codes are stored as salted hashes, never in readable form.
  • Session tokens are stored in the platform keychain on your device, not in ordinary app storage.
  • Administrative access to the server requires a code sent to a specific mailbox; there is no shared password.

No system is perfectly secure. If a breach occurs that is likely to put you at risk, we will tell affected users and the competent authority as the law requires, and we will say what actually happened rather than issue a statement about how seriously we take privacy.

Your rights

Under the GDPR, and under Article 11 of Türkiye’s KVKK, you have the right to:

  • know whether we hold data about you, and obtain a copy of it;
  • have inaccurate data corrected;
  • have your data erased — section 13 is the immediate route;
  • restrict or object to processing based on legitimate interest;
  • receive your data in a portable form;
  • withdraw consent at any time, for notifications and for location, without affecting anything done before you withdrew it.

To exercise any of these, write to contact@unmappedpeoples.org or use Feedback in the app. We will respond within thirty days. We do not charge for this, and we do not require you to justify the request.

Complaints

If you are not satisfied with how we have handled your data, tell us first — most problems are a misunderstanding we can fix the same day.

You also have the right to complain to a supervisory authority: in Türkiye, the Personal Data Protection Authority (KVKK); in the European Union, the authority in your country of residence.

Children, automated decisions, changes

Children

Vapio is a public-transport application for a general audience. It is not directed at children and we do not knowingly collect data from them. If you believe a child has given us personal data, write to us and we will remove it.

Automated decision-making

We do not make decisions about you by automated means alone. The lists described in section 12 are produced automatically, but every block is decided by a person.

Changes to this policy

If this policy changes in a way that affects you, the version and effective date at the top change with it, and material changes are announced in the app’s inbox. We will not quietly begin collecting something new.