Privacy Policy
The short version
This summary is not the whole policy, but nothing below contradicts it.
Where you are going never leaves your phone. Vapio plans journeys on the device. There is no journey-planning endpoint on our server, so your origin and destination cannot reach us.
No advertising, no analytics, no trackers, no data sales. The app ships 27 third-party packages and not one of them is an analytics, advertising or crash-reporting SDK.
You do not need an account. Everything except feedback replies and cross-device favourites works without signing in.
You can erase everything. Settings → Delete account removes your account, your conversations and your attachments immediately — see section 13.
Who we are
Vapio is a public-transport application for İstanbul, built and run by an independent developer. There is no company behind it, no investors, no advertising business and no data business — which is most of the reason this policy has so little to disclose.
That also means one person decides what happens to the data described here, and the same person answers when you ask about it: contact@unmappedpeoples.org, or the Feedback screen inside the app.
Scope of this policy
This policy covers the Vapio mobile application on Android and iOS, and the Vapio
web pages served from unmappedpeoples.org and
api.unmappedpeoples.org. Both hostnames serve the same pages.
It does not cover:
- Other sites reachable from the same domain that are not part of Vapio.
- The services of İETT and İBB, İstanbul’s transport authorities, whose open data Vapio consumes. Vapio sends them nothing about you (section 15).
- Google, Apple, or your network operator, each of whom has its own policy governing what it does with data you give it directly.
Terms used
- Install identifier. A random value the app generates the first time it runs. It is not derived from your phone, your account, or anything about you, and it changes if you uninstall and reinstall on Android.
- Device identifier. The value the operating system gives us for
the physical device —
ANDROID_IDon Android,identifierForVendoron iOS. Unlike the install identifier, it survives a reinstall. - Account. The record created when you sign in with Apple or Google, or verify an email address. Using Vapio without one is fully supported.
- Processor. A company that handles data on our instructions and may not use it for its own purposes. Section 15 lists them.
What never reaches us
Vapio carries İstanbul’s entire transit network — every stop, line, route shape and timetable — inside the application itself. That architecture, not a promise, is why the following cannot reach our servers:
- Your journeys. Origin, destination and every route suggested are computed on your device. There is no endpoint on our server that accepts a journey request, so there is nothing for us to log even accidentally.
- Your saved places — unless you sign in. Home, Work, recent destinations and saved trips live in the app’s own files on your phone. If you sign in, a copy is stored with your account on our server; that is what carries them to a new phone, and it is the only reason we hold them. Deleting your account deletes that copy. Signed out, none of it leaves the device.
- A location trail. We never receive a continuous record of where you have been. Section 6 describes the one location-derived thing we do receive.
- Your contacts, calendar, photos library, microphone or call history. Vapio does not request access to any of them. It can read a photo you choose to attach to a feedback message, and nothing else.
Data collected without an account
Vapio works without signing in. In that state, requests to our server carry:
| What | Why | Kept? |
|---|---|---|
| Map area requested (a bounding box), and sometimes a single reference point | To return the live vehicles inside the area you are looking at, and to sort them by distance | Not stored in our database; present in short-lived server request logs |
| Install identifier | To attach settings to this install and to apply per-install limits | Yes, while the install exists |
| Device identifier | Abuse prevention only — see section 12 | Yes |
| Platform, app version, interface language | To tell which build a fault belongs to and to serve the right language | Yes |
| IP address | Unavoidable in any internet request; used for rate limiting and diagnostics | In request logs, and against verification-email records (section 9) |
Location data
If you grant the location permission, your position is used on the device to centre the map, to find stops near you and to start a journey from where you are.
What reaches our server is not your position but the area of the map you are viewing — and, when you open a stop or follow a route, a single reference point so that vehicles can be ordered by distance. These are request parameters. They are not written to our database and are not joined to your account; they appear only in server request logs, which rotate automatically (section 17).
You can refuse or withdraw the location permission at any time in your device settings. Vapio continues to work: you type a starting point instead of using “Current location”.
Finding a place by name. Two features send a place to an outside service rather than to us. When you type a destination, the text you type is sent to Nominatim, the geocoder run by the OpenStreetMap Foundation, which returns matching places; the query is restricted to İstanbul. When you pick a point on the map, those coordinates are sent to the same service so that the point can be given a name. In both cases Nominatim receives the query and your IP address, as it would for any web request. We send it no account identifier, no installation identifier and nothing else about you, and it is not told who is asking. Neither request reaches our own server, and neither is stored by us.
Data collected if you sign in
Signing in is optional. Its only purposes are to carry your favourites to a new phone and to let us reply to your feedback.
Sign in with Apple
We receive the account identifier Apple assigns you and, if you allow it, your email address. Your name reaches us only if you choose to share it, and only on the first sign-in — Apple never sends it again.
If you pick Hide My Email, what we receive is a relay address ending
in @privaterelay.appleid.com. We never see the address behind it, and we
treat that relay address as a different account from any other address you may have
used here — because from where we stand, it is one.
The identifier Apple gives us is specific to our developer account. No other developer receives it, so it cannot be used to recognise you in anyone else’s app. Were we ever to publish a second app, that app would see the same identifier — Apple issues it per developer, not per app.
Google sign-in
Vapio requests three scopes and no others: openid,
userinfo.profile and userinfo.email. From them we receive
your name, email address, profile picture URL and the account identifier
Google assigns you. We request no access to your contacts, calendar, files,
photos or any other Google service.
Email sign-in
We receive the address only. There is no password: we email a six-digit code and you enter it. Section 9 describes how that code is handled.
Also stored on the account
- Your favourite lines, so they follow you to a new device.
- Interface language and app version, for support.
- The date the account was created and the date it was last seen.
An account can be signed in on one device at a time. When you sign in on a new phone, the previous device is signed out and told why.
Feedback and attachments
If you write to us from inside the app, we store the conversation so that we can answer it and find the fault you are describing:
- The subject and the text of every message, yours and ours.
- Any photos you choose to attach. Photos are stored as files on our server and are visible to the people who answer feedback.
- The platform and app version of the device you wrote from.
You can remove a conversation from the app at any time. Deleting your account (section 13) erases the conversations and the attached files themselves.
Please do not send us documents or photographs containing other people’s personal data — identity papers, tickets with names on them, screenshots of private messages. We do not need them to fix a bus route, and once sent they are on our server until the conversation is deleted.
Email verification
When you verify an email address we record the address, the time, the install it came from, the IP address of the request, and a salted hash of the code — never the code itself. The hash exists so that a copy of our database is not a way into anyone’s account.
A code expires after ten minutes, is invalidated once used, and is destroyed after five wrong attempts. We also keep a short delivery log — which address we sent to and whether the provider accepted it — so that “I never received the code” is a question we can actually answer.
Notifications
If you enable notifications, your operating system gives us a push token. It is a delivery address for that one install, not an identity, and it changes when you reinstall. We use it to send service alerts for your favourite lines and replies to your feedback.
Turning notifications off in your device settings stops us using it. Deleting your account removes it.
Identifiers, and why there are two
Vapio holds two identifiers for a phone, and the difference matters enough to explain rather than bury:
- The install identifier changes when the app is removed and reinstalled. It is what settings and feedback are attached to.
- The device identifier does not change on reinstall. It exists for one purpose: so that a block imposed for abuse cannot be undone by reinstalling. It is not used for advertising, profiling, measurement or cross-app tracking, and it is never shared with anyone.
Abuse prevention and app integrity
We record the package name, the signing certificate fingerprint and the installer of the application that is talking to our server, so that repackaged copies of Vapio are visible to us.
We can also see that two accounts have signed in on one install, or that one device has installed the app many times. These observations are listed for a person to review. Nothing is blocked automatically. When a block is imposed, it is imposed by a human and recorded with a reason.
Deleting your data
In the app: Settings → Delete account. This removes, immediately and without a recovery period:
- your account and everything on it — email address, name, profile picture, favourites, push token;
- your feedback conversations and every message in them;
- your attachments, including the files themselves on our disk;
- your inbox, your notification history, and the verification-email records tied to your address.
The app keeps working afterwards; it starts again as a new, anonymous install. Your favourites and saved places remain on your phone, because they were never on ours.
You can also write to contact@unmappedpeoples.org and we will do it for you. Uninstalling the app removes what is on the phone but not what is on our server; the button above does that.
One exception, stated plainly rather than hidden: if your account is blocked for abuse, deleting it erases your personal details but the block itself remains. Otherwise “delete account” would simply be a way to undo a block, and a block would stop meaning anything.
Legal bases for each purpose
Where the GDPR applies, we rely on the following bases. Where Türkiye’s KVKK applies, the corresponding grounds in Article 5 are relied on.
| Purpose | Data | Basis |
|---|---|---|
| Showing live vehicles and arrivals | Map area, reference point, IP | Performance of a contract — it is the service you asked for |
| Running an account | Email, name, picture, account identifier, favourites, saved places, recent destinations, saved trips | Performance of a contract |
| Answering feedback | Messages, attachments, device details | Performance of a contract |
| Sending a verification code | Email address, IP, hashed code | Performance of a contract, and legitimate interest in preventing abuse of the email channel |
| Notifications | Push token | Consent — given by enabling notifications, withdrawn by disabling them |
| Location on the device | Your position | Consent — the operating system permission, withdrawable at any time |
| Abuse prevention, blocks, integrity checks | Device identifier, package signature, IP | Legitimate interest in keeping the service usable and available to everyone |
| Diagnosing faults | Server request logs | Legitimate interest |
Who else processes your data
| Who | What they receive | When |
|---|---|---|
| Cloudflare | All traffic between your phone and our server passes through it | Always |
| Apple | The sign-in exchange | Only if you choose Sign in with Apple |
| The sign-in exchange | Only if you choose Google sign-in | |
| Brevo | Your email address and the message containing your code | Only when a verification email is sent |
| Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) | The push token and the notification text | Only if you enable notifications |
| OpenStreetMap Foundation (Nominatim) | The place name you type, or the coordinates of a point you pick on the map, plus your IP address — never an account or installation identifier | Only when you search for a place or pick a point on the map |
| Alibaba Cloud | Hosts the server; holds the database and attachment files | Always |
We do not sell personal data, and we do not share it for anyone else’s purposes. No advertising network, data broker or analytics provider receives anything from Vapio, because the app contains no such component.
Vapio reads live vehicle positions and service announcements from İETT and İBB. That traffic goes one way: nothing about you is sent to them.
Where your data is held
Our server is in Frankfurt, Germany. For users in Türkiye this means the data described in this policy is held in the European Union rather than locally.
Cloudflare, Google, Brevo and Apple operate globally, so the parts of your data that reach them (section 15) may be processed outside your country, each under its own published terms.
How long we keep things
| Data | Retention |
|---|---|
| Account, favourites, conversations, attachments | Until you delete the account, or ask us to |
| Verification codes | Ten minutes; destroyed on use or after five wrong attempts |
| Verification-email delivery log | Deleted with the account |
| Server request logs (including map areas requested) | Rotated automatically by size; kept only for diagnosing faults, never analysed, joined to accounts, or exported |
| Block records | For as long as the block applies — that is what makes a block a block |
| App integrity records (package signatures seen) | Aggregated counts, not tied to an identity |
Security
- All traffic between the app and our server is encrypted in transit (HTTPS).
- Verification codes are stored as salted hashes, never in readable form.
- Session tokens are stored in the platform keychain on your device, not in ordinary app storage.
- Administrative access to the server requires a code sent to a specific mailbox; there is no shared password.
No system is perfectly secure. If a breach occurs that is likely to put you at risk, we will tell affected users and the competent authority as the law requires, and we will say what actually happened rather than issue a statement about how seriously we take privacy.
Your rights
Under the GDPR, and under Article 11 of Türkiye’s KVKK, you have the right to:
- know whether we hold data about you, and obtain a copy of it;
- have inaccurate data corrected;
- have your data erased — section 13 is the immediate route;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable form;
- withdraw consent at any time, for notifications and for location, without affecting anything done before you withdrew it.
To exercise any of these, write to contact@unmappedpeoples.org or use Feedback in the app. We will respond within thirty days. We do not charge for this, and we do not require you to justify the request.
Complaints
If you are not satisfied with how we have handled your data, tell us first — most problems are a misunderstanding we can fix the same day.
You also have the right to complain to a supervisory authority: in Türkiye, the Personal Data Protection Authority (KVKK); in the European Union, the authority in your country of residence.
Children, automated decisions, changes
Children
Vapio is a public-transport application for a general audience. It is not directed at children and we do not knowingly collect data from them. If you believe a child has given us personal data, write to us and we will remove it.
Automated decision-making
We do not make decisions about you by automated means alone. The lists described in section 12 are produced automatically, but every block is decided by a person.
Changes to this policy
If this policy changes in a way that affects you, the version and effective date at the top change with it, and material changes are announced in the app’s inbox. We will not quietly begin collecting something new.