The short version. Near shares your live location with the specific people in your game room, only while that room is active. Nothing is sold or shared with data brokers, and nothing about where you are ever reaches an advertiser. There are no ads anywhere in the game. The only ads in Near are ones you go looking for, on a cosmetics screen you never have to open. A verified account is required to create or join a game. Firebase handles sign-in; Near never sees your password. Rooms delete themselves after seven days.
What Near collects
Location. Precise GPS coordinates — latitude, longitude, and an accuracy radius. For live presence, Near stores only your most recent position and does not build a continuous route history. A location-based game question may also retain the limited question geometry needed to show or apply its answer — for example, a Radar center, a Measuring reference, or the fixed reference point and traveler start and finish points needed to resolve a Thermometer. That geometry is kept for the game, and the shape a card produced is kept for up to seven days after the room ends so a reported problem with the map can still be looked into — with no name, account, or player attached to it, only the card, its answer, and the area it shaded. Both are deleted no later than seven days; temporary Thermometer trip snapshots are deleted within 24 hours. Near also stores and shares within the room whether each device reports that live location and Always Location permission are active. These are yes-or-no readiness checks, not coordinates, timestamps, or permission credentials, and they remain visible during a round so players can fix background sharing. Upload cadence depends on the platform. The foreground web/iPhone flow is capped at about one update every four seconds with a roughly twenty-second keep-alive. If you explicitly enable Android Background Location for a room, the installed Android app requests a battery-balanced fix about every fifteen seconds and sends a roughly one-minute stationary keep-alive while displaying Android’s persistent location notice.
A nickname. Whatever name you type when creating or joining a room, limited to 32 characters. Near does not ask for your real name and does not verify it.
Room membership. Which room you are in, which team you chose, whether you are the room owner, and when you were last seen.
Gameplay content. Questions asked, the computed answers, their limited question geometry, the shared playable border, each team’s private ruled-out map areas, and the seeking team’s shared notes. If you choose to use room Messages, Near also stores the text and photos you send so everyone in that private room can see them.
Optional room photos. Photos are kept at their original pixel dimensions. Before storage, Near removes embedded location, device, comment, and editing metadata. The sanitized image is stored privately by Cloudflare and can be read only through an authenticated membership in that room. Near never exposes the storage key or a public image URL. Room photos are limited to 15 MB each and are deleted when the room is ended, with automatic storage expiry as a final cleanup backstop.
Place and directions searches. The station, stop, address, or place you type is sent to Apple Maps to return ordinary place results and walking routes. If you ask for public-transit directions, Near sends the selected origin, destination, and departure time to Google Maps Platform. When you select a map place, Near may send that public place’s Apple name and coordinate to Wikimedia to look for one or more nearby, strongly name-matched, freely licensed photos. This is the place you selected, not your room code, account, live GPS coordinate, notes, or game answers. Near does not keep a personal search history or use these searches for advertising.
Room place cache. To avoid repeating the same stable park, station, or museum lookup throughout a game, Near may retain the Apple place IDs, names, primary categories, and coordinates returned for a rounded search point inside that room. Search result names and addresses may also be cached briefly for that room. When Wikimedia photos are found, their public thumbnail URLs, authors, licenses, and source links may be cached for the room as well; Near does not copy the images into private room storage. The typed query is represented only in a one-way cache key. These caches are deleted when the room ends or expires and are never shared between rooms.
A session token. A random value identifying your device to your room. Near stores only a SHA-256 hash of it, never the token itself. Android Background Location uses a separate room-scoped token that can submit only location, is encrypted by Android Keystore on the device, is stored only as a hash by Near, and is revoked when you leave or the room ends or expires.
Optional notification token and choices. If you use the iPhone app and allow alerts, Near stores Apple’s opaque APNs device token for your account and, during play, your room membership. Near also stores whether you enabled all notifications, Announcements, Hiding Timer, and Question Timer alerts. Near does not currently send announcements. Tokens are used only to deliver the alerts you allow; they are not location identifiers and notification payloads never contain coordinates or computed answers.
Optional launch alerts. On the public launch-alert page, you may provide an email address, an iPhone/Android/Both platform choice, and a source label. Near stores the normalized email, a one-way email hash, your choice, and the signup and unsubscribe timestamps in a separate launch-alert list. Signup is immediately confirmed, and a thank-you message is sent through Resend; no confirmation link is required. This list is not connected to a Near account, room, game, device, or location. Legacy unconfirmed entries expire after seven days; unsubscribed entries are anonymized after 30 days; confirmed entries remain only until launch notifications are complete or you unsubscribe. Every launch-alert email includes an unsubscribe link.
Near does not collect your contacts, photo library, microphone, camera, health data, advertising identifiers, device fingerprints, or browsing history. Before you sign in, Near only keeps temporary entry-screen state on your device; an account is required before any room membership or live location sharing begins. Near receives only a photo you explicitly choose to send through room Messages; it does not scan or import your library.
Your account
An account is required to create or join a room, and lets your saved games follow you between devices. Sign-in is handled by Google Firebase Authentication. Near never sees your password and never receives your Apple or Google credentials.
If you sign in, Near stores the user ID your provider issues, your email address, your display name if the provider supplies one, which provider you used, and when the account was created and last used. Rooms you create or join while signed in are tagged with your account ID. While you are signed in, this data is linked to your identity — that is what an account is for. This account is the identity boundary for your room memberships, friends, moderation, saved games, and account deletion.
Apple’s Hide My Email is fully supported. Near receives only the relay address and never your real one.
Deleting your account. Open Settings & Room, then Personal Settings, then Delete Account, or use the web account-deletion page without reinstalling the app. This erases your account record, your membership in every room, and any room you own — for everyone in it. It also deletes your sign-in credential, so signing in again creates a genuinely new account. It is immediate, irreversible, and requires no email to anyone. Near keeps only a one-way hash of the provider identifier and the deletion time as a security fence, so a token captured before deletion can never recreate or delete a later account. The hash cannot be reversed into the provider identifier, and a fresh provider sign-in can still create a new account.
Friends, blocking, and reporting
These features exist only if you have an account, and all of them are optional.
Friends are mutual. You share an eight-digit friend code — not your email — and the other person has to accept before anything connects. A code only lets someone send you a request. Being friends does not share your location: that still happens only inside a game you both joined.
Blocking removes an existing friendship, prevents further requests in either direction, and removes that signed-in account from games you host. Because an account is required to join, ending a game is the only way to invalidate its invite completely. Near stores which accounts you blocked and when.
Reports record who filed them, who or what was reported, the room if there was one, a reason, and anything you type. They are reviewed by Near’s moderator. Reports are kept for up to a year and are not deleted when the account that filed them is deleted — the filer is anonymised instead, because erasing your own account should not erase a complaint someone else may be relying on.
Bug reports and feature requests
If you submit a bug report or feature request, Near stores the subject, the details you provide, your optional reply email, and a limited user-agent string so the report can be understood and answered. These submissions are retained for up to one year, then deleted. Near sends the submission to its moderator through Resend, an email delivery provider. Do not include passwords, invite links, precise locations, or other people’s private information in a report.
Saved games and borders across devices
Your completed round summaries and saved border presets are stored on your account so they follow you between devices. Near also keeps an account-separated device copy while that account is active, and merges it with the server copy rather than replacing either. These records contain the date, duration, game size, question count, and the playable border — never locations, notes, or ruled-out map areas. When signed out, Near does not expose that device copy until its account signs in again. If you choose to publish a border to the community, its city, name, author label, and polygon become public catalog content and may remain available after you delete your account so other players can continue using that preset.
How location is protected during a game
- A hiding player’s coordinates are never sent to seekers. The server removes them before the response leaves the server. They are not merely hidden in the app — they never arrive on the seeking players’ devices.
- Game answers are computed on the server. Radar, Thermometer, Matching, Measuring, and Tentacle questions all run server-side and return only the rule-permitted answer — such as an exact “Yes” or “No”, or the selected Tentacle place — never the underlying position, distance, or tolerance.
- Answers stay private to the hiding team until they choose to send them.
- Each team’s private map is isolated from the other team.
- Coordinates that stop updating are cleared about two minutes after the last keep-alive, so a stale position is never presented as live.
Who else receives data
Cloudflare hosts the service and stores room data.
Google Firebase Authentication handles the required sign-in and holds your credential. Near receives only a verified token.
Google Maps Platform receives the origin, destination, and requested departure time only when you request public-transit directions. If you chooseOpen Google Maps for that route, your device opens a Google URL containing the selected destination and, when available, your current origin; Google and your browser may retain those URL values.
Apple Maps serves Near’s primary street, dark, and hybrid satellite maps, ordinary place searches, game-question place catalogs, place details, and walking directions. Apple receives the map area, search/category or route request, coordinates needed for that request, and your IP address. Apple does not receive your room code, game notes, question answers, or friends list from Near.
Wikimedia may receive the public name and coordinate of a map place you select so Near can look for strongly matched, freely licensed place photos. Wikimedia also receives your device’s network request when its public thumbnail is displayed; Near sets a no-referrer policy so the room URL is not included. Near displays the supplied author, license, and source attribution and silently shows no image when identity or licensing cannot be verified.
Apple Push Notification service (APNs) delivers optional iPhone game alerts. Apple receives the device token and the short alert text required to deliver the notification. Near does not send coordinates, question answers, or room invite links to APNs.
Near has no data brokers. Nothing is sold, and nothing is shared for cross-context behavioral advertising.
Ads, and where they are not
There are no ads in the game. Not on the map, not in a room, not in a round, not while you are hiding or seeking. Near shows advertising in exactly one place: an Earn Scout Points screen in Settings, which you have to open yourself, and where each ad is one you choose to watch by pressing a button. Scout Points buy marker colours and shapes and can do nothing else — they never affect a game, cannot be transferred, and are not worth money.
Those ads come from Google AdMob, which is an advertising partner and, for the ads it serves, uses your device’s advertising identifier. Before Near requests a single ad it asks for consent through Google’s own consent flow, and where that flow applies you can change your mind at any time from the Privacy choices button on the same screen. Declining changes nothing else about the app.
Near never sends your location to an advertiser. Not your coordinates, not your route, not where you are hiding, not the stops you have passed, not your room, not your account email. Ad requests carry no location targeting of any kind, and Near does not ask AdMob to target you by place.
Near records how that one screen is used — that an ad was requested, shown, finished, closed, or unavailable, and Google’s own estimate of what an ad was worth — so the feature can be judged and the estimate can be added up. Those records are kept by Near, are attached to your account, and carry only the placement name, the ad network, a currency and amount, an outcome, and the app version. No location, no room, no email, no game data can appear in them. Outside that screen, Near still runs no analytics.
How long data is kept
| Data | Retained until |
|---|---|
| Your latest coordinate | Cleared about 2 minutes after your device stops updating, when you leave, or when the room ends |
| Room, members, questions, maps, notes | 7 days after the room is created, or immediately when the owner ends it |
| Optional room messages and sanitized photos | Deleted with the room, no later than 8 days after upload |
| Limited question geometry (such as Radar center or Thermometer reference/start/finish) | Deleted with the room, no later than 7 days after creation |
| Room map cache (place IDs, names, categories, coordinates, public photo attribution, and short-lived search/route results) | Deleted with the room, no later than 7 days after creation |
| Thermometer trip snapshots | 24 hours |
| Room session and optional Android location token hashes | Deleted with the room or when you leave |
| Optional room APNs device token | Deleted when you leave, when the room ends, or after 7 days |
| Optional account APNs device token | Until account deletion, or automatically after 90 days without an update |
| Notification choices | Until you change them or delete your account |
| Optional launch-alert subscription | New signups are immediately confirmed; legacy pending entries expire after 7 days; unsubscribed entries are anonymized after 30 days; confirmed entries remain until launch notifications are complete or you unsubscribe |
| Account-deletion security marker (one-way provider-identity hash and deletion time only) | Retained as a permanent credential-replay fence; it is not an account and cannot be reversed into the provider ID |
| Account record | Until you delete it, or after a year without signing in and with no remaining room membership |
| Friends, blocks, saved games and borders | Private records are removed when you delete your account; approved community borders remain public catalog content |
| Reports | Up to 1 year. Retained if the filer deletes their account, with the filer anonymised |
What stays only on your device
After you sign in, Near keeps an account-separated lightweight record in your own browser storage: completed round summaries (date, duration, game size, question count, and the playable border) and any border presets you saved. Those same summaries and borders sync to your account as described above. A different account on the same device cannot read this local library through Near. Neither copy includes locations, notes, or ruled-out map areas. Clearing site data or deleting the app removes the device copy.
Your controls
- Leave a room at any time. This clears your session and your coordinates.
- Room owners can remove any player, revoking that player’s session.
- Room owners can end and delete a room, erasing its live game data for everyone.
- Revoke location permission in your device settings at any time. On Android, the persistent system notice also makes active background sharing visible. The rest of the app keeps working.
- Control notification categories from Personal Settings → Notifications, and revoke iPhone notification permission in iOS Settings.
- Block or report any signed-in player from the lobby, or from the Friends page.
- Remove a friend at any time, from either side.
- Delete your account and everything attached to it from Settings or the web deletion page, without contacting anyone.
- Request a copy of your data by emailing jamestumino2@gmail.com. Include the room name and approximate time so the data can be found before it expires.
Children
Near is rated 13+ and is not directed at children under 13. It is a location-sharing game and is not appropriate for young children. Do not use Near to track a minor who is not a knowing, willing participant, and do not include a minor in a game without a participating parent or guardian.
Consent and acceptable use
Near requires every player to affirm voluntary participation before creating or joining a room, and is intended only for use among people who knowingly agreed to play. Do not use it to stalk, harass, monitor someone covertly, identify someone’s home or workplace, or track anyone who has not agreed. Sharing an invite link publicly defeats the app’s privacy model.
Safety
Near is not an emergency, supervision, or personal-safety service and must not be relied on as one. GPS is approximate and can be wrong or unavailable. Do not trespass, do not use the app while driving, and follow local laws and transit rules. Stop playing if anyone withdraws consent.
Security
Session and invite tokens are randomly generated and stored only as SHA-256 hashes. All traffic uses HTTPS. The service applies rate limits, request size limits, cross-site request protections, and standard browser security headers. No system is perfectly secure, and Near has not had an independent security audit.
Changes
Material changes will be posted here with a new effective date. Continuing to use Near after a change means you accept the updated policy.
Contact
James Tumino — jamestumino2@gmail.com