Privacy policy

Last updated: 17 September 2026

The short version

1. Who we are

Halfway is an app for meeting up with friends, made by Justin Frank, an individual developer based in the United Kingdom. Justin is the data controller for the personal data described here.

For any privacy question or request, email privacy@halfway.fyi.

This policy covers the Halfway app for Android and this website, halfway.fyi.

2. What we collect and why

Your phone number

You sign in with your phone number, and we verify it by sending a one-time code by text message. Your number is held by our sign-in provider, Firebase Authentication (Google). On our own servers we store a hashed (scrambled, one-way) version of your number instead of the number itself, and use it to identify your account.

Legal basis: necessary to provide the service you asked for (contract).

Your contacts

If you allow access to your contacts, the app hashes the phone numbers in your address book on your phone and sends only those hashes to our server, to find out which of your contacts use Halfway. We don’t store the hashes you send, and your contacts’ names and other details never leave your phone.

Legal basis: necessary to provide the service; you control this through the contacts permission.

Your location

Halfway’s main purpose is to help you and a contact walk towards each other. When you share your location with a contact, it’s encrypted on your phone so that only that contact can read it. It travels directly between your phones where possible, otherwise through a relay or our server, and neither we nor the relay can read it.

To draw directions on the map, the app also sends route requests containing start and end coordinates to our server, which passes them to our mapping provider, Mapbox. These requests are not end-to-end encrypted (see section 3). Our server handles them only while working out the route, and doesn’t store or log them.

Legal basis: necessary to provide the service; you control this through location permissions and each contact’s sharing settings.

Your display name

The name you choose is stored on your phone and shared with contacts you interact with. When you ask to meet someone, it’s also included in the notification they receive (for example “Sam wants to meet you”).

Legal basis: necessary to provide the service.

Account and device data

Legal basis: necessary to provide the service.

Crash reports

If the app crashes or hits an unexpected error, a report is sent to Firebase Crashlytics (Google). It includes technical details such as the error, app version, device model and operating system. Reports are not linked to your account or phone number.

Crash reporting is on by default. You can turn it off at any time in Settings → Send crash reports. Nothing more is sent after that, and any reports still waiting on your phone are deleted.

Legal basis: our legitimate interest in keeping the app working and fixing bugs. You can object at any time by turning the setting off.

Technical and security logs

Like most online services, our servers record basic technical information such as IP addresses and request details, to keep the service secure, prevent abuse, and troubleshoot problems.

Legal basis: our legitimate interest in running a secure and reliable service.

What we don’t collect

No advertising identifiers, no analytics or tracking SDKs, and no sale or sharing of your data for advertising.

3. What is and isn’t encrypted

All connections to our servers use encryption in transit (HTTPS). On top of that:

DataEnd-to-end encrypted?Who else can see it
Live location shared with a contactYesNobody except that contact
Route requests (start and end coordinates)NoOur server and Mapbox, to calculate directions. Not stored or logged by us.
Meet-up notifications (includes your display name)NoOur server and Google’s notification service, to deliver them
Which accounts are connected and whenNoOur server, which needs this to route messages between you and your contacts
Your phone numberNoFirebase Authentication (Google). Our server stores only a hashed version.

4. Location in the background

If you give Halfway permission to use your location “all the time”, it can share your location when the app is closed or not in use, but only in these cases:

Background location is never used for advertising or anything unrelated to meeting up. Ghost mode pauses all sharing.

5. Service providers

We use these providers to run Halfway. They process data only on our behalf, or as described in their own privacy policies:

ProviderWhat forData involved
Google (Firebase Authentication, Cloud Messaging, Crashlytics)Sign-in, notifications, crash reportsPhone number, push token, notification content, crash reports
MapboxMaps and directionsRoute coordinates and map requests. We’ve turned off Mapbox’s telemetry, so the map doesn’t send usage or location data to Mapbox for its own purposes.
CloudflareRelaying connections between phones when a direct connection isn’t possibleEnd-to-end encrypted data only; Cloudflare can’t read it
IONOS (Germany)Server that routes internet traffic to our systemsEncrypted traffic passing through, IP addresses

Our own servers are in the United Kingdom.

6. International transfers

Some providers, including Google, Mapbox and Cloudflare, may process data outside the UK and European Economic Area, for example in the United States. Where that happens, they rely on recognised safeguards such as standard contractual clauses, the UK International Data Transfer Agreement or addendum, or the EU–US Data Privacy Framework.

7. How long we keep data

DataHow long
Account (hashed phone number, public key, push token)Until you delete your account
Phone number sign-in record (Firebase)Until you delete your account
Encrypted location updates on our serverOnly the latest update between you and each contact is kept, replaced each time a new one arrives, and removed when either account is deleted
Route requests and contact lookupsNot stored
Crash reports90 days
Technical and security logsOnly as long as needed for security and troubleshooting
BackupsUp to 30 days, after which deleted data is gone from backups too
Data on your phoneUntil you delete your account in the app or uninstall it

When you delete your account, your data is removed from our live systems straight away, and from backups within 30 days. Your contacts’ phones may still show your name or the last location you shared with them, because that’s stored on their devices.

8. Your rights

Under UK and EU data protection law you have the right to:

To exercise any of these, email privacy@halfway.fyi. We’ll reply within one month, and may need to confirm the request is really from you.

You can also complain to a data protection authority. In the UK that’s the Information Commissioner’s Office. In the EU, it’s the authority in your country.

9. This website

halfway.fyi uses no cookies, analytics or tracking.

10. Children

Halfway is for people aged 16 and over. We don’t knowingly collect data from anyone younger. If you think a child under 16 is using Halfway, contact us and we’ll delete their account.

11. Changes and contact

If we make significant changes to this policy we’ll let you know in the app or on this page before they take effect. The date at the top shows when it was last updated.

Questions? Email privacy@halfway.fyi.