Description
Where is a cross-platform, end-to-end encrypted realtime location sharing app.
Where is designed so the server learns as little as possible:
* No accounts. Identity is a device-scoped ephemeral key pair — no usernames, email addresses, or persistent IDs.
* End-to-end encrypted by default. Location payloads are encrypted with a Double Ratchet protocol before they leave the device. The server routes opaque ciphertext and cannot read coordinates.
* No social graph. Routing uses pairwise anonymous tokens; the server cannot reconstruct who is sharing with whom.
* Forward secrecy. Automated keepalives advance the ratchet even when only one party is sharing, so past sessions cannot be decrypted if a key is later compromised.
This build uses MapLibre and Android's built-in location APIs instead of Google Maps and Play Services. Map tiles are fetched from tiles.openfreemap.org, which sees the map area you view (but not your identity or shared locations).
What’s new (2026.09.19.1)
Fixed error conditions on devices that don't support location.
Anti-features
Properties of this app that are worth knowing about before installing.
- TetheredNet
Versions
Permissions
What the app asks the system for. Android only grants sensitive access after you confirm it.
- Internet accessSend and receive data over the internet.
- CameraTake photos and videos.
- Precise locationDetermine the location via GPS.
- Approximate locationDetermine the location via the network.
- Location in backgroundDetermine the location while the app is not open.
- Foreground serviceKeep running in the background, visible in the status bar.
- FOREGROUND_SERVICE_LOCATION
- NotificationsShow notifications.
Show 5 more permissions
- Run at startupStart automatically after the device is switched on.
- Prevent sleepingKeep the device from going to sleep.
- Network stateCheck whether and how the device is connected.
- Wi-Fi stateRead information about the Wi-Fi connection.
- where.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Comments