Privacy Policy for SquadCom
Effective date: August 19, 2026
Applies to: SquadCom for Android and SquadCom for iOS
Provider: Bareways
Bareways (“Bareways”, “we”, “us”, or “our”) provides SquadCom, a private peer-to-peer communication app for groups (“squads”).
This Privacy Policy explains how SquadCom accesses, uses, stores, and shares information when you use the app. It covers both the Android and the iOS version. Where the two platforms behave differently, the difference is noted inline, for example: (Android: foreground service, iOS: background mode).
SquadCom is designed so that communications occur directly between devices in a squad. Bareways does not operate a production backend that stores user accounts, chat messages, live locations, or recoverable account data for SquadCom. Because of this architecture, if a device is lost, deleted, reset, or its local app data is removed, Bareways generally cannot restore that data for you.
Even without a Bareways backend, SquadCom may still access and process information on your device and may transmit information directly to other members of your squad as part of the app’s core functionality.
What SquadCom does
SquadCom lets users create or join invite-based private squads, exchange end-to-end encrypted messages, and optionally share live location and movement status with selected squad members.
The app does not require a traditional account based on a phone number, email address, or centrally managed username.
Information SquadCom accesses and processes
Depending on the permissions you grant and the features you use, SquadCom may access and process the following categories of information. The same categories apply on Android and iOS; only the underlying system permission differs.
Messages and squad content
SquadCom processes content you create or receive in the app, including:
- text messages
- squad names and locally stored squad information
- invite information such as QR codes or invite codes
- profile information you set, such as a display name and a profile picture
- live location updates you choose to share
- movement status derived from activity recognition, where enabled
- audio you choose to record and send
- images you choose to send
This information is primarily stored locally on your device and transmitted directly to squad members as part of the features you use.
Location data
If you enable location sharing, SquadCom may access your device’s precise location and, where supported or selected, approximate location in order to:
- show your location on a shared map
- transmit your live location to members of your squad
- support ongoing location sharing while the feature is active
If you grant background location access, SquadCom may continue accessing location while the app is not actively open so that live location sharing can continue in the background (Android: the ACCESS_BACKGROUND_LOCATION permission, iOS: the “Always” location authorization).
Activity and motion data
If you grant access to motion and activity data (Android: “Physical activity” / ACTIVITY_RECOGNITION, iOS: “Motion & Fitness”), SquadCom may process activity state information such as whether your device appears to be stationary, walking, running, cycling, or in a vehicle.
This is used only for SquadCom’s core location-sharing functionality, including:
- determining whether a live location update should be transmitted
- reducing unnecessary transmissions while you are not moving
- optionally indicating movement status to squad members
SquadCom does not use activity recognition for health, fitness, medical, wellness, step-counting, or calorie-related purposes.
Audio / microphone
If you use the audio message feature in SquadCom, the app may access the microphone to capture audio that you intentionally choose to record or send.
SquadCom does not access the microphone for advertising or unrelated background profiling.
Camera
SquadCom may access the camera when you scan a squad invite QR code, and when you take a picture to use as a profile picture or to send to a squad. Camera access happens only while you actively use one of these functions. SquadCom does not access the camera in the background.
Photos and images
If you choose a profile picture or send an image to a squad, SquadCom accesses the image you select through your device’s system photo picker. SquadCom does not scan or index your photo library; only the images you pick are processed and transmitted.
Bluetooth and nearby devices
SquadCom uses Bluetooth to discover and communicate with nearby squad devices when no other network is available (Android: BLUETOOTH_SCAN, BLUETOOTH_ADVERTISE, BLUETOOTH_CONNECT, iOS: Bluetooth access, including while the app is in the background).
Bluetooth is used only for peer discovery and message transport between squad devices. SquadCom does not use Bluetooth for advertising, location analytics, or beacon-based tracking by third parties.
Wi-Fi and local network information
Where required for app functionality, SquadCom may use permissions and device capabilities related to Wi-Fi state, nearby Wi-Fi devices, multicast, or local network communication in order to discover or communicate with other devices on the same network (Android: NEARBY_WIFI_DEVICES and the Wi-Fi state permissions, iOS: the Local Network permission together with the app’s registered Bonjour service).
Device-to-device communication identifiers
Because SquadCom uses a peer-to-peer architecture, the app may process and share device-level communication endpoints needed for direct connectivity, including:
- a device’s Tor onion address, which is shared only with relevant squad members as part of direct communication
- a device’s advertised local name or similar local-network identifier when devices communicate or discover each other on the same Wi-Fi or local network
- a device’s Bluetooth advertising identity when devices discover each other over Bluetooth
These identifiers are used only to enable peer-to-peer communication and squad connectivity.
Device lock and biometrics
SquadCom can be configured to require your device’s screen lock or biometric authentication before the app can be opened (Android: BiometricPrompt, iOS: Face ID or Touch ID).
Biometric verification is performed entirely by your operating system. SquadCom receives only the result — whether authentication succeeded — and never receives, stores, or transmits your fingerprint or face data.
Operational and notification data
SquadCom may process limited technical information necessary to run the app, such as:
- notification state for incoming messages or sharing activity
- whether background components for messaging or location sharing are active (Android: foreground services, iOS: background modes and the app’s network extension)
- whether app components should restart after device reboot (Android only; iOS does not permit this)
How SquadCom uses information
SquadCom uses the information it accesses only to provide the app’s user-facing functionality, including to:
- create, join, and manage private squads
- send and receive end-to-end encrypted messages
- transmit live location to squad members when you enable location sharing
- continue location sharing in the background when you have enabled that feature and granted the necessary permission
- determine whether you are moving or stationary so the app can decide when to send location updates
- optionally display movement status, such as walking or driving, to squad members
- record and send audio that you intentionally choose to share
- scan squad invite QR codes and set a profile picture or send images you select
- discover and connect to peers over Tor, over the same local Wi-Fi network, or over Bluetooth
- deliver notifications and maintain core messaging and sharing services
- protect access to the app with your device lock or biometrics, if you enable that
We do not sell personal data or personal and sensitive user data.
We do not use data accessed through SquadCom for advertising, advertising profiling, or health-related purposes. SquadCom does not track you across apps or websites owned by other companies and does not include third-party advertising or analytics SDKs.
How information is shared
Shared with squad members
SquadCom’s core purpose is to let users communicate directly with selected squad members. As a result, information you choose to share through the app may be transmitted to members of the relevant squad, including:
- messages you send
- audio you send
- images you send and the profile picture you set
- live location, when enabled
- movement status, when enabled
- communication endpoints such as your device’s onion address, local-network advertised identity, or Bluetooth advertising identity as required for direct connectivity
This sharing is part of the service you actively use and is initiated by your participation in a squad.
Not stored on a Bareways production backend
Bareways does not operate a production backend for SquadCom that stores user accounts, central message history, or centrally recoverable live location history.
SquadCom is designed so that communications are exchanged directly between devices, including via Tor onion services and, where applicable, local-network or Bluetooth communication between nearby devices.
Because Bareways does not maintain a central account system for SquadCom, Bareways generally cannot recover deleted accounts, lost-device data, old messages, or prior squad state for you.
No promise about copies on other members’ devices
Although Bareways does not centrally store squad content, information you share with other squad members may be stored locally on their devices. Deleting data from your own device does not necessarily remove copies that have already been delivered to other squad members.
Legal Process and Disclosures
SquadCom is designed so that squad communications and shared live location are exchanged directly between users’ devices, not through a central Bareways production backend. As a result, Bareways generally does not possess users’ message content, live location history, or recoverable squad data and is generally not able to disclose such data to third parties. Bareways may disclose only limited information that it actually possesses, such as information you provide when contacting Bareways directly, if required by applicable law, regulation, legal process, or enforceable governmental request.
Data storage and retention
SquadCom is designed to store app data locally on your device, including messages, squad information, and related app state.
Because Bareways does not maintain a central production backend for SquadCom:
- deleting app data, removing the app, or losing your device may permanently remove your local data
- Bareways typically cannot restore your prior state
- data already received by other squad members may remain on their devices until they delete it
Permissions SquadCom requests
Depending on your device, operating system version, and the features you use, SquadCom may ask for the following access. Each entry lists the platform permission behind it.
- Live location sharing and map features — Android: ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION; iOS: Location “While Using the App”
- Continuing location sharing in the background — Android: ACCESS_BACKGROUND_LOCATION; iOS: Location “Always”
- Deciding when to send location updates, and movement status — Android: ACTIVITY_RECOGNITION (“Physical activity”); iOS: Motion & Fitness
- Recording audio messages — Android: RECORD_AUDIO; iOS: Microphone
- Scanning invite QR codes and taking pictures — Android: CAMERA; iOS: Camera
- Choosing a profile picture or an image to send — Android: the system photo picker; iOS: Photo Library
- Discovering and connecting to nearby squad devices over Bluetooth — Android: BLUETOOTH_SCAN, BLUETOOTH_ADVERTISE, BLUETOOTH_CONNECT; iOS: Bluetooth
- Discovering devices on the same Wi-Fi network — Android: NEARBY_WIFI_DEVICES, ACCESS_WIFI_STATE, CHANGE_WIFI_STATE, CHANGE_WIFI_MULTICAST_STATE, ACCESS_LOCAL_NETWORK; iOS: Local Network
- Notifying you about messages and active sharing — Android: POST_NOTIFICATIONS, VIBRATE; iOS: Notifications
- Locking the app behind your device lock — Android: USE_BIOMETRIC (and its legacy USE_FINGERPRINT alias); iOS: Face ID / Touch ID
- Communicating with peers over the network — Android: INTERNET; iOS: granted by default
- Checking whether a network connection is currently available — Android: ACCESS_NETWORK_STATE; iOS: granted by default
- Keeping messaging and location sharing running — Android: FOREGROUND_SERVICE, FOREGROUND_SERVICE_REMOTE_MESSAGING, FOREGROUND_SERVICE_LOCATION; iOS: background modes for location and Bluetooth, plus the app’s network extension
- Restoring app functionality after a device restart — Android: RECEIVE_BOOT_COMPLETED; iOS: not available on iOS
Some features may not work unless the relevant permission is granted. You can change every one of these later in your device settings.
On Android, the installed app additionally declares WAKE_LOCK, READ_PHONE_STATE, READ_EXTERNAL_STORAGE, and WRITE_EXTERNAL_STORAGE. SquadCom does not request these itself — they are merged into the app from third-party libraries it is built on. SquadCom never asks you to grant them and does not use the corresponding functionality.
Running in the background and network setup
To keep messages and live location flowing while the app is not in the foreground, SquadCom runs background components. How this looks on your device depends on the platform:
- Android: SquadCom runs a foreground service with a persistent notification while messaging or location sharing is active, so it is always visible to you when the app is working in the background.
- iOS: SquadCom uses system background modes for location and Bluetooth, and routes its Tor connectivity through a system network extension. iOS asks you to allow a VPN configuration named “SquadCom” for this, and your device shows a VPN indicator while it is active. This configuration is used only to carry SquadCom’s own peer-to-peer traffic over Tor. It is not a commercial VPN service, it does not route your other apps’ traffic, and no traffic is routed through Bareways-operated servers.
Background location and prominent disclosure
If you enable ongoing live location sharing, SquadCom may access your location while the app is in the background in order to continue sharing your live location with your squad. Background location is used for this purpose only, and only while you keep live location sharing switched on.
Security
According to the app’s technical design, SquadCom uses peer-to-peer communication and end-to-end encryption for squad messaging, including communication over Tor.
SquadCom additionally offers on-device protections:
- an optional app lock backed by your device’s screen lock or biometrics
- protection against screenshots and screen recording of app content, and a cover screen in the app switcher (Android: FLAG_SECURE, iOS: the equivalent secure-window protection)
No method of transmission, device storage, or peer-to-peer networking is completely risk-free. Users should share information only with squad members they trust, because information delivered to other members may remain stored on their devices.
Your choices and controls
You can generally control SquadCom’s access to sensitive device data through your device settings and in-app controls, including:
- location permissions
- background location access
- microphone access
- camera and photo access
- motion and activity access
- Bluetooth and local network access
- notifications
You can also stop sharing live location or movement status by turning off the relevant feature in the app, and you can remove the VPN configuration SquadCom created (iOS) or stop the foreground service by leaving the app (Android).
Because SquadCom does not use a centrally managed account system, traditional server-side account recovery or deletion workflows may not apply in the same way they do for account-based services.
