Outpost — by NomadSorted

Privacy Policy

Outpost is built to keep your travel history on your phone. This page says exactly what stays there, what leaves, and who sees it.

Last updated 4 September 2026. Applies to the Outpost Android application.

The short version. Outpost has no account, no login and no server that stores your data. Your trips, visas, documents, contacts and day counts are written to your own device and nowhere else. We cannot read them, because they never reach us. There is no analytics SDK, no advertising SDK, and no third-party tracking in the app.

What stays on your device

All of the following is stored locally, in the app's private storage, and is never transmitted anywhere by Outpost:

Uninstalling the app deletes all of it. There is no copy held elsewhere to delete. The one thing that is held elsewhere, if you switch it on, is the location beacon's trail — see Location below. Uninstalling the app does not remove points already uploaded to your endpoint.

Location

Outpost requests location permission, including background location, for one optional feature: the location beacon. The beacon is off unless you turn it on, and the app works without it.

What the beacon does

When you enable it, the app records your GPS position roughly every fifteen minutes, keeps a trail of recent points on your device, and uploads each point to an endpoint address that you supply in Settings. The purpose is that if your phone dies or you go missing, the last uploaded point is a starting place for someone looking for you.

We do not receive your location. The beacon posts to whatever URL you configure — your own server, or a service you have chosen. NomadSorted operates no location-collection service and has no access to that endpoint or its contents. If you configure nothing, nothing is uploaded.

Location used without leaving the device

Your last known position is also used locally to decide which natural hazards are near enough to show you on the Travel Safety screen. That comparison happens on the phone.

Turning it off

Switch the beacon off in the app, or revoke location permission in Android Settings. Either stops collection immediately. Clearing the trail in the app deletes the stored points.

Network requests the app makes

Outpost reads several public feeds so it can show current information. These requests carry no account identifier and no personal data. Where a request needs a location — for a weather or sea forecast, or to look up a place you typed — the coordinates for that lookup are sent, and nothing else.

ServiceWhyWhat is sent
GDACS (gdacs.org)Active natural hazardsNothing. A plain request for the worldwide event list.
Smithsonian GVP (volcano.si.edu)Weekly volcanic activityNothing.
US State Department (travel.state.gov)Travel advisoriesNothing.
travel-advisory.infoAdvisory fallbackNothing.
Open-MeteoWeather, sea conditions, place lookupThe coordinates or place name being checked.
open.er-api.comCurrency ratesNothing.
Your beacon endpointOnly if you enable the beaconYour GPS position and timestamp, to the address you set.

Each of these providers will see the network request, including the IP address it came from, as is the case for any internet request. We do not control and are not responsible for their handling of that; consult their own privacy policies.

What Outpost does not do

Sharing you initiate

Some features hand information to another app at your explicit request — sending a check-in message, opening a hazard's coordinates in a map, or dialling a number. Outpost passes that content to the app you choose. What happens next is governed by that app, not by us.

Notifications and alarms

The app schedules local notifications on your device for visa deadlines and missed check-ins, including a loud alarm if you enable the safety watch. These are generated on the phone. No push service is used and no message passes through our servers.

Security

Your records are held in the app's own private storage, which Android keeps isolated from other apps, and are protected by whatever lock you set on the phone itself. There is no NomadSorted account, no NomadSorted server holding your data, and therefore no database of users for anyone to breach.

The practical consequences are worth being plain about. Anyone who can unlock your phone can read what is in the app, and if you lose the phone without an export, the records listed above are gone with it — use the export in Settings if that matters to you.

The location beacon is the deliberate exception, and the exception is the point. Its positions are uploaded to your endpoint precisely so that they outlive the phone: a trail that vanished with a lost, broken or dead handset would be useless for finding you. Those uploaded points sit on the server you chose, under your control and your responsibility — securing that endpoint, restricting who can read it, and deleting the points when you no longer want them are all yours to do, because we cannot reach it. Choose an endpoint accordingly: a URL holding a record of where you have been is worth protecting.

Requests the app makes to the feeds listed above travel over HTTPS, and a beacon endpoint must be an https address.

International transfers

Your travel history, visas, accounts, contacts and day counts are not transferred anywhere. They stay on your device, so there is no cross-border transfer of them to describe.

Two things do cross a network, and both are listed above. The public feeds the app reads are operated by third parties in various countries, and they receive the request and its IP address as any website would; where a forecast needs coordinates, those coordinates are sent. If you turn the beacon on, your positions go to the endpoint you configured — you choose that server and where it sits, and no copy comes to us.

Children and young people

Outpost is for adults managing their own tax, visa and travel-safety affairs. It is not directed at children or young people, and we do not knowingly collect information from anyone under 16.

We use 16 rather than the 13 some services apply. The GDPR sets 16 as its default age of consent, letting individual member states lower it, and Outpost is used across many of them; rather than track which threshold applies where, we hold to the higher one everywhere. In practice the question rarely arises, because there is no account to create and nothing is collected about a user at all — but where it does arise, 16 is the line.

Your rights, in practice

Because your data never reaches us, requests to access, correct, export or delete it are things you carry out yourself, immediately, without asking anyone:

If you have enabled the beacon, deleting the points already uploaded is a matter of deleting them at your own endpoint, which only you can reach.

Changes

If this policy changes, the date at the top changes with it, and a material change will be noted in the app's release notes.

Contact

Questions about this policy: privacy@nomadsorted.com