Temporary location sharing is useful when another person needs context for a current journey but does not need a permanent view of someone’s movements. The safest design begins with a simple rule: sharing is off until the traveller makes a current, visible choice.

Use Off when timing is enough

Location is not required for every shared journey. A destination label, entered ETA, and journey status may be enough. Off is the right choice when a map would reveal more than the situation needs or when the traveller simply does not want to share a position.

In StrideSafe, starting a walk or commute while Off does not turn location on later. Pairing also does not change that decision.

Use Approximate for a broader area

Approximate sharing can show that someone is within a general area while withholding a precise pin. This may suit a familiar commute or a meeting where street-level accuracy is unnecessary.

Client-side rounding alone is not a reliable privacy boundary. StrideSafe reduces coordinate detail and widens accuracy in Postgres before partner access. The partner response is shaped by the server rather than trusting the map screen to hide raw data.

Use Precise only when the exact latest point helps

Precise mode gives the active paired person the latest approved precise snapshot. It can help when meeting at a specific entrance or when a broad area would be confusing. It also reveals more, so the traveller should choose it deliberately and keep the current state visible.

Precise does not mean continuous certainty. GPS quality, connectivity, Low Power Mode, force-quit behaviour, and operating-system limits can affect delivery. The app should show when the latest point was captured rather than implying live perfection.

Prefer latest state over route history

A selected walk does not require a permanent coordinate trail. StrideSafe uses one replaceable latest-location row shared by commute and separately approved continuous modes. A newer approved snapshot replaces the previous one. There is no coordinate route-history table.

Journey metadata such as label, timing, status, and consent state can remain until account deletion. That metadata is not a coordinate route. Private workout paths read from Apple Health are opened only on the wearer’s iPhone and are not uploaded or shown to a partner.

Make reduced-access actions win

Networks can deliver messages out of order. A delayed “start” or “update” must not re-enable location after a newer Pause, Stop, revoke, sign-out, deletion, arrival with auto-end, or journey end. StrideSafe uses ordered, idempotent commands so privacy-reducing actions beat delayed older messages.

When a commute location is more than five minutes old, StrideSafe labels it stale and omits coordinates from the stale partner response. Distinct Off, Paused, Unavailable, Revoked, Arrived, Ended, and Stale states help the viewer avoid treating uncertainty as a current position.

Questions about this topic

Is approximate location just rounded on the phone?

No. StrideSafe also reduces detail server-side before partner access, so the phone display is not the only privacy boundary.

Does StrideSafe automatically stop at the entered ETA?

No. The ETA is entered context, not a guaranteed timer. The traveller can stop, end, revoke, sign out, delete, or use arrival with auto-end enabled.

What happens to an old location?

For an active commute, a location older than five minutes is labelled stale and is not returned as a current coordinate.