> We then fuzz the location on the server.
Why not fuzz it on the device, before sending to the server?
> All data is stored in the United States, and has always been.
Why not just amend your Privacy Policy to state that data is only stored in the United States? Anything less, such as this nonbinding account of what you've historically done, strikes me as hand-waving and not fully above-board. It's like you acknowledge this is a legitimate concern, decline to formally commit to anything, but tell people a truth (or at least true at this moment) you think they want to hear, hoping they'll feel like the concern was resolved.