This text (14 September 2026) is being reviewed by Roadby's legal adviser before it is published as final. It may change without notice and should not be taken as the final version.
Privacy policy
This document explains what data Roadby handles: both in the mobile app and on this website (roadby.app). It is a single document in two parts because Google Play requires one public privacy policy address for the app, and it seems more honest to us that the same address also explains what the website itself does.
Who is responsible
The personal data described in this document is controlled by the operator of Roadby (“we”, “us”), who decides why and how it is processed. Within Roadby, access to that data is restricted to the minimum number of people needed to run the service.
[To confirm before publishing] Legal name, tax number and postal address of the operator of Roadby, as data controller. In the meantime, the valid contact channel is support@roadby.app.
A. Data the Roadby app handles
Roadby is an app for drivers: it connects people who are physically close to each other by live voice. What follows describes, in as much detail as possible, what data each part of the app generates, where it ends up and for how long.
A.1 Account
To use Roadby you create an account with your email address, a password, a name and an @username, and you confirm your email through a single-use link. There is no sign-in with Google, Apple or social networks, and no two-factor authentication.
- Your email is used as the account identifier and only you (and Roadby's administrators) can see it; it is never shown to other users.
- Your password is stored as a hash (irreversibly encrypted): nobody, not even Roadby's administrators, can read it.
- To change your email, change your password or delete your account, we ask for your current password again.
- We store the dates you signed up, confirmed your email and last signed in.
- For each session and each sign-in, the authentication system records your IP address and the type of device or browser, in a log of access events (sign-up, sign-in, changes, deletion). The technical logs of the platform we use (Supabase) and of the voice server (LiveKit) also contain the IP address of each connection, as in any internet service.
A.2 Public profile and photo
Your profile has exactly these fields: display name, @username, an optional bio (up to 80 characters) and an optional photo. We do not ask for your age, phone number or anything else.
- These people see your card (name, @username, bio, photo): anyone in range of you on the radar (see A.3), your friends, anyone who has sent you or received from you a friend request, anyone who has you in their history, anyone who has blocked you (in their blocked list, so they can unblock you) and any user who knows your @username.
- Anyone, even without an account, can check whether an @username exists (they do not get your card).
- Opening someone else's profile also shows a few counters: how many friends they have, how many friends you have in common, their total time in lobbies and how many people they have met. All of those are frozen to the previous day (they only count what happened before 00:00 today) so that nobody can work out in real time where someone is or who they are with. The time the two of you have shared is up to date, because it is time you lived yourself.
- Your profile photo is stored in a public file bucket: anyone with its address can view it without signing in, even if you block them afterwards. It is deleted when you delete your account or replace it with another. There can only be one photo, and today it cannot be removed without replacing it.
Automatic photo filter. When you upload a profile photo, we send it to Google Cloud Vision's SafeSearch API (Google LLC) for an automatic check for explicit content, through the service's European endpoint. Google's contractual commitment on data residency for Cloud Vision covers only the text recognition feature, so we cannot guarantee that this analysis is processed solely within the European Union. Google returns a probability across five categories (adult, violent, medical or racy content, and spoofed or manipulated images); Roadby only rejects a photo if Google flags adult or violent content at its highest level, and we do not request any other analysis feature (labels, faces, text). If a photo is rejected, all that remains in the server's technical logs is Google's verdict, without the image and without your account identifier. If the filter is unavailable (a failure or missing configuration), the photo is published without being analysed and a record of that, also without identifying you, is left in those same logs. To limit abuse, the server keeps a counter of upload attempts per account per day (5 maximum): a single row with the date and the number of attempts from the last day you tried to upload a photo, which is overwritten on the next attempt and deleted with your account.
A.3 Location
This is the most sensitive data in the app and the one we take most care over:
- Your position is only captured while the app is on screen and you are signed in, with the “while in use” location permission; we never ask for background location. There is one exception: if you are in the voice lobby and you lock your phone, the app keeps resending your last known position every 20 seconds (frozen, not updating) so the conversation is not cut off; when you leave the lobby you disappear from the radar.
- Your exact position travels encrypted to the server and passes through it before being stored; before being written, it is rounded to a grid of roughly 50 metres. We only store your last position: there is no location history of any kind.
- That position expires after 5 minutes, and stops being visible to others after 45 seconds without an update.
- Another person never receives your position, your distance or your direction. As for your location, their app only receives two things: that you are in range, meaning that the circle of your radius and the circle of theirs overlap, or that the gap between them is smaller than a margin of 50 to 100 metres (a tenth of the two radii added together, never less than 50 metres); and a volume level in four steps (full, three quarters, half and a quarter): full while your circles overlap, whatever the distance between you, and through the first quarter of the margin, then lower step by step across the rest of it. Past the margin you disappear from their radar.
- The server discards impossible positions (jumps that no vehicle could make) and only accepts the allowed radii (100, 300 or 500 metres).
A.4 Voice
- The voice lobby is provided by LiveKit Cloud. There you are identified by a random code per session, unconnected to your account, your name or your email.
- Voice is live and is never recorded, exported or transcribed at any point.
- Only the people in range at that moment can hear you (see A.3): at full volume while your circles overlap and through the first quarter of the margin, then more quietly further into it. Nobody you have blocked, or who has blocked you, can ever hear you; in Friends mode, only your friends can.
- On Android, while you are in the lobby, a foreground service with a persistent notification (“Roadby · Lobby active”) keeps the microphone open even if you lock the screen. It closes when you leave the lobby.
A.5 Friends, requests and blocks
- Friend requests stay visible to sender and recipient until they are accepted, declined or cancelled.
- To cap sending at 50 requests a day, the server keeps an internal record for 7 days of who sent each request and to whom; it is not shown to anyone.
- Friendships only show a counter to third parties, never the list.
- If you block someone, that person does not know: the app answers them as if your account did not exist. Blocking is immediate and mutual: you stop seeing each other on the radar, in the lobby, in your history and in notifications. You can undo it from Settings › Account › Blocked users.
A.6 Shared-time history
For each pair of users we store the accumulated seconds you have spent together in a voice lobby; never the place, the date of each encounter or the content of the audio. It is a single row shared between the two of you: if one deletes their account, the other also loses that time from their history; if you block someone, the row is not deleted, it is hidden for as long as the block lasts. Today it is not possible to delete individual entries from your history without deleting your whole account.
A.7 Reports
You can report another user for harassment, hate speech, dangerous driving, spam or another reason. The report is anonymous to the person reported, but not to Roadby's administrators, who can review it. If you delete your account, the reports you filed are kept in anonymised form; if the reported person's account is deleted, the reports against them are removed.
A.8 Push notifications
Roadby only sends two kinds of notification: that someone has sent you a friend request, and that someone has accepted yours. To deliver them we use a technical token from your device (through Expo and, on Android, Google's Firebase Cloud Messaging). The text of the notification includes the display name of the person sending or accepting the request, and it passes through those two services; it never includes your photo, your @username or your location. We keep a record for 30 days of who notified whom (kind and time), solely to limit notifications to one per person, kind and day.
A.9 Account emails
We send emails to confirm sign-up, recover your password and change your email address, through our authentication provider (Supabase) using Resend as the sending server, from no-reply@mail.roadby.app.
A.10 News and offers emails (optional)
At sign-up there is an optional checkbox, unticked by default and separate from the mandatory one with which you accept the terms of service and this privacy policy: “Email me Roadby news and offers”. If you tick it, we store that yes with its date; every time you switch it on or off afterwards, we also store that change with its date. Each entry also records where it was made (sign-up, the app's settings or the unsubscribe link of an email) and which version of the wording you saw, so we can show what you consented to and when. You can change your mind at any time from Settings › Account › “News and offers by email”. We only write to confirmed email addresses, and only Roadby's administrators can extract the list of recipients. The provider these emails would be sent through is [to be determined: it will be named here as soon as one is chosen]; none has been sent to date.
A.11 What stays on your device
The radar, your friends, your history and the rest of the information in the app live in memory and disappear when you close the app or sign out. Your session tokens (which include your email and your account identifier) are kept in the app's private storage and are deleted when you sign out or delete your account, and the cropped photo may stay in the temporary cache until the system clears it. Device settings (chosen radius, lobby mode, audio mode) are stored locally: they survive signing out, as they belong to the device and not to the account, and are reset to their defaults when you delete your account from that device.
A.12 Who we share data with (processors)
| Provider | What we use it for | Head office | Where the data is processed |
|---|---|---|---|
| Supabase Inc. | Database, authentication, photo storage and server functions. | United States | Database and photos: Frankfurt (European Union). Server functions: [to confirm the region where they run]. |
| LiveKit Inc. (LiveKit Cloud) | Live voice lobby. | United States | The data centre closest to each user; on our current plan it cannot be fixed [to confirm]. |
| Expo (650 Industries, Inc.) | Building the app and delivering push notifications. | United States | United States. |
| Google LLC (Firebase Cloud Messaging) | Delivering push notifications on Android. We do not use Google Analytics or Crashlytics inside the app. | United States | United States. |
| Google LLC (Cloud Vision) | Automatic content filter for profile photos (see A.2). | United States | European endpoint of the service; Google does not contractually guarantee that this analysis stays within the European Union. |
| Google (Google Play services, on your phone) | They resolve the GPS position the app asks for, as in any Android app; this is outside Roadby's control. | United States | On your own phone. |
| Resend Inc. | Technical sending of account emails. | United States | United States. |
Where a provider has its head office or processes data outside the European Economic Area, there may be an international transfer of data. [To confirm with our legal adviser before publishing: the safeguard mechanism that applies to each provider, for example standard contractual clauses.]
A.13 What Roadby does not do, and what permissions it asks for
The app uses no analytics, advertising or tracking tools of any kind; it does not access your contacts or the camera (the camera permission is blocked in the app); it only opens the system photo picker when you choose a profile photo, and it only receives the image you select; it never records, stores or transcribes voice; and it does not request or use your location in the background (with the single exception described in A.3). The sensitive permissions it declares are: location while in use, microphone, notifications, Bluetooth (for your car's hands-free kit) and a microphone foreground service while you are in the lobby. The rest are technical and give no access to personal data (internet, network state, audio settings and keeping the device awake), and on older versions of Android the system photo picker may add the gallery read permission it needs in order to work.
B. Data this website handles (roadby.app)
This part covers only the public site you are reading now: the home page (which holds every section — how it works, privacy, help and news — plus the donation window), this policy, the terms and the cookie policy. It shares no systems with the mobile app.
B.1 Cookies and measurement
Before you accept anything, we only use what is strictly necessary for the site to work (for example, remembering your choice about cookies, stored in your browser). Only if you expressly accept in the cookie notice do we switch on:
| Category | What for | Provider |
|---|---|---|
| Analytics | Understanding how many people visit the site and which pages they use (Google Analytics 4). | Google, through Google Tag Manager |
| Advertising | Measuring how future Google Ads campaigns perform (conversion tag). It does not enable personalised ads or remarketing. | Google, through Google Tag Manager |
Until you accept, this website loads no Google script and sends Google nothing (Google Consent Mode v2 in basic mode). Your decision is stored in your browser along with its date; we will ask you again after 24 months, or sooner if the categories change. You can change it whenever you want from the cookie button in the corner of any page, or from “Cookie preferences” at the bottom of it.
The cookie policy lists every cookie by name, with what it is for, how long it lasts and who stores it.
B.2 Donations
The buttons in the “Buy us a coffee” window take you to external platforms (for example Ko-fi, Buy Me a Coffee or PayPal). Roadby neither receives nor stores any payment data: that relationship is directly between you and the platform you choose, under its own privacy policy.
B.3 Newsletter
The sign-up form has a single purpose: to send you Roadby news by email. By signing up you are asking to receive it, and we use your email address for nothing else. The form has one required tick box, unticked by default, with which you confirm that you have read this policy and accept the terms of service. Your tick is stored with an identifier of the exact wording you agreed to (terms-web-v1), so that it can be shown later.
We send the newsletter on the basis of your consent (Article 6(1)(a) GDPR), which you give by signing up and confirming your address. You can withdraw it at any time by unsubscribing; doing so does not affect the emails sent before.
Your email address, that record and a note that you signed up on roadby.app are stored with the email provider we use to send the newsletter [to be determined: it will be named here as soon as one is chosen]. That provider sends you a confirmation email first, and you are only added to the list once you follow the link in it. You can unsubscribe at any time from the link in any email we send you. This list is separate from the news checkbox in the app itself (section A.10).
B.4 Help and contact
If you write to us at support@roadby.app or from the Help section of the home page (the “Email support” button), we handle your email address and the content of your message solely in order to reply to you.
How long we keep data
- Account, profile, photo, friendships, blocks and history: for as long as your account exists, or until you undo them.
- Reports: those you receive are deleted with your account; those you file are kept in anonymised form.
- Consent to news emails: for as long as your account exists, with the date of the yes and, if you withdraw it, the date of the withdrawal.
- Last position: up to 5 minutes.
- Voice session: until you leave the lobby, with a maximum of 1 hour without renewal.
- Internal record of friend requests sent: 7 days.
- Record of notifications sent: 30 days.
- Photo upload counter: one row per account with the date and attempts from the last day you tried to upload a photo; it is overwritten on the next attempt.
- Record of your changes of consent to news emails: for as long as your account exists.
- Device notification token: 60 days without use, or when you sign out.
- Sessions and the access audit log, and database backups: according to the provider's retention (Supabase) [to confirm in their dashboard before publishing].
- Newsletter email address: until you unsubscribe.
- Analytics or advertising cookies: as listed one by one in the cookie policy, and always revocable from the cookie button in the corner of the page or from “Cookie preferences” at the bottom of it.
What happens when you delete your account
The only route is Settings › Account › Delete account, typing your current password; nobody can delete anyone else's account. The effect on the database is immediate: the account is deleted and, in cascade, so are the profile, the position, the voice session, requests, friendships, blocks, history (for the other person in each pair as well), notification tokens, the notification record, the internal record of requests sent, the photo upload counter and the record of your consent to news emails; the photo is then deleted from the bucket. What survives deletion: the reports you filed, anonymised; the access audit log of the authentication system (account identifier, action and IP address) and backups, for as long as the provider's retention period lasts [to confirm]; local settings on any other phone where you had signed in (the one you delete from resets them); and the notification token already known to Expo and Google, who are not sent any instruction to forget it.
Your rights
You can access your data, ask us to correct it, ask us to delete it, object to a particular use, or ask for portability of whatever is technically possible. Today you can do so as follows:
- Access: the essentials are visible in the app (profile, email under Change email, friends, blocked users and history); for the rest (sign-up date, reports you filed, registered devices, technical logs) or for a full copy, write to us and we will prepare it by hand.
- Rectification: directly in the app, under Edit profile, Change email and Change password.
- Erasure: Settings › Account › Delete account, in the app.
- Objection and restriction: operating system permissions, blocking users, Friends mode and the “News and offers by email” switch.
- Any other request (including portability or unsubscribing from the newsletter): by writing to support@roadby.app; we handle it manually.
You also have the right to complain to the Spanish Data Protection Agency (aepd.es) if you believe we have not handled your request properly.
Minors
[Pending product and legal decision] Today the app does not ask for your age or verify that whoever signs up is an adult. Roadby is intended for adults; this section will be completed with the exact minimum age and, if appropriate, a verification mechanism, before the final version is published.
Security
All information travels encrypted (HTTPS/WSS). Passwords are stored as hashes; the most sensitive tables (location, voice, reports, tokens) are not readable even by their own owner from the app, only through server functions with fixed rules. Administrative access is limited to the minimum number of people needed to run the service.
Changes to this policy
If we make a significant change to this document, we will update the date shown at the top and, when the change is important, we will also give notice inside the app.
Contact
For any question about this policy or about your data: support@roadby.app.