Wbijam Privacy Policy
Effective date: July 20, 2026
This policy describes data processed by the Wbijam app, wbijam.app, and related services. Wbijam uses data needed to operate accounts, arrange meetups, keep the service safe, handle reports, and improve the product. Contacts access, profile photos, and map pins are optional.
We currently do not sell data, display advertising, or use data to track users across other companies’ apps and websites for advertising. This describes how Wbijam works now; it is not a promise that the product model can never change. Before changing how data is used, we will update this policy and complete any steps required by law or store rules, including obtaining consent where required.
The Polish version at wbijam.app/prywatnosc is binding. This English version is provided for convenience.
1. Controller and contact
The controller is Damian Mikła, operating as Workflows Lab, ul. Jana Pawła Woronicza 15/72, 02-625 Warsaw, Poland, Polish tax ID (NIP) 5214091072 and REGON 529999652.
For privacy matters and rights requests, contact kontakt@wbijam.app.
2. Data we process
Account and profile
- phone number, login code, and session token;
- name or nickname, optional surname, grammatical form of address, and optional profile photo;
- account ID, visibility settings, cities, idea preferences, notification preferences, mutes, and blocks.
Profile photos are stored in a private Supabase Storage bucket. The app issues a temporary photo link only when your visibility settings allow that person to view the profile. The link expires, but it can still be forwarded while valid, so do not add a photo you do not want to share with people who can view your profile.
Proposals, replies, and community safety
- meetup proposals, invited people, replies, counter-proposals, and plan status;
- place, date, time, and duration;
- an optional precise map pin (latitude and longitude) if you choose “Pin on map”;
- feedback sent to the creator and reports about content or a user;
- invitation codes and links, blocks, and data needed for moderation and abuse prevention.
Invited people can see the proposal, replies, and precise pin. Anyone holding a valid invitation link may open the related proposal and reply; recipients can forward that link.
Location and place search
When you open the map picker, the app may request one-time foreground location access to center the map. We do not store the current position used only for centering on our servers. If you confirm a point, we store the selected coordinates with the proposal. You can deny access and select a place manually.
A place-search query may be sent to the OpenStreetMap-based Photon service and, if no result is found, to the Apple or Google system geocoder. The provider may receive the query, approximate map context, IP address, and connection data under its own terms. Wbijam stores the place text and confirmed pin with the proposal, but does not maintain a separate place-search history.
Contacts and finding friends
If you allow contacts access, the app reads names and phone numbers from the address book. Normalized numbers and contact labels are sent over an encrypted connection to our server. The server creates an HMAC digest and compares it with Wbijam accounts.
For every imported number, including a person without an account, we retain the HMAC digest and the address-book label for up to 365 days after the most recent import. This supports “joined later” notices and directional friend discovery under visibility settings. We do not store a non-user’s raw number in the matching table, but we still treat the digest as personal data because we can compare it with a number using our secret key.
Contacts access is optional. Without it you can add people using a code, QR code, or link. Wbijam does not send SMS messages or invitations to contacts by itself. Revoking the OS permission stops further reads; existing digests expire 365 days after the last import. You can also remove earlier matches using “Forget” features in the app or by contacting us.
Device, notifications, and technical logs
- a random installation ID, Expo Push token, platform, and account association;
- technical notification-delivery status, including ticket ID, error, and push-service response;
- IP address, request time, and data needed to rate-limit login attempts, prevent spam, and diagnose failures;
- device model, OS/app version, crash data, and performance data.
Notifications are delivered through Expo and either Apple Push Notification Service or Firebase Cloud Messaging. You can disable notifications in device settings.
Product analytics and diagnostics
Our servers record events needed to evaluate the product, such as app open, onboarding completion, proposal sent, invitation link used, person added by code, tutorial progress, and feedback sent. Events may include a technical action name, recipient count, proposal mode, OS language and country, and the domain from which the app was opened. They do not include proposal text or a full invitation link.
We also use Sentry for error reports and some performance data. We disable default personal data, remove user identity, and strip query parameters from URLs. These safeguards minimize data, but a technical report may still include device, OS, and screen-sequence information.
wbijam.app
If you join the waitlist, we process your email address. The site also records a landing-page event not linked to an account, containing the path and referring domain. Cloudflare and our server may process IP addresses and technical connection data in security logs. The site does not set its own advertising cookies.
3. Purposes and legal bases
| Purpose | Example data | Legal basis |
|---|---|---|
| Account creation, login, and Wbijam features | phone, profile, proposals, replies, settings, confirmed map pin, push token | Art. 6(1)(b) GDPR — performance of a contract |
| Optional address-book matching and friend discovery | numbers, labels, HMAC digests, matches | Art. 6(1)(b) GDPR for the person requesting the feature; Art. 6(1)(f) GDPR for other people’s data — legitimate interest in providing expected friend discovery, subject to the safeguards in section 4 |
| Security, abuse prevention, and moderation | IP, login attempts, blocks, reports, content needed to review a report | Art. 6(1)(f) GDPR — protecting the service and users and establishing or defending claims |
| Product stability and improvement | usage events, diagnostics, performance data, feedback | Art. 6(1)(f) GDPR — developing a safe and useful service |
| Launch notice after waitlist signup | Art. 6(1)(a) GDPR — consent | |
| Legal obligations | data required in a specific matter | Art. 6(1)(c) GDPR |
You may object to processing based on legitimate interests. We will assess your situation and stop unless overriding legitimate grounds apply or the data is needed for legal claims.
4. Information for people in someone else’s address book
If you do not have a Wbijam account but a user has your number and imports contacts, the source of the data is that user. We receive the number and contact label, then retain the HMAC digest and label for up to 365 days after the latest import. The purpose is directional friend discovery if you later join Wbijam. We do not contact you or send an invitation ourselves.
The legal basis is the legitimate interest described in section 3. You may ask for access, object, or request deletion of the digest by writing to kontakt@wbijam.app and identifying the relevant number. We publish this notice here also because the imported number is the only contact detail available to us and we do not use it to send unsolicited notices.
5. Recipients
As needed to operate the service, data may be received by:
- people you invite and holders of a valid proposal link;
- Supabase — EU-region database, server functions, and Storage;
- SMSAPI.pl — SMS login-code delivery;
- Expo, Apple, and Google — notification tokens and delivery data;
- Sentry — minimized diagnostics and performance data;
- Cloudflare — website hosting, DNS, protection, and technical logs;
- Photon/komoot and Apple or Google — place search, geocoding, and maps when used;
- public authorities or advisers where required by law or necessary to protect rights.
We do not sell data and currently do not provide it to advertising networks. Providers may act as our processors or as independent controllers for parts of their services under their own terms.
6. Transfers outside the EEA
The main app database is hosted in an EU region. Some providers, particularly Apple, Google, Expo, Sentry, Cloudflare, and Supabase, may process data outside the European Economic Area. Depending on the provider, safeguards may include adequacy decisions such as the EU–US Data Privacy Framework, Standard Contractual Clauses, or other GDPR mechanisms.
7. Retention
- account, profile, proposals, replies, settings, and linked push tokens — until account deletion or earlier removal of the item;
- profile photo — until removed, replaced, or the account is deleted;
- imported-contact digests and labels — up to 365 days after the last import, until “Forget” is used, an objection is upheld, or the importing account is deleted;
- SMS codes — for the short verification and anti-abuse period; an active code expires within minutes;
- session — up to 30 days after the latest renewal while you use the app; logging out removes the local token immediately and asks the server to revoke it;
- feedback — until used for product improvement or the account is deleted; feedback text is erased with the account;
- safety and moderation reports — as needed to handle the matter, protect users, and establish or defend claims;
- first-party analytics events — may be linked while the account exists; on account deletion, the user ID is removed and the event may remain for product trend analysis without that account link;
- push-delivery status — for up to 30 days for diagnostics; account-linked rows are also erased when the account is deleted;
- Sentry, Cloudflare, and infrastructure logs — under current provider retention settings and only as long as needed for security, diagnostics, or analysis;
- minimized diagnostics sent by earlier test versions to Datadog — until that provider’s retention period ends; the app no longer sends new data to Datadog;
- waitlist email — until the launch notice, withdrawal of consent, or closure of the list.
Backups may be removed through the normal rotation cycle and remain isolated from active use until then.
8. Account deletion
Delete your account in Settings → Delete account. Deletion covers the profile, photo, proposals, replies, contact relationships, settings, device tokens, linked push-delivery records, and feedback text. Product events remain only without the account identifier. If you cannot access the app, submit a request at wbijam.app/delete-account.
If deleting the photo file fails, the app should not confirm completion of account deletion; the operation can then be retried.
9. Your rights
You have rights of access, copy, rectification, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent without affecting earlier lawful processing.
Write to kontakt@wbijam.app. We respond without undue delay, generally within one month, and may request information needed to confirm identity. You may also complain to the President of the Polish Personal Data Protection Office (uodo.gov.pl) or your local supervisory authority.
10. Minors
Wbijam is intended only for people who are at least 18 years old. We do not direct the app to minors. If we learn that an account belongs to a person under 18, we will suspend or delete the account and its associated data. Any future availability of Wbijam to minors will require prior changes to the product, terms, this policy, and store declarations appropriate to their age and country.
11. Automated processing
We use technical abuse limits and an automated filter for some prohibited content. We do not make solely automated decisions that produce legal or similarly significant effects. We do not score relationships or use data for cross-service advertising profiles.
12. Changes
The current version is available at wbijam.app/privacy. We will give advance notice in the app or through another appropriate channel when a change is material. If a change requires consent, we will ask before the new processing starts.