Wbijam Privacy Policy

Effective date: July 20, 2026

This policy describes data processed by the Wbijam app, wbijam.app, and related services. Wbijam uses data needed to operate accounts, arrange meetups, keep the service safe, handle reports, and improve the product. Contacts access, profile photos, and map pins are optional.

We currently do not sell data, display advertising, or use data to track users across other companies’ apps and websites for advertising. This describes how Wbijam works now; it is not a promise that the product model can never change. Before changing how data is used, we will update this policy and complete any steps required by law or store rules, including obtaining consent where required.

The Polish version at wbijam.app/prywatnosc is binding. This English version is provided for convenience.

1. Controller and contact

The controller is Damian Mikła, operating as Workflows Lab, ul. Jana Pawła Woronicza 15/72, 02-625 Warsaw, Poland, Polish tax ID (NIP) 5214091072 and REGON 529999652.

For privacy matters and rights requests, contact kontakt@wbijam.app.

2. Data we process

Account and profile

Profile photos are stored in a private Supabase Storage bucket. The app issues a temporary photo link only when your visibility settings allow that person to view the profile. The link expires, but it can still be forwarded while valid, so do not add a photo you do not want to share with people who can view your profile.

Proposals, replies, and community safety

Invited people can see the proposal, replies, and precise pin. Anyone holding a valid invitation link may open the related proposal and reply; recipients can forward that link.

When you open the map picker, the app may request one-time foreground location access to center the map. We do not store the current position used only for centering on our servers. If you confirm a point, we store the selected coordinates with the proposal. You can deny access and select a place manually.

A place-search query may be sent to the OpenStreetMap-based Photon service and, if no result is found, to the Apple or Google system geocoder. The provider may receive the query, approximate map context, IP address, and connection data under its own terms. Wbijam stores the place text and confirmed pin with the proposal, but does not maintain a separate place-search history.

Contacts and finding friends

If you allow contacts access, the app reads names and phone numbers from the address book. Normalized numbers and contact labels are sent over an encrypted connection to our server. The server creates an HMAC digest and compares it with Wbijam accounts.

For every imported number, including a person without an account, we retain the HMAC digest and the address-book label for up to 365 days after the most recent import. This supports “joined later” notices and directional friend discovery under visibility settings. We do not store a non-user’s raw number in the matching table, but we still treat the digest as personal data because we can compare it with a number using our secret key.

Contacts access is optional. Without it you can add people using a code, QR code, or link. Wbijam does not send SMS messages or invitations to contacts by itself. Revoking the OS permission stops further reads; existing digests expire 365 days after the last import. You can also remove earlier matches using “Forget” features in the app or by contacting us.

Device, notifications, and technical logs

Notifications are delivered through Expo and either Apple Push Notification Service or Firebase Cloud Messaging. You can disable notifications in device settings.

Product analytics and diagnostics

Our servers record events needed to evaluate the product, such as app open, onboarding completion, proposal sent, invitation link used, person added by code, tutorial progress, and feedback sent. Events may include a technical action name, recipient count, proposal mode, OS language and country, and the domain from which the app was opened. They do not include proposal text or a full invitation link.

We also use Sentry for error reports and some performance data. We disable default personal data, remove user identity, and strip query parameters from URLs. These safeguards minimize data, but a technical report may still include device, OS, and screen-sequence information.

wbijam.app

If you join the waitlist, we process your email address. The site also records a landing-page event not linked to an account, containing the path and referring domain. Cloudflare and our server may process IP addresses and technical connection data in security logs. The site does not set its own advertising cookies.

Purpose Example data Legal basis
Account creation, login, and Wbijam features phone, profile, proposals, replies, settings, confirmed map pin, push token Art. 6(1)(b) GDPR — performance of a contract
Optional address-book matching and friend discovery numbers, labels, HMAC digests, matches Art. 6(1)(b) GDPR for the person requesting the feature; Art. 6(1)(f) GDPR for other people’s data — legitimate interest in providing expected friend discovery, subject to the safeguards in section 4
Security, abuse prevention, and moderation IP, login attempts, blocks, reports, content needed to review a report Art. 6(1)(f) GDPR — protecting the service and users and establishing or defending claims
Product stability and improvement usage events, diagnostics, performance data, feedback Art. 6(1)(f) GDPR — developing a safe and useful service
Launch notice after waitlist signup email Art. 6(1)(a) GDPR — consent
Legal obligations data required in a specific matter Art. 6(1)(c) GDPR

You may object to processing based on legitimate interests. We will assess your situation and stop unless overriding legitimate grounds apply or the data is needed for legal claims.

4. Information for people in someone else’s address book

If you do not have a Wbijam account but a user has your number and imports contacts, the source of the data is that user. We receive the number and contact label, then retain the HMAC digest and label for up to 365 days after the latest import. The purpose is directional friend discovery if you later join Wbijam. We do not contact you or send an invitation ourselves.

The legal basis is the legitimate interest described in section 3. You may ask for access, object, or request deletion of the digest by writing to kontakt@wbijam.app and identifying the relevant number. We publish this notice here also because the imported number is the only contact detail available to us and we do not use it to send unsolicited notices.

5. Recipients

As needed to operate the service, data may be received by:

We do not sell data and currently do not provide it to advertising networks. Providers may act as our processors or as independent controllers for parts of their services under their own terms.

6. Transfers outside the EEA

The main app database is hosted in an EU region. Some providers, particularly Apple, Google, Expo, Sentry, Cloudflare, and Supabase, may process data outside the European Economic Area. Depending on the provider, safeguards may include adequacy decisions such as the EU–US Data Privacy Framework, Standard Contractual Clauses, or other GDPR mechanisms.

7. Retention

Backups may be removed through the normal rotation cycle and remain isolated from active use until then.

8. Account deletion

Delete your account in Settings → Delete account. Deletion covers the profile, photo, proposals, replies, contact relationships, settings, device tokens, linked push-delivery records, and feedback text. Product events remain only without the account identifier. If you cannot access the app, submit a request at wbijam.app/delete-account.

If deleting the photo file fails, the app should not confirm completion of account deletion; the operation can then be retried.

9. Your rights

You have rights of access, copy, rectification, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent without affecting earlier lawful processing.

Write to kontakt@wbijam.app. We respond without undue delay, generally within one month, and may request information needed to confirm identity. You may also complain to the President of the Polish Personal Data Protection Office (uodo.gov.pl) or your local supervisory authority.

10. Minors

Wbijam is intended only for people who are at least 18 years old. We do not direct the app to minors. If we learn that an account belongs to a person under 18, we will suspend or delete the account and its associated data. Any future availability of Wbijam to minors will require prior changes to the product, terms, this policy, and store declarations appropriate to their age and country.

11. Automated processing

We use technical abuse limits and an automated filter for some prohibited content. We do not make solely automated decisions that produce legal or similarly significant effects. We do not score relationships or use data for cross-service advertising profiles.

12. Changes

The current version is available at wbijam.app/privacy. We will give advance notice in the app or through another appropriate channel when a change is material. If a change requires consent, we will ask before the new processing starts.