Skip to content

Privacy

Who answers for all this

The data controller is MoleCorp Esports S.L., tax ID B-02789345, registered office at Calle Presa Encimera 13, B, Bajo 1.º A, 48800 Balmaseda (Bizkaia), España, entered in the Registro Mercantil de Bizkaia, Tomo 5962, Folio 190, Hoja BI-75904, Inscripción 1.ª. For any data protection matter: admin@whereubro.com.

What is stored

What your data is used for, and on what grounds

There is no automated decision-making and no profiling. Your data is never sold or handed to anyone, except where the law requires it.

What is NOT stored

Who can see you

Only people in one of your circles, and only while that circle is alive. Being in the same circle is what grants permission; on top of that, you decide how much detail each person gets — exact, area or city — and you can stop sharing with someone without leaving the group or removing them. That block takes effect immediately.

When you share with less detail, the server does the trimming before sending anything: the exact position never leaves here.

Third parties

The server is our own and sits in Spain; the database never leaves it. There are four external services and none of them is optional: Google and Apple, so you can sign in and so notifications reach your phone (Firebase Cloud Messaging and APNs); Cloudflare, which publishes the site on the internet and therefore sees the encrypted traffic going in and out; and Amazon SES, which delivers the only two emails this thing sends: the one confirming your address and the one for recovering your password. The notifications carry no position: they only wake the app so it can answer.

Neither the browser nor the app ever connects to someone else's map server: this server requests the tiles and keeps them in its own cache. The people who publish them, OpenStreetMap, see this server's requests — not yours — with no way of knowing who asked for which area or of linking them to you.

Google and Apple may process data outside the European Economic Area. Those transfers rely on the safeguards set out in the GDPR: the European Commission's Standard Contractual Clauses and the EU–US Data Privacy Framework. What goes out that way is the device identifier and the notification that wakes it, never your position.

How long

Security

All traffic is encrypted. If you sign in with Google or Apple, no password is stored here; if you create your own, what is stored is not the password but its fingerprint, computed with an algorithm that is slow on purpose so it is worthless even if someone takes the database. The session lives in a signed cookie, and on the phone in the system's secure store — Keychain on iPhone, EncryptedSharedPreferences on Android. Even so, no system is infallible: if a breach ever occurred that affected your rights, you would be told, and the supervisory authority within the 72 hours set out in article 33 GDPR.

Minors

This service is not aimed at children under 14 and they cannot sign up. That comes from article 7 of the Spanish LOPDGDD: below that age the consent of a parent or guardian would be required, and there is no way to verify it here. If we find an account belonging to someone under 14, it is deleted.

Your rights

You have the right to access your data, rectify it, erase it, object to processing, restrict it and to data portability, and to withdraw your consent at any time. Much of that needs no request at all: you can change how much detail you share, block someone, leave a circle or delete your account from the app itself, and it takes effect immediately. For anything else, write to admin@whereubro.com.

If you believe your data is not being handled properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es). We would appreciate it if you wrote to admin@whereubro.com first, in case it can be sorted out without going that far.

Changes

If this policy changes, the date above is updated. When a change genuinely affects what is done with your data, you will be told inside the app, not just by publishing it here.