Privacy
Last reviewed: 8 August 2026
This app tells the people you choose where you are, when they ask. What follows is exactly what is stored, for how long, and what is not stored.
In four sentences
- Where you have been is not stored: there is one position per person and it gets overwritten.
- Nobody can see you without access you granted, and you can withdraw it whenever you want.
- Every request is logged and you can read it. That log cannot be turned off or deleted.
- No ads, no analytics, no trackers. Nothing is sold to anyone.
Who answers for all this
The data controller is MoleCorp Esports S.L., tax ID B-02789345, registered office at Calle Presa Encimera 13, B, Bajo 1.º A, 48800 Balmaseda (Bizkaia), España, entered in the Registro Mercantil de Bizkaia, Tomo 5962, Folio 190, Hoja BI-75904, Inscripción 1.ª. For any data protection matter: admin@whereubro.com.
What is stored
- Your account: your email, your name —the one Google or Apple return, or the one you choose— and your profile picture if you have one. If you create your own password, its fingerprint; never the password.
- Your latest position: latitude, longitude, accuracy, speed, altitude and battery level, with the exact time it was taken. Only the latest one: each answer overwrites the previous.
- Your devices: the identifier Google or Apple assign to each phone so it can be reached, and a label so you know which is which.
- Requests: who asked where you were, when, and how it ended. This is what makes other people's use of their permission visible.
- Your circles: the group name, who is in it, and how much detail you share with each person.
- And what any web server records while serving you: your IP address, the time and the page requested. It does not go into the database and is never linked to your account; it is there so the service works and so abuse can be spotted, and it deletes itself after fourteen days.
What your data is used for, and on what grounds
- To provide the service and maintain your account and your circles: performance of the contract you accept when you sign up (art. 6.1.b GDPR).
- To answer with your position when someone asks for it: your consent (art. 6.1.a), given when you grant the location permission and choose who you share with. You can withdraw it whenever you like, from the app or from your phone settings, without giving reasons.
- To record every request: legitimate interest (art. 6.1.f), and the interest is yours. Being able to know who located you is what balances out that people can ask without alerting you at that moment; that is why the record cannot be turned off or deleted, not even by whoever asked.
- To keep the service running and curb abuse: legitimate interest (art. 6.1.f).
- To comply with the law where applicable: legal obligation (art. 6.1.c).
There is no automated decision-making and no profiling. Your data is never sold or handed to anyone, except where the law requires it.
What is NOT stored
- A history of your movements. The positions table has one row per person and is overwritten with every answer. There is nothing to reconstruct, or to hand over to anyone who asks.
- The original of the photo you upload. It is cropped and re-encoded, which strips the EXIF data — on a phone photo that includes the coordinates where it was taken.
- Your contacts, your messages, your other apps, or anything you do outside this app.
- Advertising profiles. There is no advertising identifier, and nothing is shared with advertisers or data brokers.
Who can see you
Only people in one of your circles, and only while that circle is alive. Being in the same circle is what grants permission; on top of that, you decide how much detail each person gets — exact, area or city — and you can stop sharing with someone without leaving the group or removing them. That block takes effect immediately.
When you share with less detail, the server does the trimming before sending anything: the exact position never leaves here.
Third parties
The server is our own and sits in Spain; the database never leaves it. There are four external services and none of them is optional: Google and Apple, so you can sign in and so notifications reach your phone (Firebase Cloud Messaging and APNs); Cloudflare, which publishes the site on the internet and therefore sees the encrypted traffic going in and out; and Amazon SES, which delivers the only two emails this thing sends: the one confirming your address and the one for recovering your password. The notifications carry no position: they only wake the app so it can answer.
Neither the browser nor the app ever connects to someone else's map server: this server requests the tiles and keeps them in its own cache. The people who publish them, OpenStreetMap, see this server's requests — not yours — with no way of knowing who asked for which area or of linking them to you.
Google and Apple may process data outside the European Economic Area. Those transfers rely on the safeguards set out in the GDPR: the European Commission's Standard Contractual Clauses and the EU–US Data Privacy Framework. What goes out that way is the device identifier and the notification that wakes it, never your position.
How long
- The position, until the next one replaces it.
- The request log, ninety days.
- A circle with an end date is deleted whole when it finishes, along with the list of who was in it.
- The server's technical logs, fourteen days.
- Your account, for as long as you want it. If you delete it, your position, your devices and your circle memberships go with it.
Security
All traffic is encrypted. If you sign in with Google or Apple, no password is stored here; if you create your own, what is stored is not the password but its fingerprint, computed with an algorithm that is slow on purpose so it is worthless even if someone takes the database. The session lives in a signed cookie, and on the phone in the system's secure store — Keychain on iPhone, EncryptedSharedPreferences on Android. Even so, no system is infallible: if a breach ever occurred that affected your rights, you would be told, and the supervisory authority within the 72 hours set out in article 33 GDPR.
Minors
This service is not aimed at children under 14 and they cannot sign up. That comes from article 7 of the Spanish LOPDGDD: below that age the consent of a parent or guardian would be required, and there is no way to verify it here. If we find an account belonging to someone under 14, it is deleted.
Your rights
You have the right to access your data, rectify it, erase it, object to processing, restrict it and to data portability, and to withdraw your consent at any time. Much of that needs no request at all: you can change how much detail you share, block someone, leave a circle or delete your account from the app itself, and it takes effect immediately. For anything else, write to admin@whereubro.com.
If you believe your data is not being handled properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es). We would appreciate it if you wrote to admin@whereubro.com first, in case it can be sorted out without going that far.
Changes
If this policy changes, the date above is updated. When a change genuinely affects what is done with your data, you will be told inside the app, not just by publishing it here.