Privacy First · Local-First

Your privacy
lives in your phone.

orbiTome is designed to know as little as possible about you. Here you'll find exactly what we collect, why, and for how long.

Last updated: 13 September 2026 · Version 5.9

🔒 Event history: only on your device
💨 Cloud data: deleted when the event expires
👻 Invisible event: not shown on the public map
🚫 No selling of data to third parties
Index

Who is responsible for your data

The data controller for personal data is Cesare Bramante, independent developer of orbiTome. Certified email (PEC): cesare.bramante@pec.it. For any privacy question, you can contact us at the address indicated in the Contact.

This policy applies to the orbiTome mobile app available on Google Play Store (Android) and on App Store (iOS), as well as related services such as the universal link orbitome.com/join/….


What we collect and why

orbiTome collects the data necessary for the app to work, keeping it to the bare minimum. Here is the full picture:

Data type
Where it's stored
Purpose
Phone number
☁️ Cloud (Firebase)
Unique identifier for OTP login and contact matching
Profile photo (optional)
☁️ Cloud (Firebase)
Displaying your public profile to friends
Location (GPS)
☁️ Temporary cloud
Creating events on the map; deleted when the event expires
Event history
📱 Local only
Your personal "Vault"; it never leaves the device
Phone contacts
📱 Local only
Synced locally on the device; numbers are matched against Firebase to find your friends already on orbiTome and, likewise, to make you findable by your contacts who use the app — like common messaging apps. No public directory; you are never shown to anyone who doesn't already have your number. Your address book is never uploaded to the cloud. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in letting you find the contacts who already use orbiTome; numbers that match no user are not stored. You choose which contacts to import, and you can revoke address-book permission in your system settings (Art. 21)
Tags/Groups
📱 Local only
Managing private lists (e.g. "Five-a-side"); never shared
Diagnostics data
🔗 Third party (Google)
App performance analysis; anonymized
User blocks (user_blocks)
☁️ Cloud (Firebase)
Anti-stalking protection: keeps the mutual block relationship. Automatically deleted when the account is deleted
Passwords / Private messages
🚫 Not collected
orbiTome does not collect or store this type of data

Local vs Cloud: the double vault

orbiTome uses a hybrid architecture designed with privacy as the starting point, not as an afterthought.

📱

The Vault — Local Database

Your event history, your contacts, and your personal tags are stored on your smartphone and are not transmitted to our servers in readable form. You can export the local database as an encrypted file (AES-256) to Google Drive or another personal storage app via the native Share Sheet, accessible only with your recovery code.

☁️

The Temporary Whiteboard — Cloud (Firestore)

Only the data needed to sync events travels to the cloud: public profile, event location, and status. Each item has an expires_at calculated when the event is created, which depends on how the event was set up: 2 hours from the start for a standard event, 11:59 PM the same day for the “tonight” slot, 4 hours from the start when you pick your own date and time, the stated time for an idea. If you are the host and you are on site, the event can be extended one hour at a time, up to a maximum of 6 hours from the start. An automatic Cloud Function handles hourly cleanup. Our servers are not a permanent record of where you've been.

👻
🔎

Contact filter: on your device

Invisible events appear only to your invitees, other events only to your contacts: this filtering happens directly on each orbiTome user's device, not on a server. Your event history stays only on your phone.

Invisible event

When you make an event invisible, the event's visibility is set to "tag" (private): the event disappears from the public map and is accessible only to the people you have explicitly invited via link. The «Invisible event» label is visible in the interface while in use.

⚠️

Security of local contacts

The user's contacts are stored exclusively on the local device, in unencrypted storage. On devices with root or jailbreak access, phone numbers could be accessible to third-party applications with elevated privileges: orbiTome disables Android Auto Backup (via the flag android:allowBackup="false" in the manifest) to prevent extraction of clear-text data via ADB backup. We recommend not using the app on rooted devices.


Who else touches your data

orbiTome integrates the following third-party services. Each has its own privacy policy; we provide links so you can review them directly.

Cookies and website measurement. This policy covers the app. The website www.orbitome.com uses technical cookies and, only with your consent, Google Analytics 4. The /join invitation pages use no cookies and no measurement. Full list, durations and how to give or withdraw consent: Cookie policy.

Data transfers outside the EU. App data is stored in Google Cloud's eur3 multi-region (Belgium/Netherlands). Some services we rely on — Firebase Authentication (sign-in), Firebase Cloud Messaging (push notifications) and some processing functions — are provided by Google LLC from infrastructure located in the United States. Transfers rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, to which Google LLC is certified, and, as a fallback, on the Standard Contractual Clauses included in the Google Cloud Data Processing Terms. Copies of the safeguards: https://cloud.google.com/terms/data-processing-addendum · https://www.dataprivacyframework.gov


What the stores require (Google Play and App Store)

orbiTome is distributed on Google Play Store (Android) and on App Store (iOS). Google and Apple, as store operators, collect some store-level information regardless of our choices:

This data is managed directly by Google according to its own privacy policies: orbiTome has no direct access to the data collected by the store's systems.


How long we keep your data

Data
Duration
How to delete it
Event data (cloud)
⏱ when the event expires
Automatic deletion via TTL and Cloud Function
Public profile (cloud)
Until account deletion
Profile → Settings → Delete account (also deletes all created live events and user blocks)
Local history
Until uninstall
Privacy & Vault → "Clear local data" removes all local data; or uninstall the app
User blocks (user_blocks)
Until account deletion
Automatically deleted by the Cloud Function onUserDeleted when the account is deleted
Encrypted backup
Until manually removed
Delete the file from iCloud Drive or Google Drive manually
Analytics data
Per Google policy (typically 14 months)

You're in control

If you reside in the European Union or the EEA, you have the following rights under Regulation (EU) 2016/679 (GDPR):

👁️
Access
You can request a copy of all the personal data we hold about you.
✏️
Rectification
You can correct your profile data directly from the app at any time.
🗑️
Deletion
You can delete your account and all associated data from the Profile screen. Deletion removes your profile, created live events, and user blocks, both in the cloud and locally.
📦
Portability
You can export your local history as an encrypted file (AES-256) via the backup feature.
🚫
Objection
You can object to processing based on legitimate interest, diagnostics included, by writing to the address given in the Contact section.
⚖️
Complaint
You can lodge a complaint with the competent data protection authority.

To exercise any of these rights, write to privacysicurezza@orbitome.com or use the features built into the app directly.


Use by minors

orbiTome is intended for users aged 13 or older (or the minimum age required by applicable local law). We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided personal data, please contact us immediately so we can proceed with deletion.


Got questions?

For any request regarding privacy, the management of your data, or to exercise your rights, you can contact us:

✉️

Privacy Email

Write to privacysicurezza@orbitome.com — we reply within 30 days, as required by the GDPR. For formal communications you can use the certified address cesare.bramante@pec.it.

We reserve the right to update this policy to reflect changes in our services or in the law. In case of substantial changes, we will notify you via in-app notification or email. The current version is always available at this address.