✅
The short version
The App processes almost everything locally on your device. The only external data flows are map tile requests (OpenStreetMap) and — if you consent — ad signals to Google AdMob and anonymous usage statistics to Google Analytics for Firebase. Both Google services stay off until you grant GDPR consent, and we collect no directly identifying personal information ourselves.
📍
Location (optional)
GPS coordinates for route tracking and finding nearby metro stations. Processed on-device in real time; never logged or transmitted to us.
📝
User-created content
Station notes and favourite routes you create. Stored entirely in local app storage on your device.
⚙️
App preferences
Theme, language, font size, and route-tracking behaviour. Saved locally via Android SharedPreferences.
🐞
Crash reports (opt-in)
If the app crashes, a report is saved locally. It is sent to us only if you explicitly choose to email it from Settings.
📢
Ad signals (consent)
Google AdMob collects the Advertising ID and device info for ad targeting only after you grant GDPR consent on first launch.
📊
Analytics events (consent)
Google Analytics for Firebase collects anonymous app events, screen views and device info only after you grant GDPR consent. Off by default.
🗺️
Map tile requests
Standard HTTP requests to OpenStreetMap and OSRM servers when you use the map view. Your IP address is visible to those servers.
-
Required
INTERNET
Needed to load OpenStreetMap tiles, serve AdMob advertisements, and send analytics events (after consent).
-
Optional
ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION
Used for GPS route tracking and finding nearby stations. You can deny or revoke this at any time; core route planning works without it.
-
Required (Play policy)
AD_ID
Declared as required by Google Play when AdMob is integrated. Used by AdMob and analytics only if you consent.
-
Optional
POST_NOTIFICATIONS (Android 13+)
Requested only when you start route tracking; used to display the foreground-service notification showing your current journey progress.
The following features operate entirely on your device with no network communication:
- Route planning and transfer calculation across M1–M5
- Timetable lookups and next-train calculations
- Station search and line filtering
- Door-opening direction indicators
- Station notes and favourite route storage
- Theme, language, and font-size preferences
- GPS route tracking progress display
- Crash report storage (until you send one)
The following are the only situations in which data leaves your device:
- OSM tile requests — when you open the map view, tile images are fetched from OpenStreetMap servers. These are standard HTTP GET requests; OSM servers may log your IP address per their own privacy policy.
- OSRM routing queries — when map-based navigation is active, waypoints are sent to an OSRM instance for routing calculations.
- AdMob ad requests — when ads are loaded, Google AdMob receives device and context signals (see Section 5). Only after consent.
- Analytics events — anonymous app events and device info are sent to Google Analytics for Firebase (see Section 5b). Only after consent; off by default.
- Crash report emails — only if you manually choose to send one from Settings → Crash Reporting.
- External app launches — opening a location in Google Maps or a similar app is initiated entirely by your tap.
Metrou București uses Google AdMob to display banner advertisements. AdMob is subject to Google's privacy policies and EU GDPR requirements.
On first launch the App shows a GDPR consent dialogue via Google's User Messaging Platform (UMP). Your choices:
- Consent granted — AdMob may show personalised ads using your Advertising ID, device model, OS, network type, and approximate location.
- Consent declined — AdMob shows contextual (non-personalised) ads. Some contextual signals (app context, general location) are still used.
🔁
Changing your consent
You can review and reset your GDPR consent at any time via Settings → About → Reset Consent inside the app. The consent dialogue will reappear on the next app launch.
For Google's full data practices see: Google Privacy Policy and AdMob data disclosure.
Metrou București uses Google Analytics for Firebase to collect anonymous, aggregated statistics about how the App is used (for example which features are opened and how often). This helps us prioritise improvements. We do not use it to identify you personally or to build advertising profiles.
✅
Off by default — consent first
Analytics collection is disabled by default and only activates after you grant consent via the same GDPR consent dialogue (Google's UMP). The same choice that controls ads also controls analytics: if you decline, no analytics data is collected. This is enforced in the app and via Google's consent-mode signals.
Collected only after consent: app events & screen views, session counts, device model, OS and app version, language/country, and approximate (IP-based, city-level) location. Never collected: your name, email, precise GPS, or your local notes/favourites.
See Firebase Privacy & Security for Google's data practices.
App data (local)
- Retained on your device until you clear app data or uninstall the app
- Station notes and favourites can be deleted individually within the app
- All local data is permanently removed when you uninstall Metrou București
AdMob & Analytics data
- Managed by Google per their data-retention policies
- You can reset your Advertising ID at any time via Android Settings
- Declining or resetting consent stops further ad-personalisation and analytics collection
Crash reports
- Stored locally until you delete them or send them via email
- Manageable from Settings → Crash Reporting
- Location access — grant or revoke in Android Settings → Apps → Metrou București → Permissions
- Ad personalisation & analytics — opt out via Android Settings → Google → Ads, or reset consent inside the app (this disables analytics too)
- Crash reports — view, send, or delete individual reports in Settings → Crash Reporting
- All app data — clear via Android Settings → Apps → Metrou București → Storage → Clear Data, or by uninstalling
- All local data is protected by standard Android application sandboxing
- Network connections to OSM, AdMob and Firebase use HTTPS/TLS
- No sensitive personal data (passwords, financial information, health data) is ever collected or stored
- The App does not implement its own user accounts or authentication
We will update this policy when data practices change materially — for example if new third-party services are added. Changes are indicated by the "Last updated" date above. Continued use of the App after the effective date constitutes acceptance.
For data-related questions or requests: