📱

Data Usage Policy

Metrou București, Android Application

📱 Last updated: September 2026
The short version The App processes almost everything locally on your device, and the map is included in the App so it renders without any network request. Data leaves your device only when a feature needs an outside answer: address and street-name lookups, walking routes, live arrival times, toilet reports and service alerts each reach an external provider. If you consent, ad signals and anonymous usage statistics also go to Google's advertising and analytics services; both stay off until you grant GDPR consent. We collect no directly identifying personal information ourselves.

Contents

  1. Data Categories
  2. Permissions
  3. Local Processing
  4. External Data Flows
  5. Google AdMob & GDPR
  6. Analytics & Consent
  7. Purchase Data & PRO
  8. Data Retention & Deletion
  9. Your Controls
  10. Security
  11. Policy Updates
  12. Contact
01

Data Categories

Location (optional)

GPS coordinates, used for route tracking and for finding nearby metro stations. Processed on your device and not logged or sent to us. The exception is the address and street-name lookup: if you use it, the query is handled by an external map service.

User-created content

Station notes and favourite routes you create. Stored on your device.

App preferences

Theme, language, font size and route-tracking behaviour. Stored on your device.

Crash reports (opt-in)

If the app crashes, a report is saved on your device. It reaches us only if you explicitly choose to send it from Settings.

Ad signals (consent)

Google's advertising service collects an advertising identifier and device information for ad targeting, only after you grant GDPR consent.

Analytics events (consent)

Google's analytics service collects anonymous app events, screen views and device information, only after you grant GDPR consent. Off by default.

Map and lookup queries

The map is included in the App and needs no network. Searching an address, turning your position into a street name or drawing a walking route sends that query, along with your IP address, to an external map or routing service.

Toilet reports

Reading toilet status sends nothing about you. Submitting a report sends the station, the condition you chose, the time and any note you write, with no identifier attached.

Live arrival times

The stop whose times you are viewing is sent to an external transit data provider to fetch its next arrivals.

Report validation

Submitting a toilet report involves a Google integrity check confirming the report comes from a genuine install of the App. It carries no account or personal data, and we do not store it. Submissions that fail the check are rejected.

Incident notifications (opt-in)

Off by default. If you switch them on in Settings, notifications are delivered through Google's messaging service. The same notification goes to everyone who has them enabled, so nothing identifying you is sent to us or stored. Switching them off stops delivery.

02

Permissions

03

Local Processing

The following features operate entirely on your device with no network communication:

04

External Data Flows

The following are the only situations in which data leaves your device:

05

Google AdMob & GDPR

Metrou București uses Google AdMob to display banner advertisements. AdMob is subject to Google's privacy policies and EU GDPR requirements.

On first launch the App shows a GDPR consent dialogue via Google's User Messaging Platform (UMP). Your choices:

🔁
Changing your consent You can review and reset your GDPR consent at any time via Settings → About → Reset Consent inside the app. The consent dialogue will reappear on the next app launch.

For Google's full data practices see: Google Privacy Policy and AdMob data disclosure.

5b

Analytics & Consent

Metrou București uses Google Analytics for Firebase to collect anonymous, aggregated statistics about how the App is used (for example which features are opened and how often). This helps us prioritise improvements. We do not use it to identify you personally or to build advertising profiles.

Off by default, consent first Analytics collection is disabled by default and only activates after you grant consent via the same GDPR consent dialogue (Google's UMP). The same choice that controls ads also controls analytics: if you decline, no analytics data is collected. This is enforced in the app and via Google's consent-mode signals.

Collected only after consent: app events & screen views, session counts, device model, OS and app version, language/country, and approximate (IP-based, city-level) location. Never collected: your name, email, precise GPS, or your local notes/favourites.

See Firebase Privacy & Security for Google's data practices.

5c

Purchase Data & PRO

Only relevant if you buy MetroBUC PRO, the optional paid upgrade that removes all advertising. It is sold either as a monthly subscription, which renews until you cancel it in Google Play, or as a one-time purchase that is permanent. Both remove exactly the same ads.

06

Data Retention & Deletion

App data (local)

AdMob & Analytics data

Crash reports

Submission checks & notification subscriptions

07

Your Controls

08

Security

09

Policy Updates

We will update this policy when data practices change materially, for example if new third-party services are added. Changes are indicated by the "Last updated" date above. Continued use of the App after the effective date constitutes acceptance.

10

Contact

For data-related questions or requests: