✅
Short version
Almost all data stays on your device, and we never sell it. Google's advertising and analytics services activate only after you grant GDPR consent on first launch; decline and they stay off. A few features work by asking an outside service a question: searching an address or looking up a street name, drawing a walking route, fetching live arrival times, and reading or submitting toilet reports. Incident notifications are off unless you switch them on. Each service is used only for the feature you are using at that moment, and none of them receive an account or a name.
The table below summarises every category of data touched by the App and where it goes.
| Data type | Purpose | Where it goes |
| GPS / location | Route tracking, nearby stations | Local only |
| GPS coordinates (address lookup) | Turning your position into a street name, only when you use that feature | External map service |
| Destination text you type | Finding an address you searched for | External map service |
| Walking route start & end points | Drawing the walking path on the map | External routing service |
| Toilet condition reports (with optional note) | Sharing station toilet status with other users | Google cloud database |
| Stop you are viewing | Live arrival times for that stop | External transit data provider |
| Personal notes | User-written station notes | Local only |
| Favourite routes | Saved route preferences | Local only |
| App settings & preferences | Theme, language, font size | Local only |
| Crash reports | Debugging (opt-in email only) | Local until you send |
| Advertising ID | Personalised ads (consent required) | Google AdMob |
| Device / OS info | Ad targeting (consent required) | Google AdMob |
| App usage & events | Anonymous usage statistics (consent required) | Google Analytics for Firebase |
| Approximate location (IP-based) | Analytics & ad context (consent required) | Google Analytics for Firebase |
| Integrity check for submissions | Confirming a toilet report comes from a genuine install of the App | Google integrity service |
| Notification subscription | Delivering incident notifications, only if you switch them on | Google messaging service |
| Health, contacts, messages | Not applicable | Never collected |
The following data is created and stored exclusively on your device. None of it is transmitted to our servers:
- Station notes: text notes you write for individual stations
- Favourite routes: routes you have saved for quick access
- App settings: theme (light, dark or system), language, font size, and route-tracking behaviour preference
- Crash reports: stored locally if the app crashes, and sent to us only if you explicitly choose to email one from Settings
- PRO status: whether the paid upgrade is active
- Terms & consent state: a flag indicating you accepted the terms on first launch
ℹ️
GPS during route tracking
When you activate route tracking, the App reads your GPS position to highlight your progress on the route. This data is used in real time on your device and is not logged or transmitted anywhere.
The App is free and supported by advertisements delivered by Google AdMob.
GDPR Consent
On first launch (and whenever legally required), a GDPR consent form appears, powered by Google's User Messaging Platform (UMP). You can:
- Accept personalised ads: AdMob may use your Advertising ID and device info to show relevant ads.
- Decline and use non-personalised ads: ads are still shown but without personalisation. AdMob still collects some contextual signals, such as approximate location and app context.
You can review or reset your consent at any time via Settings → About → Reset Consent.
What AdMob may collect (if consented)
- Google Advertising ID
- Device model, OS version, mobile network
- Approximate location (IP-based)
- Ad interaction data (impressions, clicks)
For full details see Google's Privacy Policy and AdMob's data practices.
To understand how the App is used and to improve it, we use Google Analytics for Firebase, a service provided by Google. Analytics collects anonymous, aggregated usage data. It does not identify you personally, and we do not use it to build advertising profiles.
✅
Consent first, off by default
Analytics collection is disabled by default and is only switched on after you grant consent through the GDPR consent form (Google's UMP) on first launch. If you decline, or while consent has not yet been given, no analytics data is collected. This is enforced both in the app and through Google's consent-mode signals.
What analytics may collect (only if consented)
- App events and screen views (e.g. which features are opened)
- Session count, session duration, and app open/close events
- Device model, OS version, app version, language and country
- Approximate location (derived from IP at city or region level, not precise GPS)
- A non-permanent app-instance identifier generated by Firebase
We do not collect your name, email, precise GPS location, or any of your locally stored content (notes, favourites) through analytics.
Changing your choice
You can withdraw or reset your consent at any time via Settings → About → Reset Consent. When you decline, analytics collection stops.
For Google's data practices see Firebase Privacy & Security and Google's Privacy Policy.
- ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION: optional, used for route tracking and finding nearby stations. Granted and revocable by you at any time in Android Settings.
- INTERNET: required to serve AdMob ads, send analytics events (after consent), and reach the lookup services listed below. The map itself is bundled and needs no network.
- AD_ID: required by Google Play policy when AdMob is present, and used by AdMob and analytics only if you consent.
- POST_NOTIFICATIONS (Android 13+): optional, used to show your journey progress while route tracking is running and, if you switch them on, transport incident notifications. Incident notifications are off by default and are enabled in Settings.
- Google AdMob: advertisement delivery and GDPR consent management (after consent).
- Google Analytics for Firebase: anonymous usage analytics (after consent).
- Map tiles: the Bucharest map is bundled inside the App and renders offline. Displaying the map makes no network request and contacts no tile server.
- External map service: the address search and the "what street am I on" lookup. When you search for a destination, the text you typed is sent. When the App turns your position into a street name, your GPS coordinates are sent. Both requests include your IP address. These are the only cases where your precise location leaves the device, and only for the lookup you asked for.
- External routing service: walking directions. The start and end points of the walking leg are sent so the route can be drawn.
- Google cloud database: stores the shared toilet status data. Reading it sends no personal data. If you submit a toilet report, the App sends the station, the condition you selected, the time and, if you write one, your optional free-text note. Reports carry no account, name, device identifier or location. Because notes are published to other users, please do not write anything personal in them.
- Google integrity service: when you submit a toilet report, Google confirms that the submission comes from a genuine install of this App. The check carries no account and no personal data, and we do not store it. Its only purpose is to keep forged reports out of the shared toilet data.
- Google messaging service: delivers transport incident notifications, and only if you switch them on in Settings. The same notification goes to everyone who has them enabled, so nothing identifying you is sent to us or stored by us. Turning them off stops delivery.
- External transit data provider: live arrival times. The App sends the stop whose times you are viewing.
- External alerts provider: supplies service alerts, news and events. The App only requests the current list and sends no information about you.
- External map apps (Google Maps, Waze and similar): launched at your explicit request when opening a location externally.
- Email apps: used only if you choose to send a crash report. No data is sent automatically.
The App offers an optional paid upgrade, MetroBUC PRO, which removes all advertising. It is sold in two forms that grant exactly the same benefit: a monthly subscription, which renews until you cancel it, and a one-time purchase, which is permanent and has nothing to cancel.
- Purchases are handled by Google. The entire purchase, payment included, is processed by Google Play. Your name, card and billing address never reach us.
- Subscriptions are managed in Google Play, not in the App. Cancelling is done from your Google Play account, and the App neither sees nor stores your billing history.
- We receive no purchase data. The App learns only whether PRO is active, so it knows whether to show ads. No information about your purchase reaches any server we control.
- While PRO is active, no ads are shown, so the advertising data flows described above stop entirely.
We do not sell, trade, or rent your personal information to any third party. The only data leaving your device is:
- Ad-related signals sent to Google AdMob (only after consent)
- Anonymous usage events sent to Google Analytics for Firebase (only after consent)
- The text you searched for, or your GPS coordinates, sent to an external map service when you search an address or look up the street name
- The start and end points sent to an external routing service when a walking route is drawn
- Toilet reports you choose to submit, stored in a Google cloud database and published anonymously to other users
- An integrity check with Google when you submit a toilet report
- A notification subscription with Google's messaging service, only while incident notifications are switched on
- The stop whose arrival times you are viewing, sent to an external transit data provider
- The request for the alerts list sent to an external provider, with no information about you
- Crash report emails, sent only if you initiate them manually
- Access & deletion: all your data is on your device. Clear it via Android Settings → Apps → Metrou București → Clear Data, or by uninstalling the app.
- Location: revoke at any time in Android Settings → Apps → Metrou București → Permissions.
- Ad & analytics consent: reset via Settings → About → Reset Consent inside the app. Declining stops both personalised ads and analytics collection.
- Incident notifications: off by default. Switch them on or off at any time in Settings, and turning them off stops delivery.
- Crash reports: stored locally, and you decide whether to send each one. Delete them in Settings → Crash Reporting.
The App is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided personal data through the App, please contact us and we will take appropriate action.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and may notify you via an in-app notification for material changes. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
For any privacy-related questions or requests: