Privacy Policy
Roamr is a place-first social app: posts are anchored to the place they are about, and are discovered by map and proximity as much as by who you follow. This policy explains exactly what we collect, why, and what we do with it. We have tried to describe what the system actually does rather than reserve every right we could.
Who we are
Roamr is operated by Roamr App, a business owned and operated by XCELBYTE PTE. LTD. You can reach us at support@roamr.place for any question about this policy, your data, or your account.
What we collect
When you create an account
- Email address — to sign you in and to send you account email (verification, password reset). We do not send marketing email.
- Date of birth — to enforce our minimum age of 18. We store the date itself.
- Display name and @handle — shown publicly.
- Password — stored only as a salted scrypt hash. We never see, log, or store your actual password.
When you use the app
- Posts — your captions and photos.
- Place information — the place a post is about. This is not a record of where you were. See "Location" below.
- Profile details — your bio and profile photo, if you add them.
- Activity — likes, comments, and who follows whom.
- Device token — only if you enable push notifications.
- Reports — if you report a post, we record that you did.
What we do not collect
- We do not track you across other apps or websites, and we show no advertising. There are no advertising or analytics trackers in the app.
- We do not collect your contacts, calendar, microphone, or health data.
- We do not record your location in the background. The app only ever asks for your location while you are using it.
Location, specifically
This is the part of Roamr most worth understanding, so we will be precise.
- A place tag records the place a post is about — not where you were when you wrote it.
- Tags are coarse by default. When you tag a place at neighbourhood precision, we round the coordinate to roughly a 1 km grid before storing it. The exact point is never sent to us and is not kept in any hidden field.
- Choosing Exact is a deliberate, per-post choice.
- Posts with no place tag never appear on the map or in Nearby.
- Location is optional. You can decline the permission and keep using the app; you simply search for a place instead.
Who can see what you post
Visibility is enforced on our servers for every request, not just hidden in the app:
- If your profile is public, your posts can appear to your followers and in the global feed and map.
- If your profile is private, your posts are visible only to followers you have approved, and never appear in the global feed or on a non-follower's map.
- Switching to private removes your existing posts from the global feed. Switching to public does not retroactively push old posts into it.
One honest limitation: photos are served from a public media URL. The app never shows a photo to someone who should not see the post, but a photo URL that someone has already obtained will continue to load without signing in. Please bear that in mind when posting sensitive images. We intend to move to signed, expiring media URLs.
Who we share data with
We do not sell your data, and we do not share it for advertising. We use these service providers, and only for the purpose listed:
| Provider | What they handle | Where |
|---|---|---|
| Hetzner | Application and database hosting | Finland (EU) |
| Cloudflare | Photo storage and delivery, map tiles | Global CDN |
| Resend | Account email (verification, password reset) | United States |
| Geoapify | Turning a coordinate into a place name | European Union |
| Sightengine | Automated moderation of your photos | France (EU) |
| OpenAI | Automated moderation of your captions and photos | United States |
| DeepL | Translating a caption, when you ask for it | Germany (EU) |
| Apple | Push notifications, if you enable them | Global |
We may also disclose information where we are legally required to, or where it is necessary to investigate abuse or protect someone's safety.
Planned, not yet in use
One capability is built into the app but not currently active; we will update this policy and this date before enabling it: crash reporting (Sentry).
Content moderation
You can report any post, and block any account. Reports are recorded and reviewed. In addition, every post is screened automatically before it appears — your photos are checked by Sightengine and your captions by OpenAI, and content that breaks our rules is blocked, restricted, or removed. This applies to public and private posts alike.
Child sexual abuse material is handled as a separate and absolute matter. Where detection is enabled we preserve and report such material to the authorities rather than silently deleting it, and we retain it as long as the law requires.
How long we keep things
- Your account and content — until you delete them.
- Deleted accounts — see below.
- Safety records — reports, moderation decisions and violations are kept after an account is deleted, with the person's name and identifying details removed. Without them, someone could erase a record of abuse simply by making a new account.
- Backups — encrypted database backups are kept for 14 days and then deleted. Content you delete may persist in a backup until it ages out.
Deleting your account
You can delete your account from inside the app: Profile → Settings → Delete account. It takes effect immediately.
It cannot be undone. There is no grace period and no way for us to restore it. When you delete:
- Your sign-in, password and every active session are destroyed.
- Your profile, posts, captions, photos, comments, likes and follows are permanently removed. Your posts leave the feed and the map immediately.
- Your photos are deleted from our storage. Copies cached at the CDN may persist briefly until they expire.
- Your @handle and email address are released and may be reused.
- We keep the anonymised safety records described above, and anything the law requires us to preserve.
Your rights
Depending on where you live, you may have the right to access, correct, export or erase your personal data, to object to or restrict processing, and to complain to your data protection authority. Deleting your account in the app exercises the erasure right directly. For anything else, write to support@roamr.place.
Children
Roamr is for adults. You must be at least 18 to use Roamr, and we do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, contact us and we will delete it.
Security
Connections use TLS 1.3, and the app additionally pins our server's public key, so it will refuse to talk to anything impersonating us. Session tokens are stored in the iOS Keychain, never in plain storage. Passwords are stored only as scrypt hashes. Backups are encrypted and stored separately from the server.
No system is perfect. If you find a security problem, please tell us at support@roamr.place before disclosing it publicly, and we will work with you.
Changes
If we change this policy materially we will update the date above and notify you in the app before the change takes effect.