MisiBi · Organizația Misiunea Bucovina

Politica de confidențialitate

Version 1.6 · in force since September 11, 2026

MisiBi Privacy Policy

Last updated: 11 September 2026

This page explains what data we collect through the MisiBi app, why, how long we keep it, who receives it, and what you can ask of us. It is written to be understood, not to be impressive. If anything is unclear, write to us and we will explain it in plain words.

This is a translation of the Romanian original. If the two ever disagree, the Romanian text is the one that applies.


1. Who we are

Bucovina Mission Organization is the controller of your data — meaning we decide why and how it is used.

For any question about your data, write to the address above with the subject "Personal data". We answer within 30 days at the latest.


2. What data we collect

2.1. When you create an account

2.2. About your phone

So that the app works and so that we can send you notifications:

2.3. What you do in the app

2.4. What the system produces about you

2.5. Your location, only if you choose to send it

Your location reaches us in one way only: when you choose to send it in a conversation. For that, the app asks for your phone's location permission and uses it only while the app is open on the screen. It does not read your location in the background.

You can send your location once, or live, for a length of time you choose, of at most 2 hours. We send the coordinates (latitude and longitude), their accuracy in metres and a short label. When live, the phone sends its position once a minute, and each new position replaces the one before, so we keep no location history. After you stop sharing, the last position stays visible, like a location sent once.

Your location is seen only by the people in the conversation where you sent it and, like any message, by an administrator only under the conditions in section 5.1. We use it for nothing else, not even for statistics.

If you tap "Open in map", the coordinates go to the map app you choose, which uses them under its own rules.


3. Why we are allowed to do this

The law (EU Regulation 2016/679 — GDPR) requires us to say what we rely on:

What we do Legal basis
Account, profile, posts, messages, calls Performance of the contract — without them the app does not work (Art. 6(1)(b))
The automatic safety check, moderation, the audit log Legitimate interest in keeping the platform safe for everybody, children included (Art. 6(1)(f))
Notifications on your phone Performance of the contract, and your consent at operating-system level
Keeping evidence and handing it to the authorities Legal obligation (Art. 6(1)(c)) and public interest (Art. 6(1)(e))
Situations where somebody appears to be in immediate danger Vital interests of that person (Art. 6(1)(d))
Usage measurements, and whose profiles you open Legitimate interest in improving the app and in showing you a feed that has something to do with you
A location sent in a conversation Performance of the contract, and your consent at operating-system level (the location permission)
The web server's access logs Legitimate interest in protecting the server and the accounts from attacks (Art. 6(1)(f))

You have the right to object to processing based on legitimate interest. Write to us and we will weigh your request against our reason, and answer you in writing.

3.1. Sensitive data

MisiBi is the network of a Christian association that helps people in need. Through what you write, you may reveal things the law considers sensitive data: religious beliefs, health, family circumstances.

We do not ask you for such data and we do not look for it. If you choose to write it in a public post, you are the one making it public — Art. 9(2)(e) GDPR. Please think twice before publishing information about your health or somebody else's.

Never publish sensitive data about another person without their agreement.


4. The automatic safety check

To keep MisiBi a place you can let a child into, every post, comment, story, message and file goes through an automatic check before it reaches anybody else.

4.1. What it looks for

Swearing, harassment, hate speech, threats, sexual content, offers of weapons or drugs, scams, spam, gambling, fake accounts, exposed personal data, and content that puts a child in danger.

4.2. How it works

The check runs on our own servers. Your photos and videos are never sent to another company to be analysed.

Text is compared against a dictionary of words, and files are given a "fingerprint" — a short signature describing what the image looks like, not what is in it. The fingerprint lets us stop a picture that has already been stopped once, even if it is sent again at a different size.

4.3. What can happen

4.4. Your right to a decision made by a person

This is an automated decision within the meaning of Art. 22 GDPR, and the law gives you a clear right, which we honour:

You can ask at any time for a person to look at any automated decision that concerns you. The appeal button is inside the refusal message itself, and the appeal reaches a person, not another machine.

The automatic check produces no legal effects on you and does not affect your rights outside the app. An account is never closed automatically: a person decides that.

4.5. When the system gets it wrong

It will. That is why we keep on display, in the administration panel, how many times a person has said the system was mistaken, and which rule is wrong most often. A rule that stops honest people is removed or weakened.


5. Private messages

The automatic check runs on private messages too, but it blocks nothing — it only notes what it found. Two people talking to each other are not publishing anything, and we do not interfere in how they speak to one another.

Three exceptions, which are not censorship: messages sent in bulk, attempted fraud and direct threats are stopped anyway. Somebody sending the same link to thirty people is not holding a conversation.

5.1. When an administrator can see a conversation

They can, but never simply because they want to. To open a private conversation, there has to be a specific reason:

Every opening:

We do this in our legitimate interest in protecting the people on the platform and, in serious cases, in fulfilling legal obligations.


6. Who else sees your data

We do not sell anybody's data, ever, in any form. For the app to work, we rely on the following providers, who process data only on our instructions:

Provider What it does What it sees
Google (Firebase) sign-in and notifications the email address, the notification token, the text of the notifications sent
Cloudflare (R2) storage of photos and videos the uploaded files
LiveKit Cloud carrying audio and video calls the sound and the picture, only during the call; nothing is recorded
Hostico hosting the server and the database everything belonging to the app, as infrastructure administrator, including the web server's access logs (the IP address, the time and the address of each request)
misiuneabucovina.org the older system, being retired the account and the data brought over from it

The map. The map images come from OpenStreetMap, but they pass through our server: we request them on your behalf, so OpenStreetMap sees neither your IP address nor the area you are looking at.

Some of these providers may process data outside the European Union. In those cases, the transfer is made on the basis of the standard contractual clauses approved by the European Commission or of an adequacy decision.

We pass on data only when:


7. When we go to the authorities

If we find content that appears to put a child in danger, or a serious threat to somebody, we keep it as evidence and hand it to the competent authorities in Romania.

In such a case, the file contains the messages, the files, the times and the accounts involved, together with the full record of who saw what and when. We do not delete this evidence at the request of the person involved, because keeping it is a legal obligation and a matter of public interest.


8. How long we keep data

What How long
Account and profile as long as you have an account, plus 30 days after you ask for deletion
Posts, comments, messages until you delete them or until you delete your account
Stories 24 hours, then deleted automatically, with one day of grace
Photos and videos as long as the content they belong to exists
Uploads started and never finished 24 hours
Whose profiles you have opened 90 days from the last time you opened it
Sign-in sessions at most 90 days, or 30 days of inactivity
Message synchronisation events 7 days
The safety log 24 months
The administrators' audit log 24 months, and it cannot be deleted from the panel
Investigations into conversations permanently — it is the proof that the access was justified
Evidence handed to the authorities for as long as the applicable law requires
A location sent once like any message; it is also deleted when you delete the message for everyone, or automatically when a temporary conversation expires (10 hours)
A live location at most 2 hours; only the last position is kept, and after it stops it remains like a location sent once
The web server's access logs 10 days, then deleted automatically; they are not included in backups

9. What we keep in addition, and what we strip ourselves

We strip out ourselves, from the photos you upload, the hidden data: where the picture was taken, with what camera and at what time. These are things you did not put there, that nobody sees, and that would travel onward with the picture. We cut them out before the picture reaches anybody else.

We do not keep: your password, the content of calls, a history of your location, and no second copy of your words. We do not keep your IP address in readable form, with a single exception: the web server's access logs, which the hosting company uses to protect against attacks and which are deleted automatically after 10 days. The text of a post is copied into the safety log only if it was stopped — because otherwise we could never explain why it was stopped.


10. How we protect your data

No system is perfect. If you find a security problem, write to us at contact@misibi.com and we will answer you as a priority. We will not take action against anybody who reports a problem to us in good faith.


11. Children and minors

MisiBi is not intended for children under 16 without the agreement of a parent or guardian. If we learn that an account belongs to a child under that age without the necessary agreement, we close it and delete the data.

Sexual content involving a minor is treated with absolute priority: it is stopped immediately, kept as evidence and handed to the authorities. There is no situation in which such content is tolerated on MisiBi.

If you are a parent and you believe a child has used your details or has an account you do not approve of, write to us and we will sort it out.


12. Your rights

By law, you have the following rights. All of them are exercised free of charge, by writing to contact@misibi.com or directly from the app:

We answer within 30 days at the latest. If the request is complicated, we tell you and may extend by a further two months, explaining why.

12.1. What we cannot delete

There are things we cannot delete even if you ask, and it is fair that you know in advance:

12.2. If you are not satisfied

You have the right to lodge a complaint with the supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — the Romanian data protection authority B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, Bucharest anspdcp.ro

We would still ask you to write to us first. Most of the time it is a misunderstanding we can clear up in a day.


13. If you are struggling

If you write something that shows us you are going through a hard time, we block nothing and we punish you in no way. We show you the numbers where you can talk to somebody, and ask one of our people to look quickly.


14. Changes to this policy

When we change something important, we tell you in the app at least 15 days beforehand and update the date at the top of this page. Small changes (wording fixes, clarifications) we make without notice.

Older versions remain available on request.


This policy is read together with the MisiBi Terms and Rules of Use.