MisiBi Privacy Policy
Last updated: 28 September 2026
This page explains what data we collect through the MisiBi app, why, how long we keep it, who receives it, and what you can ask of us. It is written to be understood, not to be impressive. If anything is unclear, write to us and we will explain it in plain words.
This is a translation of the Romanian original. If the two ever disagree, the Romanian text is the one that applies.
1. Who we are
Asociația Misiunea Bucovina MB (Bucovina Mission Association) is the controller of your data and the developer of the MisiBi app — meaning we decide why and how your data is used.
- Name: Asociația Misiunea Bucovina MB
- Tax ID (CUI): 48215616
- Registered office: Str. Prieteniei nr. 19, Vicovu de Sus, Suceava County, Romania
- App: MisiBi
- Contact address: contact@misibi.com
- Website: misiuneabucovina.org
For any question about your data, write to the address above with the subject "Personal data". We answer within 30 days at the latest.
2. What data we collect
2.1. When you create an account
- your email address and, if you choose, your phone number;
- your display name and your username;
- your password — never in the clear. Sign-in goes through Firebase (Google), and we neither see nor store your password;
- optionally: your profile description, profile picture, cover picture, and the public links you add yourself.
2.2. About your phone
So that the app works and so that we can send you notifications:
- an installation identifier, generated by us, which says nothing about you outside the app;
- the operating system and its version, the phone model, the app version, the language and the time zone;
- the notification token from Google (FCM), so we can deliver a message or a call to you;
- your IP address and the type of browser or app, kept in the database encrypted, in a form they cannot be read back from. We use them only to recognise a pattern of abuse, never to know where you are. Separately, the web server keeps access logs with the IP address for 10 days (section 8).
2.3. What you do in the app
- the posts, comments, stories and messages you write;
- the photos, videos and voice messages you upload;
- hearts, saves, who follows whom, who has blocked whom;
- whose profiles you open, and how many times. One number per person, not a log of every look, and only so the feed does not read the same for somebody who opens a person's profile every day and somebody who has never opened it. Kept for 90 days;
- calls: who called whom, when, how long it lasted and how it ended. The content of a call — the sound and the picture — is never recorded and never kept by us.
2.4. What the system produces about you
- your active sessions and on which phone;
- the decisions of the automatic safety check (section 4);
- the reports you make or that concern you;
- the requests you send us: feedback, appeals, data requests;
- simple measurements of app use, so we know which screens are awkward.
2.5. Your location, only if you choose to send it
Your location reaches us in one way only: when you choose to send it in a conversation. For that, the app asks for your phone's location permission. On Android it asks only for the "while using the app" kind, never "all the time".
You can send your location once, or live, for a length of time you choose, of at most 2 hours. A location sent once is read only while the app is open. A live location, once you start it, keeps going even with the screen off or while you use another app. As long as it runs, on Android the phone shows a persistent notification with a Stop button, and on iPhone the system shows the location indicator in the status bar. It stops by itself at the time you chose, or when you stop it. In the browser it is sent only while the page is open. Outside of these cases, the app does not read your location.
We send the coordinates (latitude and longitude), their accuracy in metres and a short label. When live, the phone reads its position every few seconds and sends it at most once every 15 seconds while you move, and once a minute while you stay put. Each new position replaces the one before, so we keep no location history. After you stop sharing, the last position stays visible, like a location sent once.
Your location is seen only by the people in the conversation where you sent it and, like any message, by an administrator only under the conditions in section 5.1. We use it for nothing else, not even for statistics.
If you tap "Open in map", the coordinates go to the map app you choose, which uses them under its own rules.
3. Why we are allowed to do this
The law (EU Regulation 2016/679 — GDPR) requires us to say what we rely on:
| What we do | Legal basis |
|---|---|
| Account, profile, posts, messages, calls | Performance of the contract — without them the app does not work (Art. 6(1)(b)) |
| The automatic safety check, moderation, the audit log | Legitimate interest in keeping the platform safe for everybody, children included (Art. 6(1)(f)) |
| Notifications on your phone | Performance of the contract, and your consent at operating-system level |
| Keeping evidence and handing it to the authorities | Legal obligation (Art. 6(1)(c)) and public interest (Art. 6(1)(e)) |
| Situations where somebody appears to be in immediate danger | Vital interests of that person (Art. 6(1)(d)) |
| Usage measurements, and whose profiles you open | Legitimate interest in improving the app and in showing you a feed that has something to do with you |
| A location sent in a conversation | Performance of the contract, and your consent at operating-system level (the location permission) |
| The web server's access logs | Legitimate interest in protecting the server and the accounts from attacks (Art. 6(1)(f)) |
You have the right to object to processing based on legitimate interest. Write to us and we will weigh your request against our reason, and answer you in writing.
3.1. Sensitive data
MisiBi is the network of a Christian association that helps people in need. Through what you write, you may reveal things the law considers sensitive data: religious beliefs, health, family circumstances.
We do not ask you for such data and we do not look for it. If you choose to write it in a public post, you are the one making it public — Art. 9(2)(e) GDPR. Please think twice before publishing information about your health or somebody else's.
Never publish sensitive data about another person without their agreement.
4. The automatic safety check
To keep MisiBi a place you can let a child into, every post, comment, story, message and file goes through an automatic check before it reaches anybody else.
4.1. What it looks for
Swearing, harassment, hate speech, threats, sexual content, offers of weapons or drugs, scams, spam, gambling, fake accounts, exposed personal data, and content that puts a child in danger.
4.2. How it works
The check runs on our own servers. Your photos and videos are never sent to another company to be analysed.
Text is compared against a dictionary of words, and files are given a "fingerprint" — a short signature describing what the image looks like, not what is in it. The fingerprint lets us stop a picture that has already been stopped once, even if it is sent again at a different size.
4.3. What can happen
- It passes — almost always;
- It passes with a word — you get a notice that you used an unsuitable word, and the content stays published;
- It passes and a person looks at it — it stays published, but it goes onto a list;
- Quarantine — you see it, others do not, until a person looks;
- It is not published — and we tell you why on the spot.
4.4. Your right to a decision made by a person
This is an automated decision within the meaning of Art. 22 GDPR, and the law gives you a clear right, which we honour:
You can ask at any time for a person to look at any automated decision that concerns you. The appeal button is inside the refusal message itself, and the appeal reaches a person, not another machine.
The automatic check produces no legal effects on you and does not affect your rights outside the app. An account is never closed automatically: a person decides that.
4.5. When the system gets it wrong
It will. That is why we keep on display, in the administration panel, how many times a person has said the system was mistaken, and which rule is wrong most often. A rule that stops honest people is removed or weakened.
5. Private messages
The automatic check runs on private messages too, but it blocks nothing — it only notes what it found. Two people talking to each other are not publishing anything, and we do not interfere in how they speak to one another.
Three exceptions, which are not censorship: messages sent in bulk, attempted fraud and direct threats are stopped anyway. Somebody sending the same link to thirty people is not holding a conversation.
5.1. When an administrator can see a conversation
They can, but never simply because they want to. To open a private conversation, there has to be a specific reason:
- a report from somebody;
- a signal from the automatic check;
- or a written decision, which the administrator puts their own name to.
Every opening:
- has a written reason, which stays in the system and cannot be deleted;
- is available only to the highest roles — a moderator or a support person cannot do it at all;
- closes itself after 24 hours, after which it has to be opened again, with the reason written once more;
- is recorded in full: which conversation, who, when, for what reason, how many times they read it and how many messages they saw.
We do this in our legitimate interest in protecting the people on the platform and, in serious cases, in fulfilling legal obligations.
6. Who else sees your data
We do not sell anybody's data, ever, in any form. For the app to work, we rely on the following providers, who process data only on our instructions:
| Provider | What it does | What it sees |
|---|---|---|
| Google (Firebase) | sign-in and notifications | the email address, the notification token, the text of the notifications sent |
| Cloudflare (R2) | storage of photos and videos | the uploaded files |
| LiveKit Cloud | carrying audio and video calls | the sound and the picture, only during the call; nothing is recorded |
| Groq (USA) | the MisiBi AI assistant's answers | the text of your conversation with the assistant — without your name, your email address or your account number |
| Google (Gemini) | the answers of the MisiBi AI and MisiBiblia assistants | the text of your conversation with the assistant — without your name, your email address or your account number |
| Hostico | hosting the server and the database | everything belonging to the app, as infrastructure administrator, including the web server's access logs (the IP address, the time and the address of each request) |
| misiuneabucovina.org | the older system, being retired | the account and the data brought over from it |
The map. The map images come from OpenStreetMap, but they pass through our server: we request them on your behalf, so OpenStreetMap sees neither your IP address nor the area you are looking at.
Some of these providers may process data outside the European Union. In those cases, the transfer is made on the basis of the standard contractual clauses approved by the European Commission or of an adequacy decision.
We pass on data only when:
- a competent authority requires it of us, through a lawful request;
- we are bound by a court order;
- it is necessary to protect somebody's life or safety.
6.1. Connected accounts (Facebook, Instagram, TikTok, YouTube)
If you choose to connect an external account in Settings → Connected accounts, MisiBi receives from that platform, with your authorisation: the account's name and picture, its identifier, the list of Pages, accounts or channels you manage, and an access token. The token is stored encrypted and is used only to publish the posts you explicitly choose to send there, and to show you their status. We do not read your messages, comments or any other data on those platforms, and we publish nothing without your action.
You can disconnect an account at any time from the same page; the token is deleted immediately and the access is also revoked at the platform. On a Facebook data deletion request, we delete everything we received for that account. Publishing records — what went where, the link, the status — stay in your MisiBi account and are deleted together with it.
6.2. The MisiBi AI and MisiBiblia assistants
In Messages you will find two accounts that answer on their own: MisiBi AI and MisiBiblia. Their replies are written by an artificial-intelligence program, not by a person, and the conversation says so under their name.
You write to them only if you want to. They never message you first, and they read nothing else in the app: not your conversations with other people, not your posts, not your profile.
What leaves us. Only the text you write in the conversation with them, together with their earlier replies, to Groq (United States) and Google (Gemini). We do not send them your name, your email address, your account number, photos, files or your location.
The answers can be wrong. A program does not understand the way a person does, and it can state untrue things with complete confidence. Do not rely on them for medical, legal or financial decisions. For matters of faith, speak with a priest or someone you trust — MisiBiblia can help you find and understand verses, but it takes no one's place.
Never write there passwords, codes received by email or SMS, card details, or anything else you would not tell a stranger.
You can report any reply. Press and hold the assistant's message and choose Report. The report reaches a person on our team, like any other.
If you would rather not use the assistants, simply do not write to them. You can delete the conversation with them at any time, from the conversation list.
7. When we go to the authorities
If we find content that appears to put a child in danger, or a serious threat to somebody, we keep it as evidence and hand it to the competent authorities in Romania.
In such a case, the file contains the messages, the files, the times and the accounts involved, together with the full record of who saw what and when. We do not delete this evidence at the request of the person involved, because keeping it is a legal obligation and a matter of public interest.
8. How long we keep data
| What | How long |
|---|---|
| Account and profile | as long as you have an account, plus 30 days after you ask for deletion |
| Posts, comments, messages | until you delete them or until you delete your account |
| Stories | 24 hours, then deleted automatically, with one day of grace |
| Photos and videos | as long as the content they belong to exists |
| Uploads started and never finished | 24 hours |
| Whose profiles you have opened | 90 days from the last time you opened it |
| Sign-in sessions | at most 90 days, or 30 days of inactivity |
| Message synchronisation events | 7 days |
| The safety log | 24 months |
| The administrators' audit log | 24 months, and it cannot be deleted from the panel |
| Investigations into conversations | permanently — it is the proof that the access was justified |
| Evidence handed to the authorities | for as long as the applicable law requires |
| A location sent once | like any message; it is also deleted when you delete the message for everyone, or automatically when a temporary conversation expires (10 hours) |
| A live location | at most 2 hours; only the last position is kept, and after it stops it remains like a location sent once |
| The web server's access logs | 10 days, then deleted automatically; they are not included in backups |
9. What we keep in addition, and what we strip ourselves
We strip out ourselves, from the photos you upload, the hidden data: where the picture was taken, with what camera and at what time. These are things you did not put there, that nobody sees, and that would travel onward with the picture. We cut them out before the picture reaches anybody else.
We do not keep: your password, the content of calls, a history of your location, and no second copy of your words. We do not keep your IP address in readable form, with a single exception: the web server's access logs, which the hosting company uses to protect against attacks and which are deleted automatically after 10 days. The text of a post is copied into the safety log only if it was stopped — because otherwise we could never explain why it was stopped.
10. How we protect your data
- passwords never reach us; sign-in goes through Firebase;
- session tokens are stored encrypted, not in the clear, and expire by themselves;
- you can turn on two-step verification for your account;
- users' IP addresses and app identifiers are kept in the database in a form they cannot be read back from; the only exception is the web server's access logs, deleted automatically after 10 days;
- administrators have separate roles with different rights, and every action they take is written into a log that cannot be deleted from the app; in the administrators' logs, their IP address is kept in readable form, so that it can be checked who did what;
- there is no "free" access to private conversations: every opening has a reason, a deadline and a record;
- the administration panel sits on a separate address, is not indexed by search engines and asks for sign-in on every page.
No system is perfect. If you find a security problem, write to us at contact@misibi.com and we will answer you as a priority. We will not take action against anybody who reports a problem to us in good faith.
11. Children and minors
MisiBi is not intended for children under 16 without the agreement of a parent or guardian. If we learn that an account belongs to a child under that age without the necessary agreement, we close it and delete the data.
Sexual content involving a minor is treated with absolute priority: it is stopped immediately, kept as evidence and handed to the authorities. There is no situation in which such content is tolerated on MisiBi.
If you are a parent and you believe a child has used your details or has an account you do not approve of, write to us and we will sort it out.
12. Your rights
By law, you have the following rights. All of them are exercised free of charge, by writing to contact@misibi.com or directly from the app:
- Access — to learn what data we hold about you and to receive a copy;
- Rectification — to correct what is wrong;
- Erasure — to ask for your account and data to be deleted (the "right to be forgotten");
- Restriction — to ask us to stop using certain data for a while;
- Portability — to receive your data in a format you can take elsewhere;
- Objection — to object to processing based on our legitimate interest;
- Withdrawal of consent, at any time, where we relied on it;
- Not to be subject to a decision made solely by a machine — see section 4.4.
We answer within 30 days at the latest. If the request is complicated, we tell you and may extend by a further two months, explaining why.
12.1. What we cannot delete
There are things we cannot delete even if you ask, and it is fair that you know in advance:
- evidence already handed to the authorities;
- the administrators' audit log and the records of investigations, because they are precisely the guarantee that the access was justified;
- the messages you sent somebody else remain in that person's conversation, just as a letter that has been sent stays with whoever received it;
- data needed to fulfil a legal obligation, for as long as the law requires it.
12.2. If you are not satisfied
You have the right to lodge a complaint with the supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — the Romanian data protection authority B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, Bucharest anspdcp.ro
We would still ask you to write to us first. Most of the time it is a misunderstanding we can clear up in a day.
13. If you are struggling
If you write something that shows us you are going through a hard time, we block nothing and we punish you in no way. We show you the numbers where you can talk to somebody, and ask one of our people to look quickly.
- Child Helpline (Romania): 116 111 — around the clock, free
- Emergencies: 112
14. Changes to this policy
When we change something important, we tell you in the app at least 15 days beforehand and update the date at the top of this page. Small changes (wording fixes, clarifications) we make without notice.
Older versions remain available on request.
This policy is read together with the MisiBi Terms and Rules of Use.