Privacy Policy
Last updated: 20 July 2026 Version: 1.0
1. Who we are
Roam is operated by:
Roam Software ApS by Trekroner Ventures ApS CVR: 46659996
Sole director: Lars Martin Ott
We are the data controller for the personal data described in this policy.
Contact for privacy matters: privacy@joinroam.app
This policy explains what data Roam collects, why, on what legal basis, how long we keep it, and what rights you have. It applies to the Roam mobile app and any related services.
2. The most important thing: Roam does not track your location
Roam has no access to your device's location. It does not use GPS. It does not track where you are, and it never has.
This is not a limitation — it is the entire design. Roam is about plans, not positions. You tell Roam where you intend to be, in the future, in your own words ("Berlin, 12–15 July"). Roam does not verify it, detect it, or observe it. If you close the app and fly to Tokyo, Roam has no idea.
Concretely, this means:
- The app requests no location permission of any kind.
- No GPS coordinates, no background location, no geofencing, no "last seen" positions.
- Photos you upload as avatars are resized and re-encoded before upload, which removes any embedded EXIF metadata (including GPS coordinates that phone cameras often attach to photos). We do not store the original file.
- The cities you enter are free-text entries you type or select. They are as precise or vague as you choose to make them.
Everything Roam knows about where you'll be, you told it deliberately.
3. What data we collect
Below is a complete and specific list, derived from Roam's actual database. We have tried not to hide anything in vague categories.
3.1 Account data
| Data | Notes |
|---|---|
| Email address | Used to log in and to contact you about your account. |
| Password | Stored only as a cryptographic hash. We never see or store your actual password. |
| Display name | Chosen by you; visible to your friends. |
| Username | Chosen by you; used so friends can find you. |
| Profile emoji | Chosen by you. |
| Avatar image (optional) | Resized to 400×400 and re-encoded before upload; EXIF/GPS metadata is removed. |
| Birthday (day and month only) | Optional. We do not ask for or store your birth year. You can hide it from friends. |
| Terms acceptance | The fact and version of the terms you accepted. |
3.2 Location plans — the core of the service
| Data | Notes |
|---|---|
| Base city | The city you consider your home base. You can hide it from all friends, or from specific friends. |
| Trips | A city, a start date and an end date, an optional note, a visibility setting, and whether the trip is confirmed or tentative. |
| Trip stops | Optional intermediate destinations within a trip (city + dates). |
| Chapters | Longer life changes involving a move: a category (work / education / personal), a title you write, the new city, a start date, and an optional end date. |
These are plans, not observations. They are dates and city names you typed in. They contain no coordinates.
Notes are free text. Anything you write in a trip note is stored as you wrote it. Please keep in mind that notes are shown to friends who can see that trip.
3.3 Social graph
| Data | Notes |
|---|---|
| Friendships | Who you are connected to, and whether a request is pending or accepted. |
| Per-friend privacy settings | If you choose to hide your destinations from a specific friend, that choice is stored. |
| Blocks | If you block someone, we store that. |
| Invites | Invitation links you create. |
3.4 Derived data — "crossings"
Roam calculates overlaps between your plans and your friends' plans. If you and a friend will both be in Berlin during the same week, Roam computes that and shows it to both of you.
We are calling this out explicitly because it is a genuine processing activity, not just storage: Roam generates new information about you and another person by combining two sets of plans. This calculation happens only between people who are already mutually accepted friends, and only using data each of you chose to share with the other.
3.5 Safety data
| Data | Notes |
|---|---|
| Reports | If you report another user, we store who reported whom, the reason category, and any details you write. These details are free text and may describe another person. |
| Blocks | As above. |
3.6 Feedback
If you send feedback through the app, we store what you wrote and that it came from you.
3.7 Calendar imports
Roam has an import from calendar file feature. This deserves precision, because it is more limited than people often assume:
- Roam does not have access to your device calendar. The app requests no calendar permission and cannot read your calendar.
- Instead, you select a calendar file (`.ics`) that you have exported yourself.
- That file is read and parsed entirely on your device. It is never uploaded.
- Roam then shows you the events it found, and you confirm each one individually.
- For each event you confirm, only the following is uploaded: the city (taken from the event's location), the start and end dates, and the event title (stored as the trip note, if it differs from the location). Nothing else from the event — no description, no attendees, no organiser, no times of day, no other events — is read or transmitted.
A note of caution: because the event title becomes the trip note, importing an event called "Berlin — job interview at Acme Corp" will store that full title as a note visible to friends who can see that trip. Review the note after importing if it contains something you'd rather not share.
3.8 What we do NOT collect
To be unambiguous, Roam does not collect:
- Your device location (GPS, coarse, background, or otherwise)
- Your phone number (in this version — see section 12)
- Your address book / contacts (in this version — see section 12)
- Your device calendar
- Your birth year
- Advertising identifiers (IDFA)
- Analytics, usage tracking, or telemetry — there is no analytics or crash-reporting SDK in the app at all (no Google Analytics, Firebase, Sentry, Amplitude, or anything comparable)
- Payment data — Roam is currently free and has no in-app purchases
4. How we use your data, and on what legal basis
Under Art. 6 GDPR, each processing activity needs a legal basis. Here is ours, per purpose:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account | Email, password hash, name, username, emoji | Art. 6(1)(b) — performance of a contract (our terms) |
| Showing your plans to the friends you chose | Base city, trips, stops, chapters, visibility settings | Art. 6(1)(b) — this is the service you signed up for |
| Calculating and showing crossings | Your plans + your friends' plans | Art. 6(1)(b) — the core feature of the app |
| Optional profile details (avatar, birthday) | Avatar, birthday day/month | Art. 6(1)(a) — consent (you choose to add them; you can remove them) |
| Local reminder notifications | Scheduled on your device only | Art. 6(1)(a) — consent (you grant notification permission; you can revoke it) |
| Handling blocks and reports | Report reason/details, block records | Art. 6(1)(f) — legitimate interests: keeping users safe and enforcing our terms |
| Preventing abuse and securing the service | Account and access data | Art. 6(1)(f) — legitimate interests: security |
| Responding to your feedback | Your feedback message | Art. 6(1)(f) — legitimate interests: improving the app |
| Complying with legal obligations | Whatever the law requires | Art. 6(1)(c) — legal obligation |
We do not rely on legitimate interests for any form of profiling, advertising, or data sale — because we do none of those things.
5. Who can see your data
This is where Roam differs from most social apps, and we want to be exact.
5.1 Nobody sees your plans by default except the friends you accepted
- A person can only see your plans if you and they are mutually accepted friends.
- A pending friend request grants no visibility whatsoever.
- If either of you has blocked the other, neither sees anything of the other.
This is enforced on the server, not just hidden in the app interface. Data you have not shared does not leave our database.
5.2 You control visibility per trip
Every trip has one of three settings:
- Full — friends see the city and dates.
- Vague — friends see that you're away, and when, but not where. The city name is removed on the server before it is ever sent to them.
- Private — friends see nothing at all. The trip exists only for you.
Tentative (unconfirmed) trips are not shown to friends until you confirm them.
5.3 You control visibility per person
You can hide your destinations from specific friends while remaining friends with them. If you do, that person sees you're away but not where — and this too is enforced server-side.
You can also hide your base city — from everyone, or from specific people.
5.4 What friends see
| Data | Visible to accepted friends |
|---|---|
| Name, username, emoji, avatar | Yes |
| Base city | Yes, unless you hide it (globally or from that person) |
| Trips | According to each trip's visibility setting, and any per-person hiding |
| Chapters | Same rules as trips |
| Birthday (day/month) | Only if you enable it |
| Crossings with you | Yes — if you can both see the relevant trips |
| Your notes on visible trips | Yes |
| Blocks, reports, private trips, per-person hiding | Never |
5.5 Reports and blocks are confidential
If you report someone, they are not told who reported them. If you block someone, they are not notified.
6. Where your data is stored
Roam's data is stored with Supabase, our infrastructure provider, in a European region. This includes the database (accounts, plans, friendships) and the storage bucket (avatars).
Supabase acts as our data processor under Art. 28 GDPR and processes data only on our instructions.
We do not transfer your personal data outside the EU/EEA for the operation of the service as described in this policy. There is no US analytics provider, no advertising network, no third-party SDK receiving your data.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account data | For as long as your account exists |
| Trips, stops, chapters | 24 months after the trip's end date, then deleted |
| Friendships | Until either party removes the friendship or deletes their account |
| Per-friend privacy settings | Until you change them or delete your account |
| Blocks | Until you unblock the person, or you delete your account |
| Reports | 12 months from submission (so we can spot repeat offenders), then deleted |
| Feedback | 12 months |
| Inactive accounts | After 24 months of inactivity we will contact you at your registered email; if you do not respond, the account and its data are deleted |
If you delete your account, deletion is immediate and complete (see section 8).
8. Deleting your account and your data
You can delete your account at any time, from inside the app: Settings → Delete account.
This is a real deletion, not a deactivation. When you confirm it, we delete:
- your profile,
- all your trips, stops and chapters,
- your friendships and pending requests,
- your privacy settings, blocks, invites and feedback,
- your avatar image,
- and your login credentials (your authentication record itself).
Nothing is retained in a "deleted" state, and the deletion cascades through our database automatically.
One honest caveat: if you sent someone a report, that report may be retained for the retention period in section 7, because it exists to protect the person you reported about — but it will no longer be linked to an active account. Likewise, if another user blocked you, their block record persists (it belongs to them, not you). Backups may take up to 30 days to cycle out.
9. Your rights
Under the GDPR (and UK GDPR), you have the right to:
- Access your data — get a copy of what we hold about you (Art. 15)
- Rectify it — correct anything wrong (Art. 16)
- Erase it — delete your account and data (Art. 17). You can do this yourself in the app, instantly.
- Restrict processing (Art. 18)
- Data portability — receive your data in a machine-readable format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, where processing is based on consent (Art. 7(3))
How to exercise them: email privacy@joinroam.app. We will respond within one month, as required by Art. 12(3) GDPR.
Most of what you need, you can do yourself: edit or delete any trip, change any visibility setting, or delete your entire account, all directly in the app.
Right to complain: you can lodge a complaint with a supervisory authority. If you are in Germany, that is the data protection authority of your federal state. If you are in Denmark, it is Datatilsynet. In the UK, it is the Information Commissioner's Office (ICO).
Note on data export: Roam does not currently have a one-click "export my data" button in the app. Until it does, email privacy@joinroam.app and we will provide your data within one month.
10. Notifications
Roam's notifications are scheduled locally on your device. There is no push server. No push token is generated, stored, or transmitted, and we cannot send you a notification remotely. If you deny notification permission, nothing about the app's data handling changes.
(This will change if we introduce server-side push notifications, and this policy will be updated before that happens.)
11. Security
- Passwords are stored only as cryptographic hashes.
- All data in transit is encrypted (HTTPS/TLS).
- Access to your data is enforced at the database level (row-level security), not merely in the app. Data you have not shared cannot be retrieved by another user even if they bypass the app interface.
- Avatars are stripped of metadata by re-encoding before upload.
No system is perfectly secure, and we won't claim otherwise. If we ever become aware of a breach affecting your data, we will notify the relevant supervisory authority within 72 hours as required by Art. 33 GDPR, and notify you directly where the law requires it.
12. Age limit
You must be at least 16 years old to use Roam.
We chose 16 because that is the threshold under Art. 8 GDPR as implemented in Germany, one of our primary markets — and because an app that shares where you'll be is not appropriate for children.
We do not knowingly collect data from anyone under 16. If you believe a child under 16 is using Roam, contact privacy@joinroam.app and we will delete the account.
13. What's coming (and what will change)
We are telling you this in advance because it affects your data:
Phone numbers and contact matching. In a future version, Roam intends to let you find friends via your phone contacts. This will require verifying your phone number and matching contacts. It does not exist in this version — Roam currently requests no contacts permission and stores no phone numbers. When we build it, we will update this policy and tell you before it launches.
Server-side push notifications. Currently notifications are local-only. If we add real push, push tokens will be involved and this policy will be updated.
Optional subscription. Roam is currently free. If we introduce a paid tier, payment processing will be handled by Apple, and this policy will be updated.
We will not quietly expand what we collect. Material changes to this policy will be announced in the app.
14. Changes to this policy
We may update this policy. If we make material changes, we will notify you in the app and update the "Last updated" date. Continued use after a change means you accept the updated policy.
15. Contact
Privacy questions, data requests, complaints: privacy@joinroam.app
Roam Software ApS by Trekroner Ventures ApS CVR: 46659996