Privacy policy
Last updated 28 September 2026. This policy covers the INIBI website, the web app at web.inibi.app and the INIBI apps for iPhone and Android.
Who we are
INIBI is published by [Company name], [Registered address], Cluj-Napoca, Romania ([Trade register no. / CUI]), the controller of the personal data described here ("we", "us"). For anything about your data, write to [email protected].
In short
- You can use INIBI without an account. Then we keep nothing that identifies you.
- Your trip history, saved places and preferences are stored on your device. They reach our server only if you create an account, to sync them.
- Your location is used to answer your request (departures near you, a route from where you are) and is not stored.
- INIBI shows ads. Personalised ads only with your consent, which you can change at any time.
- You can delete your account, and everything kept with it, at any time.
What we collect, why, and on what legal basis
| Data | Why | Legal basis (GDPR art. 6) |
|---|---|---|
| Journey requests: the origin, destination or location you plan from, the stops and lines you look at | To plan routes, predict departures and monitor a journey you started. Processed to answer, not stored with anything that identifies you. | Performing our service for you (b) |
| Your location, only if you allow it on your device | To show what's around you, plan from where you are and follow a journey in progress. Sent with the request that needs it; not stored. | Your consent (a), given through your device's location permission and withdrawable there at any time |
| Account: email address, name (if you sign in with Google), a scrambled (hashed) password or your Google account ID, when your email was confirmed, and your sign-in sessions | To create and secure your account and sign you in. | Contract (b) |
| Synced data, with an account: saved trips, saved places (such as Home or Work, with their coordinates), favourite lines, and whether you prefer walking | To keep them the same on every device you sign in on. | Contract (b) |
| Journey alerts in the iPhone and Android apps: your device's push token, the journey you started and its last known location | To warn you while the app is in the background ("Leave now", "Connection at risk"). Held in our server's memory only while that journey runs, at most 3 hours, then dropped. | Your consent (a), given through your device's notification permission; contract (b) |
| Emails we send: your address and the message (confirming your address, resetting your password, deleting your account) | To run your account. | Contract (b) |
| Messages to us: your name, email address and what you write, through the contact form or by email | To answer you. | Legitimate interest in answering (f) |
| Advertising: an advertising identifier or cookie, your approximate location from your IP address, and information about your device and the ads you see | To show ads that pay for INIBI, limit how often you see the same one, measure them and prevent fraud. See Ads. | Your consent (a) for personalised ads and for storing or reading identifiers on your device; legitimate interest (f) for non-personalised ads |
| Technical logs: IP address, time, the address requested and error details, kept by our server | To keep the service secure and working, and to limit abuse (for example, too many messages from one address). | Legitimate interest in security (f) |
We don't use your data for automated decisions that affect you legally or similarly. Suggestions based on your habits are worked out on your device, from the history stored there. Your journeys, places and trip history are never shared with advertisers.
INIBI also collects data about the vehicles, not about people: the live positions that CTP's buses, trolleybuses and trams publish through Tranzy, from which it learns how long each stretch of each line takes. None of it relates to riders.
What stays on your device
The app keeps some things in your browser's or phone's own storage: your trip history and the statistics made from it, saved places and trips, favourite lines, the journey in progress, your ad choices and your settings. Without an account none of this is sent to us. You can remove it by clearing the site's data in your browser or by uninstalling the app.
Who we share it with
We use these providers to run INIBI; each receives only what its task needs:
- Oracle Cloud Infrastructure hosts our server, where the data above is processed and the account database is stored.
- Cloudflare answers for our domain names and may carry and protect traffic to our site.
- Resend (USA) sends our emails and the contact form's messages.
- Google: if you choose "Continue with Google", Google tells us your name, email address and account ID. Journey alerts on Android are delivered through Firebase Cloud Messaging.
- Apple delivers journey alerts on iPhone (Apple Push Notification service).
- [advertising partner] shows the ads, as described under Ads.
- Photon (Komoot) and FOSSGIS / OpenStreetMap routing: when you search for a place or we work out a walking route, our server sends them the search text or the coordinates of the walk, without your IP address or account.
- OpenStreetMap Foundation: map images are loaded by your device directly from OpenStreetMap's servers, which therefore see your IP address, as with any website you visit.
Some of these providers are outside the European Economic Area. Where they are, the transfer is covered by the European Commission's adequacy decision (the EU-US Data Privacy Framework) or its Standard Contractual Clauses. We may also disclose data where the law requires it.
Ads
INIBI is free to use and is paid for by ads, shown by [advertising partner]. Before the first one, the app asks whether you agree to personalised ads. You can change your answer at any time under Ad privacy choices on the account screen. On iPhone, the app also asks for Apple's permission to track before any advertising identifier is used.
- If you agree, our advertising partner may use an advertising identifier or cookies, and information about your device, to show ads based on your interests, as described in its own privacy policy.
- If you don't, you'll still see ads, but not personalised ones. The partner may still use limited data, such as your approximate location from your IP address, to choose them, cap how often you see one, and prevent fraud.
You can also reset or limit your advertising identifier in your phone's settings (on iPhone: Settings > Privacy & Security > Tracking; on Android: Settings > Privacy > Ads).
Cookies
INIBI's own cookies are only the ones it needs to work:
- br_session keeps you signed in, for up to 90 days or until you sign out.
- br_oauth_state protects "Continue with Google" against forgery, for 10 minutes.
- site_lang remembers the language you chose on this website, for a year.
Advertising cookies and identifiers, set by our advertising partner, are used only as described under Ads, and personalised ones only with your consent.
How long we keep it
- Account data and synced data: until you delete your account. It's then deleted from our database at once.
- Sign-in sessions: 90 days at most. Links in our emails expire after 1 to 48 hours.
- Journey alerts: while the journey runs, at most 3 hours.
- Journey requests and location: not kept beyond answering the request.
- Messages to us: as long as needed to deal with them, and at most 2 years, unless you ask us to delete them sooner.
- Advertising data: as set out in our advertising partner's policy; your consent choice until you change it.
- Technical logs: a short time, at most 30 days, unless needed to investigate an incident.
Your rights
Under the General Data Protection Regulation (GDPR) you can ask us to:
- give you a copy of your personal data (access), in a portable format (portability);
- correct it (rectification) or delete it (erasure): you can also delete your account yourself;
- restrict how we use it, or object to uses based on our legitimate interest;
- withdraw a consent you gave, at any time, without affecting what was done before.
Write to [email protected]. We answer within one month. You can also complain to a data protection authority; in Romania, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).
Security
Traffic to INIBI is encrypted (HTTPS). Passwords are stored only as salted scrypt hashes, sign-in sessions and emailed links only as hashes, and access to our server is restricted.
Children
INIBI can be used by anyone without an account. Accounts are not meant for children under 16; if you believe a child has given us personal data, write to us and we'll delete it.
Changes to this policy
If we change this policy we'll update the date at the top, and tell account holders by email about changes that matter to them before they take effect.
Contact
[Company name], [Registered address], Cluj-Napoca, Romania. Email: [email protected]. Or use the contact form.