MisiBi Privacy Policy
Last updated: 11 September 2026
This page explains what data we collect through the MisiBi app, why, how long we keep it, who receives it, and what you can ask of us. It is written to be understood, not to be impressive. If anything is unclear, write to us and we will explain it in plain words.
This is a translation of the Romanian original. If the two ever disagree, the Romanian text is the one that applies.
1. Who we are
Bucovina Mission Organization is the controller of your data — meaning we decide why and how it is used.
- Contact address: contact@misibi.com
- Website: misiuneabucovina.org
- App: MisiBi
For any question about your data, write to the address above with the subject "Personal data". We answer within 30 days at the latest.
2. What data we collect
2.1. When you create an account
- your email address and, if you choose, your phone number;
- your display name and your username;
- your password — never in the clear. Sign-in goes through Firebase (Google), and we neither see nor store your password;
- optionally: your profile description, profile picture, cover picture, and the public links you add yourself.
2.2. About your phone
So that the app works and so that we can send you notifications:
- an installation identifier, generated by us, which says nothing about you outside the app;
- the operating system and its version, the phone model, the app version, the language and the time zone;
- the notification token from Google (FCM), so we can deliver a message or a call to you;
- your IP address and the type of browser or app, kept in the database encrypted, in a form they cannot be read back from. We use them only to recognise a pattern of abuse, never to know where you are. Separately, the web server keeps access logs with the IP address for 10 days (section 8).
2.3. What you do in the app
- the posts, comments, stories and messages you write;
- the photos, videos and voice messages you upload;
- hearts, saves, who follows whom, who has blocked whom;
- whose profiles you open, and how many times. One number per person, not a log of every look, and only so the feed does not read the same for somebody who opens a person's profile every day and somebody who has never opened it. Kept for 90 days;
- calls: who called whom, when, how long it lasted and how it ended. The content of a call — the sound and the picture — is never recorded and never kept by us.
2.4. What the system produces about you
- your active sessions and on which phone;
- the decisions of the automatic safety check (section 4);
- the reports you make or that concern you;
- the requests you send us: feedback, appeals, data requests;
- simple measurements of app use, so we know which screens are awkward.
2.5. Your location, only if you choose to send it
Your location reaches us in one way only: when you choose to send it in a conversation. For that, the app asks for your phone's location permission and uses it only while the app is open on the screen. It does not read your location in the background.
You can send your location once, or live, for a length of time you choose, of at most 2 hours. We send the coordinates (latitude and longitude), their accuracy in metres and a short label. When live, the phone sends its position once a minute, and each new position replaces the one before, so we keep no location history. After you stop sharing, the last position stays visible, like a location sent once.
Your location is seen only by the people in the conversation where you sent it and, like any message, by an administrator only under the conditions in section 5.1. We use it for nothing else, not even for statistics.
If you tap "Open in map", the coordinates go to the map app you choose, which uses them under its own rules.
3. Why we are allowed to do this
The law (EU Regulation 2016/679 — GDPR) requires us to say what we rely on:
| What we do | Legal basis |
|---|---|
| Account, profile, posts, messages, calls | Performance of the contract — without them the app does not work (Art. 6(1)(b)) |
| The automatic safety check, moderation, the audit log | Legitimate interest in keeping the platform safe for everybody, children included (Art. 6(1)(f)) |
| Notifications on your phone | Performance of the contract, and your consent at operating-system level |
| Keeping evidence and handing it to the authorities | Legal obligation (Art. 6(1)(c)) and public interest (Art. 6(1)(e)) |
| Situations where somebody appears to be in immediate danger | Vital interests of that person (Art. 6(1)(d)) |
| Usage measurements, and whose profiles you open | Legitimate interest in improving the app and in showing you a feed that has something to do with you |
| A location sent in a conversation | Performance of the contract, and your consent at operating-system level (the location permission) |
| The web server's access logs | Legitimate interest in protecting the server and the accounts from attacks (Art. 6(1)(f)) |
You have the right to object to processing based on legitimate interest. Write to us and we will weigh your request against our reason, and answer you in writing.
3.1. Sensitive data
MisiBi is the network of a Christian association that helps people in need. Through what you write, you may reveal things the law considers sensitive data: religious beliefs, health, family circumstances.
We do not ask you for such data and we do not look for it. If you choose to write it in a public post, you are the one making it public — Art. 9(2)(e) GDPR. Please think twice before publishing information about your health or somebody else's.
Never publish sensitive data about another person without their agreement.
4. The automatic safety check
To keep MisiBi a place you can let a child into, every post, comment, story, message and file goes through an automatic check before it reaches anybody else.
4.1. What it looks for
Swearing, harassment, hate speech, threats, sexual content, offers of weapons or drugs, scams, spam, gambling, fake accounts, exposed personal data, and content that puts a child in danger.
4.2. How it works
The check runs on our own servers. Your photos and videos are never sent to another company to be analysed.
Text is compared against a dictionary of words, and files are given a "fingerprint" — a short signature describing what the image looks like, not what is in it. The fingerprint lets us stop a picture that has already been stopped once, even if it is sent again at a different size.
4.3. What can happen
- It passes — almost always;
- It passes with a word — you get a notice that you used an unsuitable word, and the content stays published;
- It passes and a person looks at it — it stays published, but it goes onto a list;
- Quarantine — you see it, others do not, until a person looks;
- It is not published — and we tell you why on the spot.
4.4. Your right to a decision made by a person
This is an automated decision within the meaning of Art. 22 GDPR, and the law gives you a clear right, which we honour:
You can ask at any time for a person to look at any automated decision that concerns you. The appeal button is inside the refusal message itself, and the appeal reaches a person, not another machine.
The automatic check produces no legal effects on you and does not affect your rights outside the app. An account is never closed automatically: a person decides that.
4.5. When the system gets it wrong
It will. That is why we keep on display, in the administration panel, how many times a person has said the system was mistaken, and which rule is wrong most often. A rule that stops honest people is removed or weakened.
5. Private messages
The automatic check runs on private messages too, but it blocks nothing — it only notes what it found. Two people talking to each other are not publishing anything, and we do not interfere in how they speak to one another.
Three exceptions, which are not censorship: messages sent in bulk, attempted fraud and direct threats are stopped anyway. Somebody sending the same link to thirty people is not holding a conversation.
5.1. When an administrator can see a conversation
They can, but never simply because they want to. To open a private conversation, there has to be a specific reason:
- a report from somebody;
- a signal from the automatic check;
- or a written decision, which the administrator puts their own name to.
Every opening:
- has a written reason, which stays in the system and cannot be deleted;
- is available only to the highest roles — a moderator or a support person cannot do it at all;
- closes itself after 24 hours, after which it has to be opened again, with the reason written once more;
- is recorded in full: which conversation, who, when, for what reason, how many times they read it and how many messages they saw.
We do this in our legitimate interest in protecting the people on the platform and, in serious cases, in fulfilling legal obligations.
6. Who else sees your data
We do not sell anybody's data, ever, in any form. For the app to work, we rely on the following providers, who process data only on our instructions:
| Provider | What it does | What it sees |
|---|---|---|
| Google (Firebase) | sign-in and notifications | the email address, the notification token, the text of the notifications sent |
| Cloudflare (R2) | storage of photos and videos | the uploaded files |
| LiveKit Cloud | carrying audio and video calls | the sound and the picture, only during the call; nothing is recorded |
| Hostico | hosting the server and the database | everything belonging to the app, as infrastructure administrator, including the web server's access logs (the IP address, the time and the address of each request) |
| misiuneabucovina.org | the older system, being retired | the account and the data brought over from it |
The map. The map images come from OpenStreetMap, but they pass through our server: we request them on your behalf, so OpenStreetMap sees neither your IP address nor the area you are looking at.
Some of these providers may process data outside the European Union. In those cases, the transfer is made on the basis of the standard contractual clauses approved by the European Commission or of an adequacy decision.
We pass on data only when:
- a competent authority requires it of us, through a lawful request;
- we are bound by a court order;
- it is necessary to protect somebody's life or safety.
7. When we go to the authorities
If we find content that appears to put a child in danger, or a serious threat to somebody, we keep it as evidence and hand it to the competent authorities in Romania.
In such a case, the file contains the messages, the files, the times and the accounts involved, together with the full record of who saw what and when. We do not delete this evidence at the request of the person involved, because keeping it is a legal obligation and a matter of public interest.
8. How long we keep data
| What | How long |
|---|---|
| Account and profile | as long as you have an account, plus 30 days after you ask for deletion |
| Posts, comments, messages | until you delete them or until you delete your account |
| Stories | 24 hours, then deleted automatically, with one day of grace |
| Photos and videos | as long as the content they belong to exists |
| Uploads started and never finished | 24 hours |
| Whose profiles you have opened | 90 days from the last time you opened it |
| Sign-in sessions | at most 90 days, or 30 days of inactivity |
| Message synchronisation events | 7 days |
| The safety log | 24 months |
| The administrators' audit log | 24 months, and it cannot be deleted from the panel |
| Investigations into conversations | permanently — it is the proof that the access was justified |
| Evidence handed to the authorities | for as long as the applicable law requires |
| A location sent once | like any message; it is also deleted when you delete the message for everyone, or automatically when a temporary conversation expires (10 hours) |
| A live location | at most 2 hours; only the last position is kept, and after it stops it remains like a location sent once |
| The web server's access logs | 10 days, then deleted automatically; they are not included in backups |
9. What we keep in addition, and what we strip ourselves
We strip out ourselves, from the photos you upload, the hidden data: where the picture was taken, with what camera and at what time. These are things you did not put there, that nobody sees, and that would travel onward with the picture. We cut them out before the picture reaches anybody else.
We do not keep: your password, the content of calls, a history of your location, and no second copy of your words. We do not keep your IP address in readable form, with a single exception: the web server's access logs, which the hosting company uses to protect against attacks and which are deleted automatically after 10 days. The text of a post is copied into the safety log only if it was stopped — because otherwise we could never explain why it was stopped.
10. How we protect your data
- passwords never reach us; sign-in goes through Firebase;
- session tokens are stored encrypted, not in the clear, and expire by themselves;
- you can turn on two-step verification for your account;
- users' IP addresses and app identifiers are kept in the database in a form they cannot be read back from; the only exception is the web server's access logs, deleted automatically after 10 days;
- administrators have separate roles with different rights, and every action they take is written into a log that cannot be deleted from the app; in the administrators' logs, their IP address is kept in readable form, so that it can be checked who did what;
- there is no "free" access to private conversations: every opening has a reason, a deadline and a record;
- the administration panel sits on a separate address, is not indexed by search engines and asks for sign-in on every page.
No system is perfect. If you find a security problem, write to us at contact@misibi.com and we will answer you as a priority. We will not take action against anybody who reports a problem to us in good faith.
11. Children and minors
MisiBi is not intended for children under 16 without the agreement of a parent or guardian. If we learn that an account belongs to a child under that age without the necessary agreement, we close it and delete the data.
Sexual content involving a minor is treated with absolute priority: it is stopped immediately, kept as evidence and handed to the authorities. There is no situation in which such content is tolerated on MisiBi.
If you are a parent and you believe a child has used your details or has an account you do not approve of, write to us and we will sort it out.
12. Your rights
By law, you have the following rights. All of them are exercised free of charge, by writing to contact@misibi.com or directly from the app:
- Access — to learn what data we hold about you and to receive a copy;
- Rectification — to correct what is wrong;
- Erasure — to ask for your account and data to be deleted (the "right to be forgotten");
- Restriction — to ask us to stop using certain data for a while;
- Portability — to receive your data in a format you can take elsewhere;
- Objection — to object to processing based on our legitimate interest;
- Withdrawal of consent, at any time, where we relied on it;
- Not to be subject to a decision made solely by a machine — see section 4.4.
We answer within 30 days at the latest. If the request is complicated, we tell you and may extend by a further two months, explaining why.
12.1. What we cannot delete
There are things we cannot delete even if you ask, and it is fair that you know in advance:
- evidence already handed to the authorities;
- the administrators' audit log and the records of investigations, because they are precisely the guarantee that the access was justified;
- the messages you sent somebody else remain in that person's conversation, just as a letter that has been sent stays with whoever received it;
- data needed to fulfil a legal obligation, for as long as the law requires it.
12.2. If you are not satisfied
You have the right to lodge a complaint with the supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — the Romanian data protection authority B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, Bucharest anspdcp.ro
We would still ask you to write to us first. Most of the time it is a misunderstanding we can clear up in a day.
13. If you are struggling
If you write something that shows us you are going through a hard time, we block nothing and we punish you in no way. We show you the numbers where you can talk to somebody, and ask one of our people to look quickly.
- Child Helpline (Romania): 116 111 — around the clock, free
- Emergencies: 112
14. Changes to this policy
When we change something important, we tell you in the app at least 15 days beforehand and update the date at the top of this page. Small changes (wording fixes, clarifications) we make without notice.
Older versions remain available on request.
This policy is read together with the MisiBi Terms and Rules of Use.