Last updated: [PLACEHOLDER — date]
Draft pending legal review. This describes how onBubbles handles your data; it is not yet final legal advice.
onBubbles is a private social network built around small, closed groups (“bubbles”). This policy explains what personal data we collect, why, the legal basis for it, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
We designed onBubbles to be private by architecture — there is no public feed, no follower counts and no stranger discovery — and to keep your data in the European Union.
onBubbles (“we”, “us”), operating the service at onbubbles.com, is the controller of your personal data.
Operating entity, registered address and company registration number: [PLACEHOLDER — to be completed by operator].
For any privacy question or to exercise your rights, contact us at privacy@onbubbles.com (placeholder). You also have the right to lodge a complaint with your local supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP).
We collect only what we need to run the service:
onBubbles uses an EU-hosted, open-model AI service (Scaleway Generative APIs, located in the European Union) for two purposes:
Your content is sent to this EU provider only for these purposes, and the provider does not use it to train its models. This is automated processing that assists people — it is not a solely-automated decision that produces legal or similarly significant effects about you. Content the AI flags is reviewed by human moderators (a bubble’s own admins/moderators, and platform staff for escalations).
We do not sell your data. We share it only with the service providers that help us operate onBubbles, each acting on our instructions:
Some of these providers may process limited data outside the EU/EEA (for example in the United States). Where they do, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses. [PLACEHOLDER — confirm each processor’s transfer mechanism and, where relevant, list sub-processors.]
Your primary data is stored in the European Union. See the section above for the limited cases where a processor may handle data outside the EU/EEA under appropriate safeguards.
Under the GDPR (Articles 15–22) you have the right to:
We protect your data with row-level security in the database (so people can only access what they are allowed to), encryption in transit (TLS), a pseudonymised (hashed) phone value rather than the raw number, and strict access controls.
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where the law requires (GDPR Article 33), and affected users where required.
onBubbles is for people aged 16 and over. This reflects the EU and Romanian rules on the age of digital consent. We check age at sign-up and refuse accounts for anyone under 16. If we learn that an under-16 has created an account, we will remove it.
We use a small number of cookies:
We do not use third-party advertising or cross-site tracking cookies.
We may update this policy as onBubbles evolves. We will update the “Last updated” date and, for material changes, let you know in the app.
Questions about your privacy or this policy: privacy@onbubbles.com (placeholder). Operator details: [PLACEHOLDER — to be completed by operator].