Privacy policy
Last updated: 2026-09-07
This policy says what mobile collects about you, why, where it is kept and how you can have it removed. It applies to the app and to this site.
Who is responsible
[Legal entity], [Postal address], publishes mobile and is the controller of the data described here. Questions and requests go to [support email].
What we collect, and why
Your account
Your email address, your name and your password, which is stored as a hash and never in clear text. We need them to create your account and to let you sign in. Basis: performing our contract with you.
Your sessions
When you sign in, the app receives a session token. The server keeps that token with the IP address and the device description (user agent) of the sign-in, and its expiry. A session ends after seven days without use, or when you sign out. We use this to keep you signed in and to notice a session that was not yours. Basis: performing our contract with you, and our legitimate interest in keeping accounts safe.
Password reset and email verification
When you ask to reset your password or to verify your address, the server generates a six-digit code, keeps it encrypted with a five-minute expiry, and emails it to you. Resetting a password ends every session open at the time, on every device, so an account someone else reached does not stay theirs. Basis: performing our contract with you, and our legitimate interest in keeping accounts safe.
Sending those emails
The emails go out through Resend (United States), which receives your address and the message itself for as long as it takes to deliver it. Resend's own policy is at resend.com/legal/privacy-policy. Basis: performing our contract with you.
Sign-in attempts
To slow down password guessing, the server counts sign-in and sign-up attempts per IP address over the last minute. The count lives in memory and is gone after that minute. Basis: our legitimate interest in keeping accounts safe.
App updates
At launch the app asks Expo's update service whether newer code is available. Expo, Inc. (United States) receives your device's IP address and the app's version for that request; we receive nothing personal from it. Expo's own policy is at expo.dev/privacy. Basis: our legitimate interest in keeping the app current.
What we do not collect
No analytics, no advertising identifiers, no location, no contacts, no tracking across other apps or sites. This site sets no cookies.
Where it is kept
The app's server and its database run with Contabo in France. Your data leaves it in two cases only, both named above: an email on its way through Resend, and the app's update check. Both processors are in the United States, so those two flows are a transfer outside the European Economic Area, made under the contractual clauses each provider publishes.
How long
- Account data: until you delete your account.
- Sessions: until they expire or you sign out.
- Password-reset and verification codes: five minutes.
- Sign-in attempts: one minute.
Who we share it with
Nobody beyond the three processors named above: the hosting provider, which runs the server, Resend, which delivers the emails, and Expo, which answers the update check. We do not sell data, and we do not share it for advertising.
Your rights
You can ask for a copy of your data, have it corrected, have it deleted, restrict or object to its use, or receive it in a portable format. Write to [support email] from the address on your account; we answer within a month. You can also complain to the data-protection authority of the country you live in.
Deleting your account
You can delete your account from inside the app, or by email if you no longer have it. Both paths, and exactly what they remove, are on the account-deletion page.
Children
mobile is not directed at children under 16, and we do not knowingly hold an account for one. If you believe a child has created one, write to us and we will delete it.
Changes
The date at the top says when this policy last changed.