Privacy Policy
Last updated: June 2026 · BisoLobby (Belgium / EU)
BisoLobby processes personal data as a data controller under the GDPR (AVG). This policy explains what we collect, why, and your rights.
1. Data we process
- Account: username, email, password hash, age confirmation (18+).
- Profile: display name, photos, bio, interests, optional location/city.
- Communication: direct messages, room chat (ephemeral by design), voice sessions (signaling metadata).
- Device: push notification tokens, app settings, crash/telemetry (if enabled).
- AI features (optional): radar hints, room suggestions — disable via Settings → AI personalization off.
2. Legal bases
Contract performance (providing the service), legitimate interest (safety, fraud prevention), and consent where required (location, notifications, AI personalization).
3. Retention
- Account & profile: until you delete your account.
- Direct messages: until deleted by users or account deletion.
- Live room chat: ephemeral — not retained after the room session ends.
- AI observation signals: rolling window, typically ≤ 90 days unless required for safety investigations.
- Reports & moderation logs: up to 24 months for legal compliance.
4. Sharing
We use processors (hosting, Cloudinary for images, Expo push, optional Sentry). We do not sell personal data. Data may be processed in the EU/EEA.
5. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Delete your account in-app: Settings → Privacy & safety. Contact: support@bisolobby.app.
6. Security
HTTPS, access controls, moderation, reporting, and rate limiting. No system is 100% secure — report issues promptly.