Privacy Policy

ToBe — Last updated: 2026-10-09

Who we are

ToBe is built by Dilmun (دلمون). Dilmun (دلمون) is the controller of your data. This page explains what data the app collects, why, and how we use it. For privacy questions, email us at [email protected].

Data we collect

When you sign in with Google (or Apple on iOS), the sign-in system (Firebase Authentication) keeps your email only to confirm your identity — it is never copied into our own database (Firestore) and no other user ever sees it.

Our servers generate a random user ID to identify your account and presses internally. We also store, tied to your account: the pseudonym you choose, the country you pick yourself from a list (not from GPS or your IP address), your app language, and your device's time-zone offset (to work out your local day accurately, so your streak lines up with your own clock).

We keep your press log: the date and time of each press, its day number in your streak, and your total press count.

With every press you pick a mood icon (required), and may write an optional word (max 60 characters). If you publish them, they are stored under your pseudonym and shown to other users in the community ticker. A "private" word — one that signals serious distress and that you did not choose to publish — stays on your phone only, locally, and never reaches our servers.

If you report another user’s content, or are reported, we keep the reason and both parties’ identifiers solely for moderation and safety. The list of pseudonyms you block (capped at 500) is also stored tied to your account.

Every request the app sends to our servers carries an automatic integrity token (Google Play Integrity / Firebase App Check) proving it comes from a genuine, unmodified copy of the app, not a bot. That token is checked on the spot for each request and we do not store it.

We do not collect your geolocation (no GPS, no IP-based location), and we never access your photos or device files. Your daily stamp is drawn on your phone and saved to your photo gallery only when you ask it to — it is never uploaded to our servers. We do not collect any financial or health information; the current version of the app is entirely free, has no purchases, and makes no medical claim or service.

What other users see

Your real name and email are never shown to any other user. What others can see is only your pseudonym, your mood icon and word if you chose to publish them, and your streak count if you share your own card. Your country is not currently shown to other users in any form — not as a live location and not as an aggregate count.

Who processes your data, and sharing with third parties

We use Firebase and Google Cloud infrastructure (sign-in, the Firestore database, Cloud Functions, and App Check) as our technical data processor; our backend (Cloud Functions) runs in the EU region europe-west1, and these platforms encrypt traffic between your app and our servers by default (HTTPS). Google processes this data as our service provider, not as its owner.

We do not sell your data or share it with any company outside Dilmun, or with any advertiser — the app carries no ads in any version. There is no analytics tool or cross-app tracking in the app at all.

How long we keep your data

We keep your profile and press history for as long as your account exists. If you give up a pseudonym — by renaming or by deleting your account — we hold that name in reserve for 30 days before anyone else can take it. That reservation holds only the released name, a technical identifier of your former account and the time you released it — no other personal data; it exists only to stop someone impersonating you right after you let the name go.

Controlling and deleting your account

You can delete your account entirely at any time from the "Me" tab inside the app (the last, red item: "Delete account", after two confirmations), or without opening the app via the dedicated page: /apps/tobe/delete-account. Deletion immediately erases your profile, your pseudonym, every press you’ve made, your published and private words, and any reports tied to you from our servers, then deletes your sign-in account itself (for Apple sign-in users, your Apple link is revoked too), and cannot be undone.

Security

All communication between the app and our servers is encrypted (HTTPS/TLS), guaranteed by the Firebase platform itself. Every write to the database goes through our servers (Cloud Functions) only — the app never writes to the database directly.

Minimum age

ToBe is intended for people aged 13 and over, and signing up requires confirming this. We do not knowingly collect data from children under this age; if we learn that an account belongs to someone younger, we will delete it.

Changes to this policy

We may update this policy from time to time. Any change that matters will be posted here with a new effective date.

Contact us

For any question about your privacy or your data, or to request it be deleted, email [email protected].