NavIndoor app privacy policy
Last updated: [TO COMPLETE: publication date]
In short
- NavIndoor guides you inside buildings. Your position is worked out on your phone and is not sent to our servers, except the starting point when you ask for a route from outdoors.
- The app uses a device identifier, with no name, email or account, to recognise requests to our servers and for usage statistics.
- We collect usage statistics (screens opened, routes started, settings) with Umami, a service installed on our own servers, with no advertising and no sharing with third parties.
- If you allow it, Bluetooth counts how many devices are near you to estimate how busy rooms are. We send only the number, never the identifiers of those devices.
- Your lessons, personal events, height and search history stay on your phone.
1. Who handles the data
Data controller: [TO COMPLETE: name, address and contact of the controller – for example Sapienza University of Rome].
Data protection officer (DPO): [TO COMPLETE: DPO email].
For any question about this policy or your data, write to [TO COMPLETE: privacy email address].
2. Device identifier
On first launch the app obtains a device identifier:
- on iPhone and iPad, the identifier iOS gives to apps from the same developer (
identifierForVendor); - on Android, the Android ID;
- if neither is available, a random code.
It is kept in the system's protected storage (the Keychain on iOS, encrypted storage on Android). On iOS it may remain even if you uninstall and reinstall the app.
It does not contain your name, email or phone number. We use it:
- to tell one device's requests from another's on the NavIndoor servers (buildings and maps, app configuration, course catalogue and timetables, looking up how busy rooms are, and 3D models), which receive it with every request;
- as the visitor identifier in usage statistics (section 3).
It is not sent with the occupancy data your phone collects (section 5), to the outdoor routing server or to the map server. You can find it at the bottom of the app's Settings, under “Device ID”: tap it to copy it.
3. Usage statistics
To understand how the app is used and improve it, especially for people who use its accessibility features, the app sends statistics to an installation of Umami on our own servers (umami.test.sapienzaapps.it). We use no third-party analytics and no advertising.
What we send
- Device details: the device identifier, the operating system and its version, the kind of device (phone or tablet), on Android the model, the screen size, the language, the app version, the place (organisation) you chose.
- Screens opened: map, search, a room's sheet, route, navigation, personal area, settings, the steps of the first-run setup.
- Actions:
- navigation started, completed or stopped, with the building code, the room and its kind, the length, floors and duration;
- a room opened, and from where (map, search, calendar);
- searches: only how many characters and how many results, never the text searched;
- personal events created, edited or deleted: only the number, never the content;
- first-run setup completed;
- the place chosen;
- settings changed (language, light or dark theme, unit, outdoor map, occupancy).
- App settings: language, light or dark theme, unit, whether you chose a course and the course year, whether occupancy scanning is on.
Accessibility: aggregates only
Accessibility settings may indirectly concern your health (for example a visual or mobility impairment), so they are never tied to the device identifier or to the other statistics.
Once a day the app sends an anonymous summary:
- low vision support;
- screen reader;
- text size, in ranges;
- bold text, reduced motion, high contrast;
- step-free routes;
- colour palette;
- the place chosen.
The summary is sent without the device identifier, screen size or language, with only the operating system's version, and dated by day rather than time. It only serves to count how many people use each feature, and cannot be connected to you or to the other statistics.
What we do not send
- Your position or the route you walk.
- The text you type or say.
- The content of your events or lessons.
IP address and delayed sending
The server receives your connection's IP address, which Umami uses to derive an approximate country and city and to group visits. According to Umami's documentation, the IP address is not stored.
When you are offline, events are kept on your phone (500 at most) and sent as soon as possible.
[TO COMPLETE: if a switch to turn statistics off is added, say so here and in section 14]
4. Location and sensors
- Location (GPS): used to show where you are and guide you, only while you use the app. It is not sent to our servers, with one exception: when you ask for a route starting outside a building, the starting point (your position or a point you picked) and the destination are sent to our routing server (
navindoor-valhalla.test.sapienzaapps.it), also when the route is recalculated. - Motion sensors: the accelerometer, gyroscope, compass, barometer and step counter estimate your steps, direction and floor inside buildings. All of this is worked out on the phone.
- Height: if you enter it, it is used to estimate your step length. It stays on the phone.
- “I am here”: the room you say you are in is remembered on the phone for a few minutes.
- Street name: to show the street name of an outdoor starting point, the app uses the operating system's geocoding service (Apple on iOS, Google on Android), which receives those coordinates.
5. How busy rooms are (Bluetooth)
If you grant the Bluetooth permission, while the app is open your phone counts how many Bluetooth devices are near you, to estimate how busy the room you are in is. The feature is on by default once the permission is granted, and you can turn it off in Settings › Extra.
- The identifiers of the devices detected stay in memory for about 20 seconds, only to count each once. They are neither saved nor sent.
- About every 30 seconds we send to the occupancy service (
navindoor-occupancy-service.test.sapienzaapps.it):- the room the app places you in;
- the estimated count;
- the operating system;
- a code that changes every time the app starts.
- When you open a room's sheet, the app asks the service how busy that room is. That request, like the others to the NavIndoor servers, carries the device identifier.
6. Course, lessons and calendar
- Course and teachings:
- the course, year and teachings you choose are saved on the phone;
- to show your timetable, the course and teaching codes are sent to our course catalogue (
uniroma1-catalogue.test.sapienzaapps.it); - when you search for a course by name, the text you type is sent to the catalogue to find matches.
- Phone calendar, only if you turn it on:
- the app creates a “NavIndoor – Lezioni” calendar and writes your lessons in it (times, room, lecturer);
- it reads only that calendar;
- turning the feature off deletes the calendar;
- no calendar data is sent to our servers.
- Personal events: the ones you create in the app stay on the phone.
7. Voice search and spoken guidance
- If you use voice search (microphone permission), speech is recognised by the operating system's service:
- Apple on iOS, Google on Android;
- when you are online this may happen on their servers, under their own policies;
- the recognised text is matched against room names on the phone. We do not record the audio or send it to our servers.
- Spoken directions use the operating system's text-to-speech.
8. Maps and external services
- Outdoor maps:
- maps of outdoor areas come from our map server (
navindoor-tiles.test.sapienzaapps.it), which receives requests for the area you are looking at; - if that server does not respond, the app may use OpenStreetMap's maps (
tile.openstreetmap.org), which receive your IP address and the area shown.
- maps of outdoor areas come from our map server (
- Buildings, configuration and 3D models: these are downloaded from the NavIndoor servers (
navindoor-api-v2.test.sapienzaapps.it), with the device identifier. - Apple Maps and Google Maps: if you choose to open a route in one of these apps, they receive the destination's coordinates (or the place's name), not your position from us.
- Web pages: links to outside pages (this policy, OpenStreetMap's copyright) open in the system's built-in browser.
Apple, Google and the OpenStreetMap Foundation handle this data as independent controllers, under their own policies.
9. What stays on your phone
These stay only on your phone:
- settings and accessibility preferences;
- height;
- course and teachings;
- personal events;
- search history and recent rooms;
- the local copy of buildings, maps and timetables for offline use;
- statistics events waiting to be sent.
On Android this data may be included in your Google account's automatic backup, if you have it on.
10. Legal bases
[TO COMPLETE with the controller and the DPO. Proposal to be checked:]
- Performance of a task in the public interest (Art. 6(1)(e) GDPR) for navigation, timetables and information about university spaces.
- Consent (Art. 6(1)(a)), given through the system permissions, for location, motion sensors, Bluetooth, microphone and calendar. You can withdraw it at any time in your phone's settings.
- [TO DEFINE] for usage statistics and for access to the device identifier. The accessibility information may count as a special category of data (Art. 9 GDPR).
11. How long
- Usage statistics: [TO COMPLETE: retention period on Umami].
- NavIndoor server logs (IP address, device identifier, requests): [TO COMPLETE].
- Occupancy data: [TO COMPLETE].
- Data on the phone: until you delete it or uninstall the app. On iOS the device identifier may stay in the Keychain after uninstalling.
12. Where the data goes
Data sent to the NavIndoor servers and to the statistics stays on systems run by [TO COMPLETE: who runs the servers and where they are – for example the University's infrastructure in Italy]. We do not sell data or share it for advertising.
The Apple, Google and OpenStreetMap services described in sections 4, 7 and 8 may process data outside the European Union, under their own policies.
13. Your rights
Under Regulation (EU) 2016/679 (GDPR) you can ask for:
- access to your data;
- correction or erasure;
- restriction of processing;
- portability.
You can also object to processing and withdraw consent at any time.
Write to [TO COMPLETE: contact]. To find your data we will need your device identifier, which you can find at the bottom of the app's Settings, under “Device ID”.
You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
14. How to turn things off or delete them
- Permissions: location, motion, Bluetooth, microphone and calendar can be withdrawn in your phone's settings.
- Occupancy: turn it off in the app under Settings › Extra › “Bluetooth: busy rooms”.
- Phone calendar: turning it off in the app deletes the “NavIndoor – Lezioni” calendar.
- Course, teachings and personal events: these can be removed from the personal area.
- Uninstalling: this deletes the data the app saved on the phone. To delete data on our servers, write to us (section 13).
15. Changes
If we change how we handle data we will update this page and the date at the top. We will tell you in the app about important changes.