WIVO Privacy Policy

Privacy Policy

Last updated: 14 August 2026

This policy describes what the WIVO app and the WIVO server actually do with your data. It is written against the app as built, not against a template.

1. Who is responsible

NEX NEXT EXPERIENCE LLP
5307 Victoria Drive #458
Vancouver, BC V5P 3V6
Canada
Reg. LL03158 (British Columbia)

Email: support@wivo.world

For data subjects in the European Union

We accept data-protection requests from data subjects in the EU and the EEA at the email address above at any time, and answer them within the one-month period laid down in Art. 12(3) GDPR. If you prefer to write by post, please use the address above, marked “Data Protection”.

Where the servers are

The WIVO backend and its database run on a server rented from Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany, in a data centre in Germany. Your account, your subscription record and the camera data are stored there — that is, inside the European Union, under the GDPR, on hardware operated by a company established in the EU.

Who else receives data, and where they are

Nothing below is optional decoration: each of these receives something because the app cannot do its job otherwise, and each is named so you can look it up.

Contabo GmbH — Germany (EU)
The server itself: the API, the database, and the web server that delivers this page. Everything described in this policy that is “stored on the WIVO server” is stored here.
The NexStops camera service — same server, Germany (EU)
WIVO does not maintain its own camera database. When your app asks which cameras are near you, and when you report one, the WIVO server passes the coordinate on to the shared camera service of NexStops, another product of the same company. That service runs on the same machine, in the same German data centre, so this leg does not leave the server and does not leave the EU. What is passed on is the coordinate and the search radius — not your email address, not your account, and not a device identifier.
Cloudflare R2 — object storage
Holds the invoice PDFs belonging to a paid account, and the copy of your data that is prepared when you ask for one. The bucket's storage region is Western Europe (WEUR), so these files are held inside the European Union and do not leave it in the ordinary course of the service. Cloudflare, Inc. is nonetheless a company established in the United States and can be reached by its own authorities, so the transfer safeguard — Cloudflare's standard contractual clauses — continues to apply to the relationship even though the data itself is stored in the EU. It also holds a nightly backup of the WIVO database, so that the service can be restored after a failure. Backups are kept for 90 days and are then deleted.
Stripe — payments
Card details, and the invoices for a paid subscription. See section 6.
Brevo — email delivery
The messages described under “Email” in section 3 are handed to Brevo's mail relay for delivery, which means Brevo processes the recipient address and the content of the message. The contracting entity is Sendinblue SAS, trading as Brevo, established in France. The processing takes place inside the European Union, so this is not a transfer to a third country and needs no transfer safeguard.
Cloudflare Turnstile — sign-up protection
When you create an account — and only then — a check runs that confirms a person is doing it rather than a script. The check is carried out by Cloudflare, which for this purpose receives your device's IP address, technical characteristics of the connection, and the user agent of the view the check runs in. It does not receive your email address, your password, your position, or anything you have reported, and it stores nothing on your device. It runs on the sign-up screen only: signing in afterwards does not contact Cloudflare.
Cloudflare also uses these signals to improve its own bot-detection systems, and for that purpose decides on its own account what is done with them rather than acting solely on our instructions. Cloudflare, Inc. is established in the United States; the transfer safeguard is Cloudflare's standard contractual clauses. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in stopping automated systems from creating accounts in bulk, which would exhaust the daily allowance our email provider gives us and leave real users without the password reset messages they are waiting for. The contracting entity is Cloudflare, Inc., established in the United States.
Google AdMob — advertising, FREE tier only
Device and advertising identifiers, and an approximate location. Only with your consent, only on the FREE tier, and never for a PRO subscriber. See section 5.
Stadia Maps — the map background
The map you see is drawn from tiles your phone downloads directly from Stadia Maps. Stadia Maps therefore sees your device's IP address and which part of the map you are looking at — which is approximately where you are. It does not receive your account, your email address or anything you have reported. This is how any map in any app works, and it is stated here because it is a request your phone makes to somebody who is not us.
The contracting entity is Stadia Maps, Inc., established in the United States, and the tiles are not served from an EU region. This is therefore a transfer to a third country; the safeguard for it is the standard contractual clauses.
Our own log collector — a second server, Germany (EU)
The application log lines described in section 2 are copied continuously to a log viewer we run ourselves, so that a fault can be investigated after it has happened. It is not a third party: it is a second machine we rent, from the same provider named above, Contabo GmbH in Munich, and it is registered in Germany — so this leg does not leave the European Union either. It is listed here because it is a second place data reaches, and this list is meant to be complete.

2. Location data

What is collected

Your device's GPS position, together with the speed and heading the device reports. While you are driving with WIVO open, this is read continuously — that is how the app knows which camera is ahead of you rather than behind you.

What happens to it on the device

The decision about which camera to warn you about is made on your phone. Your position is not needed anywhere else for that.

What leaves the device

To know which cameras exist around you, the app asks the WIVO server for the cameras near a coordinate. That request carries your approximate position and a search radius (5 km). It is sent at most once every 30 seconds, and additionally after you have moved about 1.5 km.

These positions are not stored in the WIVO database. There is no table of user locations, no trip history and no movement profile: the query is answered and the coordinates are discarded.

One exception, and it is worth naming. In a country where camera warnings are not lawfully available, the server refuses the request instead of answering it. That refusal is recorded as a service event, and the record carries the coordinate that triggered it — otherwise we could not tell a lawful refusal apart from a fault. There is no account, no email address and no device identifier in that record. At the time of writing there are two such records in the entire database.

The coordinate is passed on one step further, and it stays on the same machine. WIVO holds no camera database of its own: the server forwards the coordinate and the radius to the shared NexStops camera service described in section 1, which runs on the same server in the same German data centre. The request carries the coordinate and nothing that identifies you — no account, no email address, no device identifier.

Server access logs — please read this one

The web server that sits in front of the API keeps ordinary access logs. Each entry holds the requesting IP address, the time, and the requested address — and for a nearby-cameras request, the requested address contains the coordinate that was queried. These logs are kept for 14 days and are then deleted automatically. They are used for operating and securing the service, not for analysis of individual users, and they are not combined with account data.

When we look at your data, that is recorded too

A small number of administrative endpoints let us look at the service from the inside — how many accounts there are, whether a payment went through, whether an export failed. Every call to one of them is written down: the time, which endpoint, whether it succeeded, and a shortened form of the requesting IP address, with the last part removed. Refused attempts are recorded as well.

The key we use is never written down, not even truncated. For a refused attempt a short fingerprint of the key that was tried is recorded, so that a run of attempts can be recognised as related; on a successful call no fingerprint is kept at all. This exists so that access to your data leaves a trace even when it is us doing the looking. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in being able to account for who reached what.

Application logs

Besides the web server's access log described above, the application writes operational log lines, and these are forwarded to a log viewer that we operate ourselves, on another of our own servers. They are not sent to any third party. That second machine is rented from the same provider as the main one and is registered in Germany, so these lines stay inside the European Union; it is named in the list in section 1. Some of these lines contain the request line, including the coordinate of a nearby-cameras request. Unlike the access log above, they do not carry your IP address: the API is reached through the web server, so the address that appears in an application log line is the web server's own. They exist so that a fault can be diagnosed, and they are not read to look at what any individual is doing.

Background location (PRO)

On the PRO tier WIVO can keep warning you with the screen off or the app in the background. On Android this runs as a foreground service with a permanent notification, so it is always visible that WIVO is active; on iOS it uses the system's background location updates. This requires the “Always” / “Allow all the time” location permission, which your operating system asks for separately. You can revoke it at any time in the system settings, and the app keeps working in the foreground.

Legal basis

Art. 6(1)(b) GDPR — processing necessary to provide the service you asked for. Warning you about a camera ahead is not possible without knowing where you are. Location access is additionally always subject to the permission your operating system asks you for, which you may refuse or withdraw.

3. Account

You can use WIVO on the FREE tier without an account. An account is only needed for a PRO subscription.

If you create one, we store your email address and a hash of your password (bcrypt — the password itself is never stored and cannot be recovered from the hash), plus the time the account was created.

After you sign in, your device holds an access token. It is stored in the operating system's secure storage (Keychain on iOS, Keystore on Android) and is valid for 30 days.

Legal basis: Art. 6(1)(b) GDPR (contract).

What you agreed to, and when

When you create an account we record the moment you accepted these Terms and this policy, and which version of each — the version is the “last updated” date printed at the top of the document you were shown. We keep it so that both sides can tell later what the wording actually said at the time. It is deleted with your account.

Email

Messages about your own account — a password reset you asked for, a notice that your password was changed, a failed payment — are sent because they are necessary to run the service, and they cannot be switched off. Legal basis: Art. 6(1)(b) GDPR.

Marketing email is separate, optional, and off unless you asked for it. The box is presented unticked when you sign up, saying no changes nothing about your account, and every marketing message carries a one‑click unsubscribe link that works without signing in. We also record that you were asked and what you answered — including a “no”. Legal basis: Art. 6(1)(a) GDPR (consent), which you may withdraw at any time with effect for the future.

4. Camera reports

When you report a camera, the app sends the position of the camera (which is your position at that moment), its type, and, where known, a speed limit and a direction. This is stored in the camera database and shown to other drivers.

A report is not linked to you. The reporting endpoint does not require a login and stores no user identifier, so a stored camera cannot be traced back to the account or device that reported it. A new report within 60 metres of an existing one is merged into that camera instead of creating a new record.

The server also writes a service event recording that a report was received, and that event carries the reported coordinate. Like the camera record itself, it carries nothing that identifies who sent it — no account, no email address, no device identifier.

Because reports are anonymous, they cannot be individually withdrawn later — there is nothing in the record that identifies which report was yours.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining a usable, community-maintained camera database).

5. Advertising (FREE tier)

On the FREE tier WIVO shows occasional full-screen ads — at most one per hour, and never while the vehicle is moving. Some of these are served by Google AdMob, others are WIVO's own notices.

Where AdMob serves an ad, Google acts as an independent party and may process device and usage data — in particular the advertising identifier of your device and an approximate location — according to its own policies. See Google's privacy information at policies.google.com/privacy.

You are asked first

WIVO uses Google's User Messaging Platform to ask for your consent. The dialog is Google's own, it appears when the app first starts, and it runs before the advertising library is started at all — not alongside it, and not after it. If you refuse, that refusal is what the advertising library is initialised with.

You can change your mind. In the app, under Account, the “Privacy settings” entry clears the answer you gave. On the FREE tier the next time you open WIVO you are asked again, and whatever you choose then replaces what you chose before. On PRO the entry still clears the stored answer, but you are not asked again while the subscription is active — no ad is shown, so there is nothing to consent to. The cleared answer is what the question starts from if the subscription later ends.

PRO removes advertising entirely. A paying subscriber sees no ad, is not asked the consent question at all, and no advertising data about them is collected by us.

One part of this is more precise than it used to be, and it is stated here rather than glossed over. WIVO's own code never starts the advertising library for a PRO subscriber — that is ours to control, and it does not happen. What we do not control is a small component that ships inside Google's advertising library itself: on Android the operating system runs it when the app's process starts, before any of our code runs, and therefore on every tier. Examined in the library on 25 August 2026, what it does at that moment is read our own app's settings from the app package and start Google's measurement component with them. Whether that component then contacts Google, or reads the advertising identifier, is decided inside Google Play Services and is not something we are able to determine by examining the app; we do not state either way. Nothing about a PRO subscriber's use of WIVO is passed to it by us, and no ad is requested, shown or counted for them.

Legal basis: Art. 6(1)(a) GDPR — consent, which you may withdraw at any time with effect for the future, as described above.

6. Payments

PRO subscriptions are handled by Stripe. Checkout opens in your browser on Stripe's own pages; card details are entered there and never reach WIVO.

What WIVO stores is the Stripe customer and subscription identifier, the subscription status, when the current period ends, and when the subscription first became paid (needed to work out the refund window). Nothing else.

Stripe processes payment data as an independent controller under its own policy: stripe.com/privacy.

Legal basis: Art. 6(1)(b) GDPR (contract).

7. Data stored only on your device

Your settings — sound, haptics, voice, units, keep-screen-awake and warning distance — are stored on the device only and are never sent to the server. Deleting the app deletes them.

8. What we do not do

  • No analytics SDK at all. The app contains no analytics, attribution, crash-reporting or product-telemetry library of any kind, and nothing about how you use the app is passed to a third party. What the app does report is three signals to WIVO's own server — two counting signals, set out directly below, and a startup-crash report under the heading after them. They are named here because a flat “nothing is reported” would no longer be true. The only third-party component that sees anything about your device is the advertising described in section 5, which runs on the FREE tier only, only with your consent, and never for a PRO subscriber.
  • No trip history, no movement profile, no location database.
  • No sale or sharing of personal data with third parties for their own purposes.
  • This website sets no cookies, loads no external fonts, scripts or images, and contains no tracking of any kind. Nothing on it reaches a third party.

The two counting signals

So that we can see how many people install WIVO and how many get as far as looking at the price list, the app sends the WIVO server two signals. Both go to our own server in the German data centre named in section 1 and no further; no third party is involved in either. Neither one carries your position — there is no location data, no route and no movement information in either of them — and neither is used to build a profile of how you drive.

That the app was started for the first time. Once per installation, the first time you open the app, it sends a message saying only that a new installation has been started. It has no content at all: no account, no email address, no device identifier, no advertising identifier, no identifier of any kind. The server does not keep it as an entry of its own — it adds one to a counter and, once a day, writes a single line saying how many first launches there were on that date. Your IP address is seen only by the rate limiter that stops one address inflating the count, and is discarded immediately afterwards; it is not written down anywhere. The resulting number can therefore never be traced back to you — not by us, not by a later maintainer, and not by anyone who obtained a copy of the database — because nothing capable of identifying anybody was collected in the first place. It also means the figure is what phones report rather than an audited count: reinstalling the app counts again.

That you opened the subscription plans. When you open the price list for a PRO subscription, the app tells the server that this happened. Opening it is something only a signed-in user can do, so — unlike the signal above — this one is recorded together with your account identifier and the time it happened. It records that the price list was opened and nothing else: not which plan you looked at, since no plan has been chosen at that point, and nothing about anything else you did in the app. Because it is attached to your account it is part of your data, and it is included in the export you can download yourself under section 9.

Legal basis for both: Art. 6(1)(f) GDPR — our legitimate interest in knowing how many people install the app and how many go on to consider paying for it, which is what tells us whether WIVO is worth continuing to build. You may object to processing based on legitimate interest, as described in section 9.

One more signal, added in August 2026

If the app crashes while starting up, it records four things and sends them to our own server the next time it starts: the platform, the app version, the type of the error, and which of our three internal error handlers caught it. The text of the error is never sent, and neither is the stack trace — an error message can contain the address of the request that failed, and that address can contain a coordinate. Nothing about you, your account or your position is included, and nothing goes to a third party: the app carries no crash-reporting library at all, only a single request to our own API.

Two further things belong in an honest description of it. The server records the time the report arrived alongside those four fields. And while the request itself carries no login and no device identifier, its IP address is necessarily seen when it is received: it is used to stop one sender flooding the endpoint, and it appears in the server access log described in section 2 — but it is not stored with the report, and the report cannot be linked to an account.

9. Your rights

Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16), to have it erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing rests on consent, you may withdraw it at any time with effect for the future.

Deleting your account

You can delete your account from inside the app, under Account. Deletion removes your account and its subscription record from the database and cancels an active subscription. If you are still inside the refund window, the app offers to refund the last payment as part of the same step. Deletion goes ahead either way.

Three things do not go with it, and we would rather say so here than leave you to find out.

The free-trial record. The 7‑day PRO trial is offered once per person. To make that mean anything after an account is deleted, we keep two irreversible SHA‑256 hashes when a trial is claimed: one of your email address and one of the random identifier the app generated for your device. They are kept in a separate table that survives account deletion. They are not reversible into an address or a device, they are never used for anything except answering “has this one already had a trial?”, and they cannot be used to contact you or to recognise you anywhere else. The legal basis is our legitimate interest in preventing repeated claims of a free offer (Art. 6(1)(f) GDPR). They are deleted 24 months after the trial was claimed, and a check that runs against that deadline means an expired record stops counting on the day it expires, whether or not it has physically been removed yet.

Invoices. Payment records that constitute accounting documents are retained for 10 years as required by German commercial and tax law (§ 147 AO, § 257 HGB). This obligation overrides a deletion request for those documents alone (Art. 17(3)(b) GDPR). The records themselves are held by Stripe, our payment processor — see section 6.

A copy of the account, for 90 days. At the moment you delete the account, and before anything is removed, we package what we hold about you into a single ZIP file — your profile, your subscription record, the account events, the free-trial record if there is one, and your invoices. That file is emailed to you, either attached or as a download link valid for seven days, so that deleting your account is not the same as losing your own data.

The same file is kept in our object storage for 90 days and is then deleted. It is kept so that a payment dispute or a suspected fraud raised shortly after a deletion can still be answered — a question that cannot be answered from a database row that no longer exists. It is not used for anything else, it is not searched, and nothing is built on top of it. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in resolving disputes and investigating fraud. Where it is stored is named in section 1.

Access and portability

You can do this yourself, from inside the app. Under Account, “Download my data” prepares a ZIP file and hands it to your phone's browser, so it lands in your Downloads folder like any other download. It contains your profile, your subscription record, the account events we hold, the free-trial record if there is one, and your invoices as PDFs. The download link is valid for five minutes and then stops working. It has to carry its own proof rather than your login, because a browser cannot present the app's credentials — and that is exactly why it expires so quickly.

You do not need an account deletion to get it, and asking for it changes nothing about your account. If the export cannot be prepared — a storage outage, for instance — the app says so rather than handing you an incomplete file.

One limit of the copy, stated plainly. It covers what is currently held in the live database. Older service events may already have been moved to the archive described in section 10, and those are not in the file the app prepares. If you need those as well, say so in your request and we will retrieve them.

You can also write to us at the address in section 1 and we will provide the same data, within the one-month period laid down in Art. 12(3) GDPR.

Complaints

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.

10. Retention

Account data
Until you delete the account. Deletion is immediate.
Subscription records
Deleted with the account. Stripe keeps its own transaction records for as long as its own legal obligations require.
Camera reports
Kept for as long as the camera entry is useful. They contain no personal data.
Service events — operational
180 days. Faults and recoveries: the database or an outside service becoming unreachable, an email that could not be sent, an allowance running out.
Service events — usage counters
90 days. The daily counts described in section 8, a marker that the app was used on a given day, a first launch.
Service events — carrying a coordinate
90 days. A camera you reported yourself, and a refusal in a country where the feature is switched off.
Administrative access records
12 months. Every call to an administrative endpoint, as described in section 2.
Administrative changes
Kept indefinitely. Where we change something on an account ourselves, the record of that change is not removed on any schedule — it is the evidence that we did it.
Records of a payment, a registration, or a consent decision
Not covered by the schedule above. These are financial, legal or consent evidence and are kept with the account, or for as long as tax and commercial law requires — see “Invoices and payment records” below.
Server access logs
14 days, then deleted automatically.
Database backups
90 days, then deleted.
Position queries
The lookups themselves are not kept: the server records a daily count and no coordinates (see section 2). Two things are the exception, and both are named rather than hidden in that sentence: a camera you report carries the coordinate you reported (section 4), and a refusal in a country where the feature is switched off records the coordinate that was refused. Both fall under the 90-day row above. The coordinate of an ordinary lookup also appears in the log lines described under “Application logs” and “Server access logs” in section 2, which have their own retention.
Free-trial record (hashes)
24 months from the day the trial was claimed, then deleted. Survives account deletion — see section 9.
Copy of a deleted account (ZIP)
90 days from the deletion, then deleted. The same file is emailed to you when you delete the account. Survives account deletion — see section 9.
Consent records
Kept with the account: when you accepted the Terms and this policy, which version of each, and whether you agreed to marketing email. Deleted with the account.
Invoices and payment records
10 years, as German commercial and tax law requires. Held by Stripe.

Older service events are not deleted outright: they are first written to an archive in the same object storage named in section 1, and removed from the live database only after that archive has been read back and checked. The archive itself is reviewed and removed by hand rather than on a timer.

11. Children

WIVO is intended for drivers and is not directed at children. We do not knowingly process the personal data of anyone under 16 — the age set by Art. 8 GDPR for consent to an information society service. A PRO subscription is a contract on top of that, and for a contract you must be at least 18.

12. Changes to this policy

If the app changes what it does with data, this page changes with it, and the date at the top is updated.