Privacy policy
Last updated: June 1, 2026.
Informative translation; in case of discrepancy, the Spanish version prevails.
Data controller
The data controller for proximapp.es is Ilia Ablamonov. For anything about privacy, write to flamefork@gmail.com.
What data we process
- Location coordinates. When you grant the browser permission, the browser hands over the coordinates of your location. We round them in the browser to 5 decimal places (roughly 1 meter of precision) before anything is sent. We use them only to work out which stops are near you. We keep no location history. Coordinates travel in the body of a POST request and never appear in the URL.
- Reverse proxy logs. They record the request method and path, the date, the time, the response code, the size, and the user agent. They do not record the client IP address, cookies, or the request body.
-
Sentry from the server. When the backend hits an error, we send
Sentry the error type, the stack trace, the endpoint path, and the user agent. We do
not send the client IP address, the body of the request to
/api/viewport/stream, or thelat,lon, andreqlocal variables from the stack trace. -
Sentry from the browser. We use
@micro-sentry/browser, a minimal Sentry client with no Session Replay, no automaticconsolecapture, and no automatic instrumentation of network requests. When the app hits an error, we send Sentry the error type, the stack trace, the page URL, the user agent, and a short technical log of the app's state (how geolocation and the connection to the backend are doing), deliberately leaving coordinates out. At the network level, Sentry may receive the client IP address when events arrive from the browser; how it handles and retains that address depends on the project configuration and on Sentry's terms. -
Umami Cloud. The Umami script loads directly from
cloud.umami.is. We send page views, technical interface events (such as reloads or granting the location permission), and page performance metrics (Core Web Vitals), with no coordinates. We honor the browser's "Do Not Track" signal. For campaign attribution, the first page view may send Umami these allowed query parameters and nothing else:utm_source,utm_campaign,utm_medium,utm_content, andutm_term. If the link uses the short fragment parameters#s,#c, or#m, we turn them intoutm_source,utm_campaign, andutm_mediumrespectively for that measurement. We send no other query parameters and no coordinates in Umami events. Links to stops are measured as/parada, without the operator or stop identifier. At the network level, Umami receives the client IP address. -
Mapbox. The browser downloads map tiles directly from
api.mapbox.com. Each tile URL encodes the geographic area you are looking at, so Mapbox receives the client IP address and the map area on screen. próximapp does not sit in the middle of these requests. -
localStorage
geo_previously_granted. A technical value that remembers you had already granted geolocation, so we don't show the onboarding as if this were your first visit. -
localStorage
selected_language. Holds the interface language you picked by hand, so your choice carries across sessions. If you have not picked one, this value is never written and we detect the language from your browser settings. -
Update sessionStorage.
We use
proximapp_required_reload_commitandproximapp_compatible_reload_committo remember, in the current tab, that we have already tried to reload a particular version of the app. This keeps the app out of a reload loop when an update fails to apply. These values hold no coordinates and no user identifiers, and they disappear when you close the tab.
What we use the data for
- Showing nearby stops and upcoming arrivals.
- Showing the map.
- Diagnosing errors and keeping the service secure.
- Understanding basic product usage without building user profiles.
Legal basis
Location is processed with your consent, given when you accept the browser permission. Technical local storage is necessary for the experience you asked for. Error diagnostics, technical logs, and security rest on our legitimate interest in keeping the service stable and secure. We use Umami for basic usage measurement, without cookies according to the provider's documentation and without any coordinates from us.
Providers that receive technical data
We may use a hosting provider, Functional Software, Inc. (Sentry) for error monitoring, Umami Software, Inc. (Umami Cloud) for basic analytics, and Mapbox for map tiles. These providers may receive the technical data needed to deliver those services, such as the IP address at the network level, the user agent, request paths, technical events, or the map area on screen.
Transit data sources
Empresa Municipal de Transportes de Valencia S.A.U. (EMT Valencia) and Ferrocarrils de la Generalitat Valenciana (FGV), which operates Metrovalencia, are our transit data sources. For MetroBús we use GTFS data from the NAP/MITRAMS as the stop catalog and Softour Sistemas purely as a source of estimated arrivals. In the current architecture none of them receive your coordinates from our backend: when we ask for upcoming arrivals, we send stop identifiers taken from our internal catalog.
International transfers
Some providers, such as Functional Software, Inc. (Sentry), Umami Software, Inc. (Umami Cloud), and Mapbox, may process data outside the European Economic Area under their own terms, data processing agreements, subprocessors, and applicable transfer safeguards.
Retention
próximapp builds no location history. Coordinates travel in the body of the POST request so we can work out which stops are near you, and they are not written to any log of ours: the application server writes no access logs, the reverse proxy records the request method and path but not the body, and coordinates are stripped from Sentry events before they are sent.
Sentry retains events according to the project configuration and Sentry's policies.
Umami Cloud retains data according to the plan we are on and the policies of Umami
Software, Inc. The reverse proxy logs carry no client IP address and rotate
automatically. The localStorage values geo_previously_granted and
selected_language stay until you clear the site data or the browser drops
that storage. The update sessionStorage values disappear when you close the tab.
Your rights
You can request access, rectification, erasure, objection, restriction, portability where applicable, and withdrawal of consent by writing to flamefork@gmail.com. You can also file a complaint with the Agencia Española de Protección de Datos at aepd.es.
How to withdraw location consent
You can withdraw the location permission from your browser or site settings. You can also clear the site data to remove local storage.