Security overview
Roam Pal Guide · roampalguide.com · last reviewed 2 October 2026
The most secure user data is the data you never hold. Roam Pal is built local-first with no accounts and no central user database, which removes whole categories of risk before they can arise. This page explains our approach plainly, for anyone running security due diligence.
Design principles
- No central store of trips or profiles. Trips, notes and access needs live on the user's device, not on our servers. We store only the reports and corrections people choose to send (none has an account), optional daily counts, and the request records listed in our privacy notice.
- No accounts, no passwords. There is nothing to sign into, so there are no credentials to steal, phish or reuse, and no account-takeover risk.
- Encrypted in transit. The app and all its content are served over HTTPS (TLS).
- Least data. The app requests the map, photo and place information it needs to work. Those requests carry no name, account or access needs. Like any web request, they carry the device’s internet address.
Hosting and infrastructure
The website is served from Google Firebase Hosting on Google Cloud infrastructure, over an encrypted connection with a global content-delivery network. Reports and corrections people choose to send go to our Hub at adaidigital.co.uk, which runs on Google Cloud Run and stores them in Google Firestore. The optional live places layer draws on OpenStreetMap data. There are no user accounts anywhere.
Application security
- The app is a static, client-side Progressive Web App. It runs in the browser and stores trips and profiles only on the device. The Hub stores only the reports and corrections people choose to send.
- Third-party code is kept to a minimum and updated as part of ordinary maintenance.
- Changes are verified in the real rendered app before release, including accessibility and behaviour checks.
- We use our own accessibility-testing software, InclusiveAccess AI, as part of pre-release checks.
Data handling
Because trips and profiles stay on the device, the user holds the controls: they can view, edit, export and delete them, and clearing the site's storage removes them entirely. There is no copy of them on our side to recover or to lose. Full detail is in our data protection and UK GDPR statement.
Reporting a security concern
If you believe you have found a security issue in Roam Pal, please tell us at admin@adaidigital.co.uk so we can look into it promptly. We welcome responsible disclosure and will work with you in good faith.
All policies · Data protection · Privacy · Back to Roam Pal Guide