Security overview

Roam Pal Guide · roampalguide.com · last reviewed 2 October 2026

The most secure user data is the data you never hold. Roam Pal is built local-first with no accounts and no central user database, which removes whole categories of risk before they can arise. This page explains our approach plainly, for anyone running security due diligence.

Design principles

Hosting and infrastructure

The website is served from Google Firebase Hosting on Google Cloud infrastructure, over an encrypted connection with a global content-delivery network. Reports and corrections people choose to send go to our Hub at adaidigital.co.uk, which runs on Google Cloud Run and stores them in Google Firestore. The optional live places layer draws on OpenStreetMap data. There are no user accounts anywhere.

Application security

Data handling

Because trips and profiles stay on the device, the user holds the controls: they can view, edit, export and delete them, and clearing the site's storage removes them entirely. There is no copy of them on our side to recover or to lose. Full detail is in our data protection and UK GDPR statement.

Scope, honestly. Roam Pal is a travel-planning and information tool, not a medical device and not a clinical system. We describe what we do rather than claim certifications we do not hold. Where an organisation needs formal assurance, we are glad to complete security questionnaires and share what we can.

Reporting a security concern

If you believe you have found a security issue in Roam Pal, please tell us at admin@adaidigital.co.uk so we can look into it promptly. We welcome responsible disclosure and will work with you in good faith.

All policies · Data protection · Privacy · Back to Roam Pal Guide