Gobelino Gobelino

Privacy Policy

Last updated: October 11, 2026

1. What Gobelino is

Gobelino is a Mobile Device Management (MDM) software for Android that lets an organization enroll, configure and monitor company-owned devices or the work profiles of its employees/collaborators through a web panel and an agent app installed on the devices. It is designed in particular for use cases such as warehouse management, rugged device control, logistics kiosk lockdown, and AOSP fleet management.

The terms of use of the service, including liability limitations and the software's beta status, are described in the Terms of Service. This notice covers data processing only.

2. Controller and processor

For administrator account data (email, company, preferences) Gobelino acts as the data controller. For the technical data collected from managed devices (section 4), Gobelino acts as a data processor on behalf of the organization using the service (the administrator), which is the controller with respect to its own employees/collaborators.

Controller/processor: Gobelino.

3. Legal basis for processing

Administrator account data is processed on the basis of performance of the service contract (GDPR Art. 6(1)(b)). Technical data from managed devices is processed on the administrator's instructions as controller, who is responsible for identifying an appropriate legal basis (e.g. legitimate interest, employment contract, consent) toward the people using the devices — see "Administrator responsibility" in the Terms of Service.

4. Data collected from managed devices

To perform its management functions, the agent app installed on devices periodically transmits technical information about the device to the administrator's panel, including: model, manufacturer, operating system version, battery level and charging status, available storage and memory, network connection type, IP address, connected Wi-Fi network, screen state (on/off, locked/unlocked), the list of installed apps (name, package, version, storage used), and, when the device is enrolled as Device Owner, hardware identifiers (serial number, IMEI).

The device's geographic location is only retrieved on the administrator's explicit request ("Locate device" command) or, if configured, at periodic intervals set by the administrator — never continuously or covertly.

5. Screen sharing and remote control

On the administrator's explicit request, a device can start a remote screen-view session: video streams in real time directly from the device to the administrator's browser (a peer-to-peer WebRTC connection) — Gobelino does not record, store, or have access to the video content of the session, which never passes through or is retained on the service's servers. No session can start without the person using the device seeing Android's own system consent prompt, shown fresh for every session and never something that can be bypassed automatically.

If the person using the device has manually enabled, as a one-time step, the remote control feature (an Android accessibility service), the administrator can also send taps and swipes on the shared screen, which are genuinely replayed on the device. This feature requires explicit activation performed directly on the device by the person using it, and can be revoked at any time from Android Settings; the accessibility service used does not read or transmit screen content — it only receives the coordinates of the taps to replay.

6. Data NOT collected

Gobelino does not collect, read, or transmit sensitive or personal data belonging to the people using the managed devices. Specifically, Gobelino has no access to: the content of messages, emails, or calls; contacts; photos, videos, or other personal files; browsing history; or passwords/credentials stored on the device (with the exception of Wi-Fi credentials set by the administrator through the panel, needed to configure the devices' network connection). The video content of a remote-view session, in particular, is never recorded or stored by Gobelino (see section 5).

7. Data retention

Location: only each device's most recent known position is retained, overwritten on every new request. No history of past positions is kept anywhere in the system.

Command queue: every command sent to a device (including location requests) is automatically deleted 7 days after creation. The coordinates returned by a location command, specifically, are removed from that command's own record as soon as they're saved as the device's "last known position" (see above) — so they aren't left readable even within that 7-day window.

Removing a device: when an administrator removes a device from the panel, all technical and operational data associated with it (location, installed apps, restrictions, command history) is deleted immediately. If the device is then permanently deleted, the entire record — including the name, serial number, and IMEI kept only to prevent accidental duplicate re-registration — is permanently erased from the live system: no data remains stored in the database the service operates on.

Backups: for service continuity, the entire database (including the devices' technical data described in this policy) is backed up automatically every day, stored on infrastructure separate from the service itself (see section 8). Older backups are automatically deleted under a retention schedule that thins out over time (kept in full for 7 days, then one per day for 16 days, then weekly for 8 weeks, then monthly for 4 months, up to a maximum of 2 years for the oldest backup retained). As a result, data deleted from the live system — e.g. following the device removal described above — may remain present in an already-existing backup until it is naturally rotated out, even though it is no longer visible or accessible through the panel.

8. Data security and sub-processors

Information collected is transmitted over an encrypted connection (HTTPS) and stored on the servers hosting the Gobelino panel, provided by Railway. The daily database backup (see section 7) is stored on Cloudflare (R2 storage service), used solely as a backup repository and not as part of the live service infrastructure. When an application error occurs, both the panel and the agent app automatically send Sentry the error's technical details (stack trace, software version, operating system) for diagnostic purposes — without any personal data belonging to the people using the devices. Transactional email (e.g. team invitations, credentials) is handled by Resend. Push notifications that immediately wake devices use Google's Firebase Cloud Messaging, which processes device identifiers. To establish a remote-view session's direct connection (see section 5), the device and the administrator's browser exchange their public IP address through a STUN server (Google's public one by default) and, if configured by the system administrator, a supporting TURN server — no session content passes through these servers, only the network address needed to establish the direct connection. The panel's "Install app" feature relies on Aptoide's search engine, which receives the search terms typed by the administrator. Access to the panel requires password authentication and two-factor verification (2FA).

9. Cookies

Gobelino uses only one strictly necessary technical cookie: the session cookie that keeps a user logged in after authentication (technical name: gobelino-session). This cookie is not used for profiling, tracking, or marketing purposes and, for that reason, does not require prior user consent under applicable cookie law (e.g. the ePrivacy Directive). Gobelino does not use third-party, analytics, or advertising cookies.

10. Data subject rights

To the extent applicable (e.g. Regulation (EU) 2016/679, "GDPR"), individuals subject to processing have the right to access, rectify, erase, restrict processing of, and port their data. They also have the right to lodge a complaint with the competent supervisory authority — for Italy, the Garante per la protezione dei dati personali (the Italian Data Protection Authority, www.garanteprivacy.it), or the corresponding supervisory authority of their EU member state. For technical data from managed devices, such requests should be directed to the administrator/IT department of the relevant organization, as the controller with respect to them (see section 2).

11. Changes to this policy

This policy may be updated over time, particularly during the product's beta phase. The most recent version is always available at this same address.

12. Contact

For data-processing requests directed to Gobelino itself, contact legal@gobelino.net. For any question regarding the management of their own specific device, users should contact their organization's administrator/IT department directly.