Privacy Policy

Last updated 8 October 2026

Bondie sends a photo from you to the people you choose, and shows it on their home-screen widget. This page describes exactly what that involves.

What we collect

Notifications

A home-screen widget cannot update itself, so a push notification is the only thing that can wake the app to show you a new photo. That means notifications are how Bondie works, not an extra.

A notification passes through Apple or Google to reach your phone, and it carries what it is announcing: the sender's name, and the caption or the message they wrote. Apple and Google handle it in order to deliver it. If you would rather they did not, turn off notification previews in your phone's settings, or turn off notifications for Bondie. Your widget will then update the next time you open the app rather than straight away.

What we do not do

Where it lives

Photos and videos are stored on Cloudflare R2 and are private: they are served only through short-lived signed links to people you sent them to. Account data, including your captions, replies and messages, is stored in a managed PostgreSQL database on DigitalOcean, which also hosts our servers. Subscription records are held by Google Play or the App Store, and by RevenueCat, which reports your subscription status to us.

The companies that process data for us, and what each receives, are: Cloudflare (every request, including your IP address, and your stored photos and videos); DigitalOcean (our servers and database); Apple and Google (push notifications, and Sign in with Apple or Google if you use them); Google Firebase (phone number verification); Resend (email sign-in codes); Expo (app update checks); PostHog (product analytics); Sentry (crash reports); RevenueCat (subscriptions); and GitHub and Discord (bug reports you send).

Deleting your data

Deleting your account removes your profile, your connections, the scrambled form of your phone number, the email address you signed in with, and every photo and video you have sent, including the stored files. It cannot be undone.

In the app: Open Bondie, tap your photo at the right end of the bottom bar to open your profile, tap the three dots at the top right of your profile, choose Settings, then scroll down to Danger zone and tap Delete account. You will be asked to confirm twice. Deletion happens immediately.

If you no longer have the app installed: Email support@bondieapp.com from the address you signed in with, asking us to delete your Bondie account. We will delete it within 30 days and confirm by reply.

Deleting your account does not cancel a Bondie Plus subscription. Subscriptions are billed by Google Play or the App Store, and only they can stop the charges: cancel in the Play Store under Payments & subscriptions, or in iPhone Settings under your name → Subscriptions.

What can remain after you delete your account

Deleting your account removes your data from our database. It does not reach into the services that process data for us, so your account identifier (a random code, not your name or email), and in two cases more than that, can remain in:

Our report records: the one thing deleting your account does not remove from our own database is the copy of anything you sent that was reported, described under What we collect. We keep it for the time stated there and then delete it.

Email support@bondieapp.com and we will ask each of these services to delete what they hold under your identifier.

Children

Bondie is not directed at children under 13, and we do not knowingly collect their data.

Contact

Questions or requests: support@bondieapp.com