Privacy Policy
Last updated 8 October 2026
Bondie sends a photo from you to the people you choose, and shows it on their
home-screen widget. This page describes exactly what that involves.
What we collect
- Your account: the name and email address your Apple or
Google sign-in gives us, and the identifier that provider uses for you.
We never receive or store a password.
- Your email address, where signing in with email is
offered: you can sign in with an email address instead of
Apple or Google. We keep that address on your account and send a
one-time code to it each time you sign in. The code is delivered for us
by Resend, an email delivery service, which receives your address and
the message carrying the code and keeps them for 30 days. On our side we
keep a scrambled record of each request for a code for up to two days,
so that codes cannot be requested or guessed without limit. We never
store the code itself, and there is still no password.
- Your profile: your display name, your username and
your photo, if you add one. Anyone who has your invite link or guesses
your username can open bondieapp.com/your-username without an
account, and that page shows your display name and photo. People who
have your phone number or email address in their contacts, and who
choose to look for friends there, are shown your name and photo as a
suggestion unless you turn off Findable by contacts in
Settings.
- Your birthday, only if you add one: the month and the
day, never the year. It is optional. Every friend you are
connected to can see it. You can remove it in Settings, and it
is deleted with your account.
- What you send: the photos and videos you post, any
caption you add, and who you sent each one to.
- What you write: your replies to a photo, the reactions
you leave on one, and the messages you send in a conversation. These are
stored so the person you sent them to can read them.
- What has been reported: when someone reports a
photo, a comment, a message, a conversation or a friend request, we keep
a copy of what was reported (its text or its photo file, and which
account it came from) for our team to review, even if the person who
sent it then edits it, unsends it, deletes it or deletes their account.
We keep the copy until the report is closed and for 30 days after that,
and for no more than 180 days in any case, then delete it.
- A copy of your messages on your phone: the app keeps
the conversations you have opened in a database file inside its private
storage on your phone, so they open quickly and can be read without a
connection. Bondie does not encrypt that file itself; it is protected by
your phone's own security, and it is erased when you sign out or delete
your account. If you unsend a message, our server blanks its text and
keeps an empty placeholder in the conversation, and your copy is
updated the same way the next time the conversation loads. A phone that
has not loaded the conversation since may still hold the old text until
it does. Your phone's own backup service may include the app's data.
- Your connections: who you are connected to.
- Your device: a push notification token, the
platform (iOS or Android), the app version and build, which update the
app is running, your device model, its operating system version and your
language setting. The token is what allows a photo to reach your widget;
the rest is what lets us tell which version of Bondie you are using when
something goes wrong. This does not include any advertising identifier,
serial number or anything else that would identify your phone outside
Bondie, and it is deleted with your account.
- App updates: each time the app starts it asks Expo's
update service (EAS Update) whether a newer version of the app's code is
available. That request goes to Expo, who operate the service, and
carries the app's version and platform and which update it is running,
so Expo receives it along with your IP address.
- Your IP address: every request to Bondie passes through
Cloudflare, who sit in front of our servers, and so Cloudflare sees your
IP address. Our own servers use it, held in memory only, to slow down
abuse, and a scrambled form of it is kept for up to two days with the
record of an email sign-in code request. The web server in front of our
API writes the address into its request log, and we have not set a
schedule that deletes that log (see below).
- Your phone number, only if you add one: so that
friends who already have your number can find you. The number is checked
with Firebase Phone Authentication, a service run by Google: the app
gives Google your number, and Google sends the SMS with the code.
In our own database we store only a scrambled form of the
number, never the number itself, and we never show it to anyone
or use it to contact you for anything else. Google may keep a record of
the number you verified in our Firebase project. Deleting your Bondie
account does not delete that record, because nothing in Bondie asks
Firebase to remove it, so email us if you want it removed. You can leave
this blank and use Bondie normally.
- Contacts, only if you ask us to: Bondie can show
you which of your contacts already use it. If you turn this on, your
phone scrambles each contact's phone number and email address and sends
only the scrambled versions, which we compare against our own users and
then discard. We never receive your contacts' names, phone
numbers or email addresses, and we do not store anything from your
address book. Bondie never asks for this on its own and never
uses it to message anyone. You can also stop other people's address
books from finding you, in Settings.
- Product analytics: how features are used, so we can tell
what works. Collected through PostHog, which receives your account identifier so
that one person's activity is grouped together.
- Visits to this website: we count visits to
bondieapp.com and which links are tapped, so we can tell whether the
pages work. This uses no cookies, stores nothing in your browser and is
not linked to a Bondie account.
- Crash and error reports: when something goes wrong, a
report of what failed, along with your device model, operating system,
app version and account identifier. Collected through Sentry. These
reports never contain your photos, your captions or your messages.
- Bug reports you send us: when you use Report a bug in
Settings, we store what you wrote (a summary, the steps, what happened
and how often) with the app version, device model and operating system
your phone last reported. If you switch on sharing your identity, the
report also carries your name, username and account identifier; if not,
it does not. We copy the report into a private GitHub repository that
only our team can open, and post a notice of it, with the same text, to
a team channel on Discord, so GitHub and Discord both receive it. Our
stored copy is deleted with your account. The copies in GitHub and
Discord are not, and you can ask us to remove them.
- Purchases: if you subscribe to Bondie Plus, the plan,
when it started, when it renews or ends, and the store's record of the
transaction. Payment is handled entirely by Google Play or the App Store;
we never see or store your card or bank details. Subscription records are
processed for us by RevenueCat.
Notifications
A home-screen widget cannot update itself, so a push notification is the only
thing that can wake the app to show you a new photo. That means notifications
are how Bondie works, not an extra.
A notification passes through Apple or Google to reach your phone,
and it carries what it is announcing: the sender's name, and the
caption or the message they wrote. Apple and Google handle it in order to
deliver it. If you would rather they did not, turn off notification previews in
your phone's settings, or turn off notifications for Bondie. Your widget will
then update the next time you open the app rather than straight away.
What we do not do
- We do not sell your data.
- We do not show your photos to anyone you did not send them to.
- We do not use your photos to train anything.
Where it lives
Photos and videos are stored on Cloudflare R2 and are private: they are served
only through short-lived signed links to people you sent them to. Account data,
including your captions, replies and messages, is stored in a managed PostgreSQL
database on DigitalOcean, which also hosts our servers. Subscription records are
held by Google Play or the App Store, and by RevenueCat, which reports your
subscription status to us.
The companies that process data for us, and what each receives, are:
Cloudflare (every request, including your IP address, and your stored photos
and videos); DigitalOcean (our servers and database); Apple and Google (push
notifications, and Sign in with Apple or Google if you use them); Google
Firebase (phone number verification); Resend (email sign-in codes); Expo
(app update checks); PostHog (product analytics); Sentry (crash reports);
RevenueCat (subscriptions); and GitHub and Discord (bug reports you send).
Deleting your data
Deleting your account removes your profile, your connections, the scrambled
form of your phone number, the email address you signed in with, and every photo
and video you have sent, including the stored files. It cannot be undone.
In the app: Open Bondie, tap your photo at the right end of the bottom bar to open your profile, tap the three dots at the top right of your profile, choose Settings, then scroll down to Danger zone and tap Delete account. You will be asked to confirm twice. Deletion happens immediately.
If you no longer have the app installed: Email support@bondieapp.com from the address you signed in with, asking us to delete your Bondie account. We will delete it within 30 days and confirm by reply.
Deleting your account does not cancel a Bondie Plus subscription.
Subscriptions are billed by Google Play or the App Store, and only they can stop
the charges: cancel in the Play Store under Payments & subscriptions,
or in iPhone Settings under your name → Subscriptions.
What can remain after you delete your account
Deleting your account removes your data from our database. It does not
reach into the services that process data for us, so your account identifier
(a random code, not your name or email), and in two cases more than that, can
remain in:
- PostHog, our product analytics: the activity recorded
under your identifier. PostHog deletes a person on request, not
automatically.
- Sentry, our crash reports: reports that carried your
identifier, until Sentry's own retention period for them ends.
- RevenueCat, which holds subscription records: the
record for your identifier, which RevenueCat removes when it is asked
to delete the customer.
- Our server logs: every request line includes your
account identifier. We have not set a schedule that deletes these
lines, so we cannot tell you how long they are kept.
- Google Firebase, if you added a phone number: the
record of the number you verified, which Bondie does not delete.
- GitHub and Discord, if you sent a bug report: the
copies of it held there.
Our report records: the one thing deleting your
account does not remove from our own database is the copy of anything you sent
that was reported, described under What we collect. We keep it for the
time stated there and then delete it.
Email support@bondieapp.com and
we will ask each of these services to delete what they hold under your
identifier.
Children
Bondie is not directed at children under 13, and we do not knowingly collect
their data.
Contact
Questions or requests: support@bondieapp.com