Privacy Policy
Last updated 28 September 2026
Bondie sends a photo from you to the people you choose, and shows it on their
home-screen widget. This page describes exactly what that involves.
What we collect
- Your account — the name and email address your Apple or
Google sign-in gives us, and the identifier that provider uses for you.
We never receive or store a password.
- What you send — the photos and videos you post, any
caption you add, and who you sent each one to.
- What you write — your replies to a photo, the reactions
you leave on one, and the messages you send in a conversation. These are
stored so the person you sent them to can read them.
- Your connections — who you are connected to.
- Your device — a push notification token, the
platform (iOS or Android), the app version and build, which update the
app is running, your device model, its operating system version and your
language setting. The token is what allows a photo to reach your widget;
the rest is what lets us tell which version of Bondie you are using when
something goes wrong. This does not include any advertising identifier,
serial number or anything else that would identify your phone outside
Bondie, and it is deleted with your account.
- Your phone number, only if you add one — so that
friends who already have your number can find you. We send a code by SMS
to check the number is yours. We store only a scrambled form of
it, never the number itself, and we never show it to anyone or
use it to contact you for anything else. You can leave this blank and
use Bondie normally.
- Contacts, only if you ask us to — Bondie can show
you which of your contacts already use it. If you turn this on, your
phone scrambles each contact's phone number and email address and sends
only the scrambled versions, which we compare against our own users and
then discard. We never receive your contacts' names, phone
numbers or email addresses, and we do not store anything from your
address book. Bondie never asks for this on its own and never
uses it to message anyone. You can also stop other people's address
books from finding you, in Settings.
- Product analytics — how features are used, so we can tell
what works. Collected through PostHog.
- Crash and error reports — when something goes wrong, a
report of what failed, along with your device model, operating system,
app version and account identifier. Collected through Sentry. These
reports never contain your photos, your captions or your messages.
- Purchases — if you subscribe to Bondie Pro: which plan,
when it started, when it renews or ends, and the store's record of the
transaction. Payment is handled entirely by Google Play or the App Store;
we never see or store your card or bank details. Subscription records are
processed for us by RevenueCat.
Notifications
A home-screen widget cannot update itself, so a push notification is the only
thing that can wake the app to show you a new photo. That means notifications
are how Bondie works, not an extra.
A notification passes through Apple or Google to reach your phone,
and it carries what it is announcing: the sender's name, and the
caption or the message they wrote. Apple and Google handle it in order to
deliver it. If you would rather they did not, turn off notification previews in
your phone's settings, or turn off notifications for Bondie — your widget will
then update the next time you open the app rather than straight away.
What we do not do
- We do not sell your data.
- We do not show your photos to anyone you did not send them to.
- We do not use your photos to train anything.
Where it lives
Photos and videos are stored on Cloudflare R2 and are private: they are served
only through short-lived signed links to people you sent them to. Account data,
including your captions, replies and messages, is stored in a managed PostgreSQL
database on DigitalOcean. Subscription records are
held by Google Play or the App Store, and by RevenueCat, which reports your
subscription status to us.
Deleting your data
You can delete your account from inside the app, under You. Deleting
your account removes your profile, your connections, the scrambled form of your
phone number, and every photo and video you have sent, including the stored
files. It cannot be undone. If you no longer
have the app installed, see deleting your account.
Deleting your account does not cancel a Bondie Pro subscription.
Subscriptions are billed by Google Play or the App Store, and only they can stop
the charges: cancel in the Play Store under Payments & subscriptions,
or in iPhone Settings under your name → Subscriptions.
Children
Bondie is not directed at children under 13, and we do not knowingly collect
their data.
Contact
Questions or requests: support@bondieapp.com