About the website waitlist. If you join the waitlist on this site, we keep only the email address you enter and the time you entered it, solely to tell you when Bondle is available. It is stored in our own database, separate from app accounts, and our email provider (Resend) sends the confirmation. To be removed, reply to that email or write to hello@bondle.app.
Bondle Privacy Policy
Version: 2026-09-07 Effective: 2026-09-07
The short version
Bondle is a private notebook about the people in your life. You write things down — "Amma's knee has been hurting", "Arun is vegetarian", "Sarah has an interview Friday" — and Bondle brings them back to you at the moment they matter.
Four things you should know before you type anything into it:
- Your notes are stored on our servers, not only on your phone. They are in a database we run, so that they survive losing your phone and can reach you on another device. We do not read them, sell them, or train anything on them — but they exist somewhere other than your pocket, and you should decide with that in mind.
- Most of your notes are about other people, and those people have not agreed to anything. See Writing about other people below — it is the most important section in this policy.
- No AI company ever sees your notes. There is no OpenAI, Anthropic or Google AI key in this app, and no call to one. The details are in Where the AI runs, and we spell out the exact configuration that claim depends on.
- You can take everything with you or delete all of it, at any time, from inside the app. Settings → Privacy → Export, or Delete my account & data.
Who we are
Bondle is operated by a sole developer.
- Contact / data-protection enquiries: grandhisai7887@gmail.com
For people in the UK and EU, we are the controller of the personal data described below. We do not believe we can rely on the "purely personal or household activity" exemption, for the reason explained further down.
What we collect
1. Your account
| Data | Why | Where it goes |
|---|---|---|
| Email address | To create your account, verify it is really yours, and send password resets | Our database; our email provider (Resend) |
| Password | To log you in. Stored only as a one-way bcrypt hash — we cannot read it, and it is not included in your data export | Our database |
| Your name (optional) | To address you properly | Our database |
| Sign-in provider (Apple / Google) and the identifier they give us | So "Sign in with Apple/Google" works | Our database |
| Time zone from your device | So "Saturday at 8" means your 8 | Our database |
| Preferences (reminder style, capture mode, AI suggestions on/off) | So the app behaves the way you set it | Our database |
| Account creation date, subscription status | Billing and support | Our database; Stripe, if you subscribe |
| Which version of these documents you accepted, when, and the IP address and browser/app identifier at that moment | So we can show what you actually agreed to | Our database |
We do not ask your date of birth, and there is no age field anywhere in the app. See Age for why that is deliberate.
2. What you write
Everything you put into Bondle:
- the people you add — names, nicknames, relationship, birthdays, contact details, roughly where they live if you record it, and anything else you write about them;
- memories and notes — the free text you type or dictate;
- conversations, meetings, plans, reminders, follow-ups, errands, saved places and shared items, and the drafted messages Bondle suggests you send;
- chat with the assistant — your questions and its answers;
- a search index derived from the above, so the assistant can find the right note. It holds a copy of the text plus a numeric representation of it.
This is stored in our database, associated with your account.
We do not read it for any purpose other than running the service and responding to a support request you send us. We do not sell it, share it for advertising, or use it to train any model. There is no advertising SDK, no analytics SDK, no crash reporter, and no third-party tracker in this app.
3. Location — only when you ask for it
If you ask Bondle a question where a place matters ("where should I take Arun for dinner?"), and only if you have granted location permission, the app sends bare coordinates — no name, no account identifier, no note text — to:
- OpenStreetMap (Overpass API) to find real nearby venues, and
- Open-Meteo to check the forecast for a date.
Coordinates alone are still personal data. We do not keep the coordinates you sent once the answer is served, and we do not send anything else with them. If you decline location permission, these features fall back to places you have saved and the app still works.
Separately, if you deliberately save a place or record where a person lives, those coordinates are stored — because storing them is the whole point of saving them. They are yours, they are in your export, and they are deleted with the place, the person, or the account.
4. Dictation
When you capture by speaking, the recording is handled by your phone's own speech recognition — Apple's on iOS, Google's on Android — through the operating system, not by us. Bondle never receives or stores the audio; only the text that comes back, and only if you keep it.
We cannot promise that transcription happens entirely on your device. Apple and Google decide that, and depending on the device, language and settings they may send the audio to their own servers to transcribe it. That is a relationship between you and your phone's maker, governed by their privacy policy, and it is the same path any dictation on your phone takes. If it matters to you, type instead of speaking.
5. What we do not collect
- No advertising identifiers, no cross-app or cross-site tracking.
- No analytics or telemetry SDK of any kind, on the phone or on the server.
- No crash reporter is running. The server has an optional error-reporting hook (Sentry) that stays off unless both a key is configured and the package is installed — neither is true of what we ship, and we would name the change here before turning it on.
- No contact-list upload. If you import a contact, only the details you choose are saved, and the import happens on your device.
- No date of birth, and no age.
- No stored audio.
Where the AI runs
Apple's Review Guideline 5.1.2(i) requires apps to disclose clearly when personal data is shared with third parties, including third-party AI, and to get permission first. Our answer is that we do not share it with any, and here is exactly what stands behind that.
There is no third-party AI provider in Bondle. There is no API key for one in the codebase or the deployment configuration, and no code path that sends a note, a name, or a message to a hosted model service. Your notes are never sent to OpenAI, Anthropic, Google, or any comparable company.
What actually happens depends on your device:
| Where | What runs | What it sees |
|---|---|---|
| iPhone (iOS 26+) | Apple Foundation Models, on the device's own Neural Engine. The model ships with iOS; nothing is downloaded and nothing is uploaded | The assistant's answers are generated here, from context the server retrieved out of your own notes. The text stays on the phone |
| Our server, if a self-hosted model is running alongside it | An open-weights model (Ollama) on infrastructure we control | The note text needed to answer, which is already in our database. No outside company is involved |
| Everywhere else, and in the deployment we ship today | Deterministic, dependency-free logic — no model at all | Nothing leaves the server |
In the configuration this app is deployed with, no model server is configured or reachable, so on any device without on-device AI every feature falls back to plain logic and no model sees anything. The app is fully functional that way; that is a design constraint, not a degraded mode.
The promise, precisely: the only model endpoint Bondle will ever call is either on your own device or on infrastructure we run ourselves. If that ever changes — if a hosted AI service is introduced — it would be a change to this policy, the version would be raised, and you would be asked to accept it before it took effect. We would not be able to do it quietly, because acceptance is recorded per version (see Changes).
You can turn AI suggestions off in Settings. That switch is enforced on the server: with it off, the endpoints that generate a prep card or a suggestion return nothing rather than generating it.
What is on your device and what is on our servers
We want to be precise here, because it is the thing people most often assume wrongly.
On your device:
- AI generation, where your device supports it (see above).
- Speech-to-text, via the operating system (see above).
- Notification scheduling.
- Composing a message: drafts open in your own Messages or WhatsApp and are only sent when you send them.
On our servers:
- Everything in What we collect above. Your people, your notes, your memories, your reminders — all of it is in our database.
PRODUCT NOTE — DO NOT REGRESS: earlier marketing copy said data "never leaves the device" and that our server "keeps only your login and subscription". That was not true, and the copy has been corrected. Any surviving claim of that kind anywhere — website, App Store listing, onboarding screens — is a deceptive-practice risk (FTC Act §5, and the equivalent consumer-protection rules elsewhere) and must be removed before launch.
Writing about other people
This is the part of Bondle that has no clean answer, so here is the honest one.
Almost everything you write in Bondle is personal data about someone else — your mother, your friend, a colleague — and that person did not install this app, has not read this policy, and has not agreed to anything.
What is actually stored about them
Only what you type: a name and optional nickname, how you know them, a birthday, contact details you enter, notes and memories you write, times you met or spoke, places they like, and messages you drafted to them. Nothing else. In particular:
- We never enrich a profile from outside sources. There is no data broker, no social-media lookup, no email or phone enrichment, anywhere in the code.
- We never suggest people to add. Every person in your Bondle is one you typed in or imported yourself.
- Nothing is pooled between accounts. Your notes about a person and someone else's notes about the same person are never joined, compared, or used to build a shared profile. Every query in the app is scoped to one account.
The legal basis, and where it is contestable
- You decide what goes in. You choose who to add and what to record.
- We hold it on your behalf, for you alone. Nobody but you (and, where you choose to send a message, its recipient) sees it.
- We rely on legitimate interests (UK/EU GDPR Article 6(1)(f)) as the lawful basis for holding notes about third parties: your interest in remembering the people you care about, balanced against their reasonable expectations. We have written this expecting it to be scrutinised.
- We cannot notify the people you write about. Article 14 GDPR normally requires us to tell someone when we hold data about them. We do not have their contact details in a form we could use for that, and contacting them would itself be intrusive and would expose what you wrote. We are relying on Article 14(5)(b) — disproportionate effort — and on publishing this policy. This is a genuinely contestable position.
If someone asks us about themselves
Write to grandhisai7887@gmail.com. We will respond. Two honest limits:
- We cannot search every user's private notebook for a name without compromising other people's privacy, so we may have to ask you for information that identifies what we hold and who holds it.
- Answering a request about you can reveal who wrote about you, which is itself personal data about them. Balancing those two is a judgement we have to make case by case.
What removing a person actually does
We would rather be exact about this than reassuring, because it is the sentence someone will rely on.
Removing a person from a notebook has two forms. The one the app does by default is archive: they stop appearing anywhere in the app — no reminders, no suggestions, never named in an answer — but the row is still in the database, and it can be brought back.
A permanent delete removes the person row itself, and the database removes with it, in the same transaction: their details, their topics, meetings and plans, prep cards, conversations and every message in them, logged interactions, notes attached to them, shared items, reminder state, and every search-index entry that pointed at them.
Two things survive a permanent delete, and you should know which:
- Memories and errands are unlinked, not erased. The row loses its connection to the person and stays in the user's notebook as a note with nobody attached. This is deliberate — a memory is often about an event as much as a person — but it means the text, which may still name them, remains until the user deletes that note too.
- Anything the user has already exported is a file on their own device, and outside our reach entirely.
So the honest answer to "can you erase me": we can remove the structured record of a person completely, we can tell a user what remains, and we cannot reach into a user's notes and delete the sentences they wrote. Where an erasure request has to reach that text, it becomes a request we have to put to the user.
Health, and other sensitive things you might write
Notes like "her knee has been hurting" or "he's been depressed" are, in all likelihood, data concerning health under Article 9 GDPR — and Article 9 prohibits processing it unless a specific condition applies. The obvious condition, explicit consent, is not available to us, because the person the note is about is not the one using the app. The same problem arises for notes that reveal religion, ethnicity, sexuality, politics or trade-union membership — all of which people naturally write about their friends and family.
We do not detect, tag, or treat this information differently from any other note today. We are telling you it exists because it is a real, unresolved legal question about this product, not a solved one.
Who we share data with
We have no data-sharing partners in the ordinary sense, and we sell nothing. We use these service providers, only for what they are listed for, and several of them only if you use the feature that needs them.
| Recipient | What they receive | When | Why |
|---|---|---|---|
| Our hosting and database provider | All account and note data, at rest | Always | To run the service |
| Resend | Your email address and the text of the email | When we send you a verification or password-reset email | Those emails |
| Stripe | Your email, your name, and an internal account number. Card details you give to Stripe directly — we never see them | Only if you subscribe | Subscription billing |
| Apple / Google | The sign-in token they issued. We fetch their public keys to check it | Only if you use "Sign in with Apple/Google" | Verifying the sign-in |
| OpenStreetMap (Overpass) | Bare coordinates | Only when you ask a question where a place matters, with location granted | Finding real nearby venues |
| Open-Meteo | Bare coordinates and a date | Same | Weather for a plan |
| Your phone's OS maker (Apple / Google) | Dictation audio, if their speech recognition sends it to them | Only when you speak instead of type | Transcription |
| Whoever you message, via your own apps | The draft you chose to send | Only when you tap send | It is your message, from your number |
| OpenTable | The venue name, date, time and party size in the link | Only if you tap "Reserve" | Opening a booking page |
No AI provider appears in this table. That is not an omission; see Where the AI runs.
A carrier relay (Twilio) exists in the code for sending a message from a Bondle number instead of your own. It is switched off and unconfigured in the app we ship. If it is ever enabled, the message text and the recipient's number would go to Twilio, and this table and the version of this policy would change first.
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising, as those terms are defined in California law.
How long we keep it
- While your account exists: everything you have written, until you delete it. Bondle is a memory — it is meant to keep things. We do not expire old notes, and we will not start without telling you.
- An archived person: kept, but hidden from every screen and every suggestion, until the user restores or permanently deletes them.
- A permanently deleted person: removed from the live database immediately, along with everything listed in What removing a person actually does.
- Deleted memories go to a trash first, so a mis-tap is recoverable, and the trash empties itself after its retention window. Deleting from the trash is immediate and permanent.
- Verification and password-reset links: the secret itself is never stored, only a hash of it, and it expires — 24 hours for a verification link, 1 hour for a reset. A link that has been used is dead immediately, and completing a password reset kills every other reset link outstanding on the account.
- Suggestion history (which prompt we last showed you) is kept only long enough to stop the same card appearing two mornings running.
- When you delete your account: every table that holds anything about you is deleted from the live database in the same request — your people, notes, memories, topics, meetings, plans, reminders, errands, places, shared items, chat history, search index, sign-in sessions, and your consent records.
Your rights, and how to exercise them
Wherever you live, you can:
- See everything we hold — Settings → Privacy → Export my data. You get a JSON file containing every table listed in What we collect, including your account row, everything about every person, your consent history, and the text held in the search index. Two things are deliberately left out: your password hash (a credential, not information about you) and the numeric vectors in the search index (a machine representation of text that is in the file already, in full, in the same row).
- Delete everything — Settings → Privacy → Delete my account & data. This is immediate and cannot be undone.
- Correct or remove any individual note or person, at any time, in the app.
- Change the email address on the account, or your password, from inside the app. Both require your current password, and both sign every other device out.
How to withdraw consent, or say no in the first place
Consent and permission in Bondle are things you can take back, one at a time:
| What | How to withdraw it | What happens |
|---|---|---|
| AI suggestions | Settings → turn off AI suggestions | The server stops generating prep cards and suggestions for your account. It is enforced on the server, not just hidden in the app |
| Location | Your phone's Settings → Bondle → Location | Nearby and weather fall back to the places you saved. Nothing is sent to OpenStreetMap or Open-Meteo |
| Dictation / microphone | Your phone's Settings → Bondle → Microphone & Speech | Capture becomes typing only |
| Notifications | Your phone's Settings → Bondle → Notifications | Reminders stay in the app and stop appearing on your lock screen |
| A particular person's data | Delete that person in the app | Everything stored about them goes with them, immediately |
| Billing | Cancel in your Apple ID subscriptions | Handled by Apple; we stop being told to charge you |
| This policy, and the Terms | Delete your account | Withdrawing acceptance and keeping the account is not something we can offer: the acceptance is what gives us a basis to store other people's details. So withdrawal and deletion are the same action, and it is one tap in Settings |
If you are in the UK or EU you also have the rights to restrict or object to processing, to portability, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office, ico.org.uk). If you are in California you have the rights to know, delete, correct, opt out of sale or sharing (we do neither), and to limit the use of sensitive personal information.
If you are not a Bondle user and believe someone has written about you in Bondle, see If someone asks us about themselves.
Age
Bondle is not for children. You must be at least 16 to create an account, and the Terms say the same.
We do not ask your date of birth and there is no age field in the app. That is deliberate. Under COPPA, collecting age information from a general-audience app is one of the things that manufactures the "actual knowledge" that triggers the rule, and the FTC does not require general-audience apps to age-screen. Asking would create more risk for children, not less, and would collect a piece of data we have no other use for.
If we learn that an account belongs to someone under 16, we delete it.
Security
- Passwords are stored as bcrypt hashes, never in plain text, and are excluded from your data export.
- New passwords must meet a published minimum — length, a mix of letters and numbers, and not one of the passwords attackers try first. The same rules apply when you register, when you reset, and when you change it.
- Changing or resetting your password signs out every other device immediately, rather than leaving a stolen session alive until it expires. So does changing your email address.
- Traffic is encrypted in transit. Access to the production database is limited to the developer.
We do not offer end-to-end encryption: your notes are encrypted in transit and at rest by our hosting provider, but we hold the keys, which means we could technically read them. We do not, and we would rather say so plainly than imply a protection we have not built.
Changes
If we change this policy in a way that affects what you agreed to, we raise the version number and ask you to accept the new version in the app. Acceptance is recorded per document and per version, so an old acceptance never silently carries over to new text — and we can always show you which words you actually agreed to, and when.