Privacy Policy

Last updated: [DATE]

Before publishing This draft describes what the Bonded app actually collects, verified against the source code. Every highlighted field still needs your real legal entity, address, and contact details, and the whole document should be reviewed by a lawyer in your jurisdiction before you rely on it.

1. Who we are

Bonded ("we", "us") is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS]. For anything relating to this policy or your personal data, contact us at [PRIVACY CONTACT EMAIL].

This policy covers the Bonded mobile app and the sirikayllc.com website. It explains what we collect, why, who we share it with, and what you can do about it.

2. What we collect

Information you give us

DataWhenWhy
Email addressSign-upAccount identity, sign-in, and service emails
PasswordSign-up, if not using Google or AppleAuthentication. Stored only as a salted hash — we never store or see the original.
Google or Apple account identifierSocial sign-inLets you sign in without a password. We receive an identifier and your email, not your password.
Name, username, bio, profile photo, cover imageProfile setupShown to other users so people can recognise you
Date of birthProfile setupConfirming you meet the minimum age and age-appropriate matching
GenderOptional, profile setupProfile display and matching preferences
Phone number and country codeOptionalAccount recovery and, where enabled, SMS verification codes
Interests and connection preferencesOnboardingMatching you with circles, events, and people
Messages, posts, photos, event highlights and reviewsWhile using the appDelivering the social features you are using
Identity documents and a selfieOnly if you become a paid hostLegally required identity checks before we can pay you out

Information collected automatically

DataWhy
Approximate and precise location (country, city, state, and GPS coordinates)Finding events, circles, and people near you. You can turn location sharing off in settings; some discovery features stop working when you do.
Device push notification token and platform (iOS/Android)Sending notifications you have enabled
Last seen time and online statusShowing availability. You control who sees this — everyone, connections, or nobody.
Subscription tier, status, and store product identifierGiving you the features you paid for
Service and error logsKeeping the service running, diagnosing faults, and detecting abuse

Payment information

We never receive or store your card details. Card payments are handled entirely by Stripe, and in-app purchases and subscriptions are handled by Apple and Google. We store only the result — that a payment succeeded, its amount, and your subscription status.

3. The AI assistant

Bonded includes an AI assistant. Your questions to it, and the answers, are stored so the feature can improve and so we can investigate problems.

The AI runs on our own servers. Your conversations with it are not sent to OpenAI, Google, Anthropic, or any other external AI provider.

4. Why we are allowed to use your data

5. Who we share it with

We do not sell your personal data. We share it only with the service providers below, and only as far as each one needs to do its job.

ProviderWhat they receivePurpose
StripePayment and payout details; identity documents for hostsProcessing payments and legally required identity checks
ApplePurchase receipts; a sign-in identifierIn-app purchases, subscriptions, and Sign in with Apple
GooglePurchase tokens; a sign-in identifier; device push tokensPlay billing, Google sign-in, and push notifications via Firebase
TwilioYour phone numberSending SMS verification codes, where that option is enabled
Our email providerYour email addressVerification codes and service notifications
ViatorBooking details for third-party experiences you choose to bookFulfilling that booking
Our hosting and storage providersData stored on our behalfRunning the service and storing uploaded media

We may also disclose data where the law requires it, or to protect the safety of our users.

6. What other users can see

Your name, username, bio, photos, and interests are visible to other Bonded users. Posts and messages are visible to the circles and people you send them to. Messages are not end-to-end encrypted — we can access their content where necessary to investigate a report of abuse or where the law requires it.

Your privacy settings control your online status and location sharing.

7. How long we keep it

8. Your rights

Depending on where you live, you can ask us to:

You can delete your account from within the app. For anything else, email [PRIVACY CONTACT EMAIL] and we will respond within [e.g. 30 days]. If you are unhappy with our response you can complain to your local data protection authority.

9. Children

Bonded is not for anyone under [MINIMUM AGE, e.g. 18]. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

10. International transfers

Your data is stored on servers located in [SERVER LOCATION]. Some of our providers operate in other countries, and where data is transferred outside your region we rely on appropriate safeguards such as standard contractual clauses.

11. Security

We protect your data with encryption in transit, hashed passwords, access controls, and authenticated database access. No service can promise perfect security, but we take this seriously and will notify you and the relevant authority if a breach affects your data.

12. Changes

We will post any update here with a new date at the top, and tell you in the app if the change is significant.