1. Who we are
Bonded ("we", "us") is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS]. For anything relating to this policy or your personal data, contact us at [PRIVACY CONTACT EMAIL].
This policy covers the Bonded mobile app and the sirikayllc.com website. It explains what we collect, why, who we share it with, and what you can do about it.
2. What we collect
Information you give us
| Data | When | Why |
|---|---|---|
| Email address | Sign-up | Account identity, sign-in, and service emails |
| Password | Sign-up, if not using Google or Apple | Authentication. Stored only as a salted hash — we never store or see the original. |
| Google or Apple account identifier | Social sign-in | Lets you sign in without a password. We receive an identifier and your email, not your password. |
| Name, username, bio, profile photo, cover image | Profile setup | Shown to other users so people can recognise you |
| Date of birth | Profile setup | Confirming you meet the minimum age and age-appropriate matching |
| Gender | Optional, profile setup | Profile display and matching preferences |
| Phone number and country code | Optional | Account recovery and, where enabled, SMS verification codes |
| Interests and connection preferences | Onboarding | Matching you with circles, events, and people |
| Messages, posts, photos, event highlights and reviews | While using the app | Delivering the social features you are using |
| Identity documents and a selfie | Only if you become a paid host | Legally required identity checks before we can pay you out |
Information collected automatically
| Data | Why |
|---|---|
| Approximate and precise location (country, city, state, and GPS coordinates) | Finding events, circles, and people near you. You can turn location sharing off in settings; some discovery features stop working when you do. |
| Device push notification token and platform (iOS/Android) | Sending notifications you have enabled |
| Last seen time and online status | Showing availability. You control who sees this — everyone, connections, or nobody. |
| Subscription tier, status, and store product identifier | Giving you the features you paid for |
| Service and error logs | Keeping the service running, diagnosing faults, and detecting abuse |
Payment information
We never receive or store your card details. Card payments are handled entirely by Stripe, and in-app purchases and subscriptions are handled by Apple and Google. We store only the result — that a payment succeeded, its amount, and your subscription status.
3. The AI assistant
Bonded includes an AI assistant. Your questions to it, and the answers, are stored so the feature can improve and so we can investigate problems.
The AI runs on our own servers. Your conversations with it are not sent to OpenAI, Google, Anthropic, or any other external AI provider.
4. Why we are allowed to use your data
- To provide the service you asked for — your account, profile, messages, bookings and payments.
- Because you consented — precise location, push notifications, and marketing emails. You can withdraw consent at any time in settings.
- Because the law requires it — identity verification for hosts, and financial and tax records.
- Because we have a legitimate interest — keeping the platform safe, preventing fraud and abuse, and fixing faults.
5. Who we share it with
We do not sell your personal data. We share it only with the service providers below, and only as far as each one needs to do its job.
| Provider | What they receive | Purpose |
|---|---|---|
| Stripe | Payment and payout details; identity documents for hosts | Processing payments and legally required identity checks |
| Apple | Purchase receipts; a sign-in identifier | In-app purchases, subscriptions, and Sign in with Apple |
| Purchase tokens; a sign-in identifier; device push tokens | Play billing, Google sign-in, and push notifications via Firebase | |
| Twilio | Your phone number | Sending SMS verification codes, where that option is enabled |
| Our email provider | Your email address | Verification codes and service notifications |
| Viator | Booking details for third-party experiences you choose to book | Fulfilling that booking |
| Our hosting and storage providers | Data stored on our behalf | Running the service and storing uploaded media |
We may also disclose data where the law requires it, or to protect the safety of our users.
6. What other users can see
Your name, username, bio, photos, and interests are visible to other Bonded users. Posts and messages are visible to the circles and people you send them to. Messages are not end-to-end encrypted — we can access their content where necessary to investigate a report of abuse or where the law requires it.
Your privacy settings control your online status and location sharing.
7. How long we keep it
- Account data — while your account is open, and for [RETENTION PERIOD] after you delete it.
- Verification codes — deleted automatically shortly after they expire.
- Payment and tax records — for as long as financial law requires, typically [e.g. 7 years].
- Moderation and safety records — retained where needed to keep users safe.
8. Your rights
Depending on where you live, you can ask us to:
- Give you a copy of the data we hold about you
- Correct anything that is wrong
- Delete your account and personal data
- Stop or limit certain uses, including marketing
- Transfer your data to another service
You can delete your account from within the app. For anything else, email [PRIVACY CONTACT EMAIL] and we will respond within [e.g. 30 days]. If you are unhappy with our response you can complain to your local data protection authority.
9. Children
Bonded is not for anyone under [MINIMUM AGE, e.g. 18]. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
10. International transfers
Your data is stored on servers located in [SERVER LOCATION]. Some of our providers operate in other countries, and where data is transferred outside your region we rely on appropriate safeguards such as standard contractual clauses.
11. Security
We protect your data with encryption in transit, hashed passwords, access controls, and authenticated database access. No service can promise perfect security, but we take this seriously and will notify you and the relevant authority if a breach affects your data.
12. Changes
We will post any update here with a new date at the top, and tell you in the app if the change is significant.