Privacy policy

Last updated: 26 August 2026

This Privacy Policy explains how Bonded Studio collects, uses, shares, stores, and protects personal data when you use Bonded Studio, including bonded.studio, the Bonded Studio blog, articles, newsletters, media, educational content, affiliate or sponsored content, advertisements, digital products, events, interactive experiences, the Bonded mobile application, web guest session pages, Premium features, gift-code features, help content, and related services (together, the “Services”).

This policy should be read together with:

1. Controller and Contact Details

owned and operated by Stefanos D. Zafeiriou, sole proprietorship trading under the distinctive title Sapphire Labs, based in Greece and conducting business under the commercial brand Bonded Studio.

Data controller: Sapphire Labs (Bonded Studio)
G.E.MI. number: 162749406000
Privacy contact: support@bonded.studio

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable Greek law, and other privacy laws that may apply to our users.

2. Summary

We collect personal data to operate Bonded Studio as a website, blog, media and content studio, newsletter publisher, product business, event and campaign operator, and app provider. This includes data needed to publish and improve content, send newsletters, measure website performance with Google Analytics, operate the Bonded app, provide Premium access, process purchases and gift codes, manage support, run events and filming campaigns, display ads or sponsored content where used, and comply with law.

Some features involve sensitive interpersonal preferences or conversation signals, such as boundaries, connection context, Private Pulse values, reveal decisions, and resonance moments. These features are designed for private two-person sessions and related account experiences, not public posting.

3. Personal Data We Collect

3.1 Website, Blog, and Content Data

When you visit bonded.studio or interact with our articles, educational content, landing pages, embedded media, affiliate links, ads, sponsored content, or social links, we may collect:

  • Approximate location inferred from IP address
  • Browser type, device type, operating system, language, and referring URL
  • Pages viewed, links clicked, scrolls, time on page, events, campaign source, and other analytics events
  • Search terms, UTM parameters, QR campaign codes, affiliate click identifiers, ad interaction data, and similar marketing attribution data
  • Comments, form submissions, survey answers, or other information you choose to provide if such features are enabled

We use Google Analytics to understand how visitors use the Site and to improve content, navigation, product pages, and campaigns. Google may process analytics identifiers, device information, and usage data according to Google’s own terms and privacy disclosures.

3.2 Newsletter, Waitlist, and Email Data

If you subscribe to a newsletter, waitlist, email course, product announcement, event list, or similar communication, we may collect:

  • Email address
  • Name or display name, if requested
  • Consent status, signup source, signup date, form metadata, and unsubscribe status
  • Email delivery, open, click, bounce, complaint, and unsubscribe events
  • Preferences, survey answers, replies, or other information you provide

We may use Hostinger to operate newsletter forms, email hosting, email delivery, website hosting, and related infrastructure. We may also use other email providers, including Resend for app transactional emails.

Newsletters and marketing emails may include editorial content, product updates, affiliate links, sponsored content, advertisements, offers, surveys, event invitations, and links to Bonded Studio products or Services. You can unsubscribe from marketing emails using the unsubscribe link where provided or by contacting us.

Marketing email is opt-in. Creating a Bonded account does not subscribe you to anything. The newsletter switch in the app starts off, and it is only ever on because you turned it on. Every time you change it, we record the change, when it happened and which version of this policy was current, so that we can show that any marketing we send you was asked for. The same applies to promotional push notifications, which are a separate switch and also start off. Turning either off is one tap in Settings and takes effect immediately.

3.3 Account and Identity Data

We may collect:

  • Email address
  • Password hash if you use password sign-in
  • Email verification status
  • Sign-in method
  • Apple or Google account identifier if you use social sign-in
  • Optional display name or first name received from Apple or Google
  • Username
  • Avatar configuration
  • Preferred language
  • Account creation, update, onboarding, and login timestamps
  • Admin or moderation status where applicable

Usernames are checked against a prohibited-content filter when set, because a username is visible to everyone you connect with.

Passwords are not stored in plain text. The backend uses argon2 password hashing. Magic links, password reset codes, and refresh tokens are stored as hashes or token records where technically required.

3.4 Authentication and Session Security Data

We process:

  • Magic-link token hashes and expiry times
  • Password reset code hashes, attempts, and expiry times
  • Refresh token hashes and expiry times
  • Access-token claims needed to authenticate API and websocket requests
  • IP address, user agent, and request metadata in server logs
  • Rate-limit and abuse-prevention metadata

The mobile app stores refresh tokens in the device secure storage mechanism provided by Expo SecureStore. The web app uses short-lived in-memory bearer tokens for current web auth flows and does not currently use first-party authentication cookies.

3.5 Onboarding, Profile, and Preference Data

During onboarding or in settings, we may collect:

  • Confirmation that you are 18 or older
  • Age range
  • Sex selection and optional “other” text
  • Default connection context, such as date, partner, friend, new person, or unsure
  • Connection goal, such as laughing together, reconnecting, breaking routine, going deeper, or easing a first meeting
  • Social energy preference
  • Default depth or intensity preference
  • Conversation boundaries, such as exes, money, family, future, sex/intimacy, religion, or politics
  • Early interest in future Discovery features
  • Matching or discoverability preferences
  • Haptic and notification settings
  • Newsletter or product-news preference

Discoverability preferences control whether other users can find you by username. We do not collect location, Bluetooth proximity, or contact-list data for discovery, and we never upload or read your device contacts.

People are found by username only, and only if you have discovery switched on.

Some preference or boundary choices may reveal sensitive information about your relationship, sex life, identity, beliefs, family situation, or other personal circumstances. These fields are optional product inputs. Where the law requires consent or explicit consent for a specific category of data, we rely on that consent and you may withdraw it by changing settings, deleting optional information where available, or contacting us.

3.6 Session and Gameplay Data

When you host, join, or participate in a Bonded session, we may process:

  • Session ID, join code, guest web token, selected pack/deck, language, intensity, and total questions
  • Host and guest account IDs where both participants have accounts
  • Optional guest web email
  • Session status, start time, completion time, duration, expiry, and answered count
  • Question order and progress through the session
  • Whether each participant answered, passed, or flagged a question
  • Response timing and presentation timing
  • Resonance moments where both participants flag the same question
  • Private Pulse values, signal timestamps, reveal/hide decisions, reveal consent flags, and reveal resolution timestamps
  • Websocket and polling activity needed to run the session

Private Pulse values are designed not to be shown live to the other participant unless the relevant reveal flow resolves according to the product rules. Revealed Private Pulse moments may be included in Memory Capsules.

Because Bonded is a shared-session product, information you choose to reveal, share, or display to another participant may be seen, saved, discussed, screenshotted, copied, or otherwise used by that person outside the Services. We cannot control what another participant does with information after it is shown to them.

3.7 Memory Capsules and Insights

For completed sessions, we may create or display:

  • Memory Capsule records linked to the session
  • Resonance question summaries
  • Revealed Private Pulse summaries
  • Session duration and total answered count
  • Language and expiry metadata
  • Connection Insights based on completed sessions, pass/flag patterns, reveal decisions, depth drift, resonance themes, and similar aggregate product signals

These features are generated from session activity. They are intended for product experience and reflection, not psychological diagnosis or professional advice.

3.8 Connections, Pings, and Notifications

If you use connection features, we may process:

  • Connection requests between two users after a completed session
  • Accepted, pending, or ignored connection status
  • Who requested the connection and when the other user responded
  • Premium-only ping records, including sender, recipient, connection ID, timestamp, which pre-written phrase was chosen, and whether and when you opened it
  • Whether you have muted ping notifications from a particular person
  • Push notification settings
  • Expo push token, platform, device name, delivery failure count, and token update time
  • Notification payload metadata such as connection ID or in-app route

Pings contain no text you write. A ping is a choice from a fixed set of phrases written by us, such as “Thinking of you”.

There is no messaging between users. You cannot send another person words of your own — not in a ping, not in a session, not anywhere. The one thing you can write that another person reads is a profile prompt answer, described in §3.8b: you write it once, for yourself, and the people you are connected with can read it. It is not addressed to anyone, it is not delivered to anyone, and it never appears in a notification.

Notifications do not reveal content. A ping notification says only that a named person sent you a Ping — never which phrase they chose. What a ping says is visible only once you open the app, so that a lock screen seen by someone else discloses nothing about your relationships.

Retention. A ping is visible in the app for 24 hours, after which it disappears from the recipient’s inbox. The record that it happened — who sent it, to whom, on which connection, which phrase was chosen, whether and when it was opened, and when it was sent — is kept for 365 days and then deleted. If a ping is reported, a copy of the report evidence is retained so that it can be reviewed — see §9 and the Content Moderation Policy.

Push notifications are optional at the device permission level. You can disable supported notification types in the App settings and through your device settings, and you can mute notifications from an individual person without blocking them.

3.8a In-App Announcements

We may show you an occasional announcement inside the app — a dismissible card with a title, a short message, and sometimes an image and a link. Announcements are written by us; they are never messages from other users, and they never contain your data.

To avoid showing you the same card repeatedly and to understand whether an announcement was useful, we record, per announcement and per account, that it was shown, how many times, whether it was dismissed, whether its button was pressed, whether you arrived from a notification, and the platform you were using. This record is what stops a dismissed announcement coming back on another device. It contains no free text, and it is deleted 180 days after the announcement finishes, or immediately if you delete your account.

Announcements about the service — releases, outages, policy or pricing changes, safety notices — may be sent as push notifications if you have allowed notifications on your device.

Promotional announcements — offers and campaigns — are only sent as push notifications if you have separately turned on Settings → Notifications → News & offers. That setting is off unless you turn it on, you can turn it off again at any time, and each change is recorded in our consent records. Turning it off stops promotional notifications; you may still see a promotional card inside the app, clearly labelled as an offer, and you can always dismiss it.

3.8b Profile Prompt Answers and Bio

You can write a short bio on your profile — up to 200 characters describing yourself — and answer prompts: up to four on the free tier, and up to ten with Bonded Premium. The prompts are written by us — for example, “My most useless talent”. The answers are written by you, in your own words, up to 300 characters each.

For each answer we store the text you wrote, which prompt it answers, its position on your profile, and when it was created and last changed. For the bio we store the text and nothing else.

Card colour and feeling. With Bonded Premium you can also give each answer a colour and a feeling — “😌 feeling proud”. Both are chosen from lists we write, never typed: there is no free-text label and no free emoji entry anywhere in Bonded. We store only which item you picked. We deliberately keep those lists clear of anything describing health, sex life, religion or political opinion, so that choosing a feeling never involves telling us something sensitive about yourself.

If your subscription ends, everything you have already written stays exactly as it is — all of your answers remain on your profile with their colours and feelings, and your friends keep seeing them. What stops is adding new answers beyond the free limit and changing the styling. You can still edit the words of anything you have written, and you can still delete it.

A badge others can see. If you subscribe, a pink badge appears next to your name for the people you are connected with. This means those people can tell that you have a Bonded Premium subscription. It does not show them the plan, the price, when it renews, or how you paid. The badge is not an identity check and we never describe it as “verified” — we do not verify anyone’s identity.

Who can read them. Only people you are connected with, after both of you have accepted the connection. Your bio and prompt answers are not public, are not shown in search results, are not visible to someone who has only sent or received a connection request, and are not visible to anyone you have blocked or who has blocked you. Someone who is not connected to you cannot tell the difference between “this person has not connected with me” and “no such account exists” — both get the same response.

Text only. There is no voice, video, or photo answer. You cannot attach an image or a recording to your profile, and there is nowhere in Bonded to upload one.

What we check before saving. Your bio and each answer are checked against the same word filter used for usernames, and links are refused. This happens on our servers before the answer is stored, so it applies no matter which version of the app you are using. Anything that filter cannot anticipate is handled through reporting instead — any friend can report a specific answer, which sends it to the same moderation queue and the same response times as any other report. See the Content Moderation Policy.

Automated safety checking of profile writing. Separately from the filter above, and not at the moment you save, we may run your bio, prompt answers and username through a language model to look for content that breaks our Community Rules. It runs when we start it, not continuously, and text that has not changed since it was last checked is not sent again.

Control and retention. You can change or delete any answer at any time from your profile, and you can clear your bio by emptying the field. Deleting an answer removes it from your profile immediately and your friends stop seeing it. Deleting your account removes your bio, every answer, and the change history described next. If an answer is reported, a copy is kept as moderation evidence on the timetable in §9 — otherwise there would be nothing left to review once the author deleted it. The result can only open an item in the moderation queue for a person to read. It cannot remove your content, hide it, or restrict your account — every enforcement decision is made by a member of our team who has read the content themselves. Because of that, this is not a decision based solely on automated processing within the meaning of Article 22.

A record of changes, and how long each part of it lasts. When you create, change or delete an answer we keep a record of the change. It has two parts, and they are kept for different lengths of time on purpose:

  • Our lawful basis is our legitimate interest in keeping the service safe for the people who use it (Art. 6(1)(f)), balanced against the fact that the writing involved is short, is already visible to your accepted connections, and is checked for one purpose only. The companies that may process it are named in the sub-processor list; they are limited to a pinned set, and none of them keeps what is sent or uses it to train a model. Nothing you write is used to train any AI system.
  • What changed, without the words — which prompt, whether it was created, edited or deleted, how long the previous version had been up, how many characters each version was, and whether it had a colour or a feeling. This contains nothing you wrote. We keep it while your account exists and use it to understand how the feature is used — for example, which prompts people abandon.
  • The previous text itself — kept for 30 days and then automatically deleted. This exists for safety, not for analysis: without it, a report about an answer someone rewrote minutes later points at text that no longer exists. It is never shown to another user.

Deleting your account deletes both parts. Both appear in the copy of your data you can request under §12.

One consequence worth stating. Because these are words you wrote and we store, they are, unlike a ping, something we could in principle be required to disclose in response to a lawful order. Nothing else you write in Bonded has that property.

3.9 Mobile Product Interaction Analytics

To understand onboarding and whether users reach Bonded’s core shared experience, we collect a limited first-party event history linked to the signed-in account. Events may record that an onboarding step was viewed, completed, or skipped; a ritual preview or paywall was shown; notification permission reached a coarse outcome; a purchase or restore completed; or a session invite, join, first answer, shared reaction, or completion occurred.

These events contain timestamps, app version, platform, environment, onboarding version, and a small allowlisted set of product-state labels. They do not contain names, email addresses, notification tokens, private answers, gift codes, free-form text, notification payloads, or RevenueCat customer identifiers. We use these events for first-party product improvement and do not use them to track you across apps or websites owned by other companies.

3.10 Web-to-App Ritual Funnel

When you open the web-to-app funnel, we create a random session UUID and process the language, browser timezone, referring hostname, allowlisted campaign parameters, funnel progress, and a versioned record that you accepted the Terms and acknowledged this Privacy Policy. Continuing through the first call-to-action is required to use the funnel, but it is not treated as consent to optional research.

After confirming that you are 18 or older, the funnel asks seven questions used to create the requested ritual: connection context, desired outcome, social energy, intended setting, available time, preferred depth, and optional topic boundaries. The result is a transparent recommendation, not a personality, compatibility, therapy, or psychological score.

After the ritual is shown, you may separately select “Help improve Bonded” and answer four optional questions about why you scanned, intentional-time frequency, barriers, and what would make the product worth returning to. This optional module does not affect the ritual, account creation, app handoff, or subscription offer. If you participate, allowlisted raw funnel answers and events may be retained for up to 90 days, aggregated into low-cardinality totals, and then deleted. You may withdraw later through the App privacy control.

If you do not participate, temporary non-profile answers and events are deleted after account claim or after an abandoned-session window of approximately 24 hours. When you claim the ritual, missing compatible profile preferences may be copied to your account, but existing profile values are not automatically overwritten. We do not put email addresses, raw IP addresses, full user-agent strings, or free-text relationship disclosures into funnel analytics or exports.

3.11 Premium, Gift, Product, and Payment-Related Data

We may process:

  • Premium status, source, start date, end date, lifetime flag, and grant status
  • RevenueCat app user ID and subscription entitlement data
  • App Store subscription status and purchase receipt information received through RevenueCat
  • Gift code hash, prefix, campaign, duration, status, redemption count, expiry, and metadata
  • Gift redemption records, including user ID, redemption date, IP hash, and user-agent hash
  • Paddle transaction ID, event ID, buyer email, recipient email, purchase kind, price ID, duration, amount, currency, status, custom data, and related grant or gift-code ID
  • Optional gift message entered by the buyer
  • Digital Product purchase records, such as reports, ebooks, templates, downloads, connection packs, gated content, or lifetime-access entitlements
  • Event ticket, workshop, activation, or campaign purchase and attendance records where applicable

We do not store full payment card numbers, card security codes, or Apple ID payment credentials. Payment details are handled by Apple, Paddle, or the applicable checkout provider shown to you at checkout.

3.12 Communications and Support Data

We may process:

  • Email address for sign-in links, password reset codes, account notices, gift code delivery, and product communications
  • Email content needed to deliver transactional messages
  • Support requests and any information you choose to include
  • Product-news preference

The current app backend uses Resend for transactional email delivery. Bonded Studio may also use Hostinger for newsletter, website, domain, email, and hosting-related services.

3.13 Affiliate, Advertising, Sponsored Content, and Marketing Data

If you interact with affiliate links, advertisements, sponsored content, partner offers, referral links, paid campaigns, or brand collaborations, we and our partners may process:

  • Link click data, affiliate or referral IDs, campaign source, UTM tags, and conversion metadata
  • Ad impression, ad click, and campaign performance data
  • Purchase attribution information received from affiliate networks, ad platforms, or commerce partners
  • Information needed to comply with sponsorship, advertising, tax, reporting, and contract obligations

We may earn commissions or other benefits from affiliate links or sponsored relationships. Third-party advertisers, affiliate networks, and sponsored partners may act as independent controllers for their own processing.

3.14 Website, Cookie, and Similar Technology Data

The website may process:

  • IP address and server log metadata
  • Browser and device information sent with requests
  • Language preference stored by the i18next language detector in localStorage
  • Google Analytics cookies, identifiers, and events
  • Affiliate, advertising, sponsored-content, and campaign attribution cookies or identifiers where used
  • Paddle checkout cookies or similar storage during payment flows
  • Short-lived tokens used in URL-based sign-in or guest-session flows

See the Cookie Policy for more detail.

3.15 Marketing, Events, Filming, and User Research Data

If you participate in a filmed session, public activation, event, interview, testimonial, user research session, waitlist, giveaway, survey, or similar campaign, we may collect:

  • Name, email address, social handle, or contact details
  • Image, voice, likeness, video, audio, photos, answers, quotes, and testimonials
  • Event attendance, QR scan, campaign code, Premium code, and redemption data
  • Consent, release, or permission records
  • Feedback, survey answers, and product-research notes

Participation in filmed marketing, testimonials, or public-facing research is optional. The specific release, consent form, event notice, or campaign terms shown to you will explain how the material may be used.

4. Sources of Personal Data

We collect personal data from:

  • You, when you visit the Site, read content, subscribe to newsletters, create an account, use sessions, update settings, buy or redeem products, attend events, or contact us
  • Your session partner, when they participate in a shared session or connection flow
  • Apple, Google, RevenueCat, Paddle, Hostinger, Resend, Expo, affiliate networks, advertising partners, sponsored partners, and other providers needed to operate the Services
  • Your device, browser, or network through normal technical requests and logs

5. Why We Process Data and Legal Bases

Processing activityMain legal basis
Create and maintain your accountContract
Authenticate sign-ins and secure sessionsContract; legitimate interests for security
Run hosted and guest sessionsContract
Store session progress, answers, passes, flags, Private Pulse decisions, and Memory CapsulesContract
Store and show your profile bio and prompt answers to your accepted connectionsContract
Show your accepted connections a badge indicating that you have a Bonded Premium subscriptionContract
Keep a record of changes to your prompt answers, without the text, to understand how the feature is usedLegitimate interests in improving the service
Keep the previous text of a changed or deleted answer for 30 daysLegitimate interests in a safe service — so a report about content that has since been edited can still be reviewed
Filter a profile bio or prompt answer against the prohibited-content list and refuse links before it is savedLegitimate interests in a safe service; legal obligation where platform rules require content filtering
Provide Premium access, gifts, grants, restores, and entitlement checksContract; legal obligation for records
Process App Store and Paddle transaction statusContract; legal obligation
Send magic links, reset codes, gift-code emails, and account noticesContract
Send optional product news or newsletter messagesConsent where required; legitimate interests only where permitted for similar-service communications
Operate the blog, publish content, measure performance, and improve editorial strategyLegitimate interests
Use Google Analytics and similar non-essential analyticsConsent where required; legitimate interests where permitted by law
Process affiliate, advertising, sponsored-content, and campaign attribution dataConsent where required; legitimate interests; contract where needed for a campaign or partner relationship
Process optional sensitive preferences or boundary dataConsent or explicit consent where required; contract where the data is necessary for a requested feature and lawful
Use identifiable testimonials, event footage, interviews, or filmed sessions in marketingConsent, release, or contract for the specific campaign
Use anonymized or aggregated product insights for research, analytics, or marketing strategyLegitimate interests, provided individuals are not identified
Maintain logs, rate limits, fraud prevention, moderation, and abuse preventionLegitimate interests
Provide push notifications requested or enabled by the userConsent or contract, depending on platform permission and message type
Improve features, troubleshoot, and understand aggregate usageLegitimate interests
Measure first-party mobile product interactions and onboarding effectivenessLegitimate interests; consent where required by applicable law
Create and resume a requested web-to-app ritual, and record the applicable service agreementContract; legitimate interests for security and reliable delivery
Use optional web-to-app answers and events for product researchConsent based on the separate affirmative research-participation action
Comply with tax, accounting, legal, regulatory, and app-store obligationsLegal obligation
Respond to support, legal requests, or disputesContract; legitimate interests; legal obligation

When we rely on legitimate interests, we balance our interests against your rights and freedoms.

Sensitive and special-category data. Some connection, relationship, intimacy, or boundary preferences you choose to share — for example, indicating that a ritual should avoid topics such as sex and intimacy, religion, or politics — could reveal, or be treated as, special-category data under Article 9 GDPR. We use these preferences only to tailor or exclude content at your request; we minimise them, treat them as sensitive, and do not use them to infer protected characteristics, for advertising, or for profiling. Where such processing requires it, we rely on your explicit consent, which you can withdraw at any time. You are never required to share this information to use the core Services.

6. How We Use Personal Data

We use personal data to:

  • Provide accounts, authentication, sessions, guest participation, and app settings
  • Operate bonded.studio as a blog, publishing platform, content library, and marketing website
  • Send newsletters, waitlist messages, product announcements, educational content, and event invitations
  • Measure article, campaign, ad, affiliate, QR, and landing-page performance
  • Deliver Bonded decks, questions, Private Pulse, Memory Capsules, Insights, connections, pings, and Premium features
  • Process subscriptions, web Premium passes, gift purchases, Digital Product purchases, event tickets, and redemptions
  • Send transactional emails and service notices
  • Send product-news emails only where we have an appropriate basis and opt-out mechanism
  • Conduct optional user research, events, filming, testimonials, and marketing campaigns where you have agreed to participate
  • Create aggregate or de-identified insights about how the product is used, which may inform product development, marketing strategy, and content planning
  • Detect, prevent, and respond to fraud, abuse, security incidents, and unauthorized access
  • Debug, maintain, and improve the Services
  • Comply with legal, accounting, tax, payment, app-store, and regulatory requirements
  • Enforce the Terms of Service

We do not:

  • Sell personal data
  • use private app session content for public advertising without separate permission
  • Share gameplay or Private Pulse data with data brokers
  • Let any automated system remove your content or restrict your account on its own — the safety check described in §5 can only raise an item for a person to review
  • Use identifiable private session content in public marketing without separate permission
  • Use session data for automated decisions that produce legal or similarly significant effects

7. Sharing and Processors

We share personal data only where needed to operate the Services, process purchases, comply with law, protect rights, or support users.

RecipientRole and data involved
Hetzner Online GmbHHosting and infrastructure in Germany/EU for application data and logs
HostingerWebsite, newsletter, domain, email, hosting, and related infrastructure, depending on the feature used
Google Analytics / Google LLCWebsite analytics, traffic measurement, campaign performance, and service improvement
ResendEmail delivery for sign-in links, password resets, gift emails, and service messages
Apple Inc.Sign in with Apple and App Store subscription processing
Google LLCSign in with Google
RevenueCat, Inc.Subscription entitlement management, receipt handling, restore/sync status, and app user ID mapping
Paddle.com Market Limited / Paddle group entitiesMerchant of Record for web purchases, payment checkout, taxes, receipts, buyer email, recipient email, purchase details, and refund handling
Expo / Expo push notification infrastructureDelivery of push notifications using Expo push tokens
Functional Software, Inc. (Sentry)Crash and error diagnostics for the mobile app and admin console. Configured not to send personal data; our API server does not use it
TikTok Technology Limited / TikTok Inc.Advertising measurement, so we can tell which campaigns work. Applies only to visitors who arrived from a TikTok advertisement. We send a conversion signal from our own servers containing the TikTok click identifier, the event, your IP address and browser user-agent, and the purchase value where relevant. Your email address is sent only as an irreversible hash, and only if advanced matching is enabled — it is off by default. Separately, the Research Lab loads a TikTok measurement tag in your browser, but only after you accept research participation; declining keeps it switched off
Discord Netherlands B.V. / Discord Inc.Internal operational alerts to our private team channel. A purchase notification carries a random internal account identifier, the amount and the event type — never your name, email, or anything you have written
Advertising, affiliate, analytics, and sponsorship partnersAds, affiliate attribution, sponsored campaigns, campaign reporting, and related commercial operations where used
Legal, accounting, tax, and professional advisorsCompliance, disputes, audits, and legal claims
Courts, regulators, law enforcement, or public authoritiesWhere legally required or necessary to protect rights

Third-party services process data under their own terms and privacy policies where they act as independent controllers, such as Apple or Paddle for payment transactions.

A current, itemised list of our processors and sub-processors — with their purpose, location, and international-transfer safeguard — is maintained at Sub-processors.

8. International Transfers

Our primary hosting is intended to remain in the European Union through Hetzner infrastructure in Germany.

Some providers may process data outside the EU/EEA, including providers based in or connected to the United States, the United Kingdom, or other countries, such as RevenueCat, Apple, Google, Paddle, Hostinger, Resend, Expo, Sentry, TikTok, Discord, affiliate partners, ad partners, and analytics providers. Where required, we rely on appropriate transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, data processing agreements, or other lawful safeguards.

For transfers to the United States, we rely on the EU–U.S. Data Privacy Framework where the recipient is certified under it, and on Standard Contractual Clauses where it is not. The European Commission adopted its adequacy decision for that framework on 10 July 2023; the General Court of the European Union upheld it on 3 September 2025 in Latombe v Commission (T-553/23), and an appeal is pending before the Court of Justice. We keep an internal assessment of these transfers and review it if that position changes.

9. Retention

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

Data categoryRetention approach
Account dataUntil account deletion, plus a limited backup or operational period where applicable
Newsletter, waitlist, and email-marketing dataUntil you unsubscribe or request deletion, subject to suppression-list, proof-of-consent, and legal retention needs
Website analytics and Google Analytics dataAccording to our analytics settings and Google’s retention controls, or until no longer needed for analytics and reporting
First-party mobile product interaction eventsUp to 90 days, after which they are deleted through routine cleanup
Non-participating web-to-app funnel answers and eventsDeleted after account claim or after approximately 24 hours of inactivity for an abandoned anonymous session; compatible profile preferences may remain as account data
Participating web-to-app research answers and eventsUp to 90 days, then aggregated and deleted; earlier deletion is available through research withdrawal
Funnel agreement and 30-day conversion recordsKept only as needed to evidence the agreement, secure the service, and measure the stated conversion window, subject to routine cleanup and legal requirements
Affiliate, ad, sponsored-content, and campaign attribution dataAs long as needed for reporting, payment, fraud prevention, tax, contract, and dispute purposes
Password hashes and linked sign-in identifiersUntil changed, unlinked, or account deletion
Magic-link and password-reset token hashesTokens expire after a short period, currently about 15 minutes; technical records may remain until cleanup or account deletion
Refresh token hashesUntil logout, rotation, expiry, revocation, or account deletion; current refresh-token validity is about 30 days
Onboarding, profile, and preference dataUntil changed or account deletion
Session records and shared session history550 days (about 18 months) from the session, then deleted along with the questions asked and any private-pulse readings attached to them. Account deletion removes them sooner
Memory Capsules1095 days (three years) from the session, then deleted — a longer horizon than the session itself, because a capsule is a keepsake people come back to. Account deletion removes them sooner; non-premium capsules may have limited availability
Profile bioFor as long as your account exists, or until you change or clear it
Profile prompt answersFor as long as your account exists, or until you change or delete the answer. Deleting your account deletes all of them
Card colour and feeling on an answerWith the answer. Both are selections from lists we publish, not text you wrote
Record of a change to an answer, excluding the textFor as long as your account exists
The previous text of a changed or deleted answer30 days from the change, then automatically deleted
Ping visibility24 hours. A ping disappears from the recipient’s app 24 hours after it was sent
Ping record (connection, sender, recipient, which phrase, whether and when it was opened, time sent)365 days from sending, then deleted. Pings carry no text you wrote — see §3.8
Connection recordsUntil you remove the connection, either party deletes their account, or the record is no longer needed for the feature
Reported ping evidenceRetained so a moderator can review it after the ping has left the recipient’s inbox: 90 days once reviewed, and 180 days if still unreviewed, so that a backlog cannot destroy evidence before anyone reads it
Reported profile answer evidenceA copy of the answer as it read when it was reported, on the same timetable as reported ping evidence: 90 days once reviewed, 180 days if still unreviewed. Kept as a copy because the author can edit or delete the answer at any time, which would otherwise destroy the thing being reviewed
Moderation report records (reporter, reported user, reason, outcome, reviewer)Kept indefinitely as the moderation audit trail — this is what shows a pattern of behaviour over time. The evidence attached to it is time-boxed as above
Block recordsUntil you unblock the person or delete your account
In-app announcement engagement (which announcement you saw, how many times, whether you dismissed it or tapped its link)180 days after the announcement itself has finished running, then deleted
Push tokensUntil logout/unregistration, token invalidation, repeated delivery failure cleanup, or account deletion
Premium grants and entitlement recordsFor the active access period and then as needed for accounting, fraud prevention, support, and legal obligations
Paddle and app-store payment, tax and accounting recordsTypically up to 7 years, or longer where tax, accounting, dispute, or legal rules require it
Buyer and recipient email on an order730 days (two years) from the order, then erased from the record. The order itself survives for the tax retention above — an invoice is a commercial record we are obliged to keep — but it stops carrying the email addresses once no support or refund question can still turn on them
Gift code and redemption recordsAs needed for redemption, fraud prevention, accounting, and support; typically up to 7 years for redeemed/purchased gifts
Server access logs and security logsUsually up to 90 days unless longer retention is needed for security, debugging, fraud prevention, or legal reasons
Support and legal correspondenceAs long as needed to respond and maintain business/legal records
Product-news preferenceUntil you opt out or account deletion, subject to legal suppression-list requirements
Fraud/abuse suppression recordsIf your account was suspended for fraud or abuse, we keep a one-way hashed record (never your plaintext email) for a limited period (about two years) to prevent ban evasion, based on our legitimate interest in protecting the Services and other users
Marketing release, event, filmed-session, testimonial, or user research recordsFor the campaign period and then as needed to prove consent, manage rights, resolve disputes, or comply with law

When you delete your account, we delete the account row and related data where the database relationship supports deletion. Some shared session records may remain without your user account attached because they also relate to another participant. Where the law lets us, we retain a minimal set of records after deletion — payment, tax, and accounting records for the statutory period, and, only if your account was suspended for fraud or abuse, a hashed suppression record to prevent re-registration.

10. Your Rights

Subject to legal conditions and exceptions, you may have the following rights:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Delete your personal data
  • Restrict processing
  • Object to processing based on legitimate interests
  • Receive data portability where applicable
  • Withdraw consent where processing is based on consent
  • Object to direct marketing
  • Lodge a complaint with a supervisory authority

Some of these you can exercise yourself, immediately, without asking us. In the app, under Settings:

RightWhere
Access and portability (Arts. 15, 20)Privacy controls → Download my data. Produces a file containing everything we hold about your account, in a standard machine-readable format. It is generated by the same code we would use to answer a formal request, so it is not an abridged version
Correction (Art. 16)Profile → Edit. Your display name, bio, prompt answers, avatar and onboarding answers are all editable
Erasure (Art. 17)Settings → Danger zone → Delete account. This is a real deletion, not a deactivation: your account row is removed and the records attached to it go with it. Shared session records survive without your identity attached, so the other person keeps their own history
Withdraw consent (Art. 7(3))Privacy controls for research participation; the newsletter and promotional-notification switches for marketing. Withdrawing is the same number of taps as consenting
Object to direct marketing (Art. 21(2))The same two switches, or the unsubscribe link in any marketing email

For anything not in that list — restriction, objection to processing based on legitimate interests, or a request made from an account you can no longer sign in to — contact support@bonded.studio. We may need to verify your identity before responding. We aim to acknowledge within 72 hours and to respond within one month, unless a lawful extension applies.

Exercising any of these rights is free, and we will not treat you differently for it.

If you are in Greece, you may contact:

Hellenic Data Protection Authority (HDPA)
Website: dpa.gr
Email: contact@dpa.gr
Address: Kifisias 1-3, 115 23 Athens, Greece

If you are in another EU/EEA member state, you may also contact your local supervisory authority.

11. California and Other US Privacy Notices

We do not sell personal information and do not currently share personal information for cross-context behavioral advertising.

If a US state privacy law applies to you and to us, you may have rights to know, access, correct, delete, port, or opt out of certain processing. You may exercise requests by contacting support@bonded.studio.

We will not discriminate against you for exercising privacy rights.

12. Cookies and Similar Technologies

We use cookies and similar technologies for website operation, language preference, analytics, affiliate attribution, advertising or sponsored-content measurement where used, checkout, and app-related flows.

The website may use localStorage for language preference, Google Analytics cookies, affiliate or campaign identifiers, advertising or sponsored-content measurement technologies, short-lived in-memory bearer tokens during web auth flows, URL tokens for magic-link or guest-session flows, server logs, and checkout-provider cookies during payment flows.

For details, see the Cookie Policy.

13. Security

We use technical and organizational measures designed to protect personal data, including:

  • HTTPS/TLS for data in transit
  • Argon2 password hashing
  • Hashed token storage for sensitive auth tokens where appropriate
  • Refresh token rotation
  • Rate limiting on sensitive routes
  • Access controls for production systems
  • EU-based primary hosting
  • Webhook signature or authorization checks for payment and entitlement events

No system is perfectly secure. If you believe your account or data may be at risk, contact support@bonded.studio.

If a personal data breach is likely to result in risk to your rights and freedoms, we will notify the competent supervisory authority as required by GDPR Article 33. If a breach is likely to result in high risk to affected users, we will notify those users as required by GDPR Article 34.

14. Children

The Services are for adults. You must be 18 or older to use Bonded, and we do not knowingly collect personal data from anyone younger.

This is enforced, not just stated:

  • On the web funnel, the first questions include an age band. Selecting “under 18” ends the funnel there. The check is applied on our server, not only in your browser, so it cannot be skipped by editing the page.
  • In the mobile app, onboarding asks your age band and includes an “Under 18” option. Choosing it deletes the account and everything attached to it, and returns you to the start. We do not keep a record that you tried, because keeping a child’s data in order to enforce a rule about children’s data would defeat the purpose.
  • In the Research Lab, participation is stated as 18+ before consent is requested.

We ask for an age band, never a date of birth. A band is enough to enforce an adults-only rule and to keep content age-appropriate; a birth date would be a stronger identifier than we have any need for.

Greek law (Law 4624/2019, Art. 21) sets the age at which a person can consent to information-society services on their own at 15, below the GDPR default of 16. That threshold is about consent, not about our product rule: Bonded is 18+ regardless, so we do not operate a parental-consent mechanism and do not knowingly process any child’s data under one.

If you believe a person under 18 has provided personal data to us, contact support@bonded.studio and we will delete it.

15. Third-Party Links and Services

The Services may link to third-party websites, app stores, payment pages, or account-management pages. This policy applies to Bonded Studio’s processing of personal data, not to third-party services acting under their own policies.

Please review the privacy policies of Apple, Google, Paddle, Hostinger, RevenueCat, Resend, Expo, affiliate networks, ad partners, and other services you use through or alongside Bonded Studio.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as through the App, website, or email.

The “Last updated” date shows when this policy was last revised.

17. Contact

Privacy questions, requests, or complaints may be sent to Email: support@bonded.studio