Privacy policy

Last updated: July 7, 2026

This Privacy Policy explains how Bonded Studio collects, uses, shares, stores, and protects personal data when you use Bonded Studio, including bonded.studio, the Bonded Studio blog, articles, newsletters, media, educational content, affiliate or sponsored content, advertisements, digital products, physical products where offered, events, interactive experiences, the Bonded mobile application, web guest session pages, Premium features, gift-code features, help content, and related services (together, the “Services”).

This policy should be read together with:

1. Controller and Contact Details

Bonded Studio is operated by Stefanos D. Zafeiriou’s sole proprietorship with the distinctive title Sapphire Labs, based in Greece.


Business details:
Email: support@bonded.studio
Company: Sapphire Labs / Bonded Studio
Address: M. Avgeri 9, 56224, Thessaloniki, Greece
GEMI Number: 162749406000

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable Greek law, and other privacy laws that may apply to our users.

We have not appointed a Data Protection Officer because we do not currently believe one is legally required. Privacy questions may be sent to the contact above.

2. Summary

We collect personal data to operate Bonded Studio as a website, blog, media and content studio, newsletter publisher, product business, event and campaign operator, and app provider. This includes data needed to publish and improve content, send newsletters, measure website performance with Google Analytics, operate the Bonded app, provide Premium access, process purchases and gift codes, manage support, run events and filming campaigns, display ads or sponsored content where used, and comply with law.

Some features involve sensitive interpersonal preferences or conversation signals, such as boundaries, connection context, Private Pulse values, reveal decisions, and resonance moments. These features are designed for private two-person sessions and related account experiences, not public posting.

3. Personal Data We Collect

3.1 Website, Blog, and Content Data

When you visit bonded.studio or interact with our articles, educational content, landing pages, embedded media, affiliate links, ads, sponsored content, or social links, we may collect:

  • IP address and approximate location inferred from IP address
  • Browser type, device type, operating system, language, and referring URL
  • Pages viewed, links clicked, scrolls, time on page, events, campaign source, and other analytics events
  • Search terms, UTM parameters, QR campaign codes, affiliate click identifiers, ad interaction data, and similar marketing attribution data
  • Comments, form submissions, survey answers, or other information you choose to provide if such features are enabled

We use Google Analytics to understand how visitors use the Site and to improve content, navigation, product pages, and campaigns. Google may process analytics identifiers, device information, and usage data according to Google’s own terms and privacy disclosures.

3.2 Newsletter, Waitlist, and Email Data

If you subscribe to a newsletter, waitlist, email course, product announcement, event list, or similar communication, we may collect:

  • Email address
  • Name or display name, if requested
  • Consent status, signup source, signup date, form metadata, and unsubscribe status
  • Email delivery, open, click, bounce, complaint, and unsubscribe events
  • Preferences, survey answers, replies, or other information you provide

We may use Hostinger to operate newsletter forms, email hosting, email delivery, website hosting, and related infrastructure. We may also use other email providers, including Resend for app transactional emails.

Newsletters and marketing emails may include editorial content, product updates, affiliate links, sponsored content, advertisements, offers, surveys, event invitations, and links to Bonded Studio products or Services. You can unsubscribe from marketing emails using the unsubscribe link where provided or by contacting us.

3.3 Account and Identity Data

We may collect:

  • Email address
  • Password hash if you use password sign-in
  • Email verification status
  • Sign-in method
  • Apple or Google account identifier if you use social sign-in
  • Optional display name or first name received from Apple or Google
  • Username
  • Avatar configuration
  • Preferred language
  • Account creation, update, onboarding, and login timestamps
  • Admin or moderation status where applicable

Passwords are not stored in plain text. The current backend uses argon2 password hashing. Magic links, password reset codes, and refresh tokens are stored as hashes or token records where technically required.

3.4 Authentication and Session Security Data

We process:

  • Magic-link token hashes and expiry times
  • Password reset code hashes, attempts, and expiry times
  • Refresh token hashes and expiry times
  • Access-token claims needed to authenticate API and websocket requests
  • IP address, user agent, and request metadata in server logs
  • Rate-limit and abuse-prevention metadata

The mobile app stores refresh tokens in the device secure storage mechanism provided by Expo SecureStore. The web app uses short-lived in-memory bearer tokens for current web auth flows and does not currently use first-party authentication cookies.

3.5 Onboarding, Profile, and Preference Data

During onboarding or in settings, we may collect:

  • Confirmation that you are 18 or older
  • Age range
  • Sex selection and optional “other” text
  • Default connection context, such as date, partner, friend, new person, or unsure
  • Connection goal, such as laughing together, reconnecting, breaking routine, going deeper, or easing a first meeting
  • Social energy preference
  • Default depth or intensity preference
  • Conversation boundaries, such as exes, money, family, future, sex/intimacy, religion, or politics
  • Early interest in future Discovery features
  • Matching or discoverability preferences
  • Haptic and notification settings
  • Newsletter or product-news preference

Current Discovery-related fields record interest and preferences only. The current implementation does not collect location, Bluetooth proximity, or contact-list data for Discovery.

Some preference or boundary choices may reveal sensitive information about your relationship, sex life, identity, beliefs, family situation, or other personal circumstances. These fields are optional product inputs. Where the law requires consent or explicit consent for a specific category of data, we rely on that consent and you may withdraw it by changing settings, deleting optional information where available, or contacting us.

3.6 Session and Gameplay Data

When you host, join, or participate in a Bonded session, we may process:

  • Session ID, join code, guest web token, selected pack/deck, language, intensity, and total questions
  • Host and guest account IDs where both participants have accounts
  • Optional guest web email
  • Session status, start time, completion time, duration, expiry, and answered count
  • Question order and progress through the session
  • Whether each participant answered, passed, or flagged a question
  • Response timing and presentation timing
  • Resonance moments where both participants flag the same question
  • Private Pulse values, signal timestamps, reveal/hide decisions, reveal consent flags, and reveal resolution timestamps
  • Websocket and polling activity needed to run the session

Private Pulse values are designed not to be shown live to the other participant unless the relevant reveal flow resolves according to the product rules. Revealed Private Pulse moments may be included in Memory Capsules.

Because Bonded is a shared-session product, information you choose to reveal, share, or display to another participant may be seen, saved, discussed, screenshotted, copied, or otherwise used by that person outside the Services. We cannot control what another participant does with information after it is shown to them.

3.7 Memory Capsules and Insights

For completed sessions, we may create or display:

  • Memory Capsule records linked to the session
  • Resonance question summaries
  • Revealed Private Pulse summaries
  • Session duration and total answered count
  • Language and expiry metadata
  • Connection Insights based on completed sessions, pass/flag patterns, reveal decisions, depth drift, resonance themes, and similar aggregate product signals

These features are generated from session activity. They are intended for product experience and reflection, not psychological diagnosis or professional advice.

3.8 Connections, Pings, and Notifications

If you use connection features, we may process:

  • Connection requests between two users after a completed session
  • Accepted, pending, or ignored connection status
  • Who requested the connection and when the other user responded
  • Premium-only ping records, including sender, recipient, connection ID, and timestamp
  • Push notification settings
  • Expo push token, platform, device name, delivery failure count, and token update time
  • Notification payload metadata such as connection ID or in-app route

Push notifications are optional at the device permission level. You can disable supported notification types in the App settings and through your device settings.

3.9 Mobile Product Interaction Analytics

To understand onboarding and whether users reach Bonded’s core shared experience, we collect a limited first-party event history linked to the signed-in account. Events may record that an onboarding step was viewed, completed, or skipped; a ritual preview or paywall was shown; notification permission reached a coarse outcome; a purchase or restore completed; or a session invite, join, first answer, shared reaction, or completion occurred.

These events contain timestamps, app version, platform, environment, onboarding version, and a small allowlisted set of product-state labels. They do not contain names, email addresses, notification tokens, private answers, gift codes, free-form text, notification payloads, or RevenueCat customer identifiers. We use these events for first-party product improvement and do not use them to track you across apps or websites owned by other companies.

3.10 Web-to-App Ritual Funnel

When you open the QR-based web-to-app funnel, we create a random session UUID and process the language, browser timezone, referring hostname, allowlisted campaign parameters, funnel progress, and a versioned record that you accepted the Terms and acknowledged this Privacy Policy. Continuing through the first call-to-action is required to use the funnel, but it is not treated as consent to optional research.

After confirming that you are 18 or older, the funnel asks seven questions used to create the requested ritual: connection context, desired outcome, social energy, intended setting, available time, preferred depth, and optional topic boundaries. The result is a transparent recommendation, not a personality, compatibility, therapy, or psychological score.

After the ritual is shown, you may separately select “Help improve Bonded” and answer four optional questions about why you scanned, intentional-time frequency, barriers, and what would make the product worth returning to. This optional module does not affect the ritual, account creation, app handoff, or subscription offer. If you participate, allowlisted raw funnel answers and events may be retained for up to 90 days, aggregated into low-cardinality totals, and then deleted. You may withdraw later through the App privacy control.

If you do not participate, temporary non-profile answers and events are deleted after account claim or after an abandoned-session window of approximately 24 hours. When you claim the ritual, missing compatible profile preferences may be copied to your account, but existing profile values are not automatically overwritten. We do not put email addresses, raw IP addresses, full user-agent strings, or free-text relationship disclosures into funnel analytics or exports.

3.11 Premium, Gift, Product, and Payment-Related Data

We may process:

  • Premium status, source, start date, end date, lifetime flag, and grant status
  • RevenueCat app user ID and subscription entitlement data
  • App Store subscription status and purchase receipt information received through RevenueCat
  • Gift code hash, prefix, campaign, duration, status, redemption count, expiry, and metadata
  • Gift redemption records, including user ID, redemption date, IP hash, and user-agent hash
  • Paddle transaction ID, event ID, buyer email, recipient email, purchase kind, price ID, duration, amount, currency, status, custom data, and related grant or gift-code ID
  • Optional gift message entered by the buyer
  • Digital Product purchase records, such as reports, ebooks, templates, downloads, connection packs, gated content, or lifetime-access entitlements
  • Physical Product order data if we offer merch, art, printed materials, cards, objects, or other goods in the future, including shipping name, delivery address, order status, fulfillment details, tax, customs, and return records
  • Event ticket, workshop, activation, or campaign purchase and attendance records where applicable

We do not store full payment card numbers, card security codes, or Apple ID payment credentials. Payment details are handled by Apple, Paddle, Lemon Squeezy, ecommerce providers, or the applicable checkout provider shown to you at checkout.

3.12 Communications and Support Data

We may process:

  • Email address for sign-in links, password reset codes, account notices, gift code delivery, and product communications
  • Email content needed to deliver transactional messages
  • Support requests and any information you choose to include
  • Product-news preference

The current app backend uses Resend for transactional email delivery. Bonded Studio may also use Hostinger for newsletter, website, domain, email, and hosting-related services.

3.13 Affiliate, Advertising, Sponsored Content, and Marketing Data

If you interact with affiliate links, advertisements, sponsored content, partner offers, referral links, paid campaigns, or brand collaborations, we and our partners may process:

  • Link click data, affiliate or referral IDs, campaign source, UTM tags, and conversion metadata
  • Ad impression, ad click, and campaign performance data
  • Purchase attribution information received from affiliate networks, ad platforms, or commerce partners
  • Information needed to comply with sponsorship, advertising, tax, reporting, and contract obligations

We may earn commissions or other benefits from affiliate links or sponsored relationships. Third-party advertisers, affiliate networks, and sponsored partners may act as independent controllers for their own processing.

3.14 Website, Cookie, and Similar Technology Data

The website may process:

  • IP address and server log metadata
  • Browser and device information sent with requests
  • Language preference stored by the i18next language detector in localStorage
  • Google Analytics cookies, identifiers, and events
  • Affiliate, advertising, sponsored-content, and campaign attribution cookies or identifiers where used
  • Paddle checkout cookies or similar storage during payment flows
  • Short-lived tokens used in URL-based sign-in or guest-session flows

See the Cookie Policy for more detail.

3.15 Marketing, Events, Filming, and User Research Data

If you participate in a filmed session, public activation, event, interview, testimonial, user research session, waitlist, giveaway, survey, or similar campaign, we may collect:

  • Name, email address, social handle, or contact details
  • Image, voice, likeness, video, audio, photos, answers, quotes, and testimonials
  • Event attendance, QR scan, campaign code, Premium code, and redemption data
  • Consent, release, or permission records
  • Feedback, survey answers, and product-research notes

Participation in filmed marketing, testimonials, or public-facing research is optional. The specific release, consent form, event notice, or campaign terms shown to you will explain how the material may be used.

4. Sources of Personal Data

We collect personal data from:

  • You, when you visit the Site, read content, subscribe to newsletters, create an account, use sessions, update settings, buy or redeem products, attend events, or contact us
  • Your session partner, when they participate in a shared session or connection flow
  • Apple, Google, RevenueCat, Paddle, Lemon Squeezy where used, Hostinger, Resend, Expo, affiliate networks, advertising partners, sponsored partners, ecommerce providers, and other providers needed to operate the Services
  • Your device, browser, or network through normal technical requests and logs

5. Why We Process Data and Legal Bases

Processing activityMain legal basis
Create and maintain your accountContract
Authenticate sign-ins and secure sessionsContract; legitimate interests for security
Run hosted and guest sessionsContract
Store session progress, answers, passes, flags, Private Pulse decisions, and Memory CapsulesContract
Provide Premium access, gifts, grants, restores, and entitlement checksContract; legal obligation for records
Process App Store, Paddle, Lemon Squeezy, ecommerce, and other checkout-provider transaction status where usedContract; legal obligation
Send magic links, reset codes, gift-code emails, and account noticesContract
Send optional product news or newsletter messagesConsent where required; legitimate interests only where permitted for similar-service communications
Operate the blog, publish content, measure performance, and improve editorial strategyLegitimate interests
Use Google Analytics and similar non-essential analyticsConsent where required; legitimate interests where permitted by law
Process affiliate, advertising, sponsored-content, and campaign attribution dataConsent where required; legitimate interests; contract where needed for a campaign or partner relationship
Process optional sensitive preferences or boundary dataConsent or explicit consent where required; contract where the data is necessary for a requested feature and lawful
Use identifiable testimonials, event footage, interviews, or filmed sessions in marketingConsent, release, or contract for the specific campaign
Use anonymized or aggregated product insights for research, analytics, or marketing strategyLegitimate interests, provided individuals are not identified
Maintain logs, rate limits, fraud prevention, moderation, and abuse preventionLegitimate interests
Provide push notifications requested or enabled by the userConsent or contract, depending on platform permission and message type
Improve features, troubleshoot, and understand aggregate usageLegitimate interests
Measure first-party mobile product interactions and onboarding effectivenessLegitimate interests; consent where required by applicable law
Create and resume a requested web-to-app ritual, and record the applicable service agreementContract; legitimate interests for security and reliable delivery
Use optional web-to-app answers and events for product researchConsent based on the separate affirmative research-participation action
Comply with tax, accounting, legal, regulatory, and app-store obligationsLegal obligation
Respond to support, legal requests, or disputesContract; legitimate interests; legal obligation

When we rely on legitimate interests, we balance our interests against your rights and freedoms.

Sensitive and special-category data. Some connection, relationship, intimacy, or boundary preferences you choose to share — for example, indicating that a ritual should avoid topics such as sex and intimacy, religion, or politics — could reveal, or be treated as, special-category data under Article 9 GDPR. We use these preferences only to tailor or exclude content at your request; we minimise them, treat them as sensitive, and do not use them to infer protected characteristics, for advertising, or for profiling. Where such processing requires it, we rely on your explicit consent, which you can withdraw at any time. You are never required to share this information to use the core Services.

6. How We Use Personal Data

We use personal data to:

  • Provide accounts, authentication, sessions, guest participation, and app settings
  • Operate bonded.studio as a blog, publishing platform, content library, and marketing website
  • Send newsletters, waitlist messages, product announcements, educational content, and event invitations
  • Measure article, campaign, ad, affiliate, QR, and landing-page performance
  • Deliver Bonded decks, questions, Private Pulse, Memory Capsules, Insights, connections, pings, and Premium features
  • Process subscriptions, web Premium passes, gift purchases, Digital Product purchases, future Physical Product purchases, event tickets, and redemptions
  • Send transactional emails and service notices
  • Send product-news emails only where we have an appropriate basis and opt-out mechanism
  • Conduct optional user research, events, filming, testimonials, and marketing campaigns where you have agreed to participate
  • Create aggregate or de-identified insights about how the product is used, which may inform product development, marketing strategy, and content planning
  • Detect, prevent, and respond to fraud, abuse, security incidents, and unauthorized access
  • Debug, maintain, and improve the Services
  • Comply with legal, accounting, tax, payment, app-store, and regulatory requirements
  • Enforce the Terms of Service

We do not:

  • Sell personal data
  • use private app session content for public advertising without separate permission
  • Share gameplay or Private Pulse data with data brokers
  • Use identifiable private session content in public marketing without separate permission
  • Use session data for automated decisions that produce legal or similarly significant effects

7. Sharing and Processors

We share personal data only where needed to operate the Services, process purchases, comply with law, protect rights, or support users.

RecipientRole and data involved
Hetzner Online GmbHHosting and infrastructure in Germany/EU for application data and logs
HostingerWebsite, newsletter, domain, email, hosting, and related infrastructure, depending on the feature used
Google Analytics / Google LLCWebsite analytics, traffic measurement, campaign performance, and service improvement
ResendEmail delivery for sign-in links, password resets, gift emails, and service messages
Apple Inc.Sign in with Apple and App Store subscription processing
Google LLCSign in with Google
RevenueCat, Inc.Subscription entitlement management, receipt handling, restore/sync status, and app user ID mapping
Paddle.com Market Limited / Paddle group entitiesMerchant of Record for web purchases, payment checkout, taxes, receipts, buyer email, recipient email, purchase details, and refund handling
Lemon Squeezy or other checkout providers, where usedMerchant-of-record, checkout, tax, receipt, refund, and purchase-access services for certain digital products
Expo / Expo push notification infrastructureDelivery of push notifications using Expo push tokens
Advertising, affiliate, analytics, sponsorship, and ecommerce partnersAds, affiliate attribution, sponsored campaigns, product fulfillment, campaign reporting, and related commercial operations where used
Legal, accounting, tax, and professional advisorsCompliance, disputes, audits, and legal claims
Courts, regulators, law enforcement, or public authoritiesWhere legally required or necessary to protect rights

Third-party services process data under their own terms and privacy policies where they act as independent controllers, such as Apple, Paddle, Lemon Squeezy, ecommerce providers, or other checkout providers for payment transactions.

A current, itemised list of our processors and sub-processors — with their purpose, location, and international-transfer safeguard — is maintained at Sub-processors.

8. International Transfers

Our primary hosting is intended to remain in the European Union through Hetzner infrastructure in Germany.

Some providers may process data outside the EU/EEA, including providers based in or connected to the United States, the United Kingdom, or other countries, such as RevenueCat, Apple, Google, Paddle, Lemon Squeezy, Hostinger, Resend, Expo, affiliate partners, ad partners, ecommerce providers, and analytics providers. Where required, we rely on appropriate transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, data processing agreements, or other lawful safeguards.

You may contact us for more information about international transfer safeguards.

9. Retention

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

Data categoryRetention approach
Account dataUntil account deletion, plus a limited backup or operational period where applicable
Newsletter, waitlist, and email-marketing dataUntil you unsubscribe or request deletion, subject to suppression-list, proof-of-consent, and legal retention needs
Website analytics and Google Analytics dataAccording to our analytics settings and Google’s retention controls, or until no longer needed for analytics and reporting
First-party mobile product interaction eventsUp to 90 days, after which they are deleted through routine cleanup
Non-participating web-to-app funnel answers and eventsDeleted after account claim or after approximately 24 hours of inactivity for an abandoned anonymous session; compatible profile preferences may remain as account data
Participating web-to-app research answers and eventsUp to 90 days, then aggregated and deleted; earlier deletion is available through research withdrawal
Funnel agreement and 30-day conversion recordsKept only as needed to evidence the agreement, secure the service, and measure the stated conversion window, subject to routine cleanup and legal requirements
Affiliate, ad, sponsored-content, and campaign attribution dataAs long as needed for reporting, payment, fraud prevention, tax, contract, and dispute purposes
Password hashes and linked sign-in identifiersUntil changed, unlinked, or account deletion
Magic-link and password-reset token hashesTokens expire after a short period, currently about 15 minutes; technical records may remain until cleanup or account deletion
Refresh token hashesUntil logout, rotation, expiry, revocation, or account deletion; current refresh-token validity is about 30 days
Onboarding, profile, and preference dataUntil changed or account deletion
Session records and shared session historyWhile needed to provide session history, Memory Capsules, Insights, security, and product functionality; account deletion removes or anonymizes the deleted user’s direct account link where technically supported
Memory CapsulesWhile available under the product rules or until account deletion/anonymization; non-premium capsules may have limited availability
Connection and ping recordsUntil account deletion, connection cleanup, or no longer needed for the feature
Push tokensUntil logout/unregistration, token invalidation, repeated delivery failure cleanup, or account deletion
Premium grants and entitlement recordsFor the active access period and then as needed for accounting, fraud prevention, support, and legal obligations
Paddle, Lemon Squeezy, app-store, ecommerce, buyer/recipient emails, payment records, tax/accounting recordsTypically up to 7 years or longer if required by tax, accounting, dispute, or legal rules
Physical Product order, shipping, return, and fulfillment recordsAs long as needed for fulfillment, returns, tax, accounting, fraud prevention, and legal obligations
Gift code and redemption recordsAs needed for redemption, fraud prevention, accounting, and support; typically up to 7 years for redeemed/purchased gifts
Server access logs and security logsUsually up to 90 days unless longer retention is needed for security, debugging, fraud prevention, or legal reasons
Support and legal correspondenceAs long as needed to respond and maintain business/legal records
Product-news preferenceUntil you opt out or account deletion, subject to legal suppression-list requirements
Marketing release, event, filmed-session, testimonial, or user research recordsFor the campaign period and then as needed to prove consent, manage rights, resolve disputes, or comply with law

When you delete your account, we delete the account row and related data where the database relationship supports deletion. Some shared session records may remain without your user account attached because they also relate to another participant.

10. Your Rights

Subject to legal conditions and exceptions, you may have the following rights:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Delete your personal data
  • Restrict processing
  • Object to processing based on legitimate interests
  • Receive data portability where applicable
  • Withdraw consent where processing is based on consent
  • Object to direct marketing
  • Lodge a complaint with a supervisory authority

To exercise rights, contact support@bonded.studio. We may need to verify your identity before responding. We aim to respond within one month, unless a lawful extension applies.

If you are in Greece, you may contact:

Hellenic Data Protection Authority (HDPA)
Website: dpa.gr
Email: contact@dpa.gr
Address: Kifisias 1-3, 115 23 Athens, Greece

If you are in another EU/EEA member state, you may also contact your local supervisory authority.

11. California and Other US Privacy Notices

We do not sell personal information and do not currently share personal information for cross-context behavioral advertising.

If a US state privacy law applies to you and to us, you may have rights to know, access, correct, delete, port, or opt out of certain processing. You may exercise requests by contacting support@bonded.studio.

We will not discriminate against you for exercising privacy rights.

12. Cookies and Similar Technologies

We use cookies and similar technologies for website operation, language preference, analytics, affiliate attribution, advertising or sponsored-content measurement where used, checkout, and app-related flows.

The website may use localStorage for language preference, Google Analytics cookies, affiliate or campaign identifiers, advertising or sponsored-content measurement technologies, short-lived in-memory bearer tokens during web auth flows, URL tokens for magic-link or guest-session flows, server logs, and checkout-provider cookies during payment flows.

For details, see the Cookie Policy.

13. Security

We use technical and organizational measures designed to protect personal data, including:

  • HTTPS/TLS for data in transit
  • Argon2 password hashing
  • Hashed token storage for sensitive auth tokens where appropriate
  • Refresh token rotation
  • Rate limiting on sensitive routes
  • Access controls for production systems
  • EU-based primary hosting
  • Webhook signature or authorization checks for payment and entitlement events

No system is perfectly secure. If you believe your account or data may be at risk, contact support@bonded.studio.

If a personal data breach is likely to result in risk to your rights and freedoms, we will notify the competent supervisory authority as required by GDPR Article 33. If a breach is likely to result in high risk to affected users, we will notify those users as required by GDPR Article 34.

14. Children

The Services are intended for users aged 18 and older. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data to us, contact support@bonded.studio and we will take appropriate action.

15. Third-Party Links and Services

The Services may link to third-party websites, app stores, payment pages, or account-management pages. This policy applies to Bonded Studio’s processing of personal data, not to third-party services acting under their own policies.

Please review the privacy policies of Apple, Google, Paddle, Lemon Squeezy, Hostinger, RevenueCat, Resend, Expo, affiliate networks, ad partners, ecommerce providers, and other services you use through or alongside Bonded Studio.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as through the App, website, or email.

The “Last updated” date shows when this policy was last revised.

17. Contact

Privacy questions, requests, or complaints may be sent to: support@bonded.studio