Privacy Policy

Last updated: July 9, 2026

bubl ("we", "our", "us", or "the app") is committed to protecting your privacy. This policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it. It applies to the bubl iOS app and the marketing site at joinbubl.com.

1. Controller and Contact

bubl is operated by Pierson Davis ("the Developer") as an independent developer. For privacy questions, data-subject requests, or complaints, contact bubapplhelp@gmail.com. If you believe we have not resolved your concern, EU users may also contact their local data-protection authority.

2. Data We Collect

We collect the following categories of personal data to provide the app's core functionality and to improve the service.

CategoryWhat it containsHow we get it
Account identifiersApple-issued user ID, name (first/last once at sign-up if you share it), email address (which may be an Apple relay address)Sign in with Apple
Saved contentURLs, text, screenshots, and notes you explicitly share or type into bublYou — via the Share Extension, paste, or in-app forms
Location (coarse)Approximate device location, requested at "When In Use" precision only, used to center the map and compute distancesiOS Location Services (only after you grant permission)
Photo library location metadataEXIF coordinates from your photos, read on-device to suggest places you've visited. Photo files themselves are never uploaded.iOS Photos framework (only after you grant permission and opt into Photo Discovery)
Device and diagnostic dataiOS version, device model, app version, crash stack traces, performance metricsiOS, Firebase Crashlytics
Product interaction eventsScreens viewed, features used, save counts, button tapsPostHog analytics SDK
Session replay (optional)Screenshotted recordings of app sessions, with all text inputs automatically maskedPostHog — only if you grant App Tracking Transparency on iOS
Subscription / purchase historyTier (free, trial, premium), active subscription status, product ID, Apple transaction identifiers, trial start and expiry dates. We do not receive payment card data.Apple StoreKit, our server
Push notification tokenAnonymous Apple Push Notification Service token, used to deliver notifications about your savesiOS, Firebase Messaging — only if you enable notifications
IP address and network metadataImplicit in any HTTPS request; used for security, abuse prevention, and rough-geo fallbackServer logs

We do not collect or derive: precise (sub-100m) location, device advertising identifier (IDFA), contacts, calendar, microphone audio, camera video, health data, payment card numbers, or government identifiers.

3. How We Use Your Data (Purposes & Legal Bases)

For users in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR:

4. Who We Share Data With (Processors & Sub-Processors)

We do not sell, rent, or share personal data with advertisers, data brokers, or cross-app tracking networks. We share data only with the processors below, and only for the purposes listed.

AI processing of saved content

In plain terms: when you save content, bubl may send the text and images of that content to third-party AI providers to extract structured details such as venue name, location, and event date. The default provider is Google (Gemini), reached through our server. If you enable the advanced option described above, OpenAI or Anthropic is used instead. These providers process the content to return structured data and do not use it to train their models under the applicable API terms. You can turn AI extraction off at any time in Settings under Advanced.

5. International Data Transfers

Our servers and most sub-processors are located in the United States. If you use the app from the European Economic Area, the United Kingdom, or Switzerland, your data will be transferred to the U.S. Transfers to Google LLC rely on the EU–U.S. Data Privacy Framework or Standard Contractual Clauses. Transfers to PostHog, Apple, OpenAI, and Anthropic rely on equivalent mechanisms. By using the app, you acknowledge this cross-border transfer.

6. Analytics and App Tracking Transparency (iOS)

We use PostHog to understand how people use bubl and to catch regressions. Events captured include, for example: "item saved", "collection created", "paywall viewed". They do not include the content of your saves or the text of your notes.

On iOS, the first time you open the app we show Apple's App Tracking Transparency prompt. This prompt gates session replay (the optional screenshot-based recording feature). Denying the prompt:

We do not use your data for cross-app or cross-site tracking, and we do not share it with advertising networks.

7. Subscriptions and Purchases

bubl Premium is an auto-renewable subscription sold through Apple's App Store. When you purchase a subscription, Apple handles payment processing; we never see your card details. Our server records only the subscription tier, product ID, Apple transaction identifiers, status dates, and a privacy-preserving account token so we can unlock the correct features and process renewals, expirations, and refunds. You can manage or cancel at any time in iOS Settings → Your Name → Subscriptions. Refunds are handled by Apple.

8. Data Retention

9. Your Rights

Regardless of where you live, you can:

Additional rights for EEA / UK / Swiss residents (GDPR)

You have the right to lodge a complaint with your local data-protection authority if you believe our processing is unlawful. No automated decision-making with legal effect occurs in the app.

Additional rights for California residents (CCPA / CPRA)

Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the right to know, delete, correct, and port your personal information, and to opt out of "sale" or "sharing". We do not sell personal information and do not share it for cross-context behavioral advertising. The "Do Not Sell or Share My Personal Information" requirement therefore does not require any action — but if you wish to confirm, email us and we will respond.

10. Security

All traffic between the app and our servers is encrypted with TLS 1.2+. Firebase App Check validates that requests originate from the authentic bubl app. Firestore security rules restrict every document so each user can read and write only their own data. Server-side Cloud Functions enforce rate limits, quota, and entitlement checks. Subscription state is written exclusively by admin-SDK functions — clients cannot upgrade themselves. We do not store payment card information; Apple does.

11. Children's Privacy

bubl is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, contact us and we will delete it.

12. Third-Party Content and Links

When you save a URL, bubl may fetch the page's Open Graph metadata (title, description, thumbnail) so we can display a preview. The destination site's operators have their own privacy policies; we are not responsible for them. When you follow a link from bubl into Safari or another app, that site's tracking and cookies apply.

13. Changes to This Policy

We will update this policy when we add new features or change processors. Material changes will be surfaced in-app. Continued use after changes constitutes acceptance.

14. Contact

Privacy questions, data-subject requests, and complaints: bubapplhelp@gmail.com.