Privacy Policy
Last updated: September 21, 2026
Bridger is a social app for real-world friendship (Updates, Friends, Events, Discover, and a member co-op). This policy explains what we collect, why, who can see it, how long we keep it, and how you can stop or delete it. It covers our iOS and Android apps, our website, and our servers.
Our privacy promises
- Real deletion, not hidden storage. Deleting your account, a fact, or a connection erases it and anything derived from it. Nothing is kept "for training."
- You control who sees what. Tiers (Close, Friends, Everyone, and custom groups) decide who can see each thing you share, enforced at the database level.
- Our matching and AI never see your name or photos. They work only from de-identified facts and your own words, using opaque IDs. Your name is only re-joined on your own device. When we embed those facts to compare people, we keep the meaning (your words and quiz dial numbers). We do not turn that meaning into an identity label first.
- No ad tracking and no third-party advertising SDKs. We do not sell your personal data.
- No vanity metrics (no follower counts, view counts, invite totals, streaks, or leaderboards).
- Capture-only media for posts (you take the photo or video in the moment), with one exception: your profile photo, which you may upload.
What we collect
Account and identity
- The default sign-in is your phone number plus a one-time text message code. You pick a country dial code and type your local number. We store the international form so we can find your account next time.
- Entering your number and tapping Send me a code is your consent to receive that sign-in text. We send codes only when you ask for one. We do not send marketing texts. Msg & data rates may apply. Reply HELP for help, STOP to opt out.
- After a successful sign-in, the session stays on this device. In Settings you may turn on an optional Face ID, Touch ID, or fingerprint lock. Bridger never receives or stores your face or fingerprint.
- Google, Sign in with Apple, or email may still be offered in some builds.
- Basic profile details you enter during onboarding, such as your display name.
- Optional onboarding preferences (how you want Bridger to connect you, a social-battery pace, an accent color). These shape only your own experience. They are never shown to other users and never used for advertising. You can skip them, and they are deleted with your account.
- Contact details you choose to share with friends inside the app. We never scrape your address book.
Website waitlist
- If you join the waitlist on bridger.social, we store your email locked in this app's database. Joining means we may email that address when Bridger is ready. Get updates means we may also email about where things stand. Be a beta tester marks that you want to try it early. We do not attach the email to a name, a phone, or an account. We do not show a list of those addresses. Email hello@bridger.social to ask us to delete yours.
Text messages (SMS)
Bridger (program name: Bridger Sign-in Texts) may text you a one-time passcode so you can create an account or sign in. Message frequency is only when you tap Send me a code (or Resend) in the Bridger app or on bridger.social. We do not send marketing, promotions, or recap texts on this program.
Sign-in texts are sent through Twilio (our SMS processor) and our auth host, Supabase. Twilio receives the phone number you entered and the short code message so the carrier can deliver it. Msg & data rates may apply. Reply HELP for help, or email hello@bridger.social. Reply STOP to opt out of further texts from this program. Carriers are not liable for delayed or undelivered messages.
We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Twilio and Supabase process the number only to deliver the sign-in code you requested. See also our Terms of Service.
Linked music accounts (optional)
- You may link Spotify or Apple Music. This is account linking, not a login method. We store the connection tokens encrypted on our servers only. They are never sent to the app or used to log you in.
- If you link an account, your picks (such as a song of the week or favorites) and top artists may be shown or used for "in common" features under the same visibility rules as your other profile facts. Disconnecting, or deleting your account, removes all of it.
Profile details, quizzes, and content you create
- Profile facts you add (hobbies, favorites, places as towns only, this-or-that answers, goals, quiz results, and similar). Each is tagged with who can see it, and separately with whether it may be used to connect you in Discover. Those are two independent choices.
- Settings includes Personalize. You can install Bridger packs and offer a pack that stays in review until we approve it. A friend who did not install it is unchanged. We do not offer a switch to train general models on your content.
- Sign in with Bridger is for another app. You still create a Bridger account to use Bridger. The other app receives only the catalog purposes you grant. You can withdraw them, and the next read leaves them out. The app does not get a database key. We do not offer a lookup for whether a phone number is on Bridger.
- Content you post: Updates (photo, text, or video), Inside Jokes, polls and votes, event details, plans signals, recap voice answers, and co-op portal ideas and comments.
- Sensitive personal fields (for example identity or beliefs) default to your Close tier and are never bulk-matchable.
- Optional "behind the scenes" context you may share for gentler matching is stored for your eyes only, is never shown on your profile, and is never revealed to matches. You can turn it off or delete it at any time.
Friends and connections
- Your connections, tiers, blocks, and optional context about how you met (place is coarse and only if you choose to add it).
- Invite links and QR codes use random tokens only. They never contain your name or photo, and short-lived QR codes are deleted after they are used.
Membership (co-op)
- Your membership status and related dates. Joining is always optional; a free tier keeps the connection essentials with no ads.
- Real payments are not yet live in the current build. When they are, they will run through the platform's own purchase system or a payment processor. Peer-to-peer "chip in" handles (such as Venmo or Cash App) are plain text links we never process.
Device permissions
We ask for these only when a feature needs them, never at launch. If you deny a permission, the app keeps working and that feature simply degrades.
| Permission | Why we ask |
|---|---|
| Camera | Posting Updates and video replies |
| Microphone | Video replies and short voice answers |
| Photo library | Choosing your profile photo, or saving a result card you made |
| Notifications | Alerts for friends, plans, and events you opted into |
| Contacts | Optional: only if you tap "Connect contacts" to pick someone to text an invite to. Your address book is never uploaded. |
| Face ID / fingerprint | Optional unlock over a saved session. Off by default. Your face or print never leaves this phone. |
| Location (coarse) | Optional "where you met," and a future local map feature if you opt in |
Product analytics
- We use PostHog, a first-party product-analytics tool, to understand which screens and buttons are used so we can improve the app.
- Events use structured screen and button names only. They never include your personal information or the text of your messages, captions, or quiz answers.
- Analytics run while you are signed in. They do not run in logged-out or demo modes. There is no ad tracking and no cross-app tracking. Deleting your account also deletes your analytics profile.
AI features
- All AI runs on our servers. The app never holds AI keys.
- AI that supports matching and summaries works only from de-identified facts and your own words, using opaque IDs. It never sees your name, your photos, or your likeness, and we do not train foundation models on your content.
- You choose what information enters a computation, and what purpose that computation serves. Bridger chooses the engineering needed to make that authorized computation reliable and secure.
- We use machine learning only on information you authorize for that feature. We do not use your private information to train general-purpose AI models without separate permission.
- Our goal is to run the models ourselves so your information stays off outside AI companies. We aim for the first of: September 2031, about 1 million accounts, or a co-op volunteer who builds and runs it. Matching scores already stay on our servers. Summaries, quiz help, and the optional assistant still go to Anthropic. Embeddings and speech-to-text still go to OpenAI. Web live captions may use your browser's speech tool and are not logged by us. This is the list we know about. We update it when that changes.
- The optional personal assistant is off by default, only ever sees your own visible data, and never acts without your explicit confirmation.
How we use your data
- To run the core app: friends, Updates, Events, limited messaging, Discover, quizzes, plans signals, and the co-op.
- To enforce your privacy tiers, blocks, and membership perks.
- To send in-app and (when you allow it) push notifications.
- To improve the product through de-identified analytics.
- To moderate reported content and enforce our Terms.
We do not sell personal data, we do not use third-party ad networks, and we do not train AI models on your content.
Who we share with
- Other users, only as you chose through your visibility settings.
- Service providers that help us run the app: Supabase (database, sign-in, and storage), Twilio (sign-in SMS), Amazon Web Services (hosting), PostHog (product analytics), Resend (email), and AI providers used server-side only. These providers process data on our behalf under contract.
- Legal authorities when required by law.
- Apps you choose to share to. If you use your phone's share sheet to send something to another app, that app's own privacy policy then governs it.
Keeping and deleting your data
- Deleting your account triggers a real, cascading delete across your data, media, and anything derived from it, including your analytics profile.
- Account deletion is available inside the app from Settings.
- You can request an export of your own data by emailing us.
Your choices and controls
- Audience and tier pickers on the things you post.
- An opt-out from being discoverable or matchable, which also drops the derived AI data about you.
- Block and report tools for both people and content.
- The option to stay on the free tier instead of joining the co-op.
Children
You must be at least 13 years old to use Bridger. We do not knowingly collect data from children under that age.
Security
Every database table enforces row-level security so people only see what they are allowed to see. Server keys and secrets live only on our servers, never in the app.
Changes to this policy
If we make material changes, we will update this page and change the "Last updated" date above.
Contact
Questions, deletion requests, or data exports: hello@bridger.social