Back to bound8

Privacy Policy

Last updated September 19, 2026

bound8 ("bound8", "we", "us") helps people organize life together — whether you are on your own, with a partner, friends, roommates, a family, or a wider circle. You do this inside a shared Space: calendars, tasks, missions, goals, budgets, and updates. This policy explains what we collect, why, and the choices you have. By using bound8 on the web or mobile, you agree to this policy.

Information we collect

  • Account details — your name, email address, password (stored only as a salted hash, never in plain text), date of birth (used only to confirm you are 13 or older at sign-up; it is deleted with your account), and an optional profile photo.
  • Space content — the data you and other members of your Space create: calendar events, tasks, projects, missions, rewards, goals, budgets and transactions, posts, and messages.
  • Connected calendars — if you link Google Calendar or Apple Calendar, we store the access credentials needed to sync (OAuth tokens for Google; an app-specific password for Apple) and the events synced to or from those calendars.
  • Voice and media — when you use the AI assistant by voice, we capture the audio you record. If you add photos (profile pictures, mission proof, or a receipt for the AI assistant to read), we store those images.
  • Device and usage data — basic technical information such as app version and error logs used to keep the service running.
  • Payments & billing — if you subscribe, we store your subscription status and a transaction/receipt identifier from Stripe (web purchases) or Apple In-App Purchase (iOS). We never see or store your raw card number.

How we use your information

  • To provide and operate bound8's features for you and your Space.
  • To sync events with the calendar services you choose to connect.
  • To power the AI assistant — your voice recording is transcribed, and the resulting text (or anything you type or photograph, like a receipt) is interpreted to create events, tasks, reminders, and other actions on your behalf, and to answer questions or generate summaries about your Space.
  • To secure accounts, prevent abuse, and fix problems.

We do not sell your personal information, and we do not use your Space content to show you third-party advertising.

AI processing and third parties

To provide the AI assistant, we send information to Google(Gemini) as the primary engine: it transcribes your voice, reads receipt photos you submit, and interprets what you're asking for so it can route your request to the right action (creating an event, adding a task, answering a question, and so on). Anthropic(Claude) is optional and off by default. If we enable it for a given deployment, it may generate natural-language summaries and advice — for example, answering "how's my budget doing" or "what's coming up this week." When Anthropic is off, those replies are handled by Gemini or by on-server fallbacks.

To understand a request, we send the provider the content from your Space that the request needs — for example calendar events (including attendee names), tasks, goals, and shopping items — along with up to the last 10 turns of your conversation with the assistant (your messages and its replies), so it can follow the thread. Your financial details — transactions (name, amount, and category), budgets, income, and balance — are sent only when your request is about money, and in the weekly email briefing if you turn that on; they are not sent on every interaction.

We send only what a given request needs, and never for advertising. Gemini calls go to Google's Gemini Developer API. Whether Google uses API prompts or responses to train models depends on Google's then-current terms and the billing status of the Google Cloud project behind the API key — this policy does not independently certify a training opt-out. Anthropic (when enabled) and the infrastructure and calendar providers we rely on to deliver the features you enable (e.g., Apple) process data under their own terms and privacy policies.

Other services we rely on

Beyond the AI providers above, we work with a handful of specialized services to run bound8. None of them receive your Space content for advertising, and each processes only what it needs to do its job:

  • Payments & billingStripe processes web subscription payments, and Apple processes In-App Purchase subscriptions on iOS. We store your subscription status and a transaction/receipt identifier; we never see or store your raw card number.
  • Paywalls & subscription screensSuperwall presents subscription options in the mobile app and is told your subscription status so it can show you the right screen. It does not control access to your account — that is enforced on our servers.
  • Push notifications — reminders and alerts are delivered through Expo'spush notification service. A notification's on-screen preview can include content you created, such as a task's title; message and comment previews only include the actual text if you've turned that on in notification settings (off by default).
  • Merchant logos— in Finance, if we don't already recognize a merchant, we look up its icon from Google'spublic favicon service, which receives the merchant's domain name and your device's IP address — never your account identity.
  • Weather — the web dashboard sends a city name or coordinates to wttr.in. The iOS/Android app uses Open-Meteo for the forecast, ipwho.is for an approximate IP-based location (the default), and Nominatim (OpenStreetMap) to turn precise coordinates into a city name. No bound8 account identifier is sent with these weather requests.
  • Email — account verification, invitations, password resets, weekly briefings, and data exports are sent through Resend.
  • Crash & performance monitoring Sentry helps us find and fix bugs; it receives diagnostic data tied to your account so we can investigate reports.
  • Hosting — our application and database run on Railway and its underlying infrastructure providers.

Device permissions

  • Microphone — used only while you are speaking to the AI assistant.
  • Camera & photos — used only when you choose to set a profile picture or attach a photo.
  • Location— used only if you turn on precise weather. The default weather mode is approximate (IP-based on mobile; wttr.in's inferred location on web) and does not request the device location permission. You can instead enter a city name. Location is not used for advertising or member tracking.

You can grant or revoke these permissions at any time in your device settings.

Cookies and local storage

We use essential cookies so you can stay signed in (the NextAuth session cookie) and related sign-in cookies for Google or Apple if you use those providers. We also store a few preferences on your device (for example weather city and unit) in local storage. We do not set advertising or cross-site tracking cookies.

Sharing within your Space

bound8 is built for shared use. Content you add to a Space is visible to other members of that Space according to their role. Administrators can manage members, roles, and Space settings. Be mindful of what you share in a shared Space.

You can report a direct message, post, or comment that violates our Terms, and you can block another member at any time — blocking hides that member's posts and comments from you and stops direct messages between you, without notifying them. A report is sent to your Space's administrator, unless the person you're reporting is themselves an administrator, in which case it comes directly to us at support@bound8.com.

Data retention & deletion

We keep your information for as long as your account is active. Items you delete (tasks, events, budget entries, and similar content) are held in a recoverable trash for 7 days, after which they are permanently removed. AI assistant chat history is kept for as long as your account is active, so the assistant can remember earlier parts of your conversation — you can clear your conversation, or delete an individual message, at any time from the AI assistant itself, and it is permanently deleted when you delete your account. We have not yet finalized a retention period for system and security logs; we will update this policy once one is set.

You can delete individual items at any time, leave a Space, or permanently delete your account from Settings (mobile: Settings → Privacy and security → Delete Account; web: Settings → Danger zone → Delete Account). If you cannot sign in, email support@bound8.com. Deleting your account removes your personal data — including your AI chat history, sessions, and personal budget records — right away. Content you contributed to a shared Space (like posts, messages, calendar events, or transactions) is reassigned to a generic "Former member" placeholder rather than deleted outright, so the shared history other members of that Space depend on isn't disrupted. On mobile, Space data cached on your device is removed when you delete the app or sign out. If you or someone else has filed a report about content in your Space, the report and the reported content it references are kept as a record even after either person's account is deleted, so it remains reviewable.

Security

Passwords are hashed, calendar credentials are stored using secure storage, and access to Space data is restricted to authenticated members. No system is perfectly secure, but we work to protect your information using reasonable safeguards.

Children

bound8 is not directed to children and is not intended for use by anyone under 13. Every new account — whether created directly or via an invite to someone else's Space — must confirm a birthdate through a standard date picker before the account is created. We do not ask "are you 13 or older?" as a yes/no question and we do not restrict the picker to years that would only allow a 13+ answer; anyone can enter any birthdate, and we calculate age from what is entered. If that birthdate indicates the person is under 13, the account is not created.

A "Young Member" on a family-type Space is an admin-assigned permission tier for a member who is 13 or older. By default they can use missions, tasks, calendar, shopping, goals, the family feed, direct messages, and the AI Concierge (including photo attachments). They cannot manage billing, invite other members, or change account-level settings, and they do not get finance tools unless an admin grants that permission. This is not a separate lockdown of AI or messaging — those features are available to Young Members today. It carries no separate age verification of its own; every member, regardless of role, has already passed the 13+ check above at sign-up.

If we learn that we have collected personal information from a child under 13, we will delete that information promptly. If you believe a child under 13 has created an account, contact us at developer@apexprimus.com and we will investigate and remove the account.

Your choices & rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. You can export or delete your data at any time from Settings (see "Data retention & deletion" above). For a formal data-protection request, contact our legal/data team at developer@apexprimus.com; for anything else, reach general support at support@bound8.com.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you in the app.

Contact

Questions about this policy or your data? Email us at support@bound8.com. For formal data-protection requests, see "Your choices & rights" above.