Privacy policy
DRAFT - pending review by legal counsel before public launch. Effective date: [TO BE SET AT LAUNCH].
- No ads, no data brokers, no selling personal data.
- What you save is used only to run the features you choose, including optional reflections and patterns.
- What you write is not used to train AI models.
- Everything you log, plus the account-tied app data we store, can be exported or deleted any time.
- We keep limited, content-free app usage logs - taps and broad app areas, never your writing - so we can improve the product.
Who we are
Blue Bonsai is operated by [OPERATING ENTITY - to be set] (“we,” “us”). For privacy questions, contact privacy@bluebonsai.life.
What we collect
We collect only what we need to operate the App for you:
- Account info. Your email address (for sign-in with an emailed code) and a small profile (onboarding answers like your goals, known triggers, or practice content preferences, if you choose to share them, plus app preferences).
- Your entries. What you log - journal entries, check-ins, ratings, notes, reflections, practice attempts. This content is private to your account.
- Derived signals. Patterns the app computes from your entries (e.g. “X tends to help when Y”). Derived from your data, never sold.
- Product usage events (in-house). A small, content-free log of broad app activity in our own database: when you opened the app, which coarse app area was viewed, which of the four doors you tapped, when a practice completed, where you are in onboarding. Just an event name, your user id, and a tiny whitelist of non-content fields (surface label, door label, practice id, onboarding step). Never your journal text, check-in selections, ratings, raw URLs, journal entry IDs, or anything you wrote.
- Basic operational data. Standard request metadata (timestamps, error logs) needed to run a reliable service, plus privacy-preserving traffic analytics and Web Vitals via Vercel (no cross-site tracking, no advertising identifiers).
The crisis and grounding flows are deliberately un-instrumented - no events fire from CrisisScreen, the public Help page, or any step of the in-app Grounding companion. Those surfaces should never appear in usage data.
What we don't collect
- No third-party advertising trackers, no data brokers.
- No precise location.
- No contacts, microphone, or camera data.
How we use what we collect
- To run the App for you - store your entries, show them back to you, compute the patterns the App is built around.
- To process specific requests on your behalf (e.g. when you tap to get an AI reflection on something you wrote, that text is sent to our AI provider to generate a response).
- To keep the App working and safe (security, abuse prevention, debugging).
We do not use your content to advertise to you. We do not sell your content. We do not share it with third parties for their own purposes.
Your per-entry privacy control
Every journal entry has a per-entry privacy toggle: keep it fully private to you (the default for sensitive entry types like reflections and flashback sessions), or allow it to inform the pattern engine. The toggle is honored absolutely; private entries are never sent to AI processing or included in pattern computation.
Who processes your data
We use a small set of service providers to operate Blue Bonsai. They process data on our behalf under their own security and privacy commitments; they are not permitted to use it for their own purposes.
- Supabase - authentication and database (your account, entries, and derived data live here).
- Anthropic - AI features. When you trigger an AI feature, the relevant text is sent to Anthropic's API to generate a response. Anthropic's commercial API terms govern how they handle that input; their public privacy materials say Anthropic API inputs and outputs are not used to train models by default.
- Vercel - hosting, plus privacy-preserving traffic and performance analytics (page views and Core Web Vitals; no cross-site tracking or advertising identifiers).
Export and delete
You can export your account-tied data as a JSON file at any time, from Settings → Your data. The export includes your profile, entries, derived patterns, reviews, memory items, AI usage rows, and content-free analytics events. You can also delete your account and all associated data at any time, from Settings → the Danger Zone. Deletion is permanent and includes your account, entries, derived patterns, usage rows, and any related records.
Retention
We keep your account and content for as long as your account exists or as needed to provide the App to you. When you delete your account, we delete the data described above. Operational backups roll over on a normal cycle (typically within 30 days).
Security
We use industry-standard technical and organizational measures to protect your data, including row-level security on the database so each user's data is isolated to their account. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you as required by applicable law.
Children
Blue Bonsai is not intended for users under [FOUNDER DECISION - see Terms; 18 recommended] years old. We do not knowingly collect data from anyone below that age. See the Terms of Service for the eligibility rule.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Effective date” above and take reasonable steps to notify you (e.g. an in-app notice on next sign-in).
Contact
Privacy questions, or to exercise rights you may have under applicable law (access, correction, deletion), contact privacy@bluebonsai.life.