Bonda Privacy Policy
Revision date: 26 July 2026 Effective from: 26 July 2026
This Policy explains in plain language what personal data the Bonda app collects, why, on what legal basis, to whom we disclose it, and what rights you have. It is written to be deliberately accessible - this is required by GDPR Art. 12. If anything is unclear, write to us: support@bonda-app.com.
1. Who is responsible for your data (controller)
The operator of the Bonda app and the controller of personal data within the meaning of GDPR is:
AMYNEBO Spółka z ograniczoną odpowiedzialnością (AMYNEBO Sp. z o.o.) Registered address: ul. Na Zjeździe 11, 30-527 Kraków, Poland Identifiers: NIP 6793307497, KRS 0001122873 (VAT: PL6793307497) Contact (privacy, rights, support): support@bonda-app.com
We have not appointed a Data Protection Officer (DPO), as the law does not currently require us to. For all data protection matters, write to support@bonda-app.com - we respond within the GDPR time limits (as a rule, within 1 month).
2. To whom and to what this Policy applies
This Policy applies to everyone who uses the Bonda mobile app for iOS and its related services (hereinafter - "Bonda", "the app", "the service").
Bonda is a service for real-life dating and meetups: users create local events, respond to others' events, chat, and rate one another after meeting. By its nature, this means that some of your data is visible to other users (see section 4), and your correspondence may be reviewed by moderators in the event of a report (see section 5).
Bonda is intended only for persons aged 18 and over (see section 12).
3. What data we collect
We collect only what is necessary for the service to function. Below is the full list.
3.1. Account data (needed to sign in)
| Data | Source | Required |
|---|---|---|
| you enter / Apple / Google | Yes (for sign-in) | |
| Password (stored as a hash, we do not see it) | you enter | Yes, if registering via email |
| Account identifier (UUID) | generated automatically | Yes |
| Account creation date | automatically | Yes |
When signing in via Apple or Google, we receive your email and name from them (Apple - only on the first sign-in; Apple may also hide your real email via "Hide My Email"). We do not receive your Apple or Google password.
3.2. Profile data - mandatory
| Data | Purpose |
|---|---|
| Name (up to 40 characters) | display in your profile and events |
| Date of birth | confirming age 18+ and showing your age to others (the date itself is not shown to others - only the age as a number) |
3.3. Profile data - optional
You may add or not add, and change or erase at any time: profile photo (avatar); "about me" description (up to 200 characters); city; languages you speak; interests; height; zodiac sign; education; field of work; relationship status; what you are looking for; lifestyle (smoking, alcohol, sport, children); Instagram, Threads, Telegram usernames.
3.4. Special categories of data (GDPR Art. 9) - strictly optional
Some profile fields may reveal especially sensitive data:
- Sexual orientation - this is a special category under GDPR Art. 9.
We process this data only if you voluntarily provide it yourself. By filling in such a field, you give us explicit consent to display it in your profile to other users. You may withdraw your consent at any time by erasing this field in profile editing or by deleting your account. This data is never mandatory for using Bonda.
3.5. Your content and activity
- Events you create: title (up to 60), description (up to 500), category, date/time, city, exact address and coordinates of the venue (see 3.7), settings (gender/age/languages of participants, "verified only", who pays, number of guests).
- Responses to others' events: intro message, status.
- Chat messages (up to 300 characters each), read receipts. See section 5 regarding moderator access in response to a report.
- Ratings and reviews of others after a meeting (1-5 stars, text, tags, "did not show up" mark).
- Reports you submit (reason, description). We store who submitted a report - reports are not anonymous.
- Friend connections (friend requests and their status).
- Bug reports (text + app version, iOS version, device model).
- Advertising inquiries (if you use the B2B form: company name, contact email, budget, message).
3.6. Verification selfie
Verification is voluntary. If you undergo it, you take a selfie with the front camera. Importantly:
- the selfie is stored in closed (private) storage, inaccessible to other users;
- our team reviews the selfie manually, by eye and visually compares it with the profile photo;
- we do not use any automatic facial recognition technology and do not create or store any biometric template (faceprint). Therefore this is not biometric processing within the meaning of GDPR Art. 9 - but we still process the photo itself as sensitive data and protect it accordingly;
- the selfie is deleted immediately after the verification decision, and also when you delete your account.
3.7. Geolocation
- City in your profile - this is text (for example, "Kraków, Poland") that you choose yourself. We also store on the server the approximate, city-level coordinates of that city, so we can show you events near you. We do not store your precise location or home address.
- Device-based city detection - with your consent (the iOS system permission "while using") we take an approximate (city-level) location once to fill in your city in the feed. Your precise device location is used only on the device; on the server we keep the city name and its approximate coordinates, not your precise location. You may decline the permission or withdraw it in iOS Settings.
- Event venue - when you create an event and choose a location on the map, the exact address and coordinates are stored on the server. Users who are not participants are shown only the city; the exact address is visible to the host and confirmed participants.
3.8. Technical data and notifications
- Device push token (APNs) - to send notifications about messages, responses, friends, etc. Deleted when you turn off notifications or sign out of your account.
- Image cache and minor settings are stored only on your device (photos of other users, internal interface flags). We have no access to them; they are cleared by the system or when the app is uninstalled.
3.9. What we do NOT do
- We do not use any third-party analytics, tracking, or advertising systems (no Google Analytics, Firebase Analytics, Facebook SDK, Sentry, etc.).
- We do not collect the advertising identifier (IDFA) and do not track you across apps and websites.
- We do not sell your personal data. Ever.
4. What other users see
Bonda is a social app, so some data is visible to others by design:
- Publicly (any user): name, age (as a number), photo, description, city, languages, interests and other filled-in profile fields, your rating, verification status, events you have created (with the city, but without the exact address for non-participants).
- Restricted (only event participants / the person you are chatting with): the exact event address, chat messages, intro messages accompanying a response.
- Privately (only you and us): email, date of birth, password, verification selfie, whom you have blocked, your settings.
Remember: other people can see and, in theory, save (for example, screenshot) what you post or send. Do not post anything you are not prepared to show.
5. Moderation, reports, and access to correspondence
Bonda is a community of real people, so safety is a priority for us. To ensure it:
- Reports. You can report another user or a specific conversation and block anyone directly in the app. Reports are not anonymous - we store who submitted the report, the reason, and the description.
- Moderator access to correspondence in response to a report. When a report about a user or a conversation is received, our moderators (these are real people, not automation) may review the relevant correspondence and content related to the report, in order to verify it and detect rule violations - harassment, threats, hate speech, fraud, spam, impersonation, etc. We review only what is necessary to handle the specific report, and we do so on the basis of legitimate interest - community safety (GDPR Art. 6(1)(f)).
- Important note on chat privacy. Chat messages are not end-to-end (E2E) encrypted. They are stored on our server over an encrypted connection with access limited to the participants of the conversation - but technically the operator can access them for moderation in response to a report or upon a lawful request from the authorities. Do not send highly sensitive information in the chat (passwords, banking data, documents, etc.).
- Consequences. Following a review, we may take measures: a warning, hiding content, a temporary suspension, or deletion of the account. The decision is made by a human (see section 11).
- Moderation records. We keep records of reports and measures taken (see the periods in section 8) in order to ensure safety, resolve disputes, and comply with the law.
6. Why we process data and on what basis (GDPR Art. 6 and 9)
| Purpose | What data | Legal basis |
|---|---|---|
| Create an account and provide access to the service | account, profile | Performance of a contract (Art. 6(1)(b)) |
| Show relevant events, connect people in chats, ratings | profile, events, chat, reviews | Performance of a contract |
| Display sensitive profile fields (e.g. orientation) | special categories | Explicit consent (Art. 9(2)(a)); consent can be withdrawn |
| Confirm age 18+ | date of birth | Performance of a contract + legal obligation |
| Selfie verification | selfie, status | Consent (you initiate verification yourself) |
| Detect city via device | approximate geolocation | Consent (iOS system permission) |
| Send push notifications | push token | Consent (system permission) / legitimate interest |
| Security, moderation, handling reports, prevention of fraud and abuse, access to correspondence upon a report | profile, content, chat, reports, blocks, technical | Legitimate interest (Art. 6(1)(f)) - community safety |
| Process a Bonda+ purchase / other purchases | subscription/purchase status | Performance of a contract |
| Respond to lawful requests from authorities, keep records | as needed | Legal obligation (Art. 6(1)(c)) |
| Communication regarding the operation of the service (service messages) | email, contact | Performance of a contract / legitimate interest |
We do not currently send marketing communications. If we ever start, we will send them only with separate consent, which can be unsubscribed from at any time.
7. To whom we disclose data (processors and sub-processors)
We do not sell data or hand it off to outsiders. We engage trusted providers who process data on our behalf under a contract:
| Provider | What it does | What data it receives |
|---|---|---|
| Supabase (hosting, database, file storage, authentication) | stores almost all app data | profile, content, chat, photos, selfies, tokens, etc. |
| Apple (Sign in with Apple, APNs push, App Store/StoreKit, MapKit, WeatherKit) | sign-in, notification delivery, payments, maps, weather | Apple identifier, push token, payment data (which Apple processes itself), map and weather requests |
| Google (Google Sign-In) | sign-in via Google | sign-in token, email, name |
| Resend (sending emails via Supabase) | authentication emails (codes, password reset) | email, email content |
We may also disclose data if required by law or by a lawful request from an authorized body, or to protect the rights, safety, and property of users or ourselves.
International transfer. Core data is stored on Supabase servers in the EU (Ireland, region eu-west-1) - that is, within the European Economic Area (EEA). Some providers (Apple, Google) may process certain technical data outside the EEA; in such cases, the transfer takes place on the basis of appropriate safeguards under GDPR - adequacy decisions or standard contractual clauses (SCCs).
8. How long we retain data
We retain data for as long as necessary for the purposes above:
- While the account is active - core profile and content data.
- After account deletion - your profile, events, chats, reviews, photos, and selfies are deleted irreversibly from the working database. Copies may temporarily remain in secure backups for up to 30 days, after which they are overwritten.
- Reports, moderation records, and security logs we may retain longer - up to 12 months after handling - for community safety, dispute resolution, prevention of repeat violations, and legal compliance.
- Purchase-related data (for accounting/tax purposes) we retain for as long as required by Polish law - as a rule, 5 years.
- Advertising inquiries are anonymized (unlinked from the account) upon account deletion, but the company's inquiry itself may be retained.
9. Your rights (GDPR)
You have the following rights regarding your personal data:
- Access - to find out what data we hold about you.
- Rectification - to correct inaccurate data (most of it directly in profile editing).
- Erasure ("right to be forgotten") - to delete your account in Settings, which irreversibly erases your data.
- Restriction of processing - to ask us to temporarily stop processing.
- Portability - to receive your data in a machine-readable format. There is not yet an export button in the app - send a request to support@bonda-app.com, and we will provide a copy within the GDPR time limit (within 1 month).
- Objection - to object to processing based on legitimate interest.
- Withdrawal of consent - where the basis is consent (sensitive fields, geolocation, notifications, verification), to withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint to a supervisory authority - in Poland this is the Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also contact the authority of your country of residence in the EU.
To exercise your rights, write to support@bonda-app.com. We may ask you to verify your identity so as not to disclose data to the wrong person. Exercising your rights is free of charge (except for manifestly unfounded or excessive requests).
Tools directly in the app: editing/clearing profile fields, deleting photos, deleting your account, blocking and reporting, turning off notifications, signing out.
10. Data security
We take technical and organizational measures to protect your data:
- the connection to the server is encrypted (TLS);
- passwords are stored only as hashes - we do not see them;
- access to data is restricted at the database level (row-level security): everyone sees only what they are permitted to;
- verification selfies are in private storage, inaccessible to other users;
- we do not hold card payment data - it is processed by Apple.
At the same time, no system is absolutely secure, and, as noted in section 5, chat messages are not end-to-end encrypted. Do not send highly sensitive information in the chat.
11. Automated decision-making
We do not make decisions that produce legal or otherwise significant effects for you based solely on automated processing (there is no automatic banning, scoring, etc.). Verification and the handling of reports are carried out by a human.
12. Children
Bonda is not intended for persons under 18. We knowingly do not collect the data of such persons. Registration is designed so that it is impossible to select a date of birth under 18. If we learn that an account is used by a minor, we will delete it. If you believe that a child has provided us with data, write to support@bonda-app.com.
13. Changes to the Policy
We may update this Policy. We will notify you of material changes in the app (and/or by email) before they take effect. The revision date is always at the top of the document. Continued use of Bonda after the changes take effect means that you have reviewed them.
14. Language of the document
The original of this Policy was drawn up in Ukrainian. We may provide translations (into English and Polish) for convenience; in the event of material discrepancies, the Ukrainian version prevails - except where mandatory consumer protection rules of your country of residence require otherwise.
15. Contacts
- All questions (privacy, rights, support): support@bonda-app.com
- Operator: AMYNEBO Sp. z o.o., ul. Na Zjeździe 11, 30-527 Kraków, Poland (NIP 6793307497, KRS 0001122873)
Thank you for trusting Bonda. We take your data seriously.