Privacy
bugungisi is a small, invite-only coffee check-in app. This page says, in plain words, what the app knows about you and what happens with it. The short version: your data exists to show your postcards to the people you chose to show them to, and for nothing else.
What the app stores
Your account. Your email address and a password (the password is stored by our authentication provider in hashed form; we never see it). Your username, display name, and, if you add them, a profile photo, a short bio, your birthday (day and month only, never a year), the city you’re based in, where you work and where you studied, and the passport prompts you chose to answer.
Your postcards. Each postcard is a photo taken live in the app, stamped with the time, the city and country you were in, and the map coordinates of that spot (that’s what draws the pins on your passport map). Optionally a café name, a caption if you wrote one, and the companions you tagged.
Your activity. Your connections, invites you’ve sent and redeemed (including who invited you), hearts, comments, and private messages between you and your companions.
What the app does not do
No ads, no selling or sharing of data with advertisers or data brokers, and no analytics or advertising trackers. Location is read only when you ask for it — at the moment you take a postcard, or when you tap “Use where I am now” while editing your passport — never in the background. Photos come only from the in-app camera (your profile picture is the one exception; it may come from your photo library).
Notifications
We send a push only when a person is waiting on you: a message, a request to connect, or being added to someone’s postcard. Hearts and comments never notify you. The text never carries a name or the content itself, so a glance at your lock screen tells somebody nothing about who you know. There is also an optional daily reminder you can set for yourself. It is off unless you turn it on, your own phone schedules it, and it never leaves the device. To deliver a push we store a device token against your account. It is used for nothing else and it goes when your account does.
Crash reports
When the app crashes we receive a technical report — what the code was doing, the device model, the operating system and the app version — so the bug can be found and fixed. It is handled for us by Sentry, on servers in the European Union. The reports carry no username and no email address, and nothing in them identifies your account. They may include an identifier for the app installed on your device — not your name and nothing you have typed, but a value that is the same each time that install reports a problem. We are removing it. Sentry does work out an approximate place — a town or a country — from the internet connection the report arrives on. We cannot turn that off, it is not tied to your account, and we do not use it for anything. We collect no usage or performance analytics of any kind.
Who sees what
Your passport is public to members. When you post a postcard you choose where it goes: to the feed, privately to particular people, or kept for yourself. Postcards you put on your passport can be seen by any signed-in member — not only your companions. Postcards you keep are visible only to you and to anyone you tagged on them.
Your feed is narrower than your passport: it shows your companions’ postcards and the ones they pass along, and nothing else.
Postcard images live in private storage and are served through short-lived signed links, not public URLs, and only to people allowed to see that postcard. Your profile — name, username, photo, bio, the city you’re based in, where you work and where you studied, your passport prompts, and your birthday if you added one (day and month, never a year) — is visible to signed-in members. Private messages are visible only to the two people in the conversation. Members you have blocked see none of it.
bugungisi is invite-only, so “members” means people someone already inside chose to invite. Your postcards are never visible on the open web or to someone without an account. Your profile photo is the one qualification: it is served from an ordinary image link. Those links are not listed or searchable anywhere, but a photo does load for anyone who has its link, signed in or not.
Where it lives
Data is stored with Supabase on servers in Frankfurt, Germany (EU). Transactional email (sign-up confirmation, sign-in codes) is sent via Resend. Notifications are delivered by Expo, in the United States: to send you one we pass Expo the notification’s device token and its text. Because that text never carries a name or the message itself (see Notifications above), what Expo receives is that a phone should be told something — not what, or who from. Expo also serves the app’s updates, so its servers see your device asking for them. Crash reports go to Sentry, on servers in the European Union (see Crash reports above). All four act as processors for us; none of them uses your data for their own purposes.
Deleting things
You can delete any postcard in the app; that removes the image and everything attached to it (hearts, comments, pass-alongs). You can delete your whole account in the app too: Settings → Delete account. It removes your postcards and their images, your connections, your comments and hearts, and your profile details immediately, and there is no undo. If you’d rather we do it, email support@bugungisi.com from your account address and we will action it within 30 days.
A few things stay, because they live in other people’s data and removing them would take something away from someone else: private chats keep their side of your conversation, people you invited keep the record of how they joined, and postcards of other people’s that you were tagged in stay theirs. In all of them your name is replaced with “A former member”. The full detail is on the Delete your account page.
Questions
Write to support@bugungisi.com. If this policy changes in a way that matters, the date at the top changes with it.