How Bounded handles account, private-context, and support data.
Last updated: July 21, 2026
Bounded stores the account email address and authentication identifiers needed to sign in. It also stores the names, profile details, private entries, Contacts, Shared Spaces, account records, sharing settings, notifications, and preferences you create while using the app.
Bounded uses this information to authenticate your account, synchronize your private and shared context across devices, deliver the notifications you choose, support account recovery, and operate the app.
Bounded uses Firebase Authentication, Firestore, Cloud Functions, Cloud Storage, and Firebase Cloud Messaging to operate account, data, image, and notification features. It uses PostHog for privacy-conscious product analytics, Resend for transactional email, and Vercel to host the web app. These providers process data to provide their infrastructure services.
Entries and Contacts are private by default. Content is visible to other people only when you deliberately share an entry or Shared Space with them. Bounded transmits app data over HTTPS.
Account and app data are retained while an account remains active. Entries moved to Delete are scheduled for removal after 30 days unless restored. Contacts and Shared Spaces moved to Delete remain there until restored or permanently deleted. Email-delivery metadata is retained for 30 days and may remain visible for up to about 24 additional hours while automated cleanup runs.
After signing in, you can permanently delete your account and associated Bounded data through the public data deletion page or the Privacy Center in Settings.
Questions about this policy can be sent to appsupport@bayonai.com. Deletion instructions are available at /data-deletion.