bond

EN · 日本語

← back

Privacy Policy

Last updated: May 29, 2026

This Privacy Policy describes how Forager Lab ("we," "us") handles information you provide when using Bond (the "app"). We've tried to write this plainly. If anything is unclear, email hello@bond.forager-lab.com.

Summary

Information we collect

Account information. When you sign in with Apple, we receive the name and email address Apple provides (which may be a private relay address you control). This is used to create and identify your account.

Profile information. A display name you choose.

Pet and care data. Everything you enter about your dog — name, breed, birthday, weight, photos, medications, vaccines, vet clinic details, care tasks, and the events you log (feeding, medication doses, walks, vet visits, journal entries, etc.).

Sharing. If you invite a co-owner or caregiver, we store the email address you invited and the invitation's status. Once an invitation is accepted, the other person's Bond account becomes associated with your dog's record so they can view and log care.

Device information. Bond stores app preferences (like appearance and language) on your device. Bond may send local notifications on your device for scheduled reminders; these never leave your phone.

Subscription information. If you subscribe to Bond Plus, Apple processes your payment and provides us with a signed transaction receipt. We store the resulting subscription record — including your tier (monthly or yearly), expiration date, trial status, environment (sandbox or production), and Apple's original transaction ID — in our database so we know whether to grant Bond Plus features to your account and the pets you own. We never see your credit card or payment details; those are handled entirely by Apple. When your subscription renews, lapses, or is refunded, Apple notifies us via App Store Server Notifications and we update our record accordingly.

We do not collect: location, contacts, microphone audio, health data, or advertising identifiers. Bond does not use advertising SDKs or cross-app tracking SDKs. We do use one product analytics SDK — see the Analytics section below for what that means and how to turn it off.

How your data is stored

Your account and pet data are stored on Supabase, a hosted Postgres database provider that acts as our data processor. Data is protected in transit (TLS) and at rest, and access is restricted by row-level security so that only you and people you've explicitly shared a pet with can read or modify its records.

Photos you attach to pet profiles, journal entries, or vet visits are stored in Supabase Storage with the same access restrictions.

Some data is additionally cached on your device (via iOS-local storage) so Bond works offline. If you delete the app, the on-device cache is removed with it.

Analytics

To understand how Bond is used — which features people reach for, where they get stuck, when a subscription starts — we collect a small set of anonymous usage events through Mixpanel, a third-party product analytics provider. This is the only analytics tool used in the app.

Anonymous, not linked to your account. The identifier we send with each event is a random install UUID generated on your device and stored in the iOS Keychain. It is not joined to your Bond account, your Apple ID, your email address, your name, your pets, or any other identifying information. From our side, an install UUID is just a number — we have no way to tie it to which Bond user it belongs to.

What is collected. Events that describe how the app is used: which screen was opened, when a medication dose was logged (the fact, not the contents), when Bond Plus was purchased, when a vet report was generated, and similar. The event payload is restricted at the SDK wrapper level by a property-key deny-list — medical content, pet names, dosages, vet notes, and other free-text content are stripped before any event leaves the device.

Data residency. Mixpanel processes this analytics data in its European Union region (Netherlands, europe-west4). We chose the EU region specifically because of the mutual adequacy decision between Japan and the EU, which provides the cleanest legal basis for processing Japanese users' data under APPI.

Your control. Settings → Privacy → "Share usage analytics" is on by default. Turning it off stops the event stream immediately. The install UUID is rotated automatically — generating a fresh one and severing any link to past data — when you (a) toggle analytics off and back on, or (b) delete your account.

Mixpanel's privacy policy is at mixpanel.com/legal/privacy-policy.

How we use your information

We do not use your data for marketing, profiling, or targeted advertising, and we do not sell it.

Who we share it with

We do not share your data with anyone else unless required by law.

Your rights

You can:

If you're in the EU/UK, California, Japan, or another jurisdiction with data privacy laws, you may have additional statutory rights (including the right to object to processing, request access or correction, or lodge a complaint with a supervisory authority). Email us and we'll honor any valid request.

Notice for users in Japan

This notice is provided in accordance with Japan's Act on the Protection of Personal Information (個人情報保護法 / APPI). The data controller for personal information collected through Bond is Forager Lab, contactable at hello@bond.forager-lab.com.

Cross-border data transfer. Your account, pet, and care data is stored on Supabase, which operates infrastructure across multiple regions. Where Supabase processes your data outside Japan, that processing is governed by Supabase's privacy and data-protection commitments (available at supabase.com/privacy) and by our data processing agreement with them. By using Bond you consent to this cross-border transfer.

Analytics processing in the EU. Anonymous usage analytics (Mixpanel) are processed in the European Union (Netherlands). The EU has been recognized by Japan's Personal Information Protection Commission as a country with an equivalent level of personal information protection (mutual adequacy decision under APPI), so this cross-border processing relies on that adequacy status as its legal basis. See the Analytics section above for what is and isn't sent.

You may at any time request access to, correction of, suspension of use of, or deletion of your personal information by contacting us at the email above, or by using the in-app controls (Settings → Delete Account).

Data retention

We keep your data as long as your account is active. When you delete your account, all associated records are removed. Transactional email logs at Resend (for debugging deliverability) are retained per Resend's standard retention policy and contain only the invitation recipient's email address and delivery status.

Children

Bond is not directed to children under 13 and does not knowingly collect personal information from them. Sign in with Apple applies Apple's age-gating. If you believe a child has created an account, email us and we'll delete it.

Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of Bond after changes take effect means you accept the updated policy.

Contact

Questions, corrections, or data requests: hello@bond.forager-lab.com

Forager Lab