This page describes what Bubbly actually does, checked against the code rather than against intention — and it is kept that way by machine. One check fails the build if this page and the in-app consent screen stop agreeing with each other; another fails it if the app ever regains a route to an AI company this page says it does not use. Nothing you say to Bubbly leaves your phone. It used to: until 18 September 2026 the words of every thought were sent to Google's Gemini to be filed, answered and untangled. That is over, and the app is now built so it cannot happen again.
Last updated: 18 September 2026 Who this is from: Yehuda Green, operating Bubbly Thoughts as an individual (no company or LLC), based in Miami, Florida, United States. Contact: mindorb.app@gmail.com
Bubbly holds the things you do not say out loud. That deserves plain language, so here it is.
The rest of this page is the detail.
Bubbly does not encrypt this separately from your phone. It relies on iOS's own protection, which means it is protected by your device passcode. If you turn on App Lock, Face ID or your passcode is also checked before the app opens — that check happens inside iOS and Bubbly never sees your face data or your passcode.
Signing in is optional and the app works fully without it. If you do sign in, we store, with our hosting provider Supabase:
Bubbly does not ask for calendar access and does not have it. It cannot read your calendar, and it cannot add anything to it on its own.
What it does instead: a thought you gave an actual time to has a Calendar button. Tapping it opens your phone's own new-event screen, run by iOS or Android rather than by Bubbly, with the title and time already filled in. You choose which calendar it goes in and whether to save it. Bubbly never sees that screen's contents, never learns which calendar you picked, and keeps no record of what you saved.
An earlier version of this feature worked differently — it kept its own "Bubbly" calendar and needed full calendar access to create it. That was removed on 19 August 2026 in favour of the approach above, which needs no permission at all. If you granted calendar access to an earlier build, you can revoke it; nothing in Bubbly uses it.
This is different from Calendar, on purpose, and worth saying plainly. Adding a bubble to your Reminders app is a real permission: the first time you use it, iOS asks you directly whether Bubbly can access your Reminders, the same system prompt any app would show you. If you say yes, tapping the button writes the bubble's title, any extra detail, and its due date (if it has one) straight into your Reminders app — unlike Calendar, there is no second screen showing you the reminder before it saves; granting the permission is the only checkpoint. You choose to use this on a per-bubble basis; it never happens on its own. Nothing about this goes to our server or anywhere else — it is a direct write from your phone to Apple's own Reminders data, the same as any other app that asks for this permission. You can revoke it any time in iOS Settings › Bubbly › Reminders, the same as any other app.
Bubbly has no advertising SDKs, no analytics SDKs, and no tracking. Beyond what's described above for Reminders, it does not read your contacts (it lets you pick ONE from the OS's own picker when you use Call — Bubbly never sees or stores the rest of your contacts), your photos library (beyond the single photo you pick), your health data, or anything else on your phone.
The one thing that happens without you doing anything is an update check on launch, which tells Expo your IP address and which version you are running. It carries nothing you have written. See §3.
This is the part most privacy policies are vague about, so it is set out in full.
This section used to be long. Until 18 September 2026 the words of every thought went to a server we run and from there to Google's Gemini. That has been removed — not switched off, removed: the app no longer contains a way to reach it, and the build is refused if one is ever added back.
What is left is short enough to state in one place. Your thoughts, your questions, your photographs of notes and your recordings do not leave your phone. The table below is everything that still does.
| When | What is sent | Where |
|---|---|---|
| You speak a thought | Nothing. Turning it into words happens on your phone, and the recording is never sent anywhere — including when your phone cannot do it, in which case Bubbly tells you and offers typing rather than falling back to sending it. | — |
| A thought is filed, named, dated, split or moved | Nothing. All of it is decided on your phone. | — |
| You ask a question about your own thoughts | Nothing. Answered on your phone from your own bubbles. If your phone cannot answer, Bubbly says so and keeps your question — it does not send it anywhere instead. | — |
| You untangle a bubble, organise a pasted list, or photograph your notes | Nothing. All three run on your phone. A photograph of a page is the most sensitive thing this app is ever handed, and it now has no route off the device at all. | — |
| You tap Directions on a bubble | Nothing leaves Bubbly. The bubble's words are narrowed to a search on your phone ("pick up dog food" becomes "pet shop"), and that search is handed to your phone's own Maps app, which opens with it. Bubbly does not ask for your location to do this, and does not contact us. Whatever Maps then does with your location is between you and Maps. | — |
| You tap Call [a business] on a bubble | The narrowed search, and your approximate location at that moment, so the nearest real branch and its real phone number can be found. Bubbly asks iOS for your location at that moment — a separate prompt, nothing to do with the Attach Location switch. | Apple Maps, from your phone — never through our server |
| You tap Call [a person] on a bubble | Nothing. Your phone's own contact picker opens; you choose who, and Bubbly only ever sees the one contact you picked. | — |
| You sign in, delete your account, redeem a referral, or send feedback | Your email address or sign-in token, the referral code, or the message you typed to us. Never the text of a thought. | Our server, then Supabase |
| You are signed in, and your galaxy syncs | Your thoughts, as stored — this is the backup that reaches your other devices. It is not sent to any AI. | Supabase |
| You buy or start Bubbly+ | Your Bubbly account id and the subscription state Apple reports. Never your card — Apple holds that. | RevenueCat |
Feedback and support messages are delivered to our inbox by email; the server records only that one was sent, and how long it was, never what it said.
Everything else in this section is a list of things you do. This part is not, and it belongs here for exactly that reason.
If you are signed in, your galaxy syncs to your account, and once a day our server runs a set of background jobs over that synced copy — tidying up, working out whether a notification is worth sending you, and similar housekeeping.
None of them send anything to an AI company any more. Until 18 September 2026, five of them did: your morning briefing was drafted before you opened the app, and jobs looking for loops and standing patterns read your galaxy and sent parts of it to Google's Gemini, on a schedule, whether or not you had opened Bubbly that day. Those five are switched off, and nothing in the app reads what they produced any longer.
If you are not signed in, none of this happens to you — nothing is synced, so there is no copy for a job to read. Deleting your account removes the synced copy these jobs run on.
Alongside the rows above, a short summary of what Bubbly has learnt from your corrections travels with each request, so the AI files things the way you have already shown it you want them filed. It is the only thing in this section that is not something you just said or wrote, which is why it has its own heading rather than a row.
| When | What is sent |
|---|---|
| A new thought is filed | Up to 25 words you use often; the before-and-after of your last 6 renames; up to 6 words you have edited *out* of names and 6 you have edited *in* — real words from your own bubble names, not a setting; whether you tend to name things short or long; whether you tend to start a name with a verb; whether you nest deeply or keep things flat; and the name of the bubble you most often file into. |
| A recording is transcribed | Nothing at all. Turning speech into words happens on your phone, with no help from us, and nothing travels with it — no hints, no history, and never the recording. |
The underlying record — every correction you have made, and when — stays on your phone always, and, if you are signed in, also goes to our server, tied to your account. Only while AI Filing & Search AND Learn From Corrections are both on. This is not the same as the per-request summary above: it is the raw record itself, kept so a periodic pass (not tied to any one capture) can fold your recent corrections into a handful of standing filing habits — the same kind of rule the on-device summary already states, just built from a longer history than one device can hold, and built for you specifically, not shared with or shown to anyone else. Each standing habit is kept for a limited time and re-derived from there forward, not accumulated forever. You can read the whole record — the device copy, the standing habits, and the server copy alike — and erase all of it in one place, in Settings › Privacy & Security › What It's Learned; erasing there reaches the server too, not just this device.
Two things are not sent:
One honest limit on that promise, because a limit you are not told about is not a promise:
While you speak, the words appear as you say them. That uses Apple's own speech recognition, and Bubbly requires it to run on your device. It is not a preference we set and let iOS override: if your phone cannot recognise speech locally for your language, the live words simply do not appear. The recording is still transcribed on your phone either way, so nothing is lost except the words-as-you-speak readout.
No audio is sent to Apple, or to us, or to anyone.
Any request to our Worker carries your IP address, as every internet request does. Cloudflare uses it to rate-limit abuse. We do not write it into our own server log.
| Who | What they get | Where they are |
|---|---|---|
| Cloudflare (Workers) | Sign-in, account deletion, referrals and feedback — the things in §2's table. No thought text passes through it any more, and neither does the Directions/Call lookup, which now goes from your phone straight to Apple. Also your IP address, which Cloudflare uses to rate-limit abuse and which we do not log. | Global edge |
| ~~Google (Gemini API)~~ | Removed 18 September 2026. Until that date this row read "everything in §2 that goes to the AI: photos, thought text, questions, and a short summary of your filing corrections". None of it is sent any more, and the app is built so it cannot be — see the note under this table. | — |
| ~~Google (Places)~~ | Removed 18 September 2026. Until that date this row read "only when you tap Directions or Call on a bubble: that bubble's words, any place you have named before that looks relevant, and your approximate coordinates at that moment". That lookup was proxied through our Worker to Google Places. It now goes from your phone directly to Apple Maps, and Google receives nothing. | — |
| RevenueCat | If you buy or start Bubbly+: your Bubbly account id, and the subscription state Apple reports. Never your card — Apple holds that, and we never see it. | United States |
| Supabase (database + sign-in) | Your account and your synced galaxy, if you sign in. Your corrections and the standing filing habits built from them (§2), if you're also signed in and Learn From Corrections is on. Also anything in a Shared Bubble you create, join, or add to (§5) — the one exception to "your own account's data": other members of that bubble can read what you add to it, by design. | United States (us-east-1) |
| Expo (app updates) | Your IP address and your app/device version, on every launch, so the app can check whether an update is waiting. No thought content, ever — and this is the one thing that happens whether or not you sign in or consent to anything. | United States |
| Web3Forms or Resend | Feedback and support messages, to deliver them to our inbox. Whichever of the two is configured; only one is used at a time, and neither receives anything else. | United States |
| Apple | Sign in with Apple, if you use it. Speech recognition, as described above — which runs on your iPhone and sends Apple no audio. The Directions/Call place search: when you tap either, a search made from that bubble's words, plus your approximate coordinates for Call, goes to Apple Maps under Apple's own privacy terms. It goes from your phone to Apple and never through us. If you turn on Attach Location (off by default) and then open a bubble carrying one, the coordinates are sent to Apple to turn into a place name; that lookup happens on your phone's behalf and we never see the result. | — |
| Google (sign-in) | Sign in with Google, if you use it. | — |
If you tap a crisis helpline, your phone dials or opens a link. Bubbly does not tell anyone you did, and does not record it.
Until 18 September 2026 this section was the most important part of this document, and it said something uncomfortable. Bubbly used the free tier of the Gemini API, and on the free tier Google's own terms say that what you send may be used to improve their products and train their AI models, and that their staff may read it. The honest advice that followed was: do not put anything into Bubbly that you would mind a stranger at Google reading.
That is over. Bubbly does not send your words to Google, or to any AI company, at all. The thinking moved onto your phone — Apple's own model, running on the device — and the ability to send anything to Gemini was removed from the app rather than switched off. A check runs on every release build and refuses it if any route to Gemini exists in the code.
Two things are worth being precise about, because a privacy claim that is nearly true is worse than none:
Nothing here is a promise about anybody else's security, only about what is sent and to whom. Apple, Supabase, RevenueCat and Cloudflare are third parties operating under their own terms; what we can tell you plainly is what reaches them, which is what the table above does.
If Bubbly ever moves onto the paid tier, this section changes first and the app's consent screen changes with it — before the change takes effect, as §11 requires. It would not be quietly left as written.
We do not use your thoughts for marketing, profiling, or automated decisions that have a legal effect on you. We do not sell your consumer health data, and we do not share it except as described in §3.
California residents have rights under the CCPA/CPRA to know what personal information we hold, to delete it, to correct it, and to opt out of the sale or sharing of personal information — we do not sell or share your information with third parties for their own advertising, so there is nothing to opt out of on that front, but you can still exercise the other rights through §6. Sensitive personal information (which your thoughts likely qualify as) is used only to provide the app, not for anything else.
Washington's My Health My Data Act and Nevada's equivalent law give you specific rights over "consumer health data" — broadly, anything that reveals or lets someone infer something about your physical or mental health. You have the right to know whether we are collecting or sharing it, to access it, to have it deleted across all our systems, and to withdraw your consent at any time without losing access to the parts of Bubbly that do not depend on it. See §6.
Bubbly has two different ways to share something, and they work differently enough that they get their own headings.
If you create a share link, that bubble and everything inside it is copied to our server. Your username is stored alongside it, so whoever opens it can see who sent it.
Opening a shared bubble does not require an account. The link goes to a plain web page — anyone who has it can read that thought and everything filed inside it, with no sign-in and no app install needed. That page also offers to download the app, but reading the shared bubble itself never requires that.
Because reading the link no longer needs a sign-in, treat the link itself as the whole protection: anyone who has it can read the bubble, including anyone it gets forwarded, screenshotted, or leaked to.
#### If someone shares a bubble with you
You can read a shared bubble on the web page the link opens without an account. Saving it into your own galaxy in the app still requires signing in — that step collects your email address and account id, the same as for anyone else who signs in, and you are told this at the sign-in step itself, not only here.
The person who sent you the link cannot agree to that on your behalf. If you would rather not have an account, you can still read what they shared on the web page; just don't sign in to save it. Nothing about your account is shared back with them beyond the fact that the link was opened.
A Shared Bubble is different from the link above in a real way: it is not a one-time copy. Everyone in it can keep adding to it, and everyone in it sees what gets added, for as long as the bubble exists.
Signing in is required on both sides — the person who makes it, and everyone who joins it. Unlike the read-only link above, there is no sign-in-free web page for a Shared Bubble; opening the invite link and joining both happen inside the app, and both require an account.
What we store, with Supabase: the bubble's title; who owns it; each member's account id and when they joined (never their email or username — see "Who can see who's in it," below); and everything anyone adds to it — its words, any deadline, and whether it's been marked done. This is never copied onto your own device's local storage the way the rest of your galaxy is (§1) — it is fetched from our server each time you open the bubble, and only kept in the app's memory while you're looking at it.
What is not stored, or not shared. A voice recording used to add something to a Shared Bubble is transcribed the same way any recording is (§2, §3) but the audio file and any location tag stay on the device that made them — neither is copied into the shared bubble or seen by anyone else in it. Only the resulting text is shared.
Who can see who's in it. Anyone in a Shared Bubble can see how many other people are in it. The bubble's owner can additionally see, for each member, an anonymous entry — an account id and the date they joined, nothing else — and can remove a member from there. We do not show your email, username, or name to other members of a bubble you're in; this app does not otherwise have a way for one user to look another up, and Shared Bubbles does not change that.
Joining, leaving, and being removed.
Responsibility. The same as the link above: you are responsible for what you add to a Shared Bubble, including anything in it about another person — and now, because more than one person can add to the same space, that applies to everyone in it, not only whoever created it. Bubbly cannot see or moderate what gets added beyond what is described in this section.
Wherever you are, you have the right to see your data, get a copy of it, have it deleted, and withdraw consent at any time. We apply these rights to everybody, not only where a specific state's law requires it.
If you are unhappy with how we handle your data, tell us first — write to mindorb.app@gmail.com with "Data complaint" in the subject. We will respond within 45 days. Where reasonably necessary we may extend that once by a further 45 days, and we will tell you why.
If we say no, we will tell you why and how to appeal. To appeal, reply to that message with "Appeal" in the subject. We will decide the appeal within 45 days and explain the outcome in writing.
You can also complain to a regulator, whether or not you have come to us first.
You can have someone else make a request for you — a lawyer, a family member, anyone you authorise. Send us written permission signed by you, or a power of attorney, along with the request.
We will check that a request is really from you before acting on it, because a deletion request honoured for the wrong person is the same harm as a breach. Usually that means replying from the email address on the account, which is enough on its own. If we cannot be reasonably sure, we will say what else we need rather than refuse quietly — and if we still cannot be sure, we will refuse rather than guess, and tell you why.
We will not ask you to create an account in order to make a request.
You do not have to ask us for most of it:
For anything else — including a request for your data in a form we do not offer, or to correct something — write to mindorb.app@gmail.com. We will respond within 45 days, on the same terms and with the same appeal route as above. One request method, one appeal method, one response period, wherever you happen to be reading — see also the Washington Consumer Health Data Privacy Policy, which uses the identical process.
Two honest limits:
1. Export produces a file; there is currently no import. You can take your data out and read it, but you cannot load it back into Bubbly, and we cannot send it to another service on your behalf. 2. Deletion reaches our systems directly, and the AI provider only through them. When you ask us to delete, we delete from our systems, and where the law requires it we direct our processors and any other recipients to delete it too. Some information may be held for a limited period where required or permitted by law, contract, security or backup requirements. We are honest about the limit: we control our own copy completely, and we can only *instruct* a processor about theirs.
Washington and Nevada residents have specific additional rights about health-related information, set out in their own documents: the Washington Consumer Health Data Privacy Policy and the Nevada Consumer Health Data Privacy Policy.
Bubbly is not for anyone under 18, and we do not knowingly collect anything from under-18s. This is not a formality: the AI provider's own terms forbid making the service available to people under 18, and the app is built for adult reflection.
If you believe a child has been using Bubbly, write to mindorb.app@gmail.com and we will delete the account and its contents.
Bubbly is operated from the United States, and our AI provider and our infrastructure are US-based. If you are using Bubbly from within the United States, your data generally is not leaving the country.
Bubbly is a US service for US users at this time. It is not currently offered to people in the UK or EU. If that changes, this section needs a full rework with each provider's actual certification status checked and cited before Bubbly is offered there — not a claimed safeguard that isn't actually in place.
We use HTTPS everywhere, our database enforces row-level security so one account cannot read another's, and Bubbly has no password of its own to store — see §1.
What we will not claim: Bubbly is not end-to-end encrypted. Your thoughts sit on our server in a form we could read if we chose to. We have chosen not to build anything that does, and we would rather say so plainly than imply a protection that is not there.
If we discover that your data has been accessed by someone who should not have it, we will tell you without unreasonable delay, and in any event within 30 days of confirming it. That message will say what we know: what was taken, when, what we have done about it, and what you can do. We will tell you even where the law would not strictly require it — including when we are not certain, in which case we will say that too.
We will also notify the authorities the law requires us to, in the states and countries where affected people live.
We will not wait to have a complete picture before telling you. A first message that says "this is what we know so far" is more use to you than a tidy one three weeks later.
If what Bubbly collects or who it shares with changes, this page changes first, and the app will say so before the change takes effect.
Bubbly is a notebook. It is not therapy, not medical advice, and not a crisis service.
If you say something that sounds like you might be in danger, Bubbly offers you phone numbers. That is all it does — it does not contact anybody, it does not alert anyone, and nobody is watching. If you are in danger, call emergency services. See the Terms for more on this.