Bubbles Legal

Privacy Policy

Last updated: June 6, 2026

Bubbles is operated by Codevival. This Privacy Policy explains what information we collect, how we use it, and how we protect it when you use Bubbles on iOS, Android, web, and desktop.

1. Information We Collect

  • Account information: when you register with an email address and password, we collect your username, email address, and password (stored only as a secure hash). If you sign in with Google instead, we receive your name, email address, and profile picture from Google.
  • Profile content: information you add to your profile, including your display name, bio, and any images you upload.
  • Messages and shared content: group and direct messages are encrypted in transit (TLS) and encrypted at rest on our servers using strong encryption (AES-256). They are not end-to-end encrypted: because the encryption keys are held by our service rather than only on your device, our systems, and trained moderators acting on a report, can access message content when needed to operate the service, keep people safe, and meet legal obligations. We also process related metadata (such as which conversation a message belongs to and when it was sent) to deliver it. Other content you create (bubbles, activities, comments, and suggestions) is stored to operate the service.
  • Location data: precise or approximate location may be used while the app is in use to show nearby bubbles and users on the map and to help you set activity locations. When you create an activity or check in to one, we store its coordinates and the time of check-in.
  • Phone number: optional. We only store a phone number if you choose to add it to your account.
  • Usage and device data: app interactions, device identifiers, push notification tokens, and crash or performance data through connected services.
  • Data stored on your device: on the web and desktop apps, your sign-in session and preferences are stored in your browser's local storage so the app can function. This storage is essential to operating the service.

2. How We Use Information

  • To create, authenticate, and manage your account
  • To show relevant nearby bubbles, users, or activity context
  • To deliver messages, send push notifications, and provide product-related updates
  • To display and measure advertising within the app
  • To improve reliability, performance, and security
  • To communicate with you about support or service issues

3. Third-Party Services

Bubbles relies on third-party providers to operate important parts of the service.

  • Google Sign-In for optional authentication
  • Firebase (a Google service) for app infrastructure and push notifications
  • Google Maps and Google Places for maps, location display, and location search inside the app
  • Google AdMob for in-app advertising (see "Advertising" below)

4. Advertising

Bubbles shows advertising through Google AdMob. To serve and measure ads, AdMob may access your device's advertising identifier and limited device and usage information. You can reset or limit the use of your advertising identifier in your device settings. For more information, see Google's advertising policies.

5. Data Sharing

We do not sell personal data. Data may be shared only with the service providers listed above that help us operate the app, or when disclosure is required by law.

6. Data Retention

We retain account data (including profile information, content you create, and activity location and check-in records) while your account is active, unless a longer retention period is required for legal or operational reasons. You can request deletion or delete your account in-app, after which associated data is removed.

7. Permissions We Request

  • Location: to show your position on the map, set activity locations, and improve nearby context
  • Notifications: to alert you about messages, activity updates, and invitations
  • Camera or photo library: to upload profile images or shared content
  • Vibration: for notification feedback

8. Children's Privacy

Bubbles is not directed to children under 13. If we become aware that we have unintentionally collected personal information from a child under 13, we will work to delete it.

9. Security

We use reasonable technical and organizational measures to protect user data. Account passwords are stored only as secure hashes, and group and direct messages are encrypted in transit and at rest. No method of transmission or storage can be guaranteed to be fully secure.

10. Your Rights

  • Request access to the personal data we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal data
  • Withdraw consent where consent is the basis for processing

11. Changes to This Policy

We may update this Privacy Policy from time to time. When changes are material, we may notify users through the app or other appropriate channels.

12. Contact

For privacy-related questions or requests, contact contact@codevival.com.