Legal

Privacy Policy

Effective date: 2026-09-18 · Last updated: 2026-09-18

Bough is a private family app for capturing, organizing, and sharing family life across past, present, and future: photos, letters, certificates, audio, video, and celebrations, all tied to people in a private family tree shared only within your family.

  • Entity and data controller: MAABLAB LLC, a California limited liability company, Los Angeles, California ("Bough," "we," "us").
  • Privacy contact: privacy@withbough.com
  • Privacy laws we address: the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the EU General Data Protection Regulation and UK GDPR, US federal law including COPPA, and other US state privacy laws where they apply.

This policy explains what we collect, why, who we share it with, how long we keep it, and the choices you have. It applies to the Bough mobile app and this website.

The short version

  • Your family's memories, the photos, scans, letters, audio, video, captions, and the people in your tree, belong to you and your family. We store them so we can show them back to you and the family you invite. We do not sell them, we do not share them for advertising, and we do not use them to advertise to you.
  • We collect a small amount of account information so you can sign in, and content-free usage analytics so we can see where the app is confusing and fix it. Analytics are on by default and never contain your memory content. If you opt out, we keep measuring aggregate usage under an anonymous token rather than stopping (see section 1d).
  • Photos can carry a hidden location, where the photo was taken. By default Bough keeps that location so a memory can show where it happened, and resolves a coarse place name for it. You can turn location off for your own uploads, or remove it from a memory (see section 3).
  • Bough can suggest which person is in a photo using face grouping that runs entirely on your device. Those face measurements never leave your device and are never sent to us (see section 5). We do not run facial recognition on our servers.
  • We use a handful of trusted service providers for storage, email, error monitoring, and so on. They are listed in section 6.

1. Information we collect

a. Account information

When you create an account we collect your email address and the sign-in method you chose (Sign in with Apple, Sign in with Google, or an email magic link; we do not store passwords), plus your display name and an optional profile photo.

b. Family and tree content

People records in your tree (names, optional birth and death dates, a short bio, optional photos, relationships, pets, and whether a person is living, deceased, or not yet invited); memories you upload (photos, scans, letters, certificates, audio, video) with captions, titles, dates, and tags; comments, questions, and likes; and your family's structure (members, roles, invitations).

c. Photos, files, and embedded metadata

When you upload a photo or video, the file may contain embedded metadata. We read the original capture date to fill in the memory's date. We read and, by default, keep GPS coordinates if present, and resolve a coarse place name from them (see section 3). We normalize images, re-encode, and generate thumbnails and display sizes. Video and audio follow the same per-user location setting.

d. Usage and analytics

We collect content-free product-analytics events (for example, a screen was viewed, an invite was sent) carrying only counts, categories, booleans, and internal IDs, never your memory content, captions, names, or photos. Events are restricted by an allowlist so content and personal detail cannot enter analytics.

  • Always collected, anonymized on opt-out. Analytics are on by default and you are identified. If you opt out, your events are still used to measure aggregate patterns, but under a stable, non-reversible anonymous token, with identifying properties stripped and no link to your real identity. If the anonymizing key is unavailable, opted-out events are dropped rather than sent.
  • First-party only. We do not track you across other companies' apps or websites, and we do not use advertising identifiers, so Bough does not show the iOS App Tracking Transparency prompt.
  • Session replay. Mobile session replay is enabled and records a roughly 10% sample of sessions. It is fully masked: every text field and image is redacted, and console logs and network content are not captured, so it records screen structure, taps, and navigation, never a photo, a name, a caption, or an email. Opting out of analytics anonymizes the recording's attribution; it does not stop the sampled recording.

e. Diagnostics

We use error-monitoring and performance tools for crashes and bugs: crash reports, error messages, stack traces, performance traces, and structured logs. We scrub these of memory content and personal information, including signed links, storage keys, email addresses, and authentication tokens, before they reach our error-monitoring provider.

f. Billing

If you subscribe, the purchase is processed by Apple (or Google Play on Android, if offered). We do not receive or store your payment-card details. We receive your purchase and subscription status through RevenueCat.

g. Push notification tokens

If you enable notifications, we store a device push token so we can send content-free alerts. Push messages carry ID references and an actor's display name only, never memory content.

2. How we use your information, and our legal bases

We use your information to:

  • Run the app: store and show your family's tree and memories, sync across devices, and deliver invites and notifications.
  • Sign you in (Apple, Google, or magic link).
  • Run the media pipeline: normalize formats, generate thumbnails, transcode video, fill in dates, and resolve a place name from coordinates when kept.
  • Power search, including optional meaning-based search (see section 6).
  • Improve the product through content-free analytics, and find and fix bugs.
  • Manage subscriptions and storage quotas, and prevent abuse.
  • Communicate with you about your account and security, and, separately and only with your opt-in, marketing.

For users in the EEA and UK, our legal bases under the GDPR and UK GDPR are: performance of a contract (running the app, sign-in, the media pipeline, subscriptions); legitimate interests (product improvement through content-free analytics, security, and abuse prevention, balanced against your rights); consent where required (for example, marketing email); and legal obligation where the law requires. Where we rely on legitimate interests, you may object as described in section 10.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use your memory content to build advertising profiles.

3. Location data

Photos often embed the GPS location where they were taken. This can reveal sensitive places, including your home address, so we treat precise location as sensitive personal information.

  • By default, Bough keeps the location of your photos. When a photo carries GPS data, we store its precise coordinates on the memory.
  • You can turn location off for your account, so your own uploads are stripped, and you can remove the location from any memory. This setting affects only the memories you upload.
  • When location is kept, we also resolve a coarse place name (for example, city and state) from the coordinates through a reverse-geocoding provider, at a coarse zoom so the label is a place, not a street address. This sends the coordinate pair only, with no identity, to the provider.

California residents have the right to limit our use of sensitive personal information; the location controls above are how you exercise that limit, and you can also contact us at privacy@withbough.com.

4. On-device image understanding and face grouping

Two features analyze your photos on your device, so the analysis and its measurements stay on your device unless you act on the result.

  • Meaning-based photo search. Bough can understand what a photo shows (for example, a beach or a birthday cake) so you can search your own photos by what is in them. This runs entirely on your device. The photo and the analysis are not sent to any third party.
  • Face grouping to suggest a tag. Bough can group photos that appear to show the same person and suggest who they are, so you do not have to tag every photo by hand. To do this, your device computes numeric face measurements ("face prints") from your photos using your device's built-in vision features. These face measurements are used only to group faces and are stored only on your device. They are never uploaded to us, never stored on our servers, and never shared with any third party. The only thing we store on our servers is the person-to-photo tag you confirm, which is an ordinary tag, not a face measurement.

We do not run facial recognition on our servers, we do not identify you or anyone else from face data, and we do not use face data across families or for any purpose other than the on-device grouping described here. If you use your device's Face ID or Touch ID to lock the app, that is your device's own authentication and is handled by your device, not by us.

5. How we protect your data

  • The app's server is the only thing that talks to the database, and the database is never publicly exposed.
  • Access is checked on the server for every request. Your data is scoped to your family, with per-item privacy checks, and row-level security in the database as an extra layer.
  • Media is reachable only through short-lived signed links, never public bucket links.
  • Data is encrypted in transit and at rest, and secrets live in a managed store.
  • We use rate limiting, strict input validation, audit logging on sensitive actions, and dependency scanning.

No system is perfectly secure, but we build to a high bar and treat never losing your memories as a core promise, with automated backups and storage redundancy.

6. Service providers (sub-processors)

To run Bough we share limited data with the trusted providers below. Each is bound by its own terms and a data-processing agreement where required, and processes data only to provide its service to us. Except where noted, these providers are located in the United States.

ProviderWhat it doesWhat it receives
Backblaze B2 (Cloudflare R2 as fallback)Stores your uploaded media and generated thumbnailsYour uploaded files and derived media, reachable only through short-lived signed links
RailwayHosts our app and databaseAccount, tree, and memory metadata, not the media files themselves
ResendSends magic-link sign-in and family invitation emailsRecipient email address and the message
PostHogProduct analytics and fully-masked session replayContent-free events with opaque IDs (or an anonymous token on opt-out) and masked session recordings; no memory content
Sentry (with OpenTelemetry instrumentation)Crash reports, performance traces, and logsCrash and error reports scrubbed of content and personal information
Google (Gemini API)Generates text embeddings for optional meaning-based searchThe text you typed into your own memories (title, caption, structured fields, extracted text). No images, audio, video, or face data
RevenueCatManages subscriptions and entitlementsPurchase and subscription status and app-store identifiers; no card details
Expo PushDelivers push notifications through Apple (APNs) and Google (FCM)Device push tokens and content-free notification payloads
Apple App Store, Google PlayApp distribution, sign-in, and billingSign-in identifiers; billing handled entirely by the store
Reverse-geocoding provider (Nominatim / OpenStreetMap)Resolves a coarse place name from photo coordinates, only when you keep locationA coordinate pair, with no user identity
Redis (rate-limiting store)Abuse and rate-limit protectionShort-lived request counters keyed by an identifier; no memory content, and entries expire automatically

About meaning-based search and Google Gemini. Meaning-based search is optional and improves how well search finds things. To power it, only the text you already wrote into your memories (the title, caption, structured fields, and any text extracted from a document) is sent to Google's Gemini API to compute a numeric "meaning fingerprint" that we store to make search smarter. No images, audio, video, face data, or identity is sent to Google. If the feature is unavailable, search falls back to ordinary keyword search and nothing breaks.

7. Sharing within your family

A family is a private sharing boundary. By default, a memory is visible to your family only. You can mark items private. You may belong to more than one family, and each family's data is kept strictly separate. We do not disclose your personal information outside your family except to the service providers above, or where the law requires or permits (for example, to comply with legal process or to protect rights and safety).

Because family trees include relatives who have not joined, or who have passed away, you can add living relatives as records and upload their images. Any person can request removal of their record or images of themselves by emailing privacy@withbough.com, and we will act on reasonable requests. This route is available to people who are in a tree but are not Bough users.

8. Data retention

  • We keep your account, tree, and memory data for as long as your account and family are active.
  • In the app, removing a person or memory generally archives or re-attributes rather than permanently deletes. A family admin can permanently discard orphaned items.
  • When you delete your account, we de-link your account and handle your data as described in section 9.
  • Backups are kept for a limited window for disaster recovery and then rotated out. Analytics and diagnostic data are kept only as long as needed for the purposes in section 2.

9. Deleting your account, and communal content

You can delete your account in the app at any time (Me, then account settings), and you can export your data first (Me, then Export my data).

Bough is a shared family record, so content is communal. When you delete your account:

  • Your account is removed and de-linked from your contributions.
  • Memories you contributed remain with the family, because other members rely on them.
  • Your person node remains in the family tree, so the tree stays whole.

We disclose this clearly so the outcome is not a surprise. If you want content you uploaded erased rather than kept with the family, or you are a person in a tree who is not a user and want your record or images removed, email privacy@withbough.com and we will handle reasonable requests, subject to the rights of other family members and our legal obligations.

10. Your privacy rights

Depending on where you live, you have some or all of the rights below. To exercise any right, email privacy@withbough.com. We will verify your request against your account and respond within the time the law requires. We will not discriminate against you for exercising your rights.

Everyone

  • Export your data in the app (Me, then Export my data).
  • Delete your account in the app (see section 9).
  • Turn analytics identification off (opt-out anonymizes, per section 1d), and turn photo location off or remove it from a memory (section 3).
  • Opt out of marketing email at any time, separately from account and security email.

California residents (CCPA/CPRA)

You have the right to know and access the personal information we collect, the right to correct it, the right to delete it, the right to opt out of sale or sharing for cross-context behavioral advertising, and the right to limit the use of sensitive personal information.

  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the past 12 months. Because we do not sell or share, there is no "Do Not Sell or Share" action to take, but you may still contact us to confirm.
  • Sensitive personal information. The precise location in your photos is sensitive personal information. We use it only to run the app (to show where a memory happened), never to infer characteristics about you. You can limit this at any time using the location controls in section 3.
  • Categories collected. Identifiers (email, name, account and device identifiers); commercial information (subscription status); internet or app activity (content-free usage analytics); geolocation (precise location from photos, kept by default); audio, electronic, and visual information (your uploaded photos, audio, and video, and the content you write); and the content and family-tree information you create. We collect these to provide and improve the app, as described in section 2, and disclose them only to the service providers in section 6.
  • Authorized agents. You may use an authorized agent to make a request; we will ask for proof of authorization and may verify your identity directly.

See "Your California privacy rights" below for a consolidated summary.

EEA and UK residents (GDPR / UK GDPR)

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent where processing is based on consent. Where we rely on legitimate interests, you may object at any time. You also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office). Our legal bases are set out in section 2, and international transfers are covered in section 12.

11. Your California privacy rights

This section is a consolidated summary for California residents under the CCPA/CPRA. In the past 12 months we have collected the categories of personal information listed in section 10, for the business purposes in section 2, and disclosed them only to the service providers in section 6. We have not sold personal information and have not shared it for cross-context behavioral advertising. California residents may exercise the rights to know, access, correct, delete, opt out of sale or sharing, and limit the use of sensitive personal information, without discrimination, and may use an authorized agent. To exercise a right, email privacy@withbough.com.

12. International data transfers

We are based in the United States, and our service providers (section 6) are primarily in the United States, so if you use Bough from the EEA, the UK, or elsewhere, your data will be transferred to and processed in the United States and other countries. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses for EEA transfers, and the UK International Data Transfer Addendum (or the UK Addendum to the SCCs) for UK transfers, together with any additional measures required. You can ask us for more information about these safeguards at privacy@withbough.com.

13. Children's data

Bough accounts are for adults and older teenagers. Account creation, sign-in, and invitations require you to be at least 13 years old in the United States, and at least 16 in the EEA and the UK (or older where local law sets a higher age). There are no accounts, logins, or invitations for anyone under the applicable age.

We do not knowingly collect personal information directly from children under 13 in a way that would trigger COPPA, because children cannot create or use accounts. Family trees do include children as records, for example a child in a family photo added by an adult family member. The removal route in section 7 applies: a parent or guardian can email privacy@withbough.com to request removal of a child's record or images, and we will act on reasonable requests. If you believe a child under the applicable age has created an account, contact us and we will close it and delete the associated personal information.

14. Apple App Store privacy

Our disclosures here are consistent with the App Privacy information we provide in the Apple App Store. In particular, we declare that we collect precise location (kept by default, with the controls in section 3), your photos and other content, contact information, usage data including a masked session-replay sample, diagnostics, and purchase status, and that none of it is used to track you across other companies' apps or websites. You can delete your account, and the personal information tied to it, from within the app, as described in section 9.

15. Changes to this policy

We may update this policy. We will post the new version with an updated date and, for material changes, notify you in the app or by email.

16. Contact

Privacy questions and rights requests: privacy@withbough.com. General support: support@withbough.com. Postal mail: MAABLAB LLC, Los Angeles, California.

Back to home