Privacy Policy
Effective August 31, 2026
This Privacy Policy explains how Bredbox ("Bredbox", "we", "us", or "our") collects, uses, and shares information when you visit our website or use any of our applications, including our iOS and Android mobile applications, browser extensions, or related services (collectively, the "Bredbox Services"). We are building a link saving and reading tool focused on simplicity, reliability, and respecting user privacy.
We want you to clearly understand what data we collect, why we collect it, and the choices you have. If you do not agree with this policy, you should not use the Bredbox Services.
1. User Accounts & Information You Provide
You may browse the public portions of Bredbox without registering. Creating an account is required to save links or access personalized features. You can create an account with an email address and password, or through a third‑party sign‑in provider — currently Apple, Google, GitHub, and Microsoft. When you use a sign‑in provider we store the email address, the provider‑supplied name (used as your display name), the provider username/handle, and the avatar URL. Sign in with Apple lets you hide your real email address; if you choose to, we receive and store only the private relay address Apple issues, and we treat it the same way we treat any other account email. If a provider omits a name we do not generate a fallback at this time. No other profile fields are collected.
Outside of billing-related checkout flows, we do not collect postal addresses, phone numbers, government identifiers, or full payment card numbers. If you start, resume, change, or cancel a paid subscription, checkout and subscription management are handled by Lemon Squeezy, our merchant of record. In that context, Lemon Squeezy may collect information such as your name, email address, billing address, tax ID, payment method details, transaction information, and subscription-management details directly from you under its own Privacy Policy and Terms . We receive limited billing metadata from Lemon Squeezy, such as order or subscription identifiers, plan selection, billing status, renewal dates, invoice availability, and partial payment-method details needed to provide paid features and support. We do not store full payment card numbers on Bredbox servers.
Account deletion. When you request to delete your account through your account settings, we will first send you a confirmation email. The deletion process will only begin after you click the link in that email to provide final authenticated confirmation. Once confirmed, we fully purge your email (no suppression list retained for that address) subject to brief backup cycling and security/legal obligations described elsewhere. If you have an active paid subscription at the time of final confirmation, we cancel that subscription as part of the deletion workflow before completing the account purge. A final notification email will be sent after the privacy worker completes the deletion.
Clear saved data. You can clear all saved items and organizational data (tags, archives, etc.) from your account at any time without deleting the account itself. This also clears your selected recommendation topics and your hidden recommendations; your personalization on-or-off choice is left as you set it. This is available through your account settings. Like account deletion, requesting this action will first send a confirmation email, and the data clearing process only begins after you provide final authenticated confirmation via the emailed link. The actual clearing is processed asynchronously, and a final notification email will be sent to you when the privacy worker successfully completes the operation.
2. Information Collected When Using Bredbox
When you save a URL, we store the canonical URL plus extracted metadata: title, description/summary, site name, favicon, normalized content attributes, full article text (parsed for reader mode), estimated reading time, language detection result, and a content hash used for deduplication. We also record the timestamp of save and any organizational data you apply.
If you use a Bredbox browser extension, the extension reads the current tab's page title and full HTML content only when you click the extension button to save that page. The HTML is transmitted to Bredbox servers for processing, metadata extraction, and storage to provide reader mode and search functionality. The extension may open a browser-managed sign-in window to complete OAuth authorization, and it may display browser notifications to tell you whether a save succeeded, failed, or requires you to sign in again.
The extension also reads the URL of the active tab when you switch tabs or navigate, without any click, and sends it to Bredbox to check whether that page is already in your library so the toolbar icon can show a checkmark. This check is read-only: it creates no saved item and changes nothing in your account. It applies only to the tab you are currently viewing, never to tabs in the background, and the extension does not record a history of the pages you visit. Page titles and full HTML content are never read for these checks — those are read only when you click to save.
For browser-extension users, the browsing activity transmitted to Bredbox is the URL of the active tab, sent either to check saved status or to complete a save you initiated, together with the page title and full HTML content needed for that save. We do not use page URLs, titles, or saved content for advertising, sale to data brokers, or unrelated profiling.
Saved-status checks are not written to our database, but the request that carries them does appear in our infrastructure provider's request logs, which record the full request URL including the page URL being checked. Those logs are retained on a rolling 7‑day window and are used only for operating and debugging the service. See 6. Data Retention.
Mobile app. Bredbox is available as a native iOS and Android application. When you use the mobile app:
- Authentication: Sign-in uses OAuth through an in-app browser
(expo-web-browser). The app receives the same profile information as
the website (email, first/last name, avatar) and stores OAuth access tokens,
refresh tokens, and token expiration in the platform's secure keychain/keystore
(expo-secure-store on iOS/Android; localStorage when the app is run on
web). These tokens are used only to authenticate API requests. The OAuth callback
uses the custom URL scheme
bredbox://oauth-callback. - Adding saves: You can paste a URL manually or use your device's native share sheet. When you share a URL to Bredbox from another app, the share intent (handled by expo-share-intent) receives only the shared URL or text; Bredbox does not access your clipboard or other apps' content outside of the share action you initiate.
- Reader view: Saved content is rendered in an in-app WebView (react-native-webview). When a readable copy is available, Bredbox displays our extracted content. When the original site is displayed, the WebView may load third-party resources from that site under its policies.
- Reading progress: While you read an article, the app tracks
your scroll position as a DOM location (node path and text offset) and a progress
ratio. This data is sent to our servers and associated with the save so it can be
restored when you reopen the article or use another signed-in device. Progress
data is labeled with the source client (
mobile) and a client timestamp. - Highlights: You can create and remove highlights in the mobile reader by selecting text in an article. A highlight stores the selected text and its position within the article, is associated with that save, and syncs to your account so it appears on every device you sign in from.
- Local caching: The saves list and associated metadata are cached locally in memory for up to one hour to improve responsiveness. This cache is cleared when you log out or uninstall the app.
- External links: Tapping a link to the original source opens it in an in-app browser (expo-web-browser) unless you are running the web build, in which case it opens in a new tab.
- Sharing out: You can share a saved URL through the native OS share sheet; this passes the URL and title to the OS and any app you select.
We do not use the mobile app to collect advertising identifiers, precise geolocation, contacts, photos, or device telemetry. The app does not run in the background to monitor your browsing or location.
Organizational features: tags, collections, and highlights are all available. Highlights store the selected text segments and associated metadata (e.g., position within the article). Collections group saved items under user-defined labels and support optional notes and manual ordering.
Usage & state events we currently store: save (create), delete, archive, favorite, trash, restore, and tag edits (add/remove). When you read an article in the mobile app, we also store reading progress (scroll location) so it can be restored across devices. Additional sync events may be added if future features require them.
External requests during content processing: we fetch the page you save directly from the origin site. We do not sell saved URLs or saved content, and we do not send them to advertising networks, data brokers, or third‑party enrichment services. Article text is processed by machine learning models hosted by Cloudflare, our infrastructure provider, in order to classify each article into a topic and to generate the numeric embedding used for search and recommendations. That inference runs on Cloudflare's own network rather than being forwarded to the organizations that authored the models, and Cloudflare states that it does not use content submitted to Workers AI to train any AI model or to improve Cloudflare or third‑party services. The only other ancillary third‑party requests related to account access and saved items are loading the sign‑in provider avatar image when rendering your profile/avatar in the UI and, when you use a browser extension, sending authentication requests to Bredbox's OAuth endpoints through the browser's identity flow.
Use of extracted content: the full text and derived metadata (reading time, language, content hash) are used to display a reader-friendly version to you and to support internal relevance ranking, trending and popularity aggregation (e.g., most-saved domains or frequently accessed items in aggregate). Aggregated outputs do not expose the underlying personal data or individual reading behavior.
We may log basic technical information: browser type, device type, operating system, preferred language, approximate time zone, and IP address at time of request in short‑term server logs for security and abuse prevention. These logs are retained for 30 days and then deleted or irreversibly aggregated.
Failed fetch diagnostics (e.g., HTTP status codes, timeout indicators) are tracked only in aggregate operational logs and are not stored as a per-user history beyond the 30‑day security log window.
We do not collect mobile advertising identifiers or precise geolocation. We do not perform behavioral ad tracking. If this changes, we will update this policy before enabling such features.
3. Cookies, Browser Storage & Extensions
We use essential Supabase authentication cookies (httpOnly, first‑party) to keep you signed in and protect your account. These persist only while your session remains active (renewed automatically when you interact, subject to provider defaults). On the website, we do not currently store any user preferences (theme, dismissals, feature flags) in local storage or additional cookies. We do not set third‑party advertising or social media tracking cookies, and we do not use separate CSRF or additional security cookies beyond what Supabase sets.
Our browser extensions separately use the browser's extension storage to keep the extension signed in and secure. This local extension storage may contain an OAuth access token, refresh token, temporary PKCE/OAuth state, and short-lived coordination data used to prevent duplicate token refreshes. This information is stored locally in your browser profile, is used only to authenticate extension requests to Bredbox, and is removed when cleared by the extension, your browser, or when you uninstall the extension.
The extensions additionally keep a saved-status cache in the browser's session storage. It holds the URLs of pages checked or saved during the current browser session, each with a saved or not-saved result, so the toolbar icon does not need to ask Bredbox again for a page you have already visited. This cache exists only in your browser, is never transmitted anywhere, and is discarded when you close the browser.
The Bredbox mobile app stores OAuth tokens and related credentials in the operating system's secure keychain/keystore (via expo-secure-store) on iOS and Android. In the web build of the app, the same values are stored in the browser's localStorage. These values are used only to keep you signed in and are removed when you log out or uninstall the app. The mobile app does not use third-party advertising or analytics SDKs, and it does not rely on mobile advertising identifiers.
We use Plausible Analytics to collect aggregate, anonymous website usage statistics (e.g., page views, referrer sources, browser type) on the bredbox.app website only. Plausible is cookieless and does not use browser cookies, local storage, or cross-site tracking. It does not collect or store any personally identifiable information, and the data it captures cannot be used to identify individual visitors. We do not pass saved content, URLs you have saved, or account-level identifiers to Plausible.
4. How We Use Information
- Provide, maintain, and improve the Bredbox Services.
- Render saved content metadata and facilitate search, filtering, and organization.
- Sync your saves across browsers or devices you sign in from.
- Detect abuse, spam, fraud, or security threats.
- Communicate service updates, onboarding guidance, or policy notices.
- Plan new features using aggregated, de‑identified usage metrics.
We do not sell your personal information. We do not use your saved content to build advertising profiles.
Personalized recommendations. Bredbox provides a Discover section and a personalized “For You” feed, alongside aggregate trending and popularity insights (e.g., frequently saved domains). Two signals produce the personalized feed. First, the topics you select under Settings → Interests (up to five) are matched against the topic our classifier assigns to each article. Second, we compute a “reader profile” by averaging the numeric embeddings of up to your 50 most recently saved articles, and rank candidate articles by similarity to that profile. At least three eligible saved articles are needed before the reader profile is built at all. Selecting no topics leaves the second signal active, so recommendations are still drawn from what you have saved.
Articles you hide are recorded so they are not shown to you again. Saves marked private, and articles from domains on our adult‑content deny list, are excluded from the reader profile and are never used to generate recommendations. We do not train external machine learning models on your saved content, we do not use recommendation signals for advertising or share them with advertisers, and we do not manually repurpose your saved items for unrelated product testing beyond aggregated, de‑identified analysis.
We do not allow humans to review your saved content, current page URLs, page titles, or authentication data except when: (1) you ask for support that requires review of specific data, (2) review is necessary to investigate abuse, fraud, or security incidents, (3) review is required by law, or (4) the information has been aggregated and de‑identified for internal operational analysis.
For the Chrome and Microsoft Edge extensions, our handling of extension user data is limited to providing and improving each extension's single purpose: saving the page you choose to Bredbox and showing whether the page you are viewing is already saved there. The Bredbox Chrome extension's use of collected information is intended to comply with the Chrome Web Store User Data Policy , including its Limited Use requirements. The Bredbox Edge extension uses the same categories of data for the same limited purpose and does not use extension-collected data for advertising, sale to data brokers, or unrelated profiling.
Your controls over personalization. Settings → Interests has a single switch that turns personalized recommendations off. While it is off, Bredbox does not use your selected topics or your saved library to generate recommendations, the For You section is removed from your home page, and the For You page is no longer available.
Turning personalization off deletes nothing. Your selected topics and your hidden recommendations are kept and simply go unused, and turning it back on resumes recommendations from those same selections — there is no second setup step. You can also change or clear your topics at any time under Settings → Interests, and you can hide any individual recommended article, whether personalization is on or off. Deleting a save removes it from your reader profile the next time recommendations are generated.
Because this control stops processing rather than erasing data, it is not a deletion request. If you want your information removed, use Clear saved data or Delete account in your account settings, both described in 1. User Accounts & Information You Provide.
5. When We Share Information
We share personal information only in these situations:
- Service providers (current):
- Supabase – hosting, database, authentication, and object storage (data residency per chosen Supabase region).
- Cloudflare – DNS, edge network, edge functions/workers used for performance and secure content delivery, and hosted machine learning inference used to classify saved articles by topic and generate content embeddings.
- Upstash – managed Redis used to cache your saves, tags, highlights, and recommendation candidates for performance. Cached entries are scoped to your account, expire automatically, and are purged when you clear your data or delete your account.
- Kit – mailing list management for account and product email.
- Cloudflare Turnstile – bot protection on the public sign‑up form. Turnstile receives your IP address and a challenge token; it does not receive your email address, password, or any saved content.
- Resend – transactional email delivery (e.g., account notices).
- Plausible Analytics – cookieless, privacy-respecting aggregate page-view analytics on bredbox.app. No personal data or saved content is sent to Plausible.
- Payment and subscription provider: Lemon Squeezy acts as our merchant of record for checkout, payment processing, subscription billing, tax collection/remittance, chargebacks, and refund processing. When you make a purchase or manage billing, Lemon Squeezy may collect and process billing contact information, billing address, tax ID, payment method details, order details, subscription details, and invoice data. We receive limited transaction and subscription metadata from Lemon Squeezy, such as order and subscription IDs, plan/variant purchased, billing status, renewal dates, invoice availability, and partial payment method details needed to provide paid features, account support, accounting, fraud prevention, and recordkeeping.
- User-directed sharing: We do not currently offer a feature to publicly share saved content or make user profiles public. If we add optional sharing in the future, it will be opt‑in and documented here before launch.
- Legal and safety: To comply with law, enforce terms, or protect rights, property, or safety.
- Business transfer: In connection with a merger, acquisition, or asset sale, subject to continued protection obligations.
- Aggregate / de‑identified data: We may publish non-identifying statistics (e.g., most-saved domains) that cannot reasonably identify an individual.
We do not provide bulk access to saved content to advertisers or data brokers.
When you leave Bredbox for a Lemon Squeezy-hosted checkout page or customer portal, Lemon Squeezy processes information as a separate service provider and merchant of record for that billing activity. Those interactions are governed by Lemon Squeezy's own policies in addition to this one.
6. Data Retention
We retain account data while your account is active. When you delete a saved item it is removed from the primary datastore immediately; only point‑in‑time encrypted backups may still contain historical copies until those backups expire.
If your trial expires or a paid subscription ends without another active entitlement, your account may move into a read-only state. During read-only, you can still access and export your saved data, but write features stay disabled. Unless you resubscribe or delete the account sooner, read-only accounts are scheduled for deletion after 90 days.
Request logs: our infrastructure provider records the URL of each request made to the Bredbox API, including the browser extension's saved-status checks and the page URL each one carries. These logs are retained on a rolling 7‑day window, after which they are automatically purged, and are used only to operate, monitor, and debug the service. They are not used to build a profile of the pages you visit.
Caches: to keep the apps responsive, parts of your library are cached in a managed Redis service (Upstash) under keys scoped to your account. This covers recently listed saves and their metadata, your tags, your highlights, and the ranked list of candidate articles behind your Discover and recommendation feeds. Cached saves and highlights expire automatically after 24 hours, per‑tag lists after 7 days, and recommendation and Discover candidates after 12 hours. The cache is refreshed from the primary database and holds no data that is not already stored there. When you clear your saved data or delete your account, your cached entries are purged as part of that job, before the account itself is removed.
Backups: database and object storage backups are encrypted at rest and retained on a rolling 7‑day window, after which they are automatically purged. We do not create separate long‑term archives.
Account deletion: when you initiate and confirm your deletion we queue your personal data and all saves for purge and complete the live data removal within 7 days, except where a longer period is required by law or for an active fraud/security investigation. After live deletion, only encrypted backup replicas (within the same 7‑day backup window) may still contain residual data until they age out; we do not otherwise retain hashes or anonymized references to your email once backups have cycled.
Operational security logs (described earlier) follow their own 30‑day retention and then are deleted or de‑identified; these logs do not retain full saved content.
7. International Transfers
We currently host primary application infrastructure (database, authentication, object storage) in us-east-1 via Supabase. Object storage resides in the same region, and the Upstash Redis cache described in 6. Data Retention is also hosted in us-east-1. By using the service, your information may be transferred to and processed in the United States (and in any other country where our service providers operate infrastructure).
Cloudflare’s global edge network caches static assets (JavaScript, CSS, images) and may transiently cache certain API responses that can include saved item metadata or minimal profile fields to improve latency. Edge cache entries are short‑lived and governed by standard cache controls; we do not intentionally push full raw saved article text into edge cache beyond what is required for normal HTTP responses you request.
For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses (and UK addendum where applicable) incorporated in our providers’ Data Processing Addenda (e.g., Supabase, Cloudflare, Upstash, Resend, Kit). Where provider participation in additional adequacy frameworks (such as the EU‑US Data Privacy Framework) is unknown or variable, we default to the SCCs plus technical safeguards (encryption in transit and at rest, access controls, least privilege).
We are evaluating offering an EU data residency option in the future but have not yet committed to a timeline. This section will be updated if regional hosting choices change.
8. Security
We apply reasonable technical and organizational safeguards: encrypted transport (HTTPS), provider‑managed encryption at rest for all primary data stores (Supabase database and object storage), enforced Row Level Security (RLS) policies on user data tables, and strict access limitation (a single administrative account with least‑privilege credentials). No application‑level (field‑level) encryption is currently layered on top of provider encryption.
Production access is restricted to one admin; credentials are stored securely and rotated as needed. RLS ensures that queries executed through the standard application context are automatically scoped to the authenticated user.
Vulnerability management: we track upstream dependency advisories informally and apply urgent security updates as they become available, but we have not yet implemented a formal periodic scan or SLA (target practice will be to patch high‑severity issues promptly once detected). This section will be updated as our process matures.
No system is perfectly secure; we cannot guarantee absolute protection. If we become aware of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
9. Phishing & Account Safety
We will not request your password or authentication codes via unsolicited email. Always verify the domain before entering credentials. Report suspicious messages to the contact email below.
10. Your Choices & Controls
- Billing management: If you have a paid subscription, payment methods, invoices, and cancellation are managed through the hosted Lemon Squeezy billing flow linked from your billing settings.
- Access & export: You can export your saved links and associated metadata (including titles, tags, and collection data) at any time through your account settings. Exports are provided in portable, open formats (JSON or CSV) for easy import into other applications or for personal backup.
- Update: Edit account profile details from settings.
- Delete items: Remove individual saves at any time.
- Clear data: Clear all your saved items and organizational data (tags, archives, etc.) at any time through your account settings. Your initial request sends a confirmation email, the clearing process starts only after final authenticated confirmation, and you will receive a completion email after the privacy worker finishes.
- Account deletion: Delete your account and all associated data through your account settings. Your initial request sends a confirmation email, deletion starts only after final authenticated confirmation, and the irreversible removal is completed within 7 days. You will receive a completion email after the privacy worker finishes.
- Email preferences: A single unsubscribe link is provided in any non‑essential email. Critical service or legal notices may still be sent.
- Do Not Track: We do not currently respond to DNT signals beyond limiting tracking already described (no third-party ads).
- Browser extension controls: You can remove a Bredbox browser extension at any time and manage extension permissions and stored extension data through your browser's extension settings.
- Mobile app controls: You can log out from the mobile app's settings screen, which clears stored tokens from the device. You can also remove the app from your device, which deletes locally cached data and stored credentials. Account deletion, data export, and other privacy controls (such as clearing all saved data) are currently managed through the Bredbox website at Settings and are described elsewhere in this Policy.
11. Children
Bredbox is not directed to children under 13 and we do not knowingly collect personal information from them. If you are a parent or legal guardian and believe a child under 13 has provided us personal data, contact us and we will delete the information. We honor verified parental/guardian deletion requests.
We do not perform active age verification beyond this policy; if we become aware that we have collected personal information from a child under 13, we will take steps to remove it promptly.
12. Changes to this Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. If changes are material, we will notify active account holders via email before the revised policy takes effect (no fixed minimum lead time, but prior to the effective date). Continued use after the effective date constitutes acceptance of the revised policy.
We will maintain an accessible archive or changelog of prior versions so you can see how the Policy has evolved over time.
13. Contact Us
Questions or requests regarding this policy may be sent to: support@humanwhocodes.com or by mail to:
Human Who Codes LLC230 Independence Way STE 1 PMB 1094
Danvers, MA 01923
USA
We respond to privacy inquiries within a reasonable timeframe consistent with applicable laws. We do not currently appoint a Data Protection Officer or EU/UK representative; this section will be updated if that changes.
This document is provided for transparency while the product is in early access and may evolve prior to public launch.