Privacy Policy for Bound
Last updated: 7 October 2026
Privacy at a glance
Bound is a voluntary accountability app. I designed it to provide app and website limits without creating a detailed record of how you use your device.
- Bound does not track your location.
- Bound does not use advertising, cross-app tracking, or third-party analytics.
- Bound does not sell your personal data.
- Detailed Screen Time activity and Apple's opaque app and website tokens stay on your device.
- A trusted person only sees the information needed to manage the apps, websites, limits, and requests that you choose to share through Bound.
- You can delete your Bound account and its associated application data from within the app.
The sections below explain the processing in detail.
1. Controller
I, Chen Yang Diep, independently design, develop, and operate Bound. I am the controller responsible for the processing of personal data through Bound:
Chen Yang Diep<br> Drechslerstr. 14<br> 41199 Mönchengladbach<br> Germany<br> Email: diepchenyang@icloud.com
2. Scope
This Privacy Policy applies to the Bound iOS app, its associated backend services, invitation links, and the Bound website.
Bound is intended for people aged 16 or older. You must confirm during onboarding that you are at least 16 before using Bound. If you believe that a person under 16 has provided personal data to Bound, contact me so that I can investigate and delete the data where appropriate.
3. Data processed by the Bound app
3.1 Account and authentication data
Bound uses Sign in with Apple. When you create or access an account, I process:
- the unique account identifier supplied by Apple;
- your email address or Apple private relay address, if Apple supplies one;
- your name, if you choose to share it through Apple or enter it in Bound;
- authentication tokens, session information, and account timestamps; and
- technical authentication logs, which may include your IP address, device or client information, and the time and result of an authentication event.
Apple does not provide your Apple Account password to Bound.
I process these data to create, authenticate, secure, and delete your account. The legal basis is Article 6(1)(b) GDPR. Security and abuse-prevention logs are also processed on the basis of my legitimate interest in operating a secure and reliable service under Article 6(1)(f) GDPR.
3.2 Profile and onboarding data
I store your display name, your selected starting area in the app, whether you completed onboarding, and related timestamps. I use these data to configure and display your account. The legal basis is Article 6(1)(b) GDPR.
3.3 Invitations and trusted relationships
To connect you with another Bound user, I process:
- account and relationship identifiers;
- whether a connected person is the primary trusted person;
- an invitation token stored only as a cryptographic hash;
- invitation status; and
- creation, acceptance, revocation, and expiry timestamps.
The person opening an invitation can see the inviting user's display name. Once connected, the participants can see each other's display names and the relationship information needed to use Bound. The legal basis is Article 6(1)(b) GDPR.
3.4 App and website selections and limits
When you publish an app or website selection to Bound, the backend stores:
- the name assigned to the selected app or website;
- whether the selection represents an app or a website;
- whether the selection and its limit are active;
- the daily limit in minutes;
- which connected account set the limit; and
- creation and update timestamps.
Apple's opaque ApplicationToken and WebDomainToken values are stored only in the app's protected local app-group storage. They are not uploaded to the Bound backend. Bound also does not upload your complete list of installed apps, the websites you visit, your exact time spent in an app, or a detailed Screen Time history.
The backend data allow the selected trusted person to identify the selection and manage the requested limit. The legal basis is Article 6(1)(b) GDPR.
3.5 Extra-time requests
For an extra-time request, I process the selected app or website, requested and approved minutes, an optional reason, the sender and recipient, the decision and status, and relevant timestamps. The connected participants can view the request information necessary to make and communicate the decision. The legal basis is Article 6(1)(b) GDPR.
3.6 View protection
If you enable view protection, I process a random device identifier, the device label you provide, the protected areas, a cryptographic hash of the six-digit protection code, failed verification attempts, temporary lockout information, reset requests, decisions, and timestamps.
The protection code itself is not stored in readable form. The data are used to enforce the protection setting, prevent repeated guessing attempts, and allow a trusted person to decide a reset request. The legal basis is Article 6(1)(b) GDPR. Protection against misuse is also my legitimate interest under Article 6(1)(f) GDPR.
3.7 NFC lock
NFC tag configuration, the hashed NFC secret, selected Apple tokens, the active lock state, and the last scan time are stored locally on your device. The NFC tag contains a Bound URL with a random station identifier and secret.
If you send an emergency unlock request, the backend processes random device and station identifiers, the sender and trusted recipient, the request status, decision, and timestamps. The NFC secret itself is not sent as part of an unlock request. The legal basis is Article 6(1)(b) GDPR.
3.8 Push notifications
If you allow notifications, I process the Apple Push Notification service (APNs) device token, app bundle identifier, development or production environment, activation status, and technical delivery information such as attempt count, status, and error code.
Notification payloads contain an event type and a random request identifier so that the app can open or refresh the relevant area. Bound sends these data to Apple to deliver the notification. The legal basis is Article 6(1)(b) GDPR. You can disable notifications in iOS Settings. After deactivation, the token is kept for a limited period as described below and is no longer used for new delivery.
3.9 Local Screen Time processing
Screen Time authorization, monitoring, and shielding are performed using Apple's Family Controls, Device Activity, and Managed Settings frameworks. The following information remains locally on the device:
- opaque app and website tokens selected through Apple's system picker;
- the local limit and shield configuration;
- whether a configured threshold was reached;
- local extra-time allowance state; and
- local NFC lock configuration.
Bound uses these data to apply the limits you configure. Bound does not create or upload a chronological history of your app or website activity.
4. Data processed through the website
The Bound website is a static website and does not currently use analytics, advertising technology, tracking pixels, or non-essential cookies. Bound does not create its own visitor profile. The hosting provider may use strictly necessary security mechanisms where required to protect the website.
When the website is requested, the hosting and content-delivery provider must process technical connection data such as the IP address, date and time, requested URL, referrer where supplied, browser or user-agent information, and security information. This processing is necessary to deliver and protect the website and is based on my legitimate interest in providing a secure and reliable website under Article 6(1)(f) GDPR.
The hosting provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States. Cloudflare may process connection data in its global network. Transfers outside the EEA are protected as described in section 8.
5. Contact by email
If you contact me, I process your email address, message, attachments, and the information required to answer the request. The legal basis is Article 6(1)(b) GDPR where the message concerns your use of Bound or steps before using it, and otherwise my legitimate interest in answering enquiries under Article 6(1)(f) GDPR.
The contact mailbox is provided through Apple iCloud Mail. Correspondence is deleted when the matter has been resolved and the message is no longer required, unless a longer period is necessary to establish, exercise, or defend legal claims or to meet a legal obligation.
6. Information visible to trusted people
A connected trusted person may see:
- your display name;
- the names and types of the apps or websites you explicitly publish in Bound;
- the limits associated with those selections;
- extra-time, protection-reset, or NFC-unlock requests addressed to them; and
- the status and decision information needed for those features.
Trusted people do not receive your email address, Apple Account identifier, opaque Apple Screen Time tokens, location, complete installed-app list, exact time spent in apps, browsing history, or a detailed activity profile from Bound.
Only connect with a person you trust. Ending a relationship removes their ongoing access to relationship-protected information, although request records already associated with an account remain subject to the retention periods in section 9.
7. Service providers and recipients
I disclose personal data only where necessary to provide Bound, where you direct me to share information with a connected person, or where disclosure is required by law.
Supabase
Supabase Pte. Ltd. provides authentication, the PostgreSQL database, realtime updates, and server-side functions. Bound's primary Supabase database is hosted in the eu-central-1 region in Frankfurt, Germany. Supabase acts as a processor on my behalf and may use subprocessors, including infrastructure providers such as Amazon Web Services. Further information is available in Supabase's privacy information and Data Processing Addendum.
Apple
Apple provides Sign in with Apple, APNs, iCloud Mail for the contact address, and the iOS Screen Time and NFC frameworks. For users in the EEA, the relevant Apple entity is generally Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple's own processing is governed by Apple's Privacy Policy and its Sign in with Apple privacy information.
Website hosting
Cloudflare, Inc. provides website hosting, content delivery, and security through Cloudflare Pages. Cloudflare acts as a processor for website connection data where applicable. Further information is available in Cloudflare's Privacy Policy and Data Processing Addendum.
I do not disclose personal data to data brokers or advertising networks, and I do not sell personal data.
8. International data transfers
Although Bound's primary database is located in Frankfurt, some providers and their subprocessors operate internationally. This may involve processing in countries outside the European Economic Area.
Where required, transfers are protected by an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary technical and organisational safeguards. Supabase's Data Processing Addendum includes the Standard Contractual Clauses for covered transfers. Apple states that its international transfers of EEA personal data are governed by Standard Contractual Clauses. Cloudflare's Data Processing Addendum and Standard Contractual Clauses apply to restricted transfers.
You may contact me if you would like more information about the safeguards applicable to a particular transfer.
9. Retention and deletion
I retain personal data only for as long as it is required for the relevant purpose:
- account and profile data are retained while the account exists;
- relationship records are deleted when the relationship is ended or an associated account is deleted;
- app-selection and limit records, including inactive records required for reauthorization and recovery, are retained until the account is deleted;
- invitation metadata is deleted 30 days after acceptance, revocation, or expiry;
- extra-time requests are deleted 90 days after they are no longer active;
- view-protection reset requests are deleted 90 days after they are no longer active;
- NFC-station unlock requests are deleted 90 days after they are no longer active;
- push events and delivery records are deleted 30 days after expiry or completion;
- inactive push installations are deleted 30 days after deactivation; and
- support correspondence is deleted once the matter is resolved and it is no longer needed, subject to legal retention needs.
Operational provider logs are retained only for the period configured by the provider and necessary for security, troubleshooting, and abuse prevention. I do not copy them into a separate analytics system.
You can delete your Bound account in the app. Account deletion revokes the Sign in with Apple authorization used by Bound and immediately removes the live account and associated application data from the Bound database. It also clears Bound's local Screen Time configuration and shields on the device performing the deletion. Other connected users' accounts are not deleted.
Residual copies may remain temporarily in encrypted, provider-managed backups until those backups rotate according to the provider's backup schedule. Such copies are isolated from ordinary use and are not used to recreate a deleted account except where technically required for disaster recovery; deletion takes effect again when a backup is restored.
Uninstalling the app removes its local app data through iOS but does not by itself delete the Bound backend account. Use the in-app account deletion feature or contact me if you want the backend account deleted.
10. Permissions and choices
Bound may request:
- Screen Time / Family Controls access, to let you select and limit apps and websites;
- notification permission, to alert you about requests, decisions, limits, and relationship changes; and
- NFC access, when you choose to configure or scan an NFC lock tag.
The permissions are used only for the described functions. You can deny or change them in iOS Settings, but the corresponding feature may no longer work.
11. Automated decisions
Bound automatically applies the limits and shields configured by you or your trusted person. This is a direct execution of the selected settings. Bound does not perform profiling or make solely automated decisions that produce legal or similarly significant effects within the meaning of Article 22 GDPR.
12. Security
I use technical and organisational measures designed to protect personal data, including encrypted network connections, access controls, database row-level security, separation of private backend tables, hashed invitation tokens and protection codes, limited client permissions, and account reauthentication for deletion.
No method of electronic storage or transmission is completely secure. If I become aware of a personal-data breach, I will act in accordance with the applicable legal notification requirements.
13. Your rights
Subject to the applicable legal conditions, you have the right to:
- request access to your personal data;
- request correction of inaccurate data;
- request deletion of your data;
- request restriction of processing;
- receive data you provided in a structured, commonly used, machine-readable format and request portability where applicable;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
- lodge a complaint with a data protection supervisory authority.
To exercise your rights, email diepchenyang@icloud.com. I may need to verify your identity before fulfilling a request.
Depending on where you live, applicable local privacy law may give you additional rights. You may contact me to exercise any privacy right available to you under the law that applies to your use of Bound.
The supervisory authority responsible for the controller is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen<br> Kavalleriestraße 2–4<br> 40213 Düsseldorf<br> Germany<br> Email: poststelle@ldi.nrw.de<br> Website: www.ldi.nrw.de
You may also contact the supervisory authority at your habitual residence, place of work, or place of the alleged infringement.
14. Obligation to provide data
The account and feature data described as necessary for providing Bound must be processed if you want to use the corresponding feature. Without account data, I cannot create or operate a Bound account. Optional information, such as an extra-time reason, does not need to be provided.
15. Changes to this Privacy Policy
I may update this Privacy Policy when Bound's features, providers, or legal requirements change. I will publish the updated version with a new “Last updated” date. If a change materially affects how I process existing account data, I will provide an appropriate additional notice in the app or through another suitable channel.
16. Contact
For privacy questions, requests, or concerns, contact:
© 2026 Bound.