Privacy Policy for Bound

Last updated: 7 October 2026

Privacy at a glance

Bound is a voluntary accountability app. I designed it to provide app and website limits without creating a detailed record of how you use your device.

The sections below explain the processing in detail.

1. Controller

I, Chen Yang Diep, independently design, develop, and operate Bound. I am the controller responsible for the processing of personal data through Bound:

Chen Yang Diep<br> Drechslerstr. 14<br> 41199 Mönchengladbach<br> Germany<br> Email: diepchenyang@icloud.com

2. Scope

This Privacy Policy applies to the Bound iOS app, its associated backend services, invitation links, and the Bound website.

Bound is intended for people aged 16 or older. You must confirm during onboarding that you are at least 16 before using Bound. If you believe that a person under 16 has provided personal data to Bound, contact me so that I can investigate and delete the data where appropriate.

3. Data processed by the Bound app

3.1 Account and authentication data

Bound uses Sign in with Apple. When you create or access an account, I process:

Apple does not provide your Apple Account password to Bound.

I process these data to create, authenticate, secure, and delete your account. The legal basis is Article 6(1)(b) GDPR. Security and abuse-prevention logs are also processed on the basis of my legitimate interest in operating a secure and reliable service under Article 6(1)(f) GDPR.

3.2 Profile and onboarding data

I store your display name, your selected starting area in the app, whether you completed onboarding, and related timestamps. I use these data to configure and display your account. The legal basis is Article 6(1)(b) GDPR.

3.3 Invitations and trusted relationships

To connect you with another Bound user, I process:

The person opening an invitation can see the inviting user's display name. Once connected, the participants can see each other's display names and the relationship information needed to use Bound. The legal basis is Article 6(1)(b) GDPR.

3.4 App and website selections and limits

When you publish an app or website selection to Bound, the backend stores:

Apple's opaque ApplicationToken and WebDomainToken values are stored only in the app's protected local app-group storage. They are not uploaded to the Bound backend. Bound also does not upload your complete list of installed apps, the websites you visit, your exact time spent in an app, or a detailed Screen Time history.

The backend data allow the selected trusted person to identify the selection and manage the requested limit. The legal basis is Article 6(1)(b) GDPR.

3.5 Extra-time requests

For an extra-time request, I process the selected app or website, requested and approved minutes, an optional reason, the sender and recipient, the decision and status, and relevant timestamps. The connected participants can view the request information necessary to make and communicate the decision. The legal basis is Article 6(1)(b) GDPR.

3.6 View protection

If you enable view protection, I process a random device identifier, the device label you provide, the protected areas, a cryptographic hash of the six-digit protection code, failed verification attempts, temporary lockout information, reset requests, decisions, and timestamps.

The protection code itself is not stored in readable form. The data are used to enforce the protection setting, prevent repeated guessing attempts, and allow a trusted person to decide a reset request. The legal basis is Article 6(1)(b) GDPR. Protection against misuse is also my legitimate interest under Article 6(1)(f) GDPR.

3.7 NFC lock

NFC tag configuration, the hashed NFC secret, selected Apple tokens, the active lock state, and the last scan time are stored locally on your device. The NFC tag contains a Bound URL with a random station identifier and secret.

If you send an emergency unlock request, the backend processes random device and station identifiers, the sender and trusted recipient, the request status, decision, and timestamps. The NFC secret itself is not sent as part of an unlock request. The legal basis is Article 6(1)(b) GDPR.

3.8 Push notifications

If you allow notifications, I process the Apple Push Notification service (APNs) device token, app bundle identifier, development or production environment, activation status, and technical delivery information such as attempt count, status, and error code.

Notification payloads contain an event type and a random request identifier so that the app can open or refresh the relevant area. Bound sends these data to Apple to deliver the notification. The legal basis is Article 6(1)(b) GDPR. You can disable notifications in iOS Settings. After deactivation, the token is kept for a limited period as described below and is no longer used for new delivery.

3.9 Local Screen Time processing

Screen Time authorization, monitoring, and shielding are performed using Apple's Family Controls, Device Activity, and Managed Settings frameworks. The following information remains locally on the device:

Bound uses these data to apply the limits you configure. Bound does not create or upload a chronological history of your app or website activity.

4. Data processed through the website

The Bound website is a static website and does not currently use analytics, advertising technology, tracking pixels, or non-essential cookies. Bound does not create its own visitor profile. The hosting provider may use strictly necessary security mechanisms where required to protect the website.

When the website is requested, the hosting and content-delivery provider must process technical connection data such as the IP address, date and time, requested URL, referrer where supplied, browser or user-agent information, and security information. This processing is necessary to deliver and protect the website and is based on my legitimate interest in providing a secure and reliable website under Article 6(1)(f) GDPR.

The hosting provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States. Cloudflare may process connection data in its global network. Transfers outside the EEA are protected as described in section 8.

5. Contact by email

If you contact me, I process your email address, message, attachments, and the information required to answer the request. The legal basis is Article 6(1)(b) GDPR where the message concerns your use of Bound or steps before using it, and otherwise my legitimate interest in answering enquiries under Article 6(1)(f) GDPR.

The contact mailbox is provided through Apple iCloud Mail. Correspondence is deleted when the matter has been resolved and the message is no longer required, unless a longer period is necessary to establish, exercise, or defend legal claims or to meet a legal obligation.

6. Information visible to trusted people

A connected trusted person may see:

Trusted people do not receive your email address, Apple Account identifier, opaque Apple Screen Time tokens, location, complete installed-app list, exact time spent in apps, browsing history, or a detailed activity profile from Bound.

Only connect with a person you trust. Ending a relationship removes their ongoing access to relationship-protected information, although request records already associated with an account remain subject to the retention periods in section 9.

7. Service providers and recipients

I disclose personal data only where necessary to provide Bound, where you direct me to share information with a connected person, or where disclosure is required by law.

Supabase

Supabase Pte. Ltd. provides authentication, the PostgreSQL database, realtime updates, and server-side functions. Bound's primary Supabase database is hosted in the eu-central-1 region in Frankfurt, Germany. Supabase acts as a processor on my behalf and may use subprocessors, including infrastructure providers such as Amazon Web Services. Further information is available in Supabase's privacy information and Data Processing Addendum.

Apple

Apple provides Sign in with Apple, APNs, iCloud Mail for the contact address, and the iOS Screen Time and NFC frameworks. For users in the EEA, the relevant Apple entity is generally Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple's own processing is governed by Apple's Privacy Policy and its Sign in with Apple privacy information.

Website hosting

Cloudflare, Inc. provides website hosting, content delivery, and security through Cloudflare Pages. Cloudflare acts as a processor for website connection data where applicable. Further information is available in Cloudflare's Privacy Policy and Data Processing Addendum.

I do not disclose personal data to data brokers or advertising networks, and I do not sell personal data.

8. International data transfers

Although Bound's primary database is located in Frankfurt, some providers and their subprocessors operate internationally. This may involve processing in countries outside the European Economic Area.

Where required, transfers are protected by an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary technical and organisational safeguards. Supabase's Data Processing Addendum includes the Standard Contractual Clauses for covered transfers. Apple states that its international transfers of EEA personal data are governed by Standard Contractual Clauses. Cloudflare's Data Processing Addendum and Standard Contractual Clauses apply to restricted transfers.

You may contact me if you would like more information about the safeguards applicable to a particular transfer.

9. Retention and deletion

I retain personal data only for as long as it is required for the relevant purpose:

Operational provider logs are retained only for the period configured by the provider and necessary for security, troubleshooting, and abuse prevention. I do not copy them into a separate analytics system.

You can delete your Bound account in the app. Account deletion revokes the Sign in with Apple authorization used by Bound and immediately removes the live account and associated application data from the Bound database. It also clears Bound's local Screen Time configuration and shields on the device performing the deletion. Other connected users' accounts are not deleted.

Residual copies may remain temporarily in encrypted, provider-managed backups until those backups rotate according to the provider's backup schedule. Such copies are isolated from ordinary use and are not used to recreate a deleted account except where technically required for disaster recovery; deletion takes effect again when a backup is restored.

Uninstalling the app removes its local app data through iOS but does not by itself delete the Bound backend account. Use the in-app account deletion feature or contact me if you want the backend account deleted.

10. Permissions and choices

Bound may request:

The permissions are used only for the described functions. You can deny or change them in iOS Settings, but the corresponding feature may no longer work.

11. Automated decisions

Bound automatically applies the limits and shields configured by you or your trusted person. This is a direct execution of the selected settings. Bound does not perform profiling or make solely automated decisions that produce legal or similarly significant effects within the meaning of Article 22 GDPR.

12. Security

I use technical and organisational measures designed to protect personal data, including encrypted network connections, access controls, database row-level security, separation of private backend tables, hashed invitation tokens and protection codes, limited client permissions, and account reauthentication for deletion.

No method of electronic storage or transmission is completely secure. If I become aware of a personal-data breach, I will act in accordance with the applicable legal notification requirements.

13. Your rights

Subject to the applicable legal conditions, you have the right to:

To exercise your rights, email diepchenyang@icloud.com. I may need to verify your identity before fulfilling a request.

Depending on where you live, applicable local privacy law may give you additional rights. You may contact me to exercise any privacy right available to you under the law that applies to your use of Bound.

The supervisory authority responsible for the controller is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen<br> Kavalleriestraße 2–4<br> 40213 Düsseldorf<br> Germany<br> Email: poststelle@ldi.nrw.de<br> Website: www.ldi.nrw.de

You may also contact the supervisory authority at your habitual residence, place of work, or place of the alleged infringement.

14. Obligation to provide data

The account and feature data described as necessary for providing Bound must be processed if you want to use the corresponding feature. Without account data, I cannot create or operate a Bound account. Optional information, such as an extra-time reason, does not need to be provided.

15. Changes to this Privacy Policy

I may update this Privacy Policy when Bound's features, providers, or legal requirements change. I will publish the updated version with a new “Last updated” date. If a change materially affects how I process existing account data, I will provide an appropriate additional notice in the app or through another suitable channel.

16. Contact

For privacy questions, requests, or concerns, contact:

diepchenyang@icloud.com

© 2026 Bound.