Privacy Policy
On this page
Effective date: September 18, 2026
1. Who is responsible for your information
Felipe Ignacio Letelier Basáez, a self-employed professional in Spain trading as Bowerbirds, is responsible for the personal data processing described in this policy where Bowerbirds acts as controller.
- Business address: C. Río Gargáligas 15, 29002 Málaga, Spain.
- Privacy contact: felipe@bowerbirds.app.
- Support contact: felipe@bowerbirds.app.
This policy covers our website, macOS and iOS apps, account and billing services, and related Bowerbirds cloud features. It explains what happens to your information; it is not a request for blanket consent.
For content processed on behalf of a business workspace, that customer may instead be the controller and Bowerbirds its processor. The customer's instructions, privacy notice, and our Data Processing Addendum then govern that processing. We remain responsible for our own account administration, security, and legal obligations. A person whose information appears in someone else's recording can have privacy rights even without a Bowerbirds account.
2. Information we process
The information involved depends on the features you use.
| Category | Examples and source |
|---|---|
| Account and authentication | Your name, email address, account identifier, profile details you supply, identity-provider identifiers, and tokens used to authenticate you. Sign-in providers supply information according to the sign-in method and permissions you authorize. |
| Content and related metadata | Notes, text, screenshots, images, documents, audio, video, transcripts, annotations, filenames, timestamps, links, and other information that you capture, upload, import, or ask a connected service to provide. Other users may include information about you in their content. |
| Workspace information | Workspace and bucket identifiers, membership, roles, invitations, settings, sharing permissions, and records associated with use of a workspace. |
| AI requests and results | Relevant source content, prompts, vocabulary or context supplied for the feature, generated results, and usage information needed to carry out and meter a request. |
| Billing and resource use | Subscription status, product and transaction identifiers, receipts, purchase and renewal events, billing details provided for invoices, credit grants and consumption, and storage use. |
| Technical and support information | Request and security logs, IP addresses received by our services, device/client and software information, errors, and correspondence or diagnostic material you send to support. |
| Website storage | Session cookies and other technologies identified in the Cookie Policy. |
Apple or our web payment provider collects the payment credentials used in its checkout. Our service uses transaction and subscription records to recognize access and address billing issues; you should not send full card numbers or security codes to support.
Your content may contain personal information about you or others, including sensitive information if you include it. Voice recordings and images can identify people; we do not describe them as anonymous merely because they are files. Do not submit sensitive material unless you have the necessary authority and the service is appropriate for it.
3. Device permissions and cloud processing
The app may request microphone, screen recording or broadcast, photo-library, keyboard, accessibility, or other permissions needed for a feature on the relevant platform. These permissions have different purposes. You can manage them in your device settings; refusing a permission may prevent the corresponding feature from working.
Bowerbirds stores some data on your device and processes other data in the cloud. Notes, captures, recordings, and other records saved to a cloud workspace may be uploaded for storage and synchronization even if AI processing is disabled. Turning AI off is not a local-only storage setting.
The information sent for AI depends on the feature: dictation can involve audio and vocabulary; summaries can involve source notes or recordings; image or video assistance can involve visual content and accompanying context. Information intentionally shared through an extension or connected tool is processed for that action. Access to a permission does not mean we need every item on your device.
4. Purposes and legal bases
Where we are controller and the GDPR applies, we use the following bases as appropriate to the specific activity:
| Purpose | Basis |
|---|---|
| Register your account, authenticate you, save and retrieve your content, and provide features you request | Performance of our contract with you, or steps you request before entering it. |
| Administer an organization's workspace and communicate with its authorized representatives | Our legitimate interest in supplying and administering the customer's service; contractual necessity when the individual is the contracting customer. |
| Optional third-party AI processing enabled by your permission | Consent for the covered sharing and processing where you are the relevant data subject; customer instructions and the customer's lawful basis for content we process on its behalf. Permission from an account holder does not substitute for another person's required consent. |
| Meter usage, recognize subscriptions, and resolve billing issues | Contract performance; legitimate interests for an organization's representatives; legal obligations for required accounting and tax records. |
| Secure the service, investigate abuse, diagnose faults, and handle claims | Legitimate interests in protecting accounts and operating a reliable service, subject to your rights; legal obligations where a specific requirement applies. |
| Answer questions and respond to privacy requests | Contract or precontractual steps for service requests; legitimate interests in responding to general inquiries; legal obligations for statutory rights requests. |
| Nonessential website tracking or optional promotional communications, if introduced | Consent where required, with separate information and controls at the point of collection. |
Providing the account information and feature inputs needed to perform a requested service is necessary for that service to work. Optional permissions and optional tracking are not conditions for unrelated functionality.
Where we rely on legitimate interests, we consider the purpose, necessity, and effects on individuals and you may object as explained below. We do not treat acceptance of the Terms as consent for unrelated marketing or AI training.
5. AI providers and your controls
The current AI integration uses Google's Gemini services for transcription and other AI features. The provider register identifies the services involved and their processing arrangements.
Before the relevant sharing, we explain what will be sent and request permission. You can manage this through Settings → Use AI on my captures. Turning it off prevents new processing covered by that permission when the change reaches the relevant service. If an account update fails, the app explains the local and account status; contact us if you cannot complete a withdrawal. Requests already sent may have completed before withdrawal.
We do not use private workspace content to train a general-purpose AI model for our own purposes. The provider's treatment of requests, including safety logging, caching, retention, and any human review, is: not yet established, and this is the most consequential open item in this package. User content reaches two different Google surfaces under different terms. Content routed through Vertex AI falls under the Google Cloud Data Processing Addendum, by which Google does not use customer data to train its models. Content sent to the Gemini Developer API — the path dictation and transcription audio takes — falls under the Gemini API terms, where the free tier permits Google to use submitted content to improve its products, including human review, and the paid tier does not. The billing tier of the configured API key must be confirmed, and the answer reflected here, in the Privacy Policy and in the in-app AI consent copy, before publication. Transcription must not be described as covered by the Cloud DPA unless that path is moved to Vertex AI.
Withdrawal of consent does not make earlier processing unlawful or automatically delete stored recordings or previous AI results. You can separately request deletion. For shared workspaces, a controller may have an independent lawful basis for information already retained; we will explain the applicable arrangement rather than treating your account setting as consent on everyone else's behalf.
AI-generated classifications, summaries, and suggestions assist your work. They are not a determination of your legal rights. You can contact us to request human consideration of an account restriction or dispute.
6. Who receives information
We disclose information only as needed for the following purposes:
- Hosting, authentication, and infrastructure providers operate the cloud, databases, storage, website delivery, and sign-in services.
- AI providers receive the source material and context needed for enabled AI processing.
- RevenueCat and payment providers process account or workspace identifiers, transactions, subscription status, and related information needed for billing and entitlements.
- Email and support providers, where enabled, process contact details and relevant service messages.
- Other workspace users and customer-selected services receive the information permitted by your sharing settings or the customer's authorized instructions.
- Authorities, advisers, or other parties may receive limited information when required by law or necessary to establish or defend legal claims, with applicable safeguards.
The provider register distinguishes our suppliers from third-party services you choose. A payment or sign-in provider may act as an independent controller for some of its own legal, fraud-prevention, or account purposes. Its separate notice applies to those activities.
If the business is reorganized or transferred, relevant information may be transferred to the successor under appropriate confidentiality and legal protections. We will provide any notice and choice required by law. We do not sell your private workspace content or use it for behavioral advertising.
7. International processing
Our operator is established in Spain, but that does not mean every provider or processing location is in Spain or the EEA. Hosting location, support access, billing infrastructure, and AI processing may differ.
Our verified locations and transfer safeguards are: **All Bowerbirds infrastructure is hosted in the United States, notwithstanding the operator's establishment in Spain: Cloud Run services and the record payload bucket in us-central1 (Iowa); the Postgres database on AWS us-east-2 (Ohio); Vertex AI on the global endpoint, which is not pinned to one region; and Cloudflare's global edge, which processes request metadata nearest the visitor. Personal data of users in the EEA is therefore transferred to the United States in the ordinary course of providing the service. The transfer mechanisms relied upon — Standard Contractual Clauses within each supplier's data processing agreement and, where applicable, that supplier's certification under the EU–US Data Privacy Framework — must be confirmed as executed for these specific accounts before this statement is published**. The provider register gives the corresponding supplier details. Where required, transfers outside the EEA use a legally available mechanism, such as an applicable adequacy decision or completed contractual safeguards with any necessary supplementary measures. We do not rely on your acceptance of this policy as a substitute for those safeguards.
Contact felipe@bowerbirds.app for information about the relevant safeguards or an appropriately redacted copy.
8. Retention and deletion
We keep personal information for the relevant service purpose, your instructions, and applicable legal requirements. Content retention and account/billing retention are different.
| Information or situation | Retention rule |
|---|---|
| Content in a free workspace that has never held a paid subscription | A rolling 15-day cloud retention window. Older content becomes eligible for removal by the retention process. |
| Content in an active paid workspace | Kept while needed to provide the service, subject to your deletion instructions, configured workspace policies, and the service agreement. There is no standard age-based expiry solely because an item is old. |
| Cloud content after a paid workspace's subscription expires | A 30-day grace period from the end of paid entitlement, after which that workspace's cloud content becomes eligible for deletion. Cancelling future renewal does not start this period while paid access remains active. |
| Bucket/workspace structure and membership | May remain after plan-related content cleanup while the workspace continues to exist. Content expiry is not account deletion. |
| Failed dictation audio retained locally for recovery | Eligible for cleanup after 72 hours. Cleanup runs when the app performs the relevant maintenance; an app that never runs cannot perform that cleanup. |
| Account deletion and content marked for removal | Access closure and active-storage cleanup are separate steps. Completion period: as follows. Sign-in access ends immediately: the account's identity record is deleted as the final step of the deletion request, and a failure at that step is reported to the person rather than recorded as success. Workspaces owned solely by the account are tombstoned in the same request. Their records and payload objects are then removed by the purge sweep, which acts on rows soft-deleted more than 30 days earlier. That 30-day delay is a recovery window, not an erasure period, and should be reconciled with what this policy promises an erasure request will achieve. |
| Backups and disaster-recovery copies | as follows, and both windows are short. Objects deleted from the payload bucket remain restorable for 7 days under the bucket's soft-delete policy — a safety net, not an administrator-browsable archive. The database retains 6 hours of point-in-time history, which is the entire window in which a past database state can be restored. Derived media chunks are deleted by lifecycle rule after 7 days. There is no separate long-term backup archive. Confirm this is the intended posture: six hours is a short window for a service that may hold a customer's only copy of a recording. Restricted copies are not restored to ordinary use without reapplying required deletions. |
| Operational and security logs | **7 days for workspace event-feed rows and for abuse and rate-limit counters, and 30 days for background job records. Platform request logs for the hosted services follow the cloud project's configured logging retention, which must be confirmed and stated**, with a justified extension only for an actual incident, claim, or legal duty. |
| Support correspondence | not yet set. Support correspondence is handled in the operator's mailbox at felipe@bowerbirds.app; there is no separate ticketing system. A retention period for that correspondence must be decided and stated here — an unbounded mailbox is not a retention policy. |
| Billing, tax, and legally necessary transaction records | not yet set. Billing records exist in Stripe and RevenueCat under their own retention, and as plan and ledger rows in the Bowerbirds database. Spanish commercial and tax law require invoices and accounting records to be kept for a set number of years; the applicable period must be confirmed with the operator's gestor and stated here. Tax retention is not authority to retain recordings or transcripts, limited to records needed for the applicable obligation or claim. |
Your own deletion instructions or an authorized workspace retention policy may remove content sooner. Legal preservation duties can require us to restrict and retain particular records rather than erase them immediately. We identify the reason and applicable period when relevant to your request.
Use Settings → Account → Delete account to initiate account deletion. The app identifies shared workspaces that require an ownership handover or other resolution to avoid destroying other people's work. Contact felipe@bowerbirds.app if this prevents you from completing a request; shared ownership is not a reason to leave a statutory request unanswered indefinitely.
Deleting an account is not a reliable way to stop Apple or web subscription renewals. Follow the separate cancellation instructions. Deletion can remove local app data and cloud access. Export material you need before deletion; neither a local cache nor a shared recipient's copy should be treated as a guaranteed recoverable backup.
9. Security
We use technical and organizational measures appropriate to the information and risks, including authenticated access, access restrictions, and protections for data transmitted to our services. Cloud processing requires the relevant services to access content; we do not represent Bowerbirds as an end-to-end encrypted service that its processing providers cannot read.
No system is completely secure. If a personal data breach occurs, we will investigate and make notifications required by applicable law. You can report a suspected issue to felipe@bowerbirds.app. Do not include passwords or unnecessary recordings in a report.
10. Your rights
Depending on applicable law and the circumstances, you can request access, correction, erasure, restriction, or a portable copy of your personal data; object to processing based on legitimate interests; withdraw consent; and exercise protections concerning decisions made solely by automated means that have legal or similarly significant effects.
Send requests to felipe@bowerbirds.app. We may ask for proportionate information to verify identity or authority. We respond within applicable legal deadlines; under the GDPR, the usual period is one month, with a permitted extension for qualifying requests and notice of the reason. We explain any lawful refusal and available remedies.
For business-controlled workspace content, contact its controller first when practicable. If you contact us, we will help identify or route the request and assist the customer as required. This does not prevent you from exercising rights over processing for which we are controller.
You may complain to the Spanish Data Protection Agency (AEPD) or the competent supervisory authority where you live or work, or where the alleged infringement occurred. You can do so without first contacting us.
11. Age eligibility
This version of Bowerbirds is for users aged 18 and over. If you believe a younger person has opened an account, contact felipe@bowerbirds.app so we can investigate and take appropriate action. This does not mean all information about a minor appearing in an adult's lawful content is automatically an unauthorized account; that content still requires a lawful purpose and appropriate safeguards.
12. Changes
We will update this policy when our processing changes and identify the effective date. Material changes receive appropriate notice. Where new consent is required, publishing an updated policy does not replace obtaining it.