Privacy Policy
Last updated: August 13, 2026
This Privacy Policy describes how Bridgit collects, uses, and protects your information when you use our social activity platform at settledbybridgit.com and in our Bridgit apps for iOS and Android. It covers our consumer app, our partner-facing surfaces (including partner and campaign programs), and the public-event pages we host. Where something works differently on your phone than on the web, we say so.
Bridgit is operated by Bridgit Networks Inc. We are the data controller for the personal information described in this policy — meaning we decide why and how it is used, and we are the company you can hold to this policy.
Bridgit Networks Inc.1111B S Governors Ave
Suite 92741
Dover, DE 19904
United States
support@settledbybridgit.com
Account information (required)
Your email address and the account identifier we generate for you. We need both to sign you in and to keep your data attached to you.
Profile information (required)
Your name, date of birth, city, interests, languages, and matching preferences. Your date of birth is required so we can confirm you meet our minimum age and apply the age range you and other members choose for matching. Other members see your age, never your date of birth. Optional profile fields stay optional.
Photos (optional)
A profile photo if you choose to add one, and cover images you upload for activities or events. Nothing requires you to upload a photo. On the apps you can pick an existing photo or take a new one — see "Permissions the apps ask for" below.
Activity and event data (optional)
Content you create: activities you create or join (private), public events you host or express interest in, ratings, reports, feedback you submit, and venue check-ins you choose to make.
App interactions (required)
How you use Bridgit — features accessed and actions taken — so we can operate the service and detect abuse. This includes the outcome of the notification-permission prompt: we record whether you granted or denied it, and whether a push token was later registered or removed. That record is written whichever way you answer and has no opt-out, because we use it to know whether we are allowed to send you anything.
Location data (optional)
We display your cityto other users, and we store coordinates derived from that city or from a venue you select, which we use server-side for distance-based matching. Coordinates are never shown to other users. Device location is optional and is only ever read after you tap something — details in "Permissions the apps ask for" below.
Messages (optional)
Messages sent through our in-app chat (per-activity, group, direct, or partner-to-partner). Content is private to the chat participants.
Crash logs and performance data
When something breaks or runs slowly we collect a crash report and performance data — the error, where in the app it happened, and basic app and platform version information. Before a report is sent we strip known personal fields (including email, name, message and activity text, addresses, and tokens) so they do not reach our error-reporting providers. We do not sample your screen or record your session. Website and server diagnostics go to Better Stack. The mobile apps also include Sentry crash reporting, which we may switch on; while it is switched on, app crash reports are processed by Sentry. See "Data Sharing & Sub-processors" below.
Authentication data
When you sign in with Google or LinkedIn, we receive your name, email address, and profile picture from those providers. LinkedIn-verified users also receive a verification flag based on the OIDC claims. We do not request or store any other data from your Google or LinkedIn accounts.
Anonymous feedback
When you submit feedback while signed out, we still capture the page you were on and a coarse device fingerprint (user agent, screen size) so we can triage the report. No persistent identifier is set.
The Bridgit apps for iOS and Android ask for a small number of device permissions. Every one of them is optional, every one is requested at the moment you use the feature that needs it, and you can withdraw any of them later in your device settings. The app keeps working without them.
Two separate, optional uses, both triggered by you:
- • Approximate location— when you tap "Use my location" to fill in your city, we take a low-accuracy fix (roughly city-block to kilometre level), turn it into a city name, and keep the city. We do not keep the fix itself.
- • Precise location— only when you tap to check in at a venue. We take a single reading at that moment, send it to our servers to confirm you are actually at the venue, and store it with the check-in record along with the distance and the reading's accuracy.
Bridgit never reads your location in the background and never tracks you continuously. The apps do not request background-location access at all — it is explicitly excluded from the Android build.
Asked for only when you add a photo. If you choose "take a photo", the app asks for camera access. Either way we receive only the single image you select — we never browse or index your photo library.
Asked for so we can send you match, message, and activity alerts. If you allow it, we store the push token your device issues. Whether you allow or deny it, we record the outcome (see "App interactions" above).
Asked for only when you tap to add an activity to your calendar. Bridgit writes that one event and nothing else. We look at the list of calendars on your device purely to know which one to save it into — we never read your existing events, and no calendar information ever leaves your device or reaches our servers. The permission is granted as a combined read-and-write permission because that is the only form the operating system offers; we use only the write half.
To be explicit, Bridgit does not collect any of the following, on the web or in the apps:
- • Advertising identifiers or device identifiers — we run no advertising and no cross-app tracking
- • Your contacts or address book
- • Your calendar entries (we only write an event you asked us to write)
- • Payment or financial information
- • Health or fitness data
- • Audio recordings — microphone access is excluded from the app build entirely
- • Files, documents, or your photo library beyond the single image you choose to upload
- • Your browsing history outside Bridgit
- • SMS or call logs
Profile photos are scanned by an automated image-moderation service (AWS Rekognition) beforethey are stored. The service returns a verdict (approve / review / reject) and a list of moderation labels. We log the verdict, label list, latency, and your user id in an audit table to support trust & safety review and to detect repeated abuse.
If the moderation service is unavailable we fail-open and queue the photo for human review rather than block legitimate uploads.
Bridgit uses two third-party AI providers to help rank matches and explain why an activity might suit you:
- OpenAI — receives a structured snippet of your profile and the activity profile to generate a one-sentence match explanation. Explanations are cached for up to 7 days.
- Mistral (with OpenAI as a fallback) — receives interest text, profile blurbs, and activity descriptions to generate vector embeddings used for semantic ranking.
Neither provider trains on your data; both are bound by their own data processing agreements. AI features have a limited opt-out at MVP — a full preference toggle is on the roadmap.
Supabase auth-session cookies. Without these you cannot stay signed in.
bridgit_aid (1-year, anonymous visitor id) and bridgit_attr (90-day, first-touch campaign snapshot — only set when missing). When you arrive via a campaign QR or short link we hash your IP with a daily-rotated salt to deduplicate visits without tracking you across days. Raw IPs are not stored.
localStorage for client-side preferences and a service worker for push and install support. We do not run third-party advertising or cross-site tracking cookies.
On the web.If you opt in, your browser issues a VAPID subscription endpoint plus auth keys, which we store so we can deliver match, message, and event alerts. Delivery is brokered by your browser vendor's push service (Apple / Google / Mozilla).
In the iOS and Android apps.If you opt in, your device issues a push token, which we store for the same purpose. Delivery goes through the Expo Push Service, which hands the notification to Apple Push Notification service or Firebase Cloud Messaging for the last hop to your device. The notification text — which can include a sender's name or a message preview — passes through those services in order to reach you.
You can revoke push consent at any time from your device settings or from your Bridgit notification preferences. If your device stops accepting a token we delete the stored subscription.
Transactional emails (sign-in links, claim confirmations, weekly digests, unread-chat reminders) are sent through an infrastructure email provider (AWS SES). Send, bounce, and open events are logged so we can detect delivery problems and respect unsubscribes. A self-service preference center is on the roadmap; until then, replying with "unsubscribe" or writing to privacy@settledbybridgit.com opts you out.
Activities (under /activity/*) are row-level-locked to the host and matched users. There is no public browsing, no shareable preview, and no search-engine indexing.
Public events (under /events/*) are world-readable. They have shareable QR posters and Open Graph metadata. If you create or host a public event, its title, description, location, and host display name are public. Companion-matching for public events runs on a separate ledger and only surfaces opt-in participants to each other.
Activities are only visible to matched users. No public browsing or endless scrolling on the consumer side.
All data is encrypted in transit and at rest using industry-standard security measures.
Other users only see your city. Coordinates stay server-side and are used only for distance-based matching and, if you check in at a venue, to confirm you were there. Device location is never read in the background.
Your private profile and activities are only shown to algorithmically matched users, never publicly browsable.
- • Match you with relevant activities and users based on interests, languages, and location
- • Generate AI-assisted ranking and one-sentence match explanations
- • Facilitate communication between activity participants
- • Send notifications and digests about matches, messages, and events
- • Measure first-touch attribution for campaigns we run
- • Deliver push notifications you have opted in to
- • Confirm you were at a venue when you choose to check in
- • Detect and prevent fraud, abuse, and harmful imagery via moderation logs
- • Diagnose crashes and performance problems so we can fix them
- • Operate our partner and campaign programs — partner-side data only
- • Improve our matching algorithms and user experience
- • Comply with legal requirements and enforce our terms
We do not sell or rent your personal information, and we do not share it with any third party for that party's own purposes. The companies below are our processors: they handle data only on our instructions, only to run Bridgit, and they are not permitted to use it for anything of their own. This is the full list of processors that can see personal data.
- • Supabase — our database, sign-in, file storage, and real-time messaging infrastructure. Holds your profile, activities, messages, and photos.
- • Vercel — hosts and serves the website and our server-side code.
- • Amazon Web Services (Rekognition) — scans profile photos for prohibited content before they are stored.
- • Amazon Web Services (SES) — sends our transactional email.
- • Google Maps Platform (Places) — venue and city search, place details, and turning coordinates into a city name. See the note below.
- • OpenAI — generates the one-sentence match explanations, and is our fallback embedding provider.
- • Mistral — generates the vector embeddings used for semantic ranking.
- • Expo, Apple, and Google — deliver push notifications to the apps (Expo Push Service, then Apple Push Notification service or Firebase Cloud Messaging).
- • Better Stack — receives our server logs and the crash and performance reports from the website and our servers. This is where web diagnostics go.
- • Sentry — crash-reporting software built into the Bridgit mobile apps. We may switch it on for app crash reporting; while it is switched on, app crash reports are processed by Sentry. The same stripping of personal fields described above applies either way.
- • Upstash — a fast cache and rate-limiter that sits in front of our database.
Beyond processors, information reaches: other matched users, only as necessary to coordinate an activity (display name, city, avatar, opt-in availability); law enforcement or others, when required by law or to protect our rights, our users, or the public; and aggregate research, in anonymized, aggregated form that cannot identify you.
Your device never talks to Google directly — the Bridgit apps carry no Google Maps key. When you search for a venue or use your location to fill in your city, the request goes to Bridgit's own servers, and our servers then query Google Maps Platform using our account. Google receives the search text or the coordinates needed to answer, but not your name, your email, or your Bridgit account. Google acts as our processor for that lookup.
Reports you submit (about other users, photos, or activities) retain a link to your user id even if the reported user later deletes their account, so we can investigate patterns. Ratings exchanged between participants of a completed activity are private; when both sides leave a rating of 4 stars or higher, a private group may be auto-created with co-participants — at that point first names and avatars become visible to the group.
For partner and campaign programs — our first was run with the San Francisco Chamber of Commerce — your business contact email may be imported by Bridgit administrators from a partner-supplied member list. If we contact you on that basis, the email will say so explicitly. You can decline to claim the venue and request deletion of the imported record at any time by writing to privacy@settledbybridgit.com.
- • Access and download your personal data
- • Correct inaccurate information in your profile
- • Delete your account and associated data
- • Control notification and sharing preferences
- • Withdraw consent for data processing
- • Request data portability in a structured format
- • Object to processing of your personal data
Downloading your data
You can download a copy of your data at any time from the web app, under Profile → Download your data. We generate a JSON file — a standard, machine-readable format — containing your account, profile, preferences, activities, events, the messages you sent, your ratings, check-ins, campaign sign-ups, and the reports and feedback you submitted. The file is generated when you ask for it and is not stored on our servers.
It does not include other people's messages or personal details: where someone else appears in your records, only their display name is shown. It also leaves out internal technical data and moderator notes. If you would like your data in another format, or you cannot reach the app, email privacy@settledbybridgit.com.
We retain your data only as long as necessary to provide our services and comply with legal obligations.
You can delete your account yourself at any time: in the iOS and Android apps under Profile → Settings → Delete account, or on the web from your profile settings. If you have already uninstalled the app, email privacy@settledbybridgit.com instead. There is no recovery window — deletion is immediate and cannot be undone by you or by us.
Deletion erases your personal information and deactivates the underlying account record rather than physically removing it in the same instant. We remove personal information within 30 days of a deletion request, except where we are required to keep it for legal compliance, dispute resolution, or trust & safety. Two specific carve-outs: reports and ratings you submitted may be retained as described in "Reports, Ratings, and Trust" above, and your profile photo's image file is removed by a nightly clean-up job that can take up to about eight days. Backups roll off on the standard backup-rotation cadence.
Our Account Deletion page lists exactly what is erased and what is kept.
Bridgit is an adults-only service, intended for users aged 18 and older. We ask for your date of birth at sign-up and refuse any account below that age. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us so we can remove it and close the account.
Our Child Safety Standards explain how we prevent and respond to child sexual abuse and exploitation on Bridgit.
We may update this Privacy Policy from time to time. We will notify users of significant changes through the platform. Continued use after changes indicates acceptance of the updated policy.
Questions about privacy? Email us at privacy@settledbybridgit.com, or reach the company at support@settledbybridgit.com. Our postal address, as the data controller, is:
Bridgit Networks Inc.1111B S Governors Ave
Suite 92741
Dover, DE 19904
United States
See also our Terms of Service.
Related policies: Child Safety Standards · Account Deletion
© 2026 Bridgit. All rights reserved.