Privacy Policy

Last updated: 2026-09-07

bontie is a business relationship app, and a significant share of what you put into it is your contacts' personal data. This policy sets out what we actually collect, why, how long we keep it, who we share it with, and what you can ask us to do.

1.Scope and operator

This policy covers the bontie mobile app (iOS and Android), its keyboard and share extensions, and the www.bontie.app website.

bontie is built and operated by AstraZenith ("we", "us"). Contact details for data protection matters are in the final section.

If you do not agree with this policy, please stop using bontie.

2.What we collect

Grouped by source. "Provided by you" means content you enter or upload; "collected automatically" means data generated as you use the service.

Account data (provided by you)
We use Firebase Authentication for sign-in. You can use Sign in with Apple, Google Sign-In, or register with an email address and password. We receive the identifier and email address that method provides. For email registration, your password is held and verified by Firebase; our servers do not store your password in plain text.
Profile (provided by you)
Display name, full name, company, job title, industry, years of experience, self-introduction, work history, networking goals, tone and formality preferences, default signature, and the quiet hours you set.
Contact data (provided by you)
Everything you record about each contact: name, company, title, industry, expertise and topics they work on, what they are currently looking for, phone, email, LINE ID, avatar and the original images you upload, birthday month and day, how and where you met, relationship goals, interests and topics, family-related notes, tags, contact cadence, last contacted date, and any free-form notes you write.
Interactions and message content (provided by you)
Interactions you log (type, channel, direction, content, time), your conversations with the AI assistant, and AI-generated drafts along with your edited versions, draft status and send time.
Material you upload (provided by you)
Profile screenshots, business card images, other images, pasted text, and shared links. These are used for recognition and content generation.
AI generation logs (collected automatically)
For each AI request: the input (text and images), the prompt script used, the result produced, the provider and model name, and the response time. Used for quality monitoring, troubleshooting and abuse prevention.
Usage and device data (collected automatically)
Device identifier, platform, app version, IP address, activation events (such as opening the app, completing signup, creating your first contact, first AI request), AI usage counts, last active time and app open count.
Push token (collected automatically)
If you allow notifications, we store a push token so we can send reminders.
Subscription status (collected automatically)
Your plan, period and trial status, plus the customer and product identifiers provided by RevenueCat.

We never see your card number or other payment instrument details. Payment is handled entirely by Apple, Google and RevenueCat.

3.Why we need it

We process your personal data to perform our agreement with you, on the basis of our legitimate interests in keeping the service secure and working, and — where required — on your consent (for example push notifications and camera or photo library access).

  • To provide the core features: storing contacts, producing today's suggestions, generating message drafts, and reading the images you upload.
  • To send reminders based on the cadence you set and the signals we detect.
  • To calculate and enforce the usage limits of your plan.
  • For quality monitoring and troubleshooting, including reviewing AI generation logs to find poor output.
  • To detect and prevent abuse, fraud and breaches of the Terms of Service.
  • To measure product performance (for example how many people complete activation) and improve the interface and flows.
  • To answer your support requests and meet our legal obligations.

4.A note specifically about contact data

The core data in bontie is other people's personal data. This section explains how we limit its use.

When you enter contact data, you are the one deciding what to collect and what to use it for. You need to make sure you have a lawful basis for doing so, and to comply with the data protection laws that apply to you and any agreement you have with that person.

  • Your contact data is used only to provide the service to you. It is never used for ad targeting.
  • We do not link contact data across different users, and we do not build a cross-user relationship graph or shared database from it.
  • We never contact your contacts. bontie does not send messages on your behalf — every message is sent by you, from your own messaging apps.
  • We do not sell, rent or trade your contact data.

5.How AI processes your content

Generating drafts, reading the images you upload and organising contact details require sending the relevant content to a model.

We route third-party model requests through a single gateway, OpenRouter. The downstream providers that actually process the content include OpenAI, Google and Anthropic, depending on the feature and the routing at the time. Some models are self-hosted by us, and content sent to those never leaves our server environment.

Only what the feature needs is sent: for example the contact you selected, the message or screenshot you supplied, and your tone settings.

  • We do not sell your content to anyone.
  • We do not proactively provide your content to third parties as model training material. How each third-party provider handles data on its own platform is governed by its own policy.
  • Text recognition on screenshots and cards runs on your device (system text recognition on iOS, ML Kit on Android). Only the recognised text is then sent onward as the feature requires.

AI output can be inaccurate, incomplete, or out of step with your actual relationship. bontie produces drafts — check them before sending. You are responsible for what you send.

6.The keyboard and share extensions

The bontie keyboard is a separate keyboard extension that lets you get drafts inside other apps.

  • On iOS, generation requires you to turn on Allow Full Access. Without it the extension cannot connect and cannot produce anything.
  • bontie does not log keystrokes. We do not record, upload or store what you type with this keyboard in the background.
  • Content is only sent for processing when you actively trigger generation — for example choosing a contact and asking for a draft, or selecting a screenshot to analyse.
  • Zhuyin input and candidate selection are computed on the device.
  • The share extension ("Save to bontie") only handles content you deliberately share into it from another app.

7.How long we keep it

Material you upload (screenshots, images, pasted content)
Kept for 180 days by default, then deleted by a scheduled job, including the stored file itself. You can also delete it yourself at any time.
Account, profile, contacts and interaction history
Kept until you delete the record yourself, or until your account data is deleted.
AI generation logs
Retained in our systems with no blanket automatic deletion schedule in place. When you delete your account in the app, the generation logs associated with your account are deleted along with it. We are working out a retention period for these logs and will update this policy once it is set.
Usage and event data
Retained for product analytics.
Records we are legally required to keep
Kept for the period applicable law requires — transaction and tax records, for example.

8.Who we share it with

We do not sell personal data. We share it only in the situations below.

Google (Firebase)
Authentication and push infrastructure.
Expo
Push notification delivery.
OpenRouter and its downstream model providers (OpenAI, Google, Anthropic)
AI content generation and recognition.
RevenueCat, Apple, Google
Subscription management and payment processing.
Cloudflare (R2)
Image and file storage.
Hosting and email providers
Servers, database, job queues, and transactional email delivery.
Legal requirements
Where required by law or lawful process from a court or authority, or where necessary to protect the rights, property and safety of us or others.
Corporate transactions
In a merger, acquisition or asset transfer, your data may transfer with it. We would notify you in advance and require the recipient to maintain protection no weaker than this policy.

9.International transfers

The providers above may process data in countries outside your own, including the United States and elsewhere. We require reasonable safeguards from the providers we choose.

10.Security

We protect data with encryption in transit (HTTPS), access controls and the principle of least privilege. Administrative access is limited to the people who need it.

No system can guarantee absolute security. If a data incident occurs that affects your rights, we will notify you as applicable law requires.

11.Your rights

You can ask us for the following.

Access and a copy
To obtain the personal data we hold about you.
Correction
To correct inaccurate or incomplete data. Most fields you can edit directly in the app.
Deletion
To delete your account and associated data. See the account and data deletion page for what that actually covers and how it works.
Restriction and objection
To restrict or stop particular processing, to the extent applicable law allows.
Withdrawing consent
For example turning off push notifications, or revoking camera, photo library and keyboard Full Access permissions in your system settings. Withdrawal does not affect processing carried out beforehand.

Account & data deletionastrazenith.ent@gmail.com

12.Children

bontie is designed for professional and business use and is not offered to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has given us data, contact us and we will delete it.

13.Changes to this policy

We may update this policy as features or laws change. We will notify you of material changes in the app or by email. The date at the top of this page is the effective date of the current version.

14.Contact us

For any question about this policy or your data:

Operator
AstraZenith
Email
astrazenith.ent@gmail.com

astrazenith.ent@gmail.com

Privacy Policy|bontie