1. About this Policy
This Privacy Policy describes how Andriy Zherebyatyev ("Bipper", "we", "us", or "our") processes personal data through the Bipper iOS application, its widget, related backend services, and the Bipper website (collectively, the "Service").
For users in the European Economic Area ("EEA"), Bipper acts as the controller of the personal data described in this Policy.
"Personal data" means information relating to an identified or identifiable person.
2. Personal Data We Collect
Account and profile information
When you create or use a Bipper account, we may process:
- your email address;
- a unique account identifier;
- your display name or username;
- your profile image, if you choose to provide one;
- account creation and account-status information.
Your Circle and social connections
To let you connect with people you choose, we process information about Circle relationships, including friend or connection requests, accepted relationships, removals, blocks and reports where those features are used.
Bipps
When you create and send a Bipp, we process the information needed to deliver it, including:
- the audio recording you choose to create;
- the emoji attached to the Bipp, if any;
- the sender and intended recipient or recipients;
- the recording duration;
- the date and time the Bipp was created and sent;
- delivery information;
- whether and when a recipient fully heard the Bipp.
Bipper uses microphone access only when you choose to record audio using a feature that requires the microphone. You can control microphone permission through iOS Settings.
Device and notification information
We may process limited technical information necessary to operate the Service, such as:
- device and operating-system information;
- app version;
- push-notification tokens;
- notification and delivery state;
- technical identifiers required for app and widget operation.
Technical and security information
Our infrastructure and service providers may generate technical logs containing information such as IP address, request timestamps, server responses, authentication events, and diagnostic or security information. We use this information to operate, protect and debug the Service.
Communications with us
If you contact Bipper for support, privacy questions, abuse reports or another reason, we process the information you provide in that communication.
3. How and Why We Use Personal Data
We use personal data to:
- create and authenticate your account;
- maintain your profile and Circle;
- record, store, deliver and play Bipps;
- show recent Bipps through the Bipper widget;
- keep delivery and heard status synchronized across the Service;
- send service and push notifications;
- protect accounts and prevent fraud, abuse and unauthorized access;
- respond to support, privacy and safety requests;
- maintain, troubleshoot and improve the reliability of Bipper;
- comply with applicable legal obligations.
Legal bases in the EEA
Where the GDPR applies, we generally process core account, Circle and Bipp information because it is necessary to provide the Service you request and perform our agreement with you.
We may rely on our legitimate interests for purposes such as security, abuse prevention, service reliability and troubleshooting, provided those interests are not overridden by your rights and freedoms.
We rely on consent where applicable law requires it, including for optional device permissions or other optional processing. You may withdraw consent at any time through the relevant iOS setting or by contacting us where applicable.
We may also process information where necessary to comply with a legal obligation.
4. Bipps, Playback and Retention
Bipper is intentionally designed around short-lived content.
- Recent Bipps from people in your Circle are available to you for approximately 48 hours.
- Your own recently sent Bipps may remain available to you for up to 7 days.
- Because the sender may access a sent Bipp for up to seven days, the underlying audio may remain in active storage for up to that period even after it is no longer visible in a recipient's 48-hour history.
- After the applicable retention period expires, Bipper removes the audio from active storage as part of its deletion process, except where retention is required by law or reasonably necessary to investigate serious abuse, fraud, security incidents, or legal claims.
A Bipp is treated as heard only when playback reaches the end. Bipper may therefore process playback progress and heard timestamps so that this state can be synchronized between the application, backend and widget.
Profile, account and Circle information is generally retained while your account remains active and for only as long afterwards as necessary for deletion, security, legal compliance or dispute resolution.
Limited residual copies may remain temporarily in encrypted or disaster-recovery backups until those backups are overwritten in the ordinary course.
6. International Data Transfers
Some infrastructure or service providers may process personal data in countries other than the country where you live.
Where personal data protected by the GDPR is transferred outside the EEA to a country that has not been recognized as providing an adequate level of protection, we use an appropriate legal mechanism where required, such as Standard Contractual Clauses approved by the European Commission, together with additional safeguards where appropriate.
7. Your Privacy Rights
Depending on where you live, you may have rights regarding your personal data. In the EEA these may include the right to:
- request access to personal data we hold about you;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data protection authority.
In Italy, the supervisory authority is the Garante per la protezione dei dati personali.
We may need to verify your identity before responding to a request. Some rights are subject to exceptions under applicable law.
8. Account Deletion
You can initiate deletion of your Bipper account from the account settings inside the Bipper app.
Account deletion is intended to remove your account and personal data associated with it from Bipper's active systems, including user-generated content that Bipper is not legally required to retain.
We aim to complete deletion without undue delay. Certain limited information may be retained where required by law, necessary to protect the Service against fraud or abuse, or needed to establish, exercise or defend legal claims.
9. Children's Privacy
Bipper is not intended for children under the age of 13.
Where applicable law requires parental or guardian authorization for a child to use an online service or for specific processing based on consent, that authorization is required.
If we learn that we have processed personal data from a child in violation of applicable law, we will take appropriate steps to delete or otherwise address that information.
10. Security
We use reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, alteration, loss, misuse or disclosure.
No internet-connected service can guarantee absolute security. You should protect access to your device, email account and Bipper account and contact us if you believe your account has been compromised.
11. Website and Server Data
When you visit the Bipper website, the hosting infrastructure may process standard technical information such as your IP address, browser type, requested page, timestamp and basic server logs.
If we later introduce analytics, advertising technologies, cookies or additional third-party SDKs that materially change the processing described in this Policy, we will update this Policy and obtain any consent required by applicable law.
12. Changes to this Policy
We may update this Policy as Bipper develops or when legal, technical or operational requirements change.
When we make material changes, we will take reasonable steps to notify users through the Service or another appropriate method. The date at the top of this page shows when this Policy was most recently updated.
13. Contact
The data controller responsible for Bipper is:
Andriy Zherebyatyev
Via Monte San Michele 1/G, 28066 Galliate (NO), Italy
andriy.zherebyatyev@gmail.com
You may contact us at this address regarding this Privacy Policy, the processing of your personal data, or the exercise of your privacy rights.