# Buno — Privacy Policy (DRAFT)

> **⚠️ DRAFT — not legal advice.** This reflects the app's actual data
> handling as built (2026-09-27) so a lawyer can turn it into the final
> policy. Fill every `{{PLACEHOLDER}}` and have a UZ-qualified lawyer review
> it before publishing or submitting to the App Store / Google Play.

**Effective date:** {{DATE}}
**Controller:** {{LEGAL_ENTITY_NAME}}, {{ADDRESS}}, Uzbekistan
**Contact:** {{PRIVACY_EMAIL}}

## 1. What we collect

- **Account:** phone number (for OTP sign-in), display name, and — if you
  provide it — home city.
- **Interests (opt-in):** if you connect Telegram and consent, we read the
  **names/metadata of the channels and groups you belong to** (title,
  @username, description) to infer interest tags. **We never read your
  messages** and do not store channel content — only the derived tags.
- **Your activity:** intents, focus sessions, goals, cohort (group)
  membership, trips, grocery/reservation lists, and interactions with the
  Bo assistant.
- **Payments:** when you pay, the transaction is processed by **Payme**. We
  store the payment record (amount, status, timestamp) but **not your card
  number** — the card is handled by the payment provider.
- **Assistant connections (opt-in):** if you connect Google (calendar,
  email) or similar services to Bo, we access only what you authorize, to
  perform the task you asked for.
- **Device & usage:** app events and basic device info for analytics and
  crash reporting.

## 2. How we use it

- Match you with relevant people, groups (cohorts), and opportunities.
- Rank your Home feed.
- Run the Bo assistant on your requests.
- Process payments and unlocks.
- Improve the product and diagnose crashes.

We do **not** sell your personal data.

## 3. AI processing

Some features send limited data to AI providers (**Anthropic**, **OpenAI**)
— e.g. the names of channels you consented to analyze, or your Bo messages
— to classify interests or answer requests. We send the minimum needed and
validate the output.

## 4. Sensitive interests

Interest tags we treat as sensitive (e.g. mental health, recovery) are kept
**private to you**: they are never used to form discoverable groups or shown
as a matching signal to other users.

## 5. Sharing / processors

We use the following services to operate Buno and share only the minimum each
service needs:

- **PostgreSQL hosting provider (configured through `DATABASE_URL`):** stores
  Buno account and product data. The deployment vendor is not fixed in code
  and must be confirmed before publication.
- **PostHog:** product analytics and feature-flag evaluation.
- **Sentry:** backend error and crash diagnostics when enabled.
- **Firebase (Google):** social sign-in token verification, push notifications
  (FCM), mobile crash reporting (Crashlytics), and performance monitoring.
- **Anthropic:** Bo responses, intent/interest classification, and selected
  ranking tasks.
- **OpenAI:** opt-in Bo speech transcription (Whisper) and text-to-speech.
- **Payme:** payment checkout, transaction processing, and refunds; Buno does
  not receive full payment-card details.
- **Telegram / TDLib:** optional Telegram sign-in and, with consent, on-device
  chat/community access used by Telegram-connected features.
- **Yandex MapKit:** map display and location-based UI in the mobile app.

## 6. Your choices & rights

- Remove an inferred interest at any time (it also removes you from any
  group that interest formed).
- Disconnect Telegram / Google connections.
- Request deletion of your account and associated data via
  {{PRIVACY_EMAIL}}.
- {{Any rights required by UZ law / other jurisdictions the lawyer adds.}}

## 7. Retention

We keep data while your account is active and delete or anonymize it within
{{RETENTION_PERIOD}} after account deletion, except where law requires
longer (e.g. payment records).

## 8. Children

Buno is not intended for children under {{MIN_AGE}}.

## 9. Changes

We'll post changes here and update the effective date; material changes will
be notified in-app.

## 10. Contact

{{PRIVACY_EMAIL}} — {{LEGAL_ENTITY_NAME}}.
