privacy policy.
Last updated: August 23, 2026
1. who we are.
BoredApp is operated by BoredApp Inc., a corporation incorporated under the laws of Ontario, Canada (“BoredApp Inc.,” “we,” “us,” “our”). This policy explains what personal information we collect, how we use it, who we share it with, and your rights regarding that information. BoredApp is currently available only to users located in Canada. Where BoredApp is distributed via third-party platforms (such as the Apple App Store or Google Play) under a developer account or identity associated with a principal, employee, or affiliate of BoredApp Inc., that distribution is conducted on behalf of BoredApp Inc., which remains the data controller for your personal information.
2. information we collect.
We collect only the information needed to operate BoredApp as a private event planning tool. Specifically:
- Account information: your name, email address, and profile photo. Collected so you can create an account and be identified by people you invite.
- Event information: event titles, descriptions, dates, locations, invite lists, RSVPs, poll responses, and chat messages. Collected so BoredApp can coordinate your event.
- Photos you post: photos you choose to send in an event chat, group chat, or direct message, and photos you add to an event's shared album — taken with your camera or picked from your photo library. Collected so we can show them to the other people in that conversation or event. Photos are processed on your device before upload, and location metadata (including GPS coordinates) is stripped before a photo leaves your device. Album photos additionally keep one full-quality copy. See section 6 for details.
- Location data: when you explicitly opt in to share your ETA for a specific event, your device briefly transmits your current coordinates to our server so we can calculate your estimated minutes-to-arrival. We do not store your coordinates. Only the resulting ETA (a minute count) is saved to our database and shown to other attendees of that event. Your coordinates exist only in transit to the routing service and are discarded after the minutes are computed.
- Battery level: when you are actively sharing an ETA, your approximate battery percentage may be visible to other attendees of that event (shown only when it drops below 30%, so others know you may go offline soon). Not collected when sharing is off.
- Device and usage data: device type, operating system, app version, crash logs, and basic usage analytics. Used to maintain service stability and improve the product.
3. how we use your information.
We use your information solely for the purposes stated below. We do not use it for any other purpose without your consent.
- Enable you to create events and invite your friends
- Send push notifications when friends invite you to events
- Provide navigation, calendar integration, and live ETAs for events
- Facilitate event chat between invited participants
- Show photos you post — in a chat or in an event's shared album — to the other people in that event or conversation
- Operate, maintain, and improve BoredApp
- Detect and prevent fraud, abuse, or security issues
- Review content reported to us so we can act on abuse reports
- Comply with legal obligations
4. who sees your information.
BoredApp is built around private events with people you invite. Your events are visible to the people you invite, and — while your event's “Anyone with the link can join” setting is on, as it is by default — to anyone who has the event's link: a link holder can open the event's invite card, view the event, and join it, unless you switch that setting off or remove them. Switching it off makes the event invite-only: the link, the invite card, and the Photo Wall's QR code stop admitting new people, and people who already joined keep their access. Your profile information is only shared with people you connect with through event invitations. We do not have public profiles, public feeds, or discovery features that expose your information to strangers.
Photos follow the same rule, whether you send them in a chat or add them to an event's shared album: a photo is visible only to the members of that specific event or conversation — the same closed invite list that governs the chat or event itself. There is no public feed and no stranger discovery for photos. The exceptions are two surfaces a host chooses to publish. The invite card: an event's link opens as an invitation page showing the event's title, date and time, location, the host's display name, and any photos the host added to the card, without a BoredApp account. And the Photo Wall: a host can generate a link that puts their own event's album on a screen at the venue, and that link opens without a BoredApp account. Section 6 explains what a wall shows, what an event link lets someone do, and how a host turns a wall off.
5. location data.
The short version: we compute your ETA. We don't store your location. Ever.
BoredApp is built on a privacy-first principle: we never store your coordinates. When you opt in to share your ETA for an event, your device sends its current coordinates to our server long enough to compute your estimated arrival time, and then they are discarded. Only the resulting minute count is saved and visible to the host and people invited to that specific event. No map, no dot, no coordinate — just “~12 min.”
Opt-in and scoped. Sharing is always opt-in, always scoped to a single event, and always time-limited. You choose when to start, and you can stop at any time from the app or your device settings.
Automatic stop. To minimise the time your location is being queried at all, BoredApp automatically ends any sharing session when: (a) you arrive at the event venue (within approximately 200 metres), (b) one hour past the event's start time (a local notification offers a “Still coming” option if you're genuinely late), or (c) after a six-hour hard cap, whichever comes first. You can also stop manually at any time.
Routing provider. For ETA calculations, your coordinates are sent to Google's routing service (Distance Matrix API) via our Cloud Function. Google processes the coordinates to return an estimated arrival time. They exist only in transit — neither BoredApp nor Google retains them for ongoing use.
Visibility to other attendees. Other people invited to the event see your minute-count (e.g. “~12 min”) and, once you arrive, a confirmation that you've arrived. They never see your coordinates, a map position, or your route.
6. photos.
The short version: photos stay inside the event or conversation you posted them to, location metadata is stripped before upload, and the copies you see in the app are kept — they have no scheduled deletion. The one thing deleted on a schedule is the album's separate full-quality copy: within 91 days of upload, unless the album's lifetime is extended.
There are two places a photo can live, and they keep photos for different lengths of time.
- Photos in chat — sent in an event chat, group chat, or direct message from the mobile app, using either your camera or your photo library. No scheduled deletion: a chat photo remains until you delete the message, you delete your account, or the event or group chat it lives in is deleted.
- Event photo albums— a shared album attached to a single event, which anyone invited to that event can add to and view. The album copy you see has no scheduled deletion; it remains until you delete the photo, a host removes it, or the event is deleted. The separate full-quality copy is deleted within 91 days of upload unless the album's lifetime is extended.
The web app displays photos from both. Everything below applies to both unless it says otherwise.
Who can see them. A photo is visible only to the members of the specific event or conversation you posted it to — the same closed invite list that governs the event or chat itself — which includes anyone who joined using the event's link, and anyone viewing the Photo Wall described below. Photos a host adds to an event's invite card are different: by placing them on the card, the host is choosing to show them to everyone who receives the event's link, and they are visible without an account. There is no public feed and no stranger discovery: nothing you post is browsable by people who were not invited to the event or given a link to it.
Photo Wall. A host can put an event's album on a screen at the venue — the Photo Wall, called the wall. in the app. A wall is optional and specific to one event: none exists until the host or a co-host generates a link for that event, and the host can turn it off at any time. Once generated, anyone holding that link can view it without a BoredApp account — the screen at a venue is usually a TV or projector nobody can sign in on, which is the point of the feature. The wall link carries a long random token we generate; walls are never listed, indexed, or discoverable by browsing, and the token cannot be guessed.
What a link lets someone do. The wall page itself only displays — it has no upload control. The QR code on it opens the event, and that is the way in: while the host's “Anyone with the link can join” setting is on — it is on by default — anyone who has an event's link can view and join that event, unless the host removes them. That is true whether or not a wall is up — an event's link is how its invitations travel — and it is what lets guests the host could not invite one by one put their photos on the screen. Joining always requires a BoredApp account, so everyone who joins has an identity the host can see, and the host can remove a participant at any time. Switching “Anyone with the link can join” off makes the event invite-only: the event link, the invite card, and the wall's QR code stop admitting new participants, membership becomes the invite list alone, and everyone who already joined keeps their access.
What a Photo Wall shows. The event title, the album's most recent photos, the display name of whoever posted each one, and a reaction summary (the most-picked emoji and a count). It also shows a QR code that opens the event's join page — how a guest signs in and adds their own photos — which means a wall link carries the same reach as the event's share link. It does not show the event's address or location, the guest list, RSVPs, chat, anyone's account identity, or who reacted to what.
Turning a Photo Wall off. The host can revoke a wall at any time, which stops any browser still holding the link, and we recommend doing so once the event is over. A wall also ends on its own: it expires after the viewing window the host chose when creating it (hours to a few days), and moving the event to Trash revokes its walls immediately. Revoking the wall closes the screen, not the event: anyone who joined while it was up remains a participant, and anyone who still has the event's link can join while link joining is on, until the host removes them. The photos on a wall are the same files as in the album, deleted on the same schedules described below — a wall never extends how long a photo is kept.
Location metadata is stripped. Before a photo leaves your device, we strip its EXIF metadata, including any GPS coordinates, as part of on-device compression. This applies to every copy we upload, including the full-quality copy described below. Photo location metadata never reaches our servers.
Resized on your device. Every photo is processed on your device before upload. For chat photos we upload a copy at a maximum of 1440 pixels on the long edge plus a small thumbnail, and nothing larger.
Album photos also keep a full-quality copy. For event albums we upload the same 1440-pixel copy and thumbnail, and additionally store one full-quality copy of the photo (up to 24 megapixels) so the album can be kept at original quality in future. That copy is stripped of location metadata like every other, is visible to nobody today, and is deleted within 91 days of upload unless the album's lifetime is extended (see below).
Where they are stored. Photos are uploaded to Firebase Storage (Google Cloud) within BoredApp's own project, encrypted in transit and at rest by the platform. To be clear about what that does not mean: photos are not end-to-end encrypted. BoredApp can technically access them, which is what makes it possible for us to act on abuse reports.
How long we keep them. Chat photos have no scheduled deletion — they are kept with the conversation, and erased when you delete the message, delete your account, or the event or group chat is deleted. Album photos work the same way for what you see: the display copy — what you see in the app — has no scheduled deletion, so albums and event timelines keep their photos until you delete a photo, a host removes it, or the event is deleted. The album's separate full-quality copy is deleted within 91 days of upload, enforced by an automated storage lifecycle rule, unless the album's lifetime is extended. Windows run from when the photo was uploaded, not from when the event happened.
When an album keeps full quality longer. For some events we extend the album's lifetime, in which case the full-quality copies stay instead of being deleted at 91 days. If that extension ends, they are deleted on the same automated schedule. The display copies are unaffected either way — they have no scheduled deletion.
Two exceptions to both windows. Content that has been reported to us may be retained longer while we review it for moderation, and we may preserve content where required to comply with legal obligations.
Deleting a photo. You can delete a photo you posted at any time from within the app, which removes it for everyone right away — from the conversation for a chat photo, or from the album for an album photo. The host and co-hosts of an event can also remove any photo from that event's album. Deleting a photo — album or chat — also erases the stored files themselves, every copy including the album's full-quality one, right away. Deleting your account removes the photos you posted, album and chat alike, the same immediate way.
What remains after a photo is deleted. Once an album photo is deleted, its image files are erased, but a small record of the photo remains in the event so the album can show a placeholder in its place and keep its counts accurate. That record identifies who posted it and when; it does not contain the image.
Copies you saved. You can download album photos to your own device at any time. Anything you have saved to your device is yours — deletion and expiry only ever remove our copy, never yours.
Not used for anything else. We do not share your photos with third parties, and we do not use them for analytics, advertising, or personalization. Google Cloud/Firebase stores them as our infrastructure provider, acting on our instructions — not as a recipient of shared user data.
7. third-party service providers.
We use a small number of trusted third parties to operate BoredApp. These providers only receive the information needed to provide their service and are contractually required to protect it:
- Google Firebase (hosting, database, file storage for photos you send in chat, authentication, and push notifications)
- Google Analytics (anonymous usage analytics for our marketing website)
- Apple (iOS app distribution, TestFlight, and push notification delivery)
- Google Maps Platform (Apple Maps and Google Maps for turn-by-turn directions when you tap navigate; Google's Distance Matrix API to compute live arrival ETAs when you opt in to ETA sharing for an event)
We do not sell your personal information. We do not share your data with advertisers.
8. connecting an ai assistant.
You can connect an AI assistant you already use — such as Claude or ChatGPT — to your BoredApp account so it can help you plan: creating events, building trip itineraries, managing checklists, and looking up your own plans. A connection only exists after you approve it on a BoredApp consent screen while signed in to your own account, and it is limited to the permissions shown on that screen.
- What it can access: your events, trips, and checklists — and, only when the connection's permissions include them, your confirmed friends (to invite them to events) and your event chats (to post messages). The consent screen lists exactly what a connection can do before you approve it.
- What it cannot access: your sign-in credentials (connections use revocable access tokens, of which we store only a cryptographic hash), other people's accounts, or your device's location — location handling is unchanged (see section 5).
- Where your information goes: when your assistant reads or creates something for you, the relevant details flow to the AI provider you chose (for example, Anthropic or OpenAI), acting on your instructions. That provider's handling of the information is governed by its own privacy policy. We never send your information to an AI provider on our own initiative.
Disconnecting BoredApp in your AI app ends its use of your account. To have a connection's access token revoked entirely, contact us at privacy@boredapp.io and we will disable it.
9. where your data is stored.
BoredApp users are located in Canada, and our infrastructure runs on Google Cloud in the United States (Northern Virginia region). Your personal information will therefore be transferred to and processed in the United States. By using BoredApp, you consent to this transfer. We take commercially reasonable steps to ensure your data receives a comparable level of protection regardless of where it is processed.
10. how long we keep your data.
We retain your personal information only as long as needed to provide BoredApp and fulfill the purposes described in this policy.
- Active accounts: data is retained for as long as your account is active.
- Deleted accounts (in-app): when you delete your account from within the app, your personal information — including photos you posted — is removed from our active systems immediately.
- Deleted accounts (by email request): if you can't access the app and email us at privacy@boredapp.io to request deletion, your personal information is removed from our active systems within 30 days.
- Backups: residual copies may remain in encrypted backups for up to 90 days before being permanently purged through routine backup rotation.
- Deleted events: if a host deletes an event, it is moved to the host's Trash and hidden from all participants. While it sits in Trash, the event's data — its guest list, chat, polls, tasks, and any remaining photos — is still retained on our servers, and only the host can restore it, for up to 90 days. After that, the event is permanently deleted from our servers — including its chat, polls, tasks, and any remaining photos — within 91 days of deletion, enforced by an automated process that runs nightly.
- Event chat: chat messages you sent are removed from your account when you leave an event or delete your account. Other participants' copies of messages already delivered may persist in their own event history.
- Photos in chat: kept with the conversation — no scheduled deletion. Deleting a photo message removes it from the conversation for everyone right away and erases the stored file. Deleting your account erases the chat photos you sent right away, and deleting an event or group chat erases the photos posted in its chat. Reported content may be retained longer for moderation review, and content may be preserved where required to comply with legal obligations.
- Event album photos: the display copy you see in the app has no scheduled deletion — it remains until you delete the photo, a host removes it, or the event is deleted. The separate full-quality copy is automatically deleted within 91 days of upload, enforced by an automated storage lifecycle rule, unless the album's lifetime is extended; when an extension ends, it is deleted on the same automated schedule. Deleting a photo, or your account, removes it from the album for everyone right away and erases the stored files, including the full-quality copy. A record of the photo (who posted it and when, never the image) stays in the event so the album can show a placeholder and keep its counts accurate. The same moderation and legal-obligation exceptions apply.
- Live ETA data: automatically deleted within six hours of your last update, whether you stop sharing manually or a session ends via auto-stop. A scheduled cleanup sweeps any older records every fifteen minutes as a secondary safeguard. Coordinates used to compute ETAs are never stored; only the resulting minute counts, which are deleted on the same six-hour rolling basis.
- Legal retention: we may retain certain information longer if required by law (e.g., to resolve disputes or enforce agreements).
11. your rights.
Depending on where you live, you have the following rights over your personal information. To exercise any of them, contact us at privacy@boredapp.io.
- Access: request a copy of the personal information we hold about you.
- Correction: update or correct inaccurate information.
- Deletion: delete your account and associated personal information (you can do this directly in the app).
- Portability: receive a copy of your personal information in a structured, commonly used format.
- Withdraw consent: revoke permissions (for example, turn off location sharing) at any time.
- Complaint: lodge a complaint with a privacy regulator, such as the Commission d'accès à l'information du Québec (for Quebec residents) or the Office of the Privacy Commissioner of Canada.
12. data security and breach notification.
We use industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and secure authentication. However, no method of electronic storage is 100% secure. If we become aware of a security incident that compromises your personal information, we will notify affected users and the appropriate regulators without undue delay, in accordance with applicable law.
13. age requirement.
BoredApp is intended for users 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us at privacy@boredapp.io and we will delete it promptly.
14. cookies and analytics.
Our marketing website (boredapp.io) uses Google Analytics to measure traffic and understand how visitors find and use the site. This data is aggregated and does not personally identify you. The BoredApp mobile and web applications do not use advertising cookies or cross-site tracking.
15. changes to this policy.
We may update this privacy policy from time to time. When we make material changes, we will notify you through the app, by email, or by updating the “last updated” date at the top of this policy. Continued use of BoredApp after changes take effect constitutes acceptance of the updated policy.
16. privacy officer and contact.
BoredApp Inc. is the person in charge of protecting your personal information and responding to privacy requests under Quebec's Law 25 and applicable privacy laws. You can reach our Privacy Officer at:
BoredApp Inc. — Privacy Officer
Email: privacy@boredapp.io
We respond to privacy requests within 30 days of receiving them.