Privacy Policy
Effective
What Bleep processes, why it is needed, and the choices you have.
1. Who is responsible
This policy covers the Bleep app and bleep.talk. The operator named below is responsible for deciding how personal data is used. “We”, “us”, and “Bleep” refer to that operator.
Maurice Scheffmacher, operating Bleep as an individualhello@bleep.talk
2. Information we process
- Account and profile. Your account identifier, handle, profile name, avatar, public profile link, passkey public credentials, and account status. Your passkey provider keeps the private authentication key; we do not receive your Face ID or Touch ID data.
- Messages and photos. Text and images you send in Bleeps, the sender and recipient, delivery information, and related timestamps. Uploaded photos and generated profile artwork are processed and stored to provide these features.
- Connections and calls. Information about who connects with whom, readiness, call and conversation identifiers, timing, duration, delivery outcomes, and network quality.
- Device and security information. Registered-device identifiers, operating-system and app versions, push tokens, App Attest evidence, session records, IP addresses, network endpoints, and security events.
- Usage and diagnostics. Feature-use events, connection and performance measurements, errors, diagnostic traces, and feedback. These records can be linked to your account or device. A problem report can also contain the text you choose to send.
- Optional phone discovery. Your own phone number and verification information when you choose to make yourself discoverable. Address-book discovery uses encrypted queries derived on your device. Contact names stay on your device; the service processes encrypted queries and returns encrypted matches.
- Website and support. Your email when you join the waitlist, correspondence you send us, and technical request information such as IP address, browser information, request time, and page requested.
3. Live audio and stored content
Live voice is encrypted on the sending device and decrypted on the receiving device. When a relay is needed, it forwards encrypted audio. Bleep does not keep recordings of your live conversations.
This protection for live audio does not mean that all account data or content is end-to-end encrypted. Bleep text, uploaded photos, profile artwork, connection metadata, and diagnostics are processed separately. Photos can be processed for image safety and delivery. A recipient can keep or record information you share using their own device.
4. Why we use information
We use information to create and secure accounts, authenticate devices, find participating friends, deliver Bleeps and notifications, connect live conversations, display profiles, and provide support. We also use operational and usage information to diagnose failures, measure reliability and feature use, prevent abuse, and improve Bleep.
We use waitlist emails to manage early access and contact people about their request. The waitlist service also sends the operator a signup notification.
Where a legal basis is required, we rely on performance of our agreement for the service you request; consent for processing that requires it, such as optional permissions and communications; legitimate interests for proportionate security, reliability, and service improvement; and legal obligations when applicable. You can withdraw consent without affecting processing that was lawful before withdrawal. A device permission does not authorize unrelated uses of your data.
6. Permissions and your choices
You control microphone, camera, photo-saving, contacts, local-network, and notification permissions in your device settings. Microphone access supports live speech. Camera access supports QR scanning and photos. The photo picker lets you choose images without giving Bleep general access to your photo library.
Phone discovery is optional. You can remove your number through the app’s Find friends settings. Removing the number does not delete your Bleep account. Revoking Contacts access stops future address-book access but does not automatically remove information already processed or an existing relationship.
The website does not use advertising cookies or a third-party marketing analytics SDK. The app stores local settings, session credentials, caches, and a bounded queue of operational events. Uninstalling the app does not itself delete server-side data.
7. How long information remains
Account, profile, relationship, and stored-content records remain while needed to provide the service, resolve a request, maintain security, or meet a legal obligation. Different records have different lifetimes; there is no single expiry period for all Bleep data.
Product-event records are configured to expire after 13 months. Detailed media-observation records use a 30-day cleanup cutoff. Expiry makes records eligible for backend cleanup; it does not mean every copy disappears at that exact instant. Some public image revisions remain while referenced by the service. Unreferenced revisions have a seven-day cleanup grace period.
Other logs, support correspondence, provider records, and backups require separate retention handling. Copies held by recipients cannot be recalled by Bleep. A deletion response should identify any data that must be retained and explain the reason.
8. Your rights and deletion requests
Depending on where you live, you may have rights to access, correct, receive a copy of, delete, or restrict use of your personal data; object to processing based on legitimate interests; and withdraw consent. You may also complain to your local data-protection authority, including the Swiss Federal Data Protection and Information Commissioner if applicable.
Contact the operator listed above to make a privacy request or ask to leave the waitlist. Identify your Bleep handle or waitlist email and the request. Do not send a passkey, verification code, session token, or identity document unless a secure and necessary verification process has been agreed.
We may need to verify that the request concerns your account before disclosing or deleting data. The current app does not yet provide in-app account deletion. Signing out revokes the current session; it does not erase the account. Account deletion, including associated storage and provider records, requires a separate process.
9. International processing and security
Bleep uses infrastructure and providers in more than one country. Information may be processed outside your country, including in Europe and the United States. Media relays currently include Switzerland and Mexico. A storage-region preference is not a guarantee that all processing stays in that region.
Where applicable law requires safeguards for an international transfer, the operator must establish an appropriate transfer mechanism, such as an adequacy decision or approved contractual safeguards. You can ask the operator about the safeguards applicable to your information.
We use access controls, authenticated requests, encrypted connections, and the live-audio encryption described above. No service can guarantee complete security. Keep your devices and passkey provider secure.
10. Children
Bleep is intended for people aged 16 and older. If the operator learns that a child below the applicable minimum age has provided personal data, the operator will address the account and data under applicable law. A parent or guardian can contact the operator with a concern.
11. Changes to this policy
We will publish updates on this page and change the date. Material changes will receive additional notice where required. A policy update does not by itself grant consent to a new use that requires consent.