Privacy Policy
Last Updated: September 2026
1. Introduction
Bombajom Photos ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
By using Bombajom Photos, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our App.
2. Information We Collect
2.1 Photos and Videos
We do not collect, store, or process your photos or videos. At home, your photos and videos travel directly from your device to storage you own, such as a Network Attached Storage (NAS) device. Away from home, if you have turned on backing up from anywhere, they travel through a relay we operate; see Section 4.1 for exactly what that means. We do not keep a copy of your media files, and nobody at Bombajom browses or analyzes them.
- Photos and videos remain on your device until successfully transferred to your storage
- Transfers occur over your local network, or over an encrypted connection when routed through our relay
- We do not maintain copies of your photos or videos on any of our servers
2.2 NAS Credentials
To connect to your NAS, the App requires your NAS username and password. This information is stored securely on your device:
- iOS: Stored in the Secure Enclave/Keychain, protected by Face ID, Touch ID, or device passcode
- Android: Stored in Android Keystore with hardware-backed encryption (when available)
- Credentials are encrypted at rest and never transmitted to our servers
- We never have access to your NAS credentials
2.3 Device Information
We may collect limited device information for app functionality and error reporting:
- Device model and operating system version
- App version number
- Device identifiers (anonymized where possible)
- Network connectivity information
2.4 Error and Crash Reports
The App contains a crash-reporting tool (Sentry, on mobile only) that, if switched on for a build, would send error messages, stack traces, and your device model, operating system version and app version. Whether it is switched on is decided when we build the App, not by anything you do in the App. The current version of the App does not have it switched on, so it sends no crash reports. There is no in-app setting to turn this on or off. If we ever ship a build with it switched on, we will update this policy and both app store listings before that build reaches anyone, and no personal data or photo content would be included in a crash report.
2.5 Usage Data
The App also contains a usage-analytics tool that can queue events such as which features are used or whether a sync succeeded. As with crash reporting, whether it actually sends anywhere is decided when we build the App. The current version of the App does not have it switched on, so these events stay queued on your device and are never sent anywhere. There is no in-app setting to turn this on or off. If it is ever switched on, events would go to infrastructure we operate ourselves, not a third party, tied to a randomly generated identifier created on your device rather than your name or email, and we will update this policy and both app store listings before that build reaches anyone.
2.6 Your Bombajom Account
Backing up requires a Bombajom account. Creating one means we hold:
- Your email address and, if you provide one, your name
- An account id
- Which plan you are on and your licence state, including the identifiers Stripe or the app stores use for your subscription or purchase
- A notification token for each device, so we can tell you when something needs your attention
If you install the companion server, we also hold a record that it was activated, which includes any label you give your own computer, for example "Home Mac" or "Living room NAS".
This account data is held in our database, provided by Supabase; see Section 5.5. No payment card details are ever included.
3. How We Use Your Information
We use the information we collect for the following purposes:
- App Functionality: To enable photo backup to your NAS, manage sync queues, and provide core features
- Account and Notifications: To operate your Bombajom account, apply your plan and licence, and notify you about your backups through Firebase Cloud Messaging or APNs
- Error Resolution: To identify and fix bugs, crashes, and technical issues, in any future release where crash reporting is switched on
- App Improvement: To understand how the App is used and improve user experience, in any future release where usage analytics is switched on
- Security: To protect against fraud, abuse, and security threats
- Legal Compliance: To comply with applicable laws and regulations
We do not:
- Access, view, or analyze your photos or videos
- Share your data with third parties for advertising or marketing
- Sell your personal information
- Use your photos for machine learning or AI training
4. Data Storage and Location
4.1 Your Photos and Videos
At home, your photos and videos travel straight from your phone to storage you own: a NAS device, a computer, or an external drive. We do not maintain any servers that store your media files.
Away from home, if you have turned on backing up from anywhere, your photos travel through a relay we operate. The relay passes traffic between your phone and your own storage and stores nothing: there are no database writes, no file writes, and no object storage on the relay, and it does not inspect what passes through beyond what is needed to route it. It does terminate the encrypted connection on both legs, so there is no end-to-end encryption layer between your phone and your storage in that case. The relay is equipment we operate rather than a direct connection, and we will not pretend it is not there.
4.2 App Data
The following data is stored locally on your device:
- NAS connection credentials (encrypted in device keychain/keystore)
- Sync queue and status information
- App settings and preferences
- Local database of synced assets (metadata only, not photo content)
This data stays on your device. Separately, using the App requires a Bombajom account, so your account details, your plan and licence state, and a notification token for each device do reach our servers; see Section 2.6. Crash reports and usage data would also reach us if they were switched on for a build, which they are not in the current version; see Sections 2.4 and 2.5.
5. Third-Party Services
5.1 Sentry (Error Monitoring)
We use Sentry (sentry.io) to monitor app crashes and errors, on mobile only, when it is switched on for a build. Sentry may collect:
- Error messages and stack traces
- Device information (model, OS version, app version)
- App state at time of error
The current version of the App does not have Sentry switched on, so no crash reports are sent to it; see Section 2.4. No personal data or photo content is ever sent to Sentry. For more information, see Sentry's Privacy Policy: https://sentry.io/privacy/
5.2 Stripe (Payment Processing)
We use Stripe (stripe.com) to process subscription payments made through our website. Stripe may collect:
- Payment card details (processed directly by Stripe, never stored by us)
- Billing address
- Transaction history
We never store or have access to your full payment card details. For more information, see Stripe's Privacy Policy: https://stripe.com/privacy
5.3 App Stores
When you download the App from the Apple App Store or Google Play Store, those platforms may collect information according to their respective privacy policies. We do not control this data collection. Apple and Google each play two further roles, described in Sections 5.6 and 5.7.
5.4 Google ML Kit (On-Device Only)
The App uses Google ML Kit for on-device image labeling. This processing occurs entirely on your device:
- No images or image data are sent to Google servers
- The ML model is bundled with the App (~3 MB)
- Generated labels are stored locally in the App's encrypted database
5.5 Supabase (Account Database)
We use Supabase to run the database behind Bombajom accounts. It holds the account information described in Section 2.6: your email address, name if provided, account id, plan and licence state (including Stripe customer and subscription ids, and in-app purchase transaction ids), a notification token for each device, and server activation records, including any label you give your own computer. Supabase never processes payment card details.
5.6 Google (Sign-In and Notifications)
Beyond distributing the App through the Play Store (Section 5.3), Google plays two further roles:
- Google Sign-In, if you choose to sign in to your Bombajom account with your Google account instead of an email and password
- Firebase Cloud Messaging, which delivers push notifications to your device
5.7 Apple (Sign-In and Notifications)
Beyond distributing the App through the App Store (Section 5.3), Apple plays two further roles:
- Sign in with Apple, if you choose to sign in to your Bombajom account that way instead of an email and password
- APNs (Apple Push Notification service), which delivers push notifications to your device on iOS
5.8 Resend (Transactional Email)
We use Resend to send email, for two flows only:
- A one-time reminder if you create an account and never start a backup
- A password reset email, sent when an administrator initiates one on your behalf
5.9 Cloudflare (Binary Hosting and Bot Protection)
Cloudflare plays two distinct roles:
- R2 hosts the downloadable installers and binaries for the companion app. No user data is stored there.
- Turnstile is a CAPTCHA on the web dashboard's sign-in and sign-up pages. It sends your browser and request signals to Cloudflare so it can score whether the request is from a bot.
5.10 Subprocessor List
The following table lists all third-party services that may process personal data on our behalf. We maintain Data Processing Agreements (DPAs) with processors that handle personal data subject to GDPR.
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Sentry (Functional Software, Inc.) | Error monitoring (not active in the current App release; see Section 2.4) | Error logs, device info, app state (no PII) | United States |
| Stripe, Inc. | Payment processing | Payment details, billing address, transaction history | United States |
| Apple Inc. | App distribution and in-app purchases (App Store); Sign in with Apple; push notification delivery (APNs) | Purchase history, device identifiers; sign-in identity if you use Sign in with Apple; notification delivery tokens | United States |
| Google LLC | App distribution and in-app purchases (Play Store); Google Sign-In; push notification delivery (Firebase Cloud Messaging) | Purchase history, device identifiers; sign-in identity if you use Google Sign-In; notification delivery tokens | United States |
| Supabase, Inc. | Account database | Email, name, account id, plan and licence state (including Stripe and in-app purchase identifiers), notification tokens, server activation records including any label you give your own computer | United States |
| Resend | Transactional email | Email address, for a one-time backup reminder or an admin-triggered password reset | United States |
| Cloudflare, Inc. | R2: binary hosting. Turnstile: bot-detection CAPTCHA on the web dashboard | R2: no user data. Turnstile: browser and request signals | United States |
| Plausible Insights OÜ (Analytics) | Privacy-friendly website analytics | Page views, referrers (no cookies, no PII) | European Union |
This list was last updated in September 2026. We will update this list when we add or remove subprocessors and notify users of material changes.
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption: NAS credentials are encrypted using device hardware security (Secure Enclave, Android Keystore)
- Secure Connections: All data transfers use encrypted protocols (SMB3, HTTPS/WebDAV, or TLS through our relay when backing up away from home)
- Local Processing: All photo processing, including image labeling, occurs on your device, not on remote servers
- No Cloud Photo Storage: Your photos and videos are never stored on a server we operate. We do run cloud infrastructure for your account and, when you back up away from home, the relay described in Section 4.1, but neither stores or processes your media
- Minimal Data Collection: We only collect the minimum information necessary for app functionality
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or United Kingdom, you have certain data protection rights under the General Data Protection Regulation (GDPR):
7.1 Right to Access
You have the right to request copies of your personal data. You can export your app data (including settings, sync queue, and metadata) through the App's Privacy Rights section in Settings → About → Privacy Rights.
7.2 Right to Rectification
You have the right to request correction of inaccurate personal data. You can update your NAS credentials and app settings directly in the App.
7.3 Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data. You can delete all locally stored app data, including stored credentials, through the App's Privacy Rights section. To delete the account data described in Section 2.6 (held by Supabase), use Settings → Account → Delete Account in the App. Note: Deleting app data will require you to reconfigure your NAS connection.
7.4 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You can export your data as JSON through the App's Privacy Rights section.
7.5 Right to Object
You have the right to object to processing of your personal data. There is no in-app setting to disable crash or usage reporting, because the current release does not send either (see Sections 2.4 and 2.5). You can delete your Bombajom account (Settings → Account → Delete Account) or uninstall the App.
7.6 Right to Restrict Processing
You have the right to request restriction of processing of your personal data. You can stop using the App or disable specific features.
7.7 Right to Withdraw Consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. You can do this by uninstalling the App or disabling features that require consent.
7.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. Contact your local data protection authority.
To exercise any of these rights, please contact us at privacy@bombajom.com.
8. Your Rights Under CCPA (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with additional rights regarding your personal information.
8.1 Right to Know
You have the right to request that we disclose what personal information we collect, use, and disclose about you. The categories of personal information we collect are described in Section 2 of this Privacy Policy.
8.2 Right to Delete
You have the right to request deletion of your personal information. You can delete all locally stored app data through the App's Privacy Rights section in Settings → About → Privacy Rights, and delete your Bombajom account (Section 2.6 data, held by Supabase) through Settings → Account → Delete Account.
8.3 Right to Correct
You have the right to request correction of inaccurate personal information. You can update your settings and credentials directly in the App.
8.4 Right to Opt-Out of Sale or Sharing
We do not sell or share your personal information as defined under the CCPA/CPRA. We do not sell personal information to third parties for monetary or other valuable consideration. We do not share personal information for cross-context behavioral advertising.
8.5 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. We will not deny you services, charge you different prices, or provide a different quality of service because you exercised your rights.
8.6 Categories of Personal Information
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
| Category | Collected | Sold | Disclosed for Business Purpose |
|---|---|---|---|
| Identifiers (device ID, account email, account id) | Yes | No | Yes (Supabase: account database; Google or Apple: sign-in, if used; Resend: a backup reminder or a password-reset email) |
| Internet activity (app usage, error logs) | No (crash and usage reporting exist in the App but are not switched on in this release; see Sections 2.4 and 2.5) | No | No |
| Commercial info (purchase history) | Yes | No | Yes (Stripe and App Stores: payment processing) |
| Geolocation | No | No | No |
| Biometric data | No | No | No |
| Sensitive personal information | No | No | No |
8.7 How to Exercise Your Rights
To exercise your CCPA rights, you may:
- Use the in-app Privacy Rights section (Settings → About → Privacy Rights) for locally stored app data
- Use Settings → Account → Delete Account in the App for your Bombajom account data
- Email us at privacy@bombajom.com
We will respond to verifiable consumer requests within 45 days. If we need more time (up to 90 days total), we will inform you of the reason and extension period in writing.
9. Children's Privacy
Our App is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
10. Data Retention
We retain your information only for as long as necessary to provide the App's functionality and comply with legal obligations:
- Locally Stored App Data: Retained on your device until you delete the App or clear app data
- Account Data: Retained by Supabase for as long as your Bombajom account exists, and removed from our systems when you delete your account (Settings → Account → Delete Account)
- Error Reports: Not currently generated, because crash reporting is not switched on in this release (see Section 2.4). If a future release switches it on, reports would be retained by Sentry according to their retention policies (typically 90 days)
- Analytics Data: Not currently generated, because usage analytics is not switched on in this release (see Section 2.5). If a future release switches it on, events would be retained in a form tied to the random per-device identifier described there
When you delete the App, all locally stored data is removed. Deleting the App does not delete your Bombajom account; to remove your account data from our systems, delete your account as described above.
11. International Data Transfers
Your photos and videos are stored on storage you own, and the app data described in Section 4.2 is stored locally on your device. Your Bombajom account data (Section 2.6) and communications with the subprocessors listed in Section 5.10 may be processed in the United States and other countries outside the EEA and UK.
We ensure that any international transfers comply with applicable data protection laws, including GDPR requirements for transfers outside the EEA.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
Material changes will be communicated through:
- In-app notifications (if significant)
- Email notification (if you have provided your email address)
- Update to this page
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: privacy@bombajom.com
Support Email: support@bombajom.com
Website: https://photos.bombajom.com