Effective 11 August 2026

Privacy, in plain language.

This policy explains how Bora Technologies handles information when you use Alongside on iOS or Android.

Who we are

Alongside is a private reciprocal accountability and support app operated by Bora Technologies (“we”, “us”, or “our”). This policy applies to the Alongside mobile apps, website, and related services.

You can start using Alongside locally without an account. Data saved only on your device is not uploaded until you sign in or use a feature that requires the service.

What we collect

Account and identity

If you create an account, we collect an internal user ID, display name, email address where provided, identity-provider references, device/session identifiers, and your 16+ and Terms/Privacy acceptance records. We do not use your Apple, Google, or email identity as the canonical application user ID.

Content you create

This includes commitments, schedules, check-ins, outcomes, optional notes, optional images, current focus, Need Support signals, short contextual replies, support actions, invitations, and sharing choices. Free-form content may contain information you choose to enter.

Connections and activity

We process connections, accepted support roles, sharing audiences, blocks, reports, supporter breaks, Away periods, and the actions needed to operate the reciprocal support loop.

Device and diagnostics

We may collect platform and app version, IANA timezone, locale, push token, device-specific session identifier, notification settings, crash logs, diagnostics, performance information, and structural product events. We do not request contacts or precise location for the MVP.

How we use information

  • Provide local and cloud-backed check-ins, sharing, invitations, support actions, notifications, export, and account recovery.
  • Authorise access to each shared item and private image.
  • Protect accounts, rotate sessions, prevent abuse, investigate reports, and enforce blocks.
  • Maintain reliability, diagnose crashes, and understand structural feature use.
  • Meet legal, safety, and store-platform obligations.

Analytics boundaries

Analytics is on by default with an in-app opt-out. Structural events may describe that an action occurred, but analytics must not receive commitment text, notes, Ask or reply text, photos, names, email, phone numbers, OTPs, tokens, or signed media URLs.

When information is shared

People you choose

Sharing is specific to each commitment. New supporters see updates from acceptance onward unless you explicitly share the previous seven days. A support mode does not grant extra content visibility. Current Focus has its own audience. Cloud backup alone never makes content visible to another user.

Service providers

We use replaceable providers to operate the service. Launch providers may include AWS for APIs, private object storage, configuration and scheduling; MongoDB Atlas for cloud data; Expo Push Service for notifications; MSG91 for email OTP; PostHog for structural analytics; Sentry for crash diagnostics; and Apple or Google for sign-in. They process information only for the relevant service and under their own applicable terms.

We do not sell personal information and do not use private content for advertising. Alongside has no public profiles or public feed.

Legal and safety disclosures

We may disclose limited information where required by law, to protect users and the service, or during a business transaction subject to appropriate safeguards. We will not treat a support relationship as permission to disclose additional content.

Your choices and controls

  • Use private local features before creating an account.
  • Choose an audience for each commitment and for Current Focus.
  • Keep an image “Only me” even when a check-in is otherwise shared.
  • Leave a commitment, remove a connection, or block another person.
  • Use private notification previews or deny notifications.
  • Opt out of analytics in Settings.
  • Export a basic machine-readable copy of your account data.
  • Delete individual check-ins and their images, or request account deletion.

Retention and deletion

We keep account and cloud content while your account is active and as needed to operate the service. Private image retention follows its check-in: deleting the check-in deletes the image and revokes future access.

Account deletion has a 7-day recovery window. During that period the account is disabled and can be recovered. After the window, private content and live profile data are permanently deleted. Shared history that another user legitimately needs may retain an inert, anonymised or tombstoned record instead of a live profile. Operational logs are configured for 30-day retention. Encrypted backups may retain deleted data for a limited backup lifecycle and are not restored except for disaster recovery.

See the account deletion page for request steps and details.

Security

Production traffic is encrypted in transit. Tokens and secrets are stored using platform-protected storage on the device. Refresh sessions are stored server-side and can be revoked per device or everywhere. Images use private storage with short-lived authorised upload and read URLs; permanent public image URLs are not used.

No service can guarantee absolute security. Please contact us promptly if you believe your account or data is at risk.

Age, international use, and changes

Alongside is intended for people aged 16 and over. We ask for a simple 16+ confirmation and do not collect date of birth unless a later legal requirement makes it necessary.

Information may be processed in countries where our providers operate. We use contractual and technical safeguards appropriate to the service. We may update this policy as Alongside changes or legal requirements evolve; the effective date at the top will change, and material changes will be communicated in the app or through another appropriate channel.

Contact us

For privacy questions, access requests, or concerns, use the subject “Alongside privacy request.”