Privacy Policy
Last updated: [[EFFECTIVE DATE]]
Booniverse is a peer-support app for teens and young adults. This policy explains what we collect, why, who we share it with, and what you can do about it. We've tried to write it so you can actually read it. If anything here is unclear, email us at support@booniverse.boo and we'll explain it properly.
Booniverse is operated by Booniverse Inc., 115 West 27th Street, New York, NY 10001, USA.
The short version
- You must be 13 or older to use Booniverse.
- We collect your email, username, birthday, and whatever you choose to write or upload — journals, chats, forum posts, your profile photo.
- Everything you write in chats, forums, journals and reflections is sent to automated safety systems run by OpenAI and Google before or shortly after it appears. This is how we keep the app safe. It is not a person reading over your shoulder, but it is a real thing we do and you should know about it.
- We do not sell your data, we do not show you ads, and we do not use your content to train AI models.
- You can delete your account from Profile → About → Delete Account.
1. Who this applies to and how old you have to be
You must be at least 13 to create a Booniverse account. We ask for your birthday during setup and we block accounts that don't meet the minimum age.
If we find out someone under 13 has an account, we delete it and the data associated with it.
[[LAWYER: EEA/UK 13–16 parental-consent position goes here. Under GDPR Art. 8 the digital-consent age is 13–16 depending on the country. Decide whether to geo-restrict, raise the floor for the EEA, or implement parental consent, then write this paragraph to match.]]
2. What we collect
Things you give us
| What | When |
|---|---|
| Email address | Sign-up |
| Password | Sign-up (stored hashed by Firebase Authentication — we never see it) |
| Google account details | Only if you choose "Sign in with Google" |
| Username, Boo ID, birthday | Account setup |
| Profile photo, avatar, bio | Optional, any time |
| Journals and dream logs | When you write them |
| Moon reflection answers | When you do a reflection |
| BooFriend chat messages | When you chat |
| Forum posts and comments | When you post |
| Notes and anonymous (Mail-Bun) posts | When you send them |
| Reports you file about other users | When you report someone |
| Boo-Logy quiz answers and results | When you take the quiz |
| Volunteer training answers | If you train as a listener |
Things we collect automatically
- Device and app information — device model, operating system, app version.
- Login sessions — so you can see where your account is signed in. Deleted after 30 days of inactivity.
- Push notification token — so we can send you notifications.
- Country — worked out from your IP address using a service called ipapi.co, and only while your Location Access setting is on. Turning it off clears it.
- Crash reports — if the app crashes, Firebase Crashlytics sends us the technical details. These are linked to your account ID so we can tell whether a crash is affecting one person or everyone.
- Purchase records — if you buy BOO or subscribe to Boo+.
Things we don't collect
We don't collect your precise location, your contacts list, your browsing history outside the app, or anything from your camera or photo library other than the image you deliberately pick as a profile photo.
3. Why we collect it
| Purpose | What it covers |
|---|---|
| Running your account | Sign-in, profile, settings, your BOO balance |
| Making the features work | Journals, chats, forums, reflections, friends |
| Keeping people safe | Automated moderation, reports, blocking, suspensions, detecting messages about self-harm |
| Payments | Verifying purchases and Boo+ subscriptions |
| Support | Answering you when you email us |
| Fixing the app | Crash reports and error diagnostics |
| Legal obligations | Where the law requires us to keep or hand over records |
[[LAWYER: map each of these to a GDPR Art. 6 lawful basis, and an Art. 9(2) condition for the mental-health content. Safety processing is probably "substantial public interest" or vital interests — needs a real answer.]]
4. Automated safety checks — please read this one
Booniverse is a mental-health app used by teenagers. To keep it safe we check content automatically:
- Text you write — chat messages, forum posts, comments and your bio are sent to OpenAI's moderation service to check for abuse, harassment, sexual content, threats and grooming patterns. We also run our own keyword checks.
- Images you upload — profile photos and forum images are scanned by Google Cloud Vision before they are visible to anyone else. A profile photo is held in a private area where nobody can see it, including you, until it passes.
- Moon reflections and journal entries you submit for a reflection are sent to OpenAI (GPT-4o-mini) to generate the reflection you get back.
- Messages that look like they're about self-harm or a crisis are logged for our safety team to review, so we can check you're okay and show you crisis resources.
What this means in plain terms: if you write something in Booniverse, assume a computer has read it, and that a human on our safety team may read it if the computer flags it or if someone reports you.
We do not use your content to train AI models, and our providers are contractually restricted from doing so.
5. What other people can see
These are enforced by our database rules, so the limits below are real limits, not just what the app chooses to display.
| Content | Who sees it |
|---|---|
| Username, Boo ID, avatar, profile photo, bio | Any signed-in Booniverse user |
| Journal entry with friend feed on | Your friends, and nobody else |
| Journal entry with public on | Anyone who views your profile |
| Journal entry with both off | Only you |
| Forum posts and comments | Everyone |
| BooFriend chat messages | You and the person you're chatting with (plus our safety systems and, if flagged or reported, our safety team) |
| Notes | The person you send them to |
| Anonymous (Mail-Bun) posts | See below |
| Your birthday | See below |
About anonymous posts
Mail-Bun posts are anonymous to the person who receives them — their content does not carry your name, and the recipient cannot find out who sent it.
They are not anonymous to us. We keep a separate, locked record linking each anonymous post to the account that sent it, so that we can investigate abuse, harassment and safety incidents. If you use an anonymous post to hurt someone, we can identify you, and we will.
About your birthday
Your contacts see the day and month only — never the year.
Your full date of birth, your email address, your country, your push token and your notification and privacy settings are stored in a private area of your account that only you can read. Other users can't retrieve them, and that's enforced by our database rules — not just by what the app chooses to display.
We use your full date of birth to check you're old enough to be here, and to enforce the 18+ requirement for becoming a listener.
6. Who we share it with
We don't sell your personal information. We share it with service providers who help us run Booniverse:
| Provider | What they get | What for |
|---|---|---|
| Google Firebase | Account data, content, files, notifications, crash reports | Our core infrastructure. Data is stored in the United States |
| OpenAI | Text you write; journal/reflection content | Safety moderation and generating reflections |
| Google Cloud Vision | Images you upload | Scanning for unsafe images |
| Giphy | Your GIF search terms and IP address | GIFs and stickers in chat (restricted to G-rated) |
| ipapi.co | Your IP address | Working out your country |
| Apple / Google Play | Purchase information | Processing in-app purchases |
| RevenueCat | Your account ID and purchase history | Managing subscriptions |
| Google Sign-In | Sign-in identity | Only if you use it |
We may also disclose information where we're legally required to, or where we believe in good faith that it's necessary to prevent serious harm to you or someone else.
International transfers: Booniverse Inc. is a US company and our servers are in the United States, so if you're in the EEA or UK your information is handled there.
[[LAWYER: the framing above changed once the entity was confirmed as US. We are a US controller collecting directly from users, not an EEA exporter sending data out — so Chapter V transfer tools (SCCs / UK IDTA) may not be the right instrument here, while GDPR still reaches us through Art. 3(2) extraterritoriality because we offer the service to people in the EU. Confirm which analysis applies before this paragraph is published.]]
7. How long we keep things
| Data | Retention |
|---|---|
| Account and profile | While your account is open |
| Journals, reflections, forum posts, notes, anonymous posts | While your account is open |
| BooFriend chat messages | 12 months, then deleted automatically |
| Login sessions | 30 days after last activity |
| Reports, moderation flags and crisis logs | 24 months, then deleted automatically |
| Record linking an anonymous post to its sender | 24 months, then deleted automatically |
| Purchase records | As required by tax and accounting law |
| Crash reports | Per Firebase Crashlytics defaults (90 days) |
Anything kept "while your account is open" is removed when you delete your account, except the safety and purchase records described above.
[[LAWYER: confirm 12/24 months fits your jurisdiction's expectations and any mandatory-reporting duty. These are engineering defaults, set so the policy states a real period — they are not a legal determination.]]
8. Your rights and choices
You can:
- See and edit most of your information in the app (Profile → settings).
- Change your username or email once every 90 days.
- Control who sees your journals with the friend-feed and public toggles.
- Turn off push notifications, login alerts, and QR/ID discoverability.
- Block any user, and report any user or piece of content.
- Delete your account — Profile → About → Delete Account.
Depending on where you live you may also have the right to request a copy of your data, correct it, ask us to delete it, object to how we use it, or complain to your data protection regulator. Email support@booniverse.boo and we'll respond within 30 days.
What deleting your account actually removes. Your profile, journals and dream logs, moon reflections, notes and anonymous posts you received, your contacts and friend connections, your forum notifications and activity, your listener/speaker records, your profile photo and any images you uploaded, and your sign-in itself.
What we redact rather than delete. Forum posts, comments and BooFriend chat messages are removed from you — your name and the content come off them — but the entry itself stays in place, because deleting it outright would tear a hole in someone else's conversation or a live forum thread.
What we keep. Safety records (reports, moderation flags, crisis logs) and purchase records, for the reasons and periods described in section 7. If your account was suspended or banned when you deleted it, we keep a one-way scrambled version of your email address so the ban can't be shed by deleting and signing up again.
9. Security
We use Firebase Authentication, App Check, and default-deny database rules. Your password is hashed and we never see it. Sensitive actions — your BOO balance, purchases, moderation, reports — are enforced on our servers, not in the app, so they can't be faked by a modified client.
No service is perfectly secure. If we discover a breach affecting your personal data we'll notify you and the relevant regulator as required by law.
10. Changes to this policy
If we make a significant change we'll tell you in the app and ask you to accept the updated version before you continue.
11. Contact
Booniverse Inc. 115 West 27th Street, New York, NY 10001, USA support@booniverse.boo
[[LAWYER — likely REQUIRED, not optional. Art. 27 obliges a controller outside the EU that targets EU users to appoint an EU representative. The narrow exemption is for processing that is occasional, low-risk and excludes special-category data at scale — this app processes mental-health content about minors, which is the opposite of every limb of that test. UK GDPR Art. 27 is a separate appointment. Both are named in the privacy policy and cost real money, so decide early: appoint them, or geo-restrict the EEA/UK at launch.]]