Privacy policy
Last updated: May 11, 2026.
This Privacy Policy explains how Get Bouncy ("we", "us", "our"), a desktop focus timer with webcam-based exercise mini-games, collects, uses, and protects information when you use our service.
By using Get Bouncy, you agree to the collection and use of information described in this policy.
The short version
Your webcam feed never leaves your device. Pose detection runs locally in your browser via WebAssembly. We do not record, store, or upload video, frames, or pose data. We only collect the minimum needed to run accounts, billing, and product analytics.
1. Information we collect
1.1 Account information
When you create an account, we collect:
- Email address
- Password (hashed, never stored in plain text)
- Optional name
- OAuth provider information (if you sign in with a social provider)
1.2 Subscription and payment information
Payments are processed by our payment provider. We do not see or store your full card details. We do store:
- Subscription status and plan
- Customer ID from the payment provider
- Billing history and invoices
1.3 Usage and product analytics
To improve the product, we collect anonymized data about how the Service is used:
- Number and length of focus sessions
- Game scores and completion rates
- Aggregated movement metrics (for example, calories estimated, range of motion totals)
- Performance metrics (load times, errors)
- Country-level location, derived from IP address
1.4 Information we do NOT collect
- Webcam video, frames, or images of you
- Pose keypoints or biometric identifiers
- Your full IP address (we discard it after deriving country)
- Browsing history outside the Service
- Personal data about people other than the account holder
2. Webcam and pose detection
Important
Pose detection runs entirely on your computer. When you start a game, a WebAssembly model loads in your browser. It analyzes your webcam feed locally, frame by frame, to detect body position. Frames are processed in memory and discarded immediately. Nothing leaves your device.
Your browser or operating system will ask for webcam permission before any game starts. You can revoke permission at any time through your browser or OS settings. Without webcam access, the games will not run.
Nothing from your camera is ever saved or shared. We do not record, transmit, or store any video, image, frame, or pose data from your webcam:
- No webcam frames or video are uploaded to our servers.
- No images, video, or pose data are written to our application database (Convex) or any other server-side storage.
- No webcam data is sent to any third-party service, analytics provider, or model training pipeline.
- Pose keypoints exist only in memory on your computer for the duration of a frame and are then discarded.
Your camera stays on your computer. Nothing about your face, body, or surroundings leaves your device.
3. How we use your information
We use the information described above to:
- Provide and operate the Service (run your account, deliver games, save settings)
- Process payments and manage subscriptions
- Send service-related emails (receipts, password resets, important notices)
- Analyze aggregated usage to improve the Service
- Detect and prevent abuse or fraud
- Comply with legal obligations
We do not sell or rent your personal data. We do not use your data to train machine learning models.
4. Third-party services
We use the following providers to deliver the Service:
| Service | Purpose | Data shared |
|---|---|---|
| Vercel (Vercel Inc., USA) | Hosting, edge delivery, and first-party analytics (Vercel Analytics, Speed Insights) | Request metadata, anonymized usage and performance data |
| Convex (Convex, Inc., USA) | Application database for accounts, settings, and usage metrics (no webcam, image, or pose data) | Account ID, settings, session metrics |
| Google Analytics 4 (Google Ireland Ltd., Ireland) | Aggregated audience and traffic analytics | Anonymized IP, page views, device and browser type, country |
| Payment provider | Billing and subscriptions | Email, billing details |
| Email provider | Transactional email (receipts, password resets) | Email address, message content |
| Authentication provider | Sign-in and session management | Email, hashed credentials |
Each provider acts as a data processor on our behalf, under a data processing agreement. Google Analytics is configured with IP anonymization and loads only after you accept analytics cookies on our consent banner.
5. Data retention
| Data type | Retention period |
|---|---|
| Account data | Until you delete your account |
| Usage analytics | 90 days, then aggregated and anonymized |
| Billing records | 7 years (legal and tax compliance) |
| Server logs | 30 days |
6. Cookies
Essential cookies are always on. They are required for the Service to work:
- Authentication (keep you signed in)
- Theme preference (dark or light mode, where applicable)
- Cookie consent state
Analytics cookies are loaded only after you accept on our consent banner. They are used by Google Analytics 4 to measure aggregated traffic. IP addresses are anonymized before storage and we do not combine analytics data with your account identity.
We do not use third-party advertising cookies, cross-site tracking, or social media tracking pixels.
7. International data transfers
Your data is stored and processed in the European Union and the United States, depending on the provider:
- Convex (application database): hosted in the EU West (Ireland) region. Customer account, settings, and usage data physically reside in the EU.
- Vercel (hosting and edge delivery): operates globally; some processing occurs in the United States.
- Google Analytics: operated by Google Ireland Ltd. (EU) with onward access to Google LLC (United States). IP addresses are anonymized before storage.
For any transfer of personal data outside the European Economic Area, we rely on:
- Standard Contractual Clauses (SCCs) signed with each non-EU processor, as approved by the European Commission under Article 46(2)(c) GDPR
- Independent security certifications held by our processors (for example, Vercel and Convex hold SOC 2 Type II; Vercel also holds ISO 27001), which provide third-party assurance of their security controls
- Data Processing Agreements (DPAs) signed with each processor under Article 28 GDPR
These mechanisms apply to the providers listed above and to any other processor we use that transfers data outside the EEA.
8. Your rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated data
- Export your data in a portable format
- Object to certain processing
- Withdraw consent for processing based on consent
To exercise any of these rights, email hello@getbouncy.app with the subject line "Privacy request" and the email on your account. We respond within 30 days.
8.1 EU residents (GDPR)
You have the rights listed above plus the right to lodge a complaint with your local supervisory authority.
8.2 California residents (CCPA)
You have the rights listed above plus the right to know what personal information we collect and the right to non-discrimination for exercising your privacy rights. We do not sell personal information.
9. Security
We protect your data with:
- TLS 1.2+ encryption in transit
- Encryption at rest for stored data
- Password hashing with industry-standard algorithms
- Access controls and least-privilege principles for our team
- Regular review of dependencies and infrastructure
No system is 100% secure. We cannot guarantee absolute security but we take it seriously.
10. Children
Get Bouncy is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. For material changes we will:
- Post the updated policy on this page and update the "Last updated" date
- Email you for significant changes
- Show a notice in the app
12. Contact
For privacy questions or to exercise your rights, email hello@getbouncy.app.