Bridge

Legal

Privacy Policy

Last updated: July 15, 2026


1. Introduction

This Privacy Policy explains how Bridge Agentic Solutions LLC ("Bridge," "we," "us," or "our") collects, uses, stores, and shares information when you use Bridge — including the Bridge mobile application, the bridgedev.io website, the newsletter, and any related services (collectively, the "Service").

This policy applies to information collected through the Service. It does not cover the practices of third-party services that you connect to Bridge (for example, the LLM provider whose API key you supply — see Section 4) or websites that link to or from Bridge.

If you do not agree with this policy, do not use the Service.

2. Information We Collect

Account Information

When you create a Bridge account, we collect:

  • Your email address and authentication metadata (handled by Google Firebase Authentication).
  • Display name and account preferences you provide.
  • Records of password resets, sign-ins, and similar account events.

User Content

We store the notes, ideas, prompts, generated outputs (specifications, schemas, plans, chat transcripts), and other content you create or generate through the Service. This is necessary to provide the Service — without storing your notes, we cannot show them to you across sessions or run AI features on them.

Newsletter Data

If you sign up for the Bridge newsletter, we collect:

  • The email address you provide.
  • The free-text idea you optionally share through the Share Your Idea form (stored on your contact record in Loops as idea_text).
  • Classification, expansion, and proposed-next-feature notes the founder may add to your contact record while preparing personalized newsletter emails (idea_classification, idea_expansion, idea_next_features).
  • Email engagement metadata (opens, clicks, send timestamps).

Website Analytics

On the bridgedev.io website (not in the mobile app), we use Google Analytics 4 to understand site usage in aggregate. GA4 may collect:

  • Pages visited, referrer, browser type, and approximate location (city-level, derived from IP).
  • Anonymized device and session identifiers.

IP addresses are anonymized by GA4 before storage. See our Cookie Policy for cookie details. The mobile app does not use GA4.

Mobile App Diagnostics

The Bridge mobile app uses Google Firebase Crashlytics to collect crash reports and diagnostic data so we can identify and fix stability problems. When the app crashes or encounters an unhandled error, Crashlytics may collect:

  • Crash stack traces and error messages;
  • Device model, operating system version, and app version;
  • A randomly generated app-instance identifier.

This diagnostic data does not include your notes, chats, or other content. Crash data is retained by Google for up to ninety (90) days. We do not use it for advertising, and diagnostic collection is disabled in development builds.

Payment Information

Payments are processed by Stripe, Inc. We do not see or store your full payment card details. What Bridge receives from Stripe is limited to: customer ID, billing email, subscription tier, subscription status, renewal date, and invoice metadata. Refer to Stripe's Privacy Policy for how Stripe handles your card details.

If you subscribe in the future via Apple In-App Purchase, Apple processes your payment under Apple's policies. RevenueCat (our subscription reconciliation layer, when added) processes only the metadata required to link your Apple transaction to your Bridge account.

Communications

If you reply to an email we send (welcome, newsletter, support), we receive your reply in our inbox and store it there as part of our normal communications records.

3. How We Use Information

We use the information we collect to:

  • Operate, maintain, and improve the Service.
  • Process subscriptions, send payment receipts, and manage your account.
  • Respond to your support requests and communications.
  • Send transactional emails (account verification, password resets, subscription confirmations) and product communications (newsletter, feature announcements) you have opted in to.
  • Understand product usage in aggregate, identify issues, and prioritize roadmap work.
  • Detect, prevent, and investigate fraud, abuse, or security issues.
  • Comply with legal obligations and enforce our Terms of Service.

We send commercial email in compliance with the CAN-SPAM Act. Every marketing email includes a one-click unsubscribe link. Unsubscribing stops marketing emails but not transactional emails (such as receipts or critical service notices).

4. AI Sub-processors and BYOAPI

AI processing in Bridge takes one of two paths, depending on whether the work runs on your free monthly allowance or on an API key you supplied.

Free monthly allowance. Every account receives five (5) classify-and-expand runs per calendar month, paid for by Bridge. For these runs, your note text is sent to Google Vertex AI (Gemini 3.5 Flash) under Bridge's Google Cloud account; the result is returned and stored on your note. This includes notes submitted through the "try it" demo on bridgedev.io.

Your own API key. For all other AI usage (note classification, semantic expansion, Build Plan generation, Chat), Bridge sends the content of your notes and prompts to the third-party LLM provider you have selected, using the API key you have supplied. The provider processes that content and returns a response, which Bridge surfaces in the app.

What this means in practice:

  • Content sent on your own key is processed by your chosen provider (Anthropic, OpenAI, or Google) under that provider's privacy terms — not Bridge's. Content sent on your free monthly allowance is processed by Google Vertex AI under Bridge's Google Cloud account.
  • Bridge does not enter into Business Associate Agreements or other data-processing agreements on your behalf with these providers. The provider's standard API terms apply between you and the provider.
  • Your API key is stored encrypted in Google Secret Manager on Bridge's infrastructure, and is used only to authenticate the calls Bridge makes on your behalf to the provider you selected. We do not transmit your key to any party other than that provider.
  • The bridgedev.io "try it" demo: when you are signed in and submit a note on the website, the site (a Cloudflare Worker) forwards your Firebase authentication token to a Bridge Cloud Function, which runs the classify-and-expand on your free allowance and saves the note to your Bridge account — so it is waiting for you when you open the app.
  • Note content is sent to an LLM provider only when you use an AI feature — either on your free monthly allowance (to Google Vertex AI) or on your own key (to the provider you chose). If you never use an AI feature, no note content is sent to any provider.

Each provider has its own privacy policy and data-retention practices:

  • Anthropic — Privacy Policy (commercial API data is not used to train Anthropic models by default).
  • OpenAI — Privacy Policy (commercial API data is not used to train OpenAI models by default).
  • Google (Gemini API) — Privacy Policy and Gemini API-specific terms apply.

If you switch providers in your Bridge settings, future AI requests go to the new provider. Past requests remain governed by the prior provider's terms with respect to any data they retained.

5. Data Storage and Retention

Bridge stores data with the following providers:

  • Google Firebase (United States) — account data, user content (notes, plans, generated artifacts), app configuration.
  • Google Vertex AI (United States) — note text processed for the free monthly classify-and-expand allowance (see Section 4), under Google Cloud's data-processing terms.
  • Google Secret Manager (United States) — the LLM API key you supply, encrypted at rest.
  • Google Firebase Crashlytics (United States) — mobile app crash reports and diagnostic data (see Section 2, "Mobile App Diagnostics").
  • Loops (operated by Loops Inc., using Amazon SES for delivery; United States) — newsletter contacts and the contact properties described in Section 2.
  • Stripe (United States) — subscription billing records.
  • Cloudflare Workers (global edge network) — website traffic and edge function execution data for bridgedev.io.
  • Google Analytics 4 (United States) — website measurement data for bridgedev.io.

Retention:

  • Account and user content: retained for the life of your account. If you delete content within the app, it is removed from active storage and from backups within thirty (30) days.
  • Closed accounts: account data is deleted within ninety (90) days of account closure, except for records we must retain by law (for example, payment records for tax purposes, typically seven years).
  • Newsletter data: retained until you unsubscribe. Unsubscribing removes you from active sends within seven (7) days; we keep the suppression-list record indefinitely to honor your opt-out.
  • Analytics: GA4 default retention applies (currently fourteen months for event data unless extended).
  • Mobile diagnostics: Crashlytics crash data is retained by Google for up to ninety (90) days.
  • Payment records: retained by Stripe per its policies. Bridge's subscription metadata is retained for at least seven (7) years for tax and accounting compliance.

6. How We Share Information

We do not sell your data. We do not rent your data. We do not share your User Content for cross-context behavioral advertising.

We share data only as needed to operate the Service, with the following categories of recipients:

  • LLM providers you have selected (Anthropic, OpenAI, Google) — note content and prompts, when you use AI features. See Section 4.
  • Infrastructure providers we use to operate the Service — Google Firebase, Cloudflare, Loops / Amazon SES, Stripe, RevenueCat (future), Google Analytics. Each acts as a sub-processor and is bound by their own privacy commitments.
  • Legal compliance. We may disclose information when required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Bridge, our users, or others.
  • Business transfers. If Bridge Agentic Solutions LLC is acquired, merged, or sells substantially all of its assets, user information may be transferred as part of that transaction. We will provide notice and any required consent opportunity in line with applicable law.

7. Cookies and Similar Technologies

The bridgedev.io website uses a small set of strictly necessary cookies and privacy-first analytics cookies. The Bridge mobile application does not use web cookies (the app uses platform-standard secure storage). Full details are in our Cookie Policy.

8. Your Rights and Choices

You can:

  • Access the personal information we hold about you by writing to privacy@bridgedev.io.
  • Correct inaccurate information by editing your account settings or contacting us.
  • Export your notes, plans, and generated artifacts. Export functionality is available in-app and is also available on request. If we discontinue the Service, we commit to providing data export during the 90-day discontinuation notice period (see Terms of Service §5).
  • Delete your account and associated content by contacting privacy@bridgedev.io. Deletion takes effect within thirty (30) days, subject to legal retention requirements.
  • Unsubscribe from marketing email via the one-click link at the bottom of any marketing email. Transactional email related to your subscription continues regardless.

9. U.S. State Privacy Rights

Bridge applies a uniform set of privacy rights to all U.S. residents, regardless of state of residence. We do this because (a) state-by-state privacy laws now cover a substantial majority of U.S. residents, and (b) it is simpler and fairer for us to honor the same rights for everyone than to gate them by ZIP code.

Rights We Honor for All U.S. Residents

Regardless of which state you live in, you have the following rights with respect to your personal information:

  • Right to know. Request confirmation of whether we process your personal information and the categories of information we collect, the purposes we use it for, and the categories of third parties we share it with.
  • Right of access. Request a copy of the personal information we hold about you.
  • Right to delete. Request deletion of your personal information, subject to legal retention requirements (for example, tax records).
  • Right to correct. Request correction of inaccurate personal information.
  • Right to portability. Request a copy of your data in a structured, machine-readable format.
  • Right to opt out of sale or sharing. Direct us not to sell or share your personal information. (We do not sell or share personal information — see below.)
  • Right to opt out of targeted advertising. Direct us not to use your personal information for targeted advertising. (We do not engage in targeted advertising.)
  • Right to opt out of profiling. Direct us not to use automated profiling that has legal or similarly significant effects on you. (We do not perform such profiling.)
  • Right to limit use of sensitive personal information. Direct us to limit our use of sensitive personal information to what is reasonably necessary to deliver the Service.
  • Right to non-discrimination. We will not deny you the Service, charge you a different price, or provide a different level of service because you exercised any of these rights.
  • Right to appeal. If we deny a privacy request, you may appeal by replying to our denial; we will respond to appeals within sixty (60) days.

We Do Not Sell or Share Personal Information

Bridge does not sell or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA / CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), or any analogous U.S. state privacy law. Bridge has not sold or shared personal information in the past twelve (12) months and does not intend to do so.

We honor Global Privacy Control (GPC) browser signals as an opt-out request where required by applicable law (including Colorado and Connecticut).

State-Specific Frameworks

The following state laws may apply to you depending on your residence. The rights above are designed to satisfy each. The applicable statute is identified for your reference:

  • California — California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act.
  • Virginia — Virginia Consumer Data Protection Act (Va. Code § 59.1-575 et seq.).
  • Colorado — Colorado Privacy Act (Colo. Rev. Stat. § 6-1-1301 et seq.).
  • Connecticut — Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq.).
  • Utah — Utah Consumer Privacy Act (Utah Code § 13-61-101 et seq.).
  • Texas — Texas Data Privacy and Security Act (Tex. Bus. & Com. Code § 541.001 et seq.).
  • Other states — including Iowa, Tennessee, Indiana, Montana, Oregon, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, and Rhode Island. Where state law grants you rights additional to those listed above, we will honor those rights to the extent required.

How to Exercise Your Rights

To exercise any of the rights above, contact us at privacy@bridgedev.io. Include enough information for us to verify your identity (typically your account email address) and clearly describe the right you are exercising. We will:

  • Acknowledge receipt within ten (10) business days, where required by law.
  • Respond substantively within forty-five (45) calendar days, with a one-time forty-five (45) day extension where reasonably necessary and permitted.
  • Provide our response free of charge, unless your request is manifestly unfounded or excessive (e.g., repetitive).

Authorized agents. You may use an authorized agent to submit a privacy request on your behalf. We may require you to verify your identity directly and to provide written authorization to the agent.

10. European Privacy Rights (GDPR / UK GDPR)

Bridge is operated from the United States and currently intended for use by residents of the United States. If you access the Service from the European Economic Area, United Kingdom, or Switzerland, the following additional rights apply to your personal data under the GDPR (and UK GDPR for UK residents):

  • Right of access to your personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure ("right to be forgotten"), subject to exceptions.
  • Right to restriction of processing.
  • Right to data portability in a machine-readable format.
  • Right to object to processing based on legitimate interest.
  • Right to lodge a complaint with your local supervisory authority.

Lawful basis for processing under GDPR: we process account and content data to perform our contract with you (Article 6(1)(b)); we send marketing communications based on your consent (Article 6(1)(a)); we use analytics on the basis of our legitimate interest (Article 6(1)(f)) in understanding site usage to improve the Service.

International transfers. Bridge's infrastructure is located primarily in the United States. To the extent we transfer personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards such as the EU Standard Contractual Clauses entered into with our sub-processors.

To exercise European privacy rights, contact privacy@bridgedev.io.

11. Children's Privacy

Bridge is not directed at, and is not intended for use by, children under the age of thirteen (13). We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, contact privacy@bridgedev.io and we will delete the information.

12. Security

We use commercially reasonable technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption in transit (TLS) for data moving between your device and our infrastructure and between our infrastructure and sub-processors.
  • Encryption at rest for data stored in Firebase and other sub-processor systems where the provider supports it.
  • Role-based access controls within our organization. Bridge is currently a single-member LLC; access to user content is limited to what is strictly necessary for service operation and support.
  • Platform-level secure storage on iOS and Android for sensitive on-device data, including your LLM provider API key.

No security measure is perfect. If we become aware of a security incident involving your personal information, we will notify you in line with applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide notice by email or in-app notice before the change takes effect. The "Last updated" date at the top reflects the most recent update. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

Questions about this policy, requests to exercise privacy rights, or other privacy concerns may be directed to privacy@bridgedev.io, or in writing to:

Bridge Agentic Solutions LLC 215 N Payne St, #58958 Alexandria, VA 22314 United States