Effective 3 August 2026 · Operated by BellyButton · Contact: support@bellybutton.global · https://bellybutton.global
Plain-language promise up front: we collect only what the app needs to work, we don't sell your data, we show no ads, we use no third-party ad trackers, and your photos delete themselves on a schedule you can see in the app.
1. What we collect, and why
- Phone number — it IS your account. Used to sign you in (a one-time SMS code) and so hosts can invite you by number.
- Display name — shown with your photos and in events; attribution is part of the product.
- Email (optional) — only if you add it. Used to verify you and as the only recovery anchor if you lose your number.
- Photos you upload, and when they were taken — the product itself. We process each photo (resize, convert, and strip location/EXIF metadata — see below).
- Event details you enter (title, times, venue if you add one) — to run the event.
- Phone numbers you choose to invite — sent to us only for the numbers you pick, only to deliver the invite.
- Reactions ("loves") — the photos you love; shown as a count and, within an event, who reacted.
- Referral activity — if you use refer-and-earn: your referral code and the link between you and someone who joined with it, so we can credit the reward.
- Push token (a device identifier from Google or Apple) — only if you allow notifications; it's how a notification finds your phone.
- Product-analytics events — pseudonymous in-app usage events (for example sign-in success or failure, keyed by a one-way hash) processed on our own backend to improve the product. Not sold, not shared with ad networks.
- Crash and diagnostic data — if part of the app crashes, we collect a crash report to fix it (via Google Firebase Crashlytics).
- Technical logs (IP address, request records, error traces) — for security, rate-limiting, and fixing problems. Traces are scrubbed of personal content.
What we deliberately do NOT collect: your contact book — matching happens entirely on your phone and your contacts are never uploaded. No advertising identifiers, no ad tracking, no data brokers, no sale of personal data, ever.
2. Your photos, specifically
- Location data is stripped. When we process your photo, GPS coordinates and identifying camera metadata (EXIF) are removed from every version we serve to others — including the full-quality "download everything" a host can take (exported originals are EXIF- and GPS-stripped before delivery).
- Who sees a photo is controlled, always: first the uploader's event, then the host's moderation settings, then — only if the host switches it on — a public web page reachable by an unguessable link. Public pages never show original files, only protected smaller versions behind expiring links.
- Photos self-delete 7 days after the event starts (once extendable to 14 by the host). Deletion is physical and audited — the bytes are removed, not hidden.
3. Who we share data with
We use service providers who process data on our instructions, under their own security obligations: Amazon Web Services (all storage, databases, SMS delivery, and email) and Google Firebase (push-notification delivery and crash/diagnostic reporting via Crashlytics). Our product analytics are first-party — processed on our own backend, not handed to any third-party analytics or advertising network. We share data with authorities only when the law requires it — and proactively in child-safety cases. Our infrastructure is hosted on Amazon Web Services and your data may be processed in a country other than your own; we apply the same protections regardless of location.
4. How long we keep things
- Photos — until the event's deletion date (7 days after start; up to 14 with the one extension), or earlier if removed by you, the host, or moderation.
- Account (phone, name, email, events) — until your account is deleted.
- Reactions ("loves") — until the photo is deleted or you remove the reaction; erased on account deletion.
- Referral records — kept while the accounts exist; erased or anonymised on account deletion.
- Account deletion — scheduled for the end of the current calendar month when you request it (date shown in the app; cancellable until then). Need it sooner? Contact us for expedited erasure.
- Technical logs and traces — 30 days.
- Pseudonymous product-analytics events (keyed by a one-way hash, no message content) — 90 days, then auto-deleted; erased on account deletion.
- Crash and diagnostic reports — per the processor's default retention; not linked to your identity beyond what's needed to fix the crash.
- Safety and report evidence — only as long as the law requires.
5. Your rights
You can: see and correct your profile in the app; request a copy of your data (an in-app data request, or email support@bellybutton.global) — including your profile, events, reactions, and referral summary; delete your account; withdraw consents (for example turn off notifications — the app's Permissions screen shows you how); and complain to us or your data-protection authority. We answer requests within the statutory window.
6. Security
All traffic is encrypted in transit (TLS); all stored data — photos and databases — is encrypted at rest. Access is role-restricted and audited; sign-in codes are stored only as one-way hashes; internal administrative access requires separate authentication and every privileged action is logged. No system is perfectly secure — if a breach affects you, we will notify you and the authorities as the law requires.
7. Children
BellyButton is for adults (18 and over). We do not knowingly collect data from anyone under 18; accounts found to belong to minors are deleted. We have zero tolerance for child sexual abuse or exploitation material: we preserve evidence, report confirmed material to the relevant authorities (including the National Center for Missing & Exploited Children), cooperate with law enforcement, and ban the account. Our child-safety standards are published at https://privacy.bellybutton.global/legal/child-safety.
8. Changes and contact
We'll update this policy as the product evolves; material changes are shown in the app before they take effect. Questions, requests, or complaints: support@bellybutton.global, acknowledged within the statutory window.