Privacy Policy
Last updated: 2026-08-10.
BringUp is owned and operated by Irving Place Services LLC ("we", "us") as a free, non-commercial research project. It helps you remember what you want to say, ask, or share with the people who matter, and bring it up at the right moment. Privacy is the core of the product, not an afterthought.
The short version
- Private until you connect. Everything you capture is private to you until you and another person both agree to connect. Connecting shares everything you've each written about each other — past and future, both directions. The accept screen says this at the moment you decide.
- Local-first. Your data lives on your device (encrypted by iOS). It syncs to our backend only after you sign in, and only so you can use it across your devices and share with people you connect with.
- We never sell your data, and we never use the content of your BringUps or notes for advertising.
What we store
- Account: your email (for email sign-in) or an Apple-provided identifier (Sign in with Apple). Used only to authenticate and sync.
- Your content: people you add, the things you want to bring up, notes, reminders, and attachments. Items about a person you haven't connected with are visible only to you. Once you connect with someone, the items you've each written about each other are visible to both of you — and only to the two of you. Items you capture to a group are visible to that group's members only.
- Contacts: if you grant access, contacts are read on your device to help you add people quickly. We do not upload your contacts. When you explicitly add an email or phone number for someone, only an irreversible hash of that single value is sent — never the raw value. See "Contact matching" below.
- Verified identity: if you confirm your own email or phone number (via a one-time code), we store a hash of it so other users' hashes of your email/phone can be matched against it. See "Contact matching" below.
- Analytics: privacy-safe, aggregate product analytics consisting solely of counts, enumerated categories, and booleans. By design it is structurally impossible for analytics to contain the text of a BringUp, a note, a name, an email, a phone number, or a URL.
- Diagnostics: crash/error reports with PII scrubbed.
Contact matching
BringUp can tell you, anonymously, when someone you know has things to bring up with you — without either of you ever uploading an address book.
- How it works: when you add someone's email or phone number to a person card, or confirm your own, the value is normalized (email lowercased, phone in standard international format) and run through a one-way HMAC-SHA256 hash with a secret server-side key. Only that hash is stored — the raw email or phone number is never saved on our servers.
- Matching: if the hash of a contact value you added matches the hash of an email or phone number another user has verified as their own, our server can tell each of you that "someone" has active things to bring up — as a count only, never a name, title, or timestamp.
- Double opt-in reveal: if you and another user have each added or verified matching contact info for one another, each of you sees an anonymous "someone you know wants to connect" prompt. Names are revealed to each other only if both of you choose to accept. Declining reveals nothing to the other person, ever — their prompt simply disappears.
- Phone verification: not offered in the current version. If we add it, confirming a phone number will send a one-time SMS code to prove you control that number before it's added to the matching registry. (Phone numbers you attach to your own contacts are still stored only as irreversible hashes.)
- Deletion: deleting your account removes your verified identity hashes and any pending or connected matches along with the rest of your data (see "Your controls" below).
Sharing
Since version 2.0, sharing follows the relationship, not the individual item:
- Connecting is the consent. When you and another person connect (one of you invites, the other accepts — or you both accept a contact match), everything either of you has written about the other becomes visible to both of you, including items written before you connected and anything either of you adds later. The invitation screen states this before you accept.
- Until you connect, items stay private to you and are marked "Will share" in the app.
- Groups share only what members capture directly to the group. Your one-to-one items about a group member are never shared with the rest of the group.
- Taking something back: moving an item to a different person stops sharing it with the previous person (the app confirms this with you first). Deleting a shared item removes it for everyone in its space. Deleting a person's card does not remove items already shared with them.
- When you updated to 2.0: if you were already connected with someone, the items you had each written about the other became shared at that time. The app shows a one-time notice explaining this.
Your controls
- Export: download a full JSON copy of your data from Settings → Privacy & data.
- Delete: delete your account from Settings; your synced content, verified identity hashes, and any contact-matching state are removed, and you leave any shared spaces. (Local data is removed when you delete the app.)
- Permissions: Contacts, Notifications, and Calendar are all optional and requested only at the point of use; you can change them anytime in iOS Settings.