Privacy
Bubbeans is a private app for two people. This page says what is stored, where it is stored, and who can see it. It also says what we cannot promise.
Bubbeans is for adults 18 and over.
Your content
Your answers, notes, doodles, photos and memories are stored in the couple's shared iCloud space. This uses Apple's CloudKit. The space is shared between the two iCloud accounts. The invite is meant for one person. The app does not stop you adding more people to the share, so send it only to your partner.
Text fields are written as encrypted fields. Photos and doodles are stored as CloudKit assets, which CloudKit encrypts by default. Each phone also keeps a local copy so the app works and the widgets can show data. The app's local copy is kept out of iPhone and iCloud backups, because it can be downloaded again. The widgets' small data files, which hold the last note or photo thumbnail they show, are not excluded from backups.
The same space holds your dates, bucket list, countdowns and game rounds. Your partner can see and change what is in it. That is the point of the app.
This content is not on a server we run. The app has no code that sends it to us. The developer cannot read it through the app's design.
What "encrypted" means here
What it means. Your content is stored in CloudKit as encrypted fields. The keys come from each person's iCloud Keychain, and they are protected by that person's Apple account. We never receive the keys. The relay never receives your content at all.
What it does not mean. We do not claim end-to-end encryption in the strict sense. We do not run the encryption. Apple runs the CloudKit servers, and Apple manages the iCloud Keychain that holds the keys. So the protection depends on Apple and on your Apple accounts. We cannot check how Apple's systems work from the inside.
It also does not hide anything from the two people in the couple, or from anyone who can unlock a phone or sign in to an Apple account. Some information CloudKit needs to do its job, such as record names, record types and change times, is not part of the encrypted fields. For example, a note about a date idea is encrypted, but the name of its record is built from the idea's id in the app's bundled list, so someone who has that list could tell which ideas have a record, though not whether you saved, did or rated them.
Bubbeans is built by one of the people who uses it. He sees his own couple's content because he is one of the two people in the space, not because of any special access.
The relay
Phones cannot wake each other directly. So we run a small relay at relay.bubbeans.app. It sends a short notification to the other phone when something happens, such as a new note, a doodle, a photo, an answer, a changed countdown, or a thumb kiss. It also asks the widgets to refresh. Widgets show what the app last saved on the phone, so they can lag if the app has not had a chance to refresh in the background.
What the relay stores
- A push token for each phone, and a widget push token if there is one.
- A random pair id for the couple, and a random id for each of the two phones.
- A shared signing secret. The phones use it to prove each request is real.
- Whether each push token belongs to a test build or a normal build.
- Timestamps, such as when a phone last registered. Short-lived counters for rate limiting are kept in memory only.
The relay never stores or receives the text of a note, a photo, a doodle or an answer. Notifications use fixed phrases, such as "Thinking of you" or "New photo".
What the relay sees
- The IP address of each phone when it connects.
- When a ping happens, and which kind it is.
- For a thumb kiss, the touch position sent over a live connection. It is passed to your partner's phone from memory and is not stored.
The relay uses IP addresses in memory for rate limiting. It does not write them to its log or its store. The relay's log has event names, times, and the first 8 characters of a pair id. It has no tokens and no secrets. The web server in front of the relay is set up to keep no access log.
Apple's push service
Notifications go through Apple's push service (APNs). Apple sees that a notification was sent to a device. It also sees the fixed phrase in it. No content from your notes, photos, doodles or answers is in a notification. Widget updates carry no content either.
This website
This website collects nothing. It sets no cookies, runs no scripts, and loads nothing from other sites. The server it runs on keeps standard access logs for security. They contain the IP address, the time and the page requested. They are rotated and deleted after about 30 days.
What we do not use
- No analytics.
- No ad SDKs.
- No third-party SDKs of any kind. The app uses Apple frameworks only.
- No AI. The daily questions and ideas are bundled in the app and were written by us.
Location
If you allow it, Bubbeans can use your location to show nearby date ideas through Apple Maps. The location is used on your phone. It is never sent to us, and the relay never sees it. You can turn the permission off in iOS settings at any time.
Deleting everything
- End sharing. In Settings, once you are paired, choose End sharing. Whoever owns the shared space stops sharing it. The partner's phone then wipes its local copy. The partner can also leave the share from their own Settings, which wipes their copy.
- Delete the app. This removes the local copy on that phone. It does not remove anything stored in iCloud, and it does not remove the relay entry.
- Remove the iCloud data. Content in the shared space is in iCloud. You can manage or delete an app's iCloud data in iPhone Settings, under your name, then iCloud. If the other phone is still running Bubbeans it may upload its copy again, so end sharing first.
- Relay deletion. Email tomis@cyberbeans.net and we will delete your couple's entry from the relay by hand. The relay stores no names, so tell us roughly when you first set up the app.
Contact
Questions or deletion requests: tomis@cyberbeans.net.
If we change this page, the date at the top changes too.