privacy
last updated · 2026-07-18
at a glance
- we collect the data needed to run b3rri: your account and profile, the content you make, and the technical signals that keep the service safe.
- your data is protected with encryption in transit and at rest; passwords are hashed, never stored in plaintext.
- we don't sell your data. ever. no ad pixels, no third-party analytics, no fingerprinting.
- we use your content and activity to run and improve b3rri and to train and improve our own machine-learning models (language matching, translation, captioning, recommendation, safety). first-party only — never sold, never handed to a third-party ad or analytics network. see Terms §7. you can object where the basis is legitimate interest.
- self-service deletion: delete your account in-app, or email [email protected]. either way we confirm by email and complete the deletion promptly.
- in the EU/UK you have full GDPR rights. in korea, full 개인정보보호법 and 정통망법 rights. in the US, full CCPA/CPRA rights. none of these are optional for us.
- if there's a breach, we'll tell the regulator (72h GDPR, 24h korea) and tell you without delay if you're at real risk. we'll say what happened, not soft-pedal it.
who we are
b3rri is built by B3RRI LLC. this policy covers the b3rri app (on iPhone) and the b3rri website (b3rri.com).
contact: [email protected].
what personal data we collect
- account and profile: display name, photo, bio, your native and learning language (the matching primitive for voice rooms).
- OAuth identifiers from apple or google.
- voice and video streams. not recorded by default.
- media you upload (loopi, photofeed, boards).
- messages and posts.
- your social graph (follows, blocks, mutes).
- in-app purchase receipts only. we do not see card numbers.
- device and push tokens, OS version, locale, crash diagnostics.
- the user-agent and referer of a request, capped at 512 characters.
- moderation signals tied to reports or trust and safety review.
the lawful basis (GDPR art. 6)
| basis | what we rely on it for |
|---|---|
| consent | optional marketing; sensitive processing where required |
| legitimate interest | abuse defense, rate limiting, moderation, improving the service, and training and improving our own models |
| contract | profile, content, voice rooms, payments |
| legal obligation | tax, fraud, and reporting duties tied to payments |
for model training that would use special-category or biometric data we rely on your explicit consent where the law requires it. you can object to processing based on legitimate interest — including model training — by emailing [email protected].
in korea we collect granular consent per 개인정보보호법 and 정통망법, separated by purpose.
how we collect, use, and share it
we collect data directly from you, from server logs of your requests, from your sign-in provider, and from your mobile device.
we use it to run the service, match people by language pair, defend against abuse, process payments, send notifications you've opted into, improve the service, train and improve our own machine-learning models (for example language matching, translation, captioning, recommendation, and trust-and-safety systems), and comply with the law. the models are ours and first-party — your content is never sold or handed to a third-party ad or analytics network for training.
voice rooms and calls are not recorded by default, so we don't train on their audio or video unless recording happened with the in-room consent our Terms require. special-category or biometric data, private messages, and the content of users we know to be minors are used for training only where the law allows.
sub-processors include apple and google for in-app purchases and push, a media CDN, a real-time communications provider, an observability vendor, and the cluster operator. each handles a defined slice under contract.
we do not sell your personal data, under any definition. we respond to law enforcement only on a valid legal order. we push back when an order is overbroad. we notify the affected person where the law allows.
how we protect it
we use appropriate technical and organizational measures to protect your data, including:
- encryption in transit and at rest for sensitive data, with encryption keys managed separately from the database.
- passwords hashed with a modern algorithm — never stored in plaintext.
- access controls, audit logging for sensitive operations, signed media URLs with short expiry, and secure token storage on device.
- the production service refuses to start if its security secrets are missing.
no system is perfectly secure. we won't pretend otherwise.
how long we keep it
- server logs: 30 days.
- self-service deletion: immediate row delete after you confirm the OTP email. the request itself is kept for 7 days as an audit record (no PII, just a hash and a timestamp).
- account data after deletion: hard purge within 30 days, except where retention is required for tax or abuse history.
- voice rooms and calls: not recorded.
- uploaded media: until you delete it; CDN caches expire within 24 hours.
- moderation records: up to 2 years.
international transfers
we process and store your data in the United States.
for the EU, EEA, and UK, this transfer is covered by the standard contractual clauses (Commission Decision 2021/914) and the UK IDTA, supported by the encryption and access-control measures described above. for korea we disclose and obtain consent for the overseas transfer to the United States as required by 개인정보보호법 §28; for other jurisdictions we use equivalent contractual safeguards.
your rights
everyone: email [email protected]. we acknowledge within 7 days and complete within 30.
- GDPR (EU/EEA). access, rectification, erasure, portability, restriction, objection, and withdrawal of consent. you can complain to your national data protection authority.
- korea (개인정보보호법 / 정통망법). 열람, 정정, 삭제, 처리정지, 동의철회. you can contact KISA at 118 or the personal information protection commission.
- CCPA / CPRA (california). the right to know, delete, correct, limit use of sensitive personal information, and non-discrimination for exercising those rights. we don't "sell" or "share" your data in the CCPA sense.
- LGPD (brazil), PIPEDA (canada), privacy act (australia). the equivalent local rights apply.
children
b3rri is not for anyone under 13. the app gates signup at 13, or higher where the law requires (16 in parts of the EU, 14 in parts of korea). if you believe a child has signed up, email [email protected]. there is no child-oriented version of b3rri.
cookies and tracking
only strictly-necessary cookies. no third-party analytics, no ad pixels, no fingerprinting. this is deliberate, not provisional.
we use first-party product analytics with a visible opt-out. nothing third-party.
if something goes wrong
- under GDPR we notify the lead supervisory authority within 72 hours of becoming aware, and notify you without undue delay if the risk to you is high.
- under korea's 정통망법 and 개인정보보호법 we notify the regulator within 24 hours and notify you without undue delay.
- in the US we follow each state's breach-notification law.
we will tell you what happened, what data was involved, what we've done, and what we recommend you do. plain language.
changes
we update the last updated date when this page changes. for material changes we publish in-app notice before the change takes effect.
Questions? [email protected]