BestFriend
Privacy Policy
BestFriend is a private notebook for your close friendships. Everything stays on your phone unless you turn on encrypted backup — and if you do, your device encrypts it before it leaves, with a key only you hold.
The short version
BestFriend is a private notebook for your close friendships. It is local-first: by default everything you write — names, notes, birthdays, photos, reminders — is stored only in the app's database on your own phone. We cannot read it, because we never receive it.
You can optionally create an account to back your data up to our servers. When you do, your device encrypts the data before it leaves the phone, using a key derived from a recovery phrase that only you hold. Our servers store ciphertext. We cannot decrypt it, and neither can anyone who compromises our servers or serves us a legal demand.
We do not sell your data. We do not share it with advertisers or data brokers. We do not build advertising profiles. There is no social feed, no follower graph, and no algorithm ranking your friends.
1. Who we are
BestFriend ("the app") is published by Henry Love (individual). The optional account and encrypted cloud backup service are operated by Odd Community LLC. "We" and "us" in this policy cover both, as applicable: the app comes from the publisher, and anything that leaves your device goes to the service operator. Privacy contact: oddcommunityreview@gmail.com.
2. What stays only on your device
Unless you explicitly turn on encrypted backup, all of the following is stored solely in the app's local database on your phone and is never transmitted to us:
- Friends you add: names, nicknames, phone numbers, email addresses, city, notes
- "Satellites": partners, children, pets and their details
- Birthdays and other important dates
- Your contact-frequency goals and engagement history
- Avatar photos you choose or take
- Anything you type into a note
Because this data lives only on your phone, if you lose the phone and have not enabled backup, the data is gone. We cannot recover it for you. The app tells you this in plain language during onboarding; this policy repeats it because it is the single most important consequence of the local-first design.
Contacts
If you choose to import friends from your address book, the app asks for the iOS/Android contacts permission and reads your contacts on the device so it can show you a picker. Only the entries you actively select are copied into BestFriend's local database. Your address book is never uploaded to us, in whole or in part, and contacts you do not select are not retained by the app after the picker closes. You can decline the permission and add friends manually; nothing else in the app is gated on it.
Photos and camera
Used only so you can attach an avatar to a friend. Images are stored locally alongside that friend's record. We do not upload your photo library.
3. Optional account (email sign-in)
Creating an account is optional. The app is fully usable, forever, with no account.
If you sign up, we use Supabase (Supabase Inc.) as our authentication provider. In that case Supabase processes, on our behalf:
- your email address
- authentication tokens and session identifiers
- the timestamps and IP address associated with sign-in requests, as an ordinary part of operating an internet service and detecting abuse
Purpose: to authenticate you and to associate your encrypted backup blob with your account. Legal basis (EEA/UK): performance of a contract you asked for.
4. Encrypted cloud backup
Backup is off by default and must be switched on by you.
- Your device generates a BIP39 recovery phrase. From it we derive, on the device, a master key and from that a backup key.
- Your data is encrypted on the device with AES-256-GCM before any upload.
- We receive and store only ciphertext, in storage scoped by row-level security to your account id. We never receive your recovery phrase, your keys, or your plaintext.
- We cannot decrypt your backup and we cannot reset your recovery phrase. If you lose the phrase, the backup is permanently unrecoverable. This is a deliberate property of the design, not a limitation we can work around for you.
- Deleting your account deletes the stored ciphertext.
How much we back up depends on your account's backup capacity. Some accounts back up your 5 closest friends; others back up your whole roster.
Adding friends in the app is unlimited and free forever, with or without an account. This number describes only how many friends we hold an encrypted copy of — never how many you can add or keep. Friends beyond it remain stored on your device permanently and at no cost; they are simply not copied to us. Nothing is deleted and nothing is blocked.
Account state changes how much ciphertext we hold. It does not change what we can read, which is nothing.
5. Location sharing (optional)
Location sharing works in both directions. If you turn it on, the app collects a coarse, city-level location and shares it with the specific friends you have chosen. The same feature lets you see the city of a friend, if that friend has separately chosen to share it with you. Each direction is its own choice: you sharing with a friend does not require, or grant, seeing theirs, and vice versa.
This is end-to-end encrypted the same way backups are: your device encrypts your city separately for each friend you share it with, before anything leaves the phone. Our servers store and relay ciphertext only and cannot read anyone's location, in either direction.
- Off by default; requires the OS location permission, which you can revoke at any time.
- BestFriend uses "While Using the App" location only. It does not use background location and cannot check where you are while the app is closed. Your city is read when you open the app, so the city your friends see is the city you were in the last time you used BestFriend.
- What you see of a friend's location is a city name, not a live map or a real-time position — it updates when their shared city changes, not continuously.
- We do not collect precise coordinates for analytics, advertising, or any other purpose.
- Turning sharing off stops future updates. It cannot delete a city a friend has already seen, because that copy is already on their device.
6. Your profile
BestFriend lets you create a profile for yourself — separate from the friends you add. It holds:
- a display name, and optionally an avatar;
- a base city — where you live, or where you expect to be a lot — which you set yourself and which only changes when you change it;
- a current city, which the app may refresh when you open it, if you have granted location permission;
- interests you enter, each stamped with when you last confirmed it so that a stale interest can be flagged to you rather than shown to someone as though it were current.
Your profile is stored in the same encrypted local database as everything else and stays on your phone. Creating one is optional; you can skip it during onboarding and the app works exactly as it otherwise would.
Each part of your profile carries its own visibility setting, which you control:
- Private — never leaves the device. Your current city is private by default.
- Visible to connections — eligible to be shared with people you have actively connected with.
If and when a part of your profile is shared with a connection, it travels over the same per-recipient end-to-end encrypted path already used for location sharing (section 5): it is encrypted on your device for that specific recipient, the server relays ciphertext only, and we cannot read it. There is no separate, unencrypted route for profile data.
Changing your city never changes who can see it, and the app never creates a profile for you as a side effect of anything else — a profile exists only because you made one. Deleting your account deletes your profile and interests along with the rest of your data (section 10).
7. Analytics and crash reporting
These are the only third parties that receive anything about you, and none of them receive your friends' data.
| Provider | What it receives | Why |
|---|---|---|
| PostHog | Anonymous product-usage events (screen views, feature usage, counts, performance timings) keyed to a rotating anonymous identifier that is not your account, email, device advertising id, or phone number | To see which features are used and where the app is slow |
| Sentry | Crash and error reports: stack traces, OS/app version, device model | To find and fix crashes |
Notes:
- Analytics events never contain your friends' names, notes, phone numbers, emails, photos, or location. They describe interactions with the app, not the contents of it.
- BestFriend contains no in-app purchases, so we operate no payment processing and receive no billing or payment-card data of any kind.
- Apple and Google provide us aggregate, non-identifying download and crash statistics under their own privacy policies.
We do not track you
"Tracking", as Apple defines it, means linking your data with data from other companies' apps or websites for advertising, or sharing it with data brokers. BestFriend does none of this. We do not use the advertising identifier (IDFA/AAID), we run no ad SDKs, and we sell no data. Our iOS privacy manifest declares NSPrivacyTracking = false accordingly.
8. Notifications
Reminders and birthday nudges are scheduled and delivered locally by your device. Their contents are not sent to our servers.
9. Children
BestFriend is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data. If you record a child's name or birthday as a "satellite" of a friend, that information is your own note about someone in your life, and it stays under the same local-first and end-to-end-encrypted rules as everything else.
10. Retention and deletion
- Local data stays on your device until you delete it in the app or uninstall the app.
- Backup ciphertext is retained while your account exists.
- Deleting your account removes your Supabase auth record, deletes your stored backup ciphertext, wipes the local database, and clears the encryption keys held in the device keychain. This is not reversible.
- Crash and analytics records are retained by Sentry and PostHog under their own retention windows and are not linked to your account.
You can request deletion from within the app. If you cannot, contact us at the address in section 1.
11. Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. For anything stored only on your device, you already hold all of these rights directly — the data is in your hands, not ours. For account data, contact us and we will act within the period required by applicable law.
We do not sell or "share" personal information as those terms are defined by the California Consumer Privacy Act.
12. International transfers
Our infrastructure providers may process data in the United States and the European Union. Because backup content is end-to-end encrypted, any cross-border transfer of that content is a transfer of ciphertext only.
13. Security
Two different things are encrypted, in two different ways, and we describe them separately rather than blurring them together:
- The database on your phone is encrypted at rest with SQLCipher (AES-256). Its key is generated on the device and stored in the iOS Keychain / Android Keystore, protected by your device passcode and available only when the device is unlocked.
- Backup content is encrypted on the device with AES-256-GCM before upload, under a key derived from your recovery phrase using Argon2id. Transport is TLS in both cases.
A consequence worth stating plainly: because the database key lives in your device's secure storage, and because we hold no copy of it, a device wipe or a lost keychain entry means that local data cannot be recovered by us — only a backup you enabled, plus your recovery phrase, can restore it.
No system is perfect, and we will notify affected users of a breach as required by law. But a breach of our servers would expose ciphertext, not your notes.
14. Changes
We will update the "last updated" date above and, for material changes, notify you in the app before the change takes effect.