BestFriend

Privacy Policy

Henry Love · Effective 2026-09-07 · odd.community/bestfriend

BestFriend is a private notebook for your close friendships. Everything stays on your phone unless you turn on encrypted backup — and if you do, your device encrypts it before it leaves, with a key only you hold.


The short version

BestFriend is a private notebook for your close friendships. It is local-first: by default everything you write — names, notes, birthdays, photos, reminders — is stored only in the app's database on your own phone. We cannot read it, because we never receive it.

You can optionally create an account to back your data up to our servers. When you do, your device encrypts the data before it leaves the phone, using a key derived from a recovery phrase that only you hold. Our servers store ciphertext. We cannot decrypt it, and neither can anyone who compromises our servers or serves us a legal demand.

We do not sell your data. We do not share it with advertisers or data brokers. We do not build advertising profiles. There is no social feed, no follower graph, and no algorithm ranking your friends.


1. Who we are

BestFriend ("the app") is published by Henry Love (individual). The optional account and encrypted cloud backup service are operated by Odd Community LLC. "We" and "us" in this policy cover both, as applicable: the app comes from the publisher, and anything that leaves your device goes to the service operator. Privacy contact: oddcommunityreview@gmail.com.

2. What stays only on your device

Unless you explicitly turn on encrypted backup, all of the following is stored solely in the app's local database on your phone and is never transmitted to us:

Because this data lives only on your phone, if you lose the phone and have not enabled backup, the data is gone. We cannot recover it for you. The app tells you this in plain language during onboarding; this policy repeats it because it is the single most important consequence of the local-first design.

Contacts

If you choose to import friends from your address book, the app asks for the iOS/Android contacts permission and reads your contacts on the device so it can show you a picker. Only the entries you actively select are copied into BestFriend's local database. Your address book is never uploaded to us, in whole or in part, and contacts you do not select are not retained by the app after the picker closes. You can decline the permission and add friends manually; nothing else in the app is gated on it.

Photos and camera

Used only so you can attach an avatar to a friend. Images are stored locally alongside that friend's record. We do not upload your photo library.

3. Optional account (email sign-in)

Creating an account is optional. The app is fully usable, forever, with no account.

If you sign up, we use Supabase (Supabase Inc.) as our authentication provider. In that case Supabase processes, on our behalf:

Purpose: to authenticate you and to associate your encrypted backup blob with your account. Legal basis (EEA/UK): performance of a contract you asked for.

4. Encrypted cloud backup

Backup is off by default and must be switched on by you.

How much we back up depends on your account's backup capacity. Some accounts back up your 5 closest friends; others back up your whole roster.

Adding friends in the app is unlimited and free forever, with or without an account. This number describes only how many friends we hold an encrypted copy of — never how many you can add or keep. Friends beyond it remain stored on your device permanently and at no cost; they are simply not copied to us. Nothing is deleted and nothing is blocked.

Account state changes how much ciphertext we hold. It does not change what we can read, which is nothing.

5. Location sharing (optional)

Location sharing works in both directions. If you turn it on, the app collects a coarse, city-level location and shares it with the specific friends you have chosen. The same feature lets you see the city of a friend, if that friend has separately chosen to share it with you. Each direction is its own choice: you sharing with a friend does not require, or grant, seeing theirs, and vice versa.

This is end-to-end encrypted the same way backups are: your device encrypts your city separately for each friend you share it with, before anything leaves the phone. Our servers store and relay ciphertext only and cannot read anyone's location, in either direction.

6. Your profile

BestFriend lets you create a profile for yourself — separate from the friends you add. It holds:

Your profile is stored in the same encrypted local database as everything else and stays on your phone. Creating one is optional; you can skip it during onboarding and the app works exactly as it otherwise would.

Each part of your profile carries its own visibility setting, which you control:

If and when a part of your profile is shared with a connection, it travels over the same per-recipient end-to-end encrypted path already used for location sharing (section 5): it is encrypted on your device for that specific recipient, the server relays ciphertext only, and we cannot read it. There is no separate, unencrypted route for profile data.

Changing your city never changes who can see it, and the app never creates a profile for you as a side effect of anything else — a profile exists only because you made one. Deleting your account deletes your profile and interests along with the rest of your data (section 10).

7. Analytics and crash reporting

These are the only third parties that receive anything about you, and none of them receive your friends' data.

ProviderWhat it receivesWhy
PostHogAnonymous product-usage events (screen views, feature usage, counts, performance timings) keyed to a rotating anonymous identifier that is not your account, email, device advertising id, or phone numberTo see which features are used and where the app is slow
SentryCrash and error reports: stack traces, OS/app version, device modelTo find and fix crashes

Notes:

We do not track you

"Tracking", as Apple defines it, means linking your data with data from other companies' apps or websites for advertising, or sharing it with data brokers. BestFriend does none of this. We do not use the advertising identifier (IDFA/AAID), we run no ad SDKs, and we sell no data. Our iOS privacy manifest declares NSPrivacyTracking = false accordingly.

8. Notifications

Reminders and birthday nudges are scheduled and delivered locally by your device. Their contents are not sent to our servers.

9. Children

BestFriend is not directed at children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data. If you record a child's name or birthday as a "satellite" of a friend, that information is your own note about someone in your life, and it stays under the same local-first and end-to-end-encrypted rules as everything else.

10. Retention and deletion

You can request deletion from within the app. If you cannot, contact us at the address in section 1.

11. Your rights

Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. For anything stored only on your device, you already hold all of these rights directly — the data is in your hands, not ours. For account data, contact us and we will act within the period required by applicable law.

We do not sell or "share" personal information as those terms are defined by the California Consumer Privacy Act.

12. International transfers

Our infrastructure providers may process data in the United States and the European Union. Because backup content is end-to-end encrypted, any cross-border transfer of that content is a transfer of ciphertext only.

13. Security

Two different things are encrypted, in two different ways, and we describe them separately rather than blurring them together:

A consequence worth stating plainly: because the database key lives in your device's secure storage, and because we hold no copy of it, a device wipe or a lost keychain entry means that local data cannot be recovered by us — only a backup you enabled, plus your recovery phrase, can restore it.

No system is perfect, and we will notify affected users of a breach as required by law. But a breach of our servers would expose ciphertext, not your notes.

14. Changes

We will update the "last updated" date above and, for material changes, notify you in the app before the change takes effect.