Privacy
Privacy Policy
Effective June 15, 2026
Overview
Bump Bracket is a private prediction pool for baby arrival details. The app collects only the account, bracket, invite, prediction, family-message, image, result, and audit data needed to run the service, keep brackets private, and calculate recaps.
Data We Collect
- Account details such as email address, display name, and password hash.
- Bracket membership and role data.
- Invite codes needed to join private brackets.
- Prediction, optional family-message, baby-count, and official result details entered by users, including per-baby details for twin or triplet pools.
- Optional pool images uploaded by admins or managers.
- Optional guest contact emails provided for bracket updates.
- Operational audit logs for key bracket actions.
- Basic technical logs needed for security, debugging, and deployment health.
Passwords are salted and hashed before storage. Plaintext passwords are never intentionally stored.
How We Use Data
- Authenticate users and keep private brackets limited to members.
- Save predictions, family messages, and optional pool images.
- Lock official results, calculate scores, and show reveal recaps.
- Show role-appropriate bracket controls.
- Investigate errors, abuse, security issues, and support requests.
- Comply with valid legal, safety, and data-rights obligations.
Analytics
Bump Bracket uses self-hosted Umami privacy-focused analytics to understand basic app usage and reliability, such as aggregated page views and allowlisted feature events. This helps us see whether core workflows like private invite sharing, prediction submission, and reveal are working as expected.
Analytics data does not include invite codes, account emails, display names, pool titles, prediction values, family messages, image metadata, official result details, setup tokens, raw form payloads, advertising identifiers, or cross-site tracking. Analytics is not used for advertising, is not sold, and is hosted under Bump Bracket control.
Sharing
Guests may optionally provide a contact email for bracket updates. If a guest opts in, admins for that pool can view and export the provided address so they can send those updates.
Bump Bracket does not sell personal data. Data may be processed by hosting, database, email, logging, or infrastructure providers needed to operate the app. Data may also be disclosed if required by law, to protect users, or to secure the service.
Data Rights
Depending on where you live, privacy laws such as GDPR and California privacy laws may give you rights to access, correct, delete, restrict, or object to certain processing of your personal data. You may also have the right not to be discriminated against for exercising privacy rights.
Account Export And Deletion Requests
To request an account export or deletion, email [email protected] using this template:
Subject: Account Privacy Request
Per GDPR and/or California data privacy laws, I am requesting an export and/or deletion of my account and associated personal data. Account email: [enter your email here]
Verified requests are handled through a master-admin privacy workflow. Admins can export account, pool membership, prediction, family message, family note, score, result, and audit-reference data as JSON. Deletion requests are fulfilled by anonymizing account identifiers while preserving pool records needed for recaps, scores, and audit integrity.
Some information may be retained when required for security, legal compliance, dispute resolution, backups, or legitimate operational records.
Security And Retention
Bump Bracket uses access controls, private invite links, hashed passwords, private upload storage, and operational logging to protect the service. Data is kept while needed to provide the app, maintain records, resolve support issues, or comply with legal obligations. Automatic age-based retention cleanup is not active in this version; verified privacy requests are handled through the admin process above.