Legal
Privacy Policy
Effective date: August 31, 2026 · Version 2026-08-31
This policy explains what BundleProof collects while it is in beta, what it is used for, who processes it on our behalf, how long it is kept, and how to have your account and its records removed. It is written in plain English on purpose.
Information you give us
Your account. The email address you register with and the password you choose. Your password is handled by our authentication provider; it is not visible to us and we cannot read it.
Your household. The household name you enter and, if you invite a partner, the membership record that connects the two accounts.
Your Vault records. The products your family owns and the details you enter about them — brand, product name, category, model number, date code, lot number, purchase and expiration dates, where you bought it, and any notes you add.
Information you import or paste. If you import a gift registry, paste a product link, or bring in a list of products, BundleProof reads that text to fill in product fields. Registry text often names the people who bought a gift; BundleProof keeps the product details and discards those names rather than saving them to your Vault.
Support and feedback. Whatever you choose to include when you email us — your message, your email address, and anything you attach or describe.
Beta access requests. If you ask for beta access, we store the email address you submit and the time of the request so we can manage invitations and related beta communication. Requesting access does not create a BundleProof account.
Everything in your Vault is information you entered or checked yourself. BundleProof does not collect it from anywhere else, and nothing is saved to your Vault until you choose to save it.
Information created as you use BundleProof
Recall check records. Which official recall notices were flagged as possible matches for your products, and how you reviewed them.
Product status history. A dated record of the status changes you make to a product — checked, removed from use, replaced.
Your acceptance of these documents. When you create an account, we record that you accepted the Terms of Service and acknowledged this policy: the versions shown to you, the date and time, which screen you accepted on, and your account identifier.
Beta activity records. During the closed beta, BundleProof records a small set of events so we can understand whether the app is working as intended. These include account activation, household setup, products being added, milestones such as the first and fifth tracked product, scan or import failures, and possible recall matches being shown. They include the event, date, an internal account reference and, depending on the event, limited details such as product category, how the product was added, a short failure type or reason, or the number of possible recall matches. They do not include product names, brands, serial or lot numbers, date codes, purchase details, receipt text, or uploaded photos.
Technical logs. The platforms that host BundleProof keep ordinary operational records of requests made to the service, such as time, request path, and general technical information about the connection. These are generated by our hosting and database providers as part of running the service and are used to keep it working and secure.
Photo-assisted product entry
BundleProof includes a feature that reads the text on a product label or receipt from a photo to help fill in a product. It may not be switched on for your account during beta. This section describes what happens when it is used.
If you use a photo to help fill in a product, the photo is sent to Google Cloud Vision, a Google service that reads the text in an image. That is the only way the text on a label or receipt can be turned into details BundleProof can fill in for you. The photo does leave your device to make this work.
The text that Cloud Vision reads is then sent to the Gemini Developer API, another Google service, which sorts it into fields like brand, model number, or purchase date. Gemini receives that text and its layout — not the original photo.
For receipt photos, before that text is sent on for sorting, BundleProof tries to remove or hide lines a product record does not need — such as card and payment details, authorization or transaction codes, loyalty or member numbers, email addresses and phone numbers. This reduces what is shared, but it is not a guarantee that every sensitive line is caught or that a receipt has been made anonymous: it works on the text as it was read, so an unusual receipt layout or an imperfect reading may slip through.
BundleProof does not keep the original photo. It is used to read the text and is not stored as part of your saved product record. Google handles what it receives under its own terms for those services.
Whatever is read from a photo is a suggestion, not a verified fact. Some details may not be filled in at all — BundleProof leaves a field blank rather than guessing when the photo does not clearly support it. You review what was filled in on the normal product form, you can change anything, and nothing is saved until you choose to save it. You can also choose to enter the details manually instead.
Forwarding a receipt by email
BundleProof can give your household a private email address you can forward a purchase receipt to, so the products on it can be added to your Vault without typing them in. It may not be switched on for your account during beta. This section describes what happens when it is.
The address is long and random, and it is yours to share or not. Anyone who knows it can send mail to it, which is why you can replace it at any time from your dashboard — the old address stops working immediately.
Mail sent to that address is delivered by Mailgun, which receives the message and passes it straight to BundleProof over a signed request. Mailgun handles what it receives under its own terms for that service. BundleProof never asks Mailgun for a stored copy of a message; it only reads what arrives on that request.
Mailgun has told us in writing that on the plan BundleProof uses, message retention is set to zero days — meaning Mailgun does not keep the email itself, its headers or its body as stored content. They have also told us that while a message is being handed to BundleProof, Mailgun may hold it temporarily in order to try again if our endpoint is briefly unavailable. Mailgun describes that hold as part of delivering the mail rather than as retention being switched on. They did not give us a figure for how long it can last, and we have not verified one, so this policy does not state one.
BundleProof reads the text of the email looking for durable baby gear — car seats, strollers, cribs and the like — and ignores the rest. What it keeps is deliberately small: a product name, a brand and category if it could tell, a quantity, and a note about anything it was unsure of. It also keeps which retailer the mail came from, worked out from the sending domain, and how many attachments there were.
Attachments are not opened. If a receipt arrives as a PDF or an image attachment, BundleProof counts it and tells you it was not read. It does not open, store, or forward the attachment, and it does not follow any link in the message.
What BundleProof does not keep from a forwarded receipt: the message itself, the subject line, the sender or recipient names and addresses, any postal address or phone number, the order or tracking number, the payment details, the prices and the total. None of that is written to your account.
Nothing found this way becomes a product on its own. The suggestions wait for you to look at them, you choose which ones to add and can correct them first, and only what you tick is saved. If you never act on a forwarded receipt, BundleProof removes the waiting suggestions about thirty days later. You can also discard one yourself at any time.
How we use information
We use the information described above to:
- operate BundleProof — keep your Vault, compare the product details you saved against official recall notices, show your product status history, and share a household with a partner you invite;
- create and secure your account, sign you in, and keep records of your acceptance of these documents;
- answer you when you contact support — if you email us about a problem, we may look at your account to help;
- understand whether the closed beta is working and improve BundleProof, using the beta activity records described above;
- keep the service running, diagnose problems, prevent abuse, and meet legal obligations.
We do not sell your information, and we do not use it for advertising or for third-party behavioral analytics.
Recall information
This tool helps organize recall information and product records. Recall matches may be incomplete or approximate. Always verify product model numbers, date codes, lot numbers, and recall details using the official recall source. BundleProof does not guarantee that all recalls or hazards will be detected.
BundleProof re-checks the products you have saved against the recall notices it has recorded — automatically once a day, and whenever you run a check yourself. The recall catalog behind those checks is reviewed and recorded manually, so it will not contain every recall, and BundleProof does not send you alerts during beta: possible matches appear in the app for you to review. Continue to rely on official manufacturer and government sources for safety-critical decisions.
Checking your products does not send your product details to any recall agency. The official notices are recorded into BundleProof ahead of time, and the comparison happens inside BundleProof.
Cookies and browser storage
BundleProof uses cookies for one purpose: keeping you signed in. These are set by our authentication provider and are necessary for the service to work. There are no advertising cookies, no tracking pixels, and no third-party analytics scripts, which is why you are not asked to make a cookie choice.
BundleProof may also keep a small amount of information in your own browser's local storage — for example, products you entered before you had an account, so they can be offered for import once you sign in. That information stays in your browser until it is imported or you clear it, and clearing your browser data removes it.
Who processes information for us
BundleProof is a small operation and relies on established service providers to run. They process information on our behalf, for the purposes above, and are not permitted to use it for their own purposes:
- Vercel — hosts and serves the BundleProof application.
- Supabase — provides the database that stores your account, household, and Vault records, and the authentication service that manages sign-in and sends account-related email.
- Google — Cloud Vision and the Gemini Developer API, used only on the photo-assisted entry path described above, and only if you use it. Google handles what it receives under its own terms for those services.
- Mailgun — receives mail sent to your household's private forwarding address, on the receipt-forwarding path described above, and only if you use it. Mailgun handles what it receives under its own terms for that service.
- Our email provider — delivers operational email related to the beta.
These providers host and process information in facilities they operate, which may be in a different location than you are. Beyond them, we share information only with people in your own household (see below), or where we are legally required to, must protect someone's safety or our rights, or if BundleProof is ever transferred to another operator — in which case this policy would continue to apply to information collected under it.
Sharing a household
If you invite a partner to your household, or accept an invitation to join one, the members of that household can see and manage the same products and recall information. That is what the feature is for, and it is the main way your information becomes visible to another person.
The household owner can remove a member at any time, which ends that person's access immediately. An invitation link is single-use, expires, and can be cancelled before it is used — only share it with the person you intend to invite.
How long we keep information
We keep your account, household and Vault records for as long as your account exists, so BundleProof can do its job.
When you delete your account from inside BundleProof, the account and its active Vault data are removed immediately. Beta activity records associated with an account are deleted with that account. If you ask us to delete an account by email instead, our policy is to complete it within 7 days of verifying the request.
A few things outlive that by design: beta access request records, so we can manage invitations; the record that an account accepted these documents, kept as evidence of that acceptance; and backups and provider logs, which age out on their providers' ordinary cycles rather than being deleted individually. We may also keep information longer where we are legally required to.
Security
Access to your records is enforced by rules in the database itself, so one household's records are not readable by another account. Your password is managed by our authentication provider and is not something we can read.
No online service can promise complete security, and we do not. If you believe something is wrong with your account, or you have found a security problem, please tell us at support@bundleproofapp.com.
Your choices
Most of what BundleProof holds is there because you entered it, and you can change or delete individual products at any time from within the app. You can choose not to use photo-assisted entry and enter details manually instead. You decide whether to invite anyone to your household, and you can remove them afterwards.
You can ask us for a copy of the information associated with your account, ask us to correct it, or ask us to delete the account entirely. Email support@bundleproofapp.com and we will help. Depending on where you live you may have further rights over your information; tell us what you need and we will do our best to honor it.
Deleting your account and data
You can delete your account yourself, from inside BundleProof. Sign in, open Account, and choose Delete BundleProof account. The screen tells you exactly what will be removed before you confirm.
Deletion happens immediately once you confirm it. It removes your sign-in, your household membership, and — where nobody else depends on it — your household and every product record in it. It cannot be undone, and we cannot restore anything afterwards.
If you share a household with someone else, deleting your account does not delete their records. When you are the only owner of a household another member is part of, BundleProof hands that household to them as part of deleting your account: they keep the products and the recall information, and you are removed from it.
If you cannot sign in, email support@bundleproofapp.com from the address associated with your account and ask us to delete it. Our policy for a request handled that way is to complete it within 7 days of verifying that the request is really yours.
Children's privacy
BundleProof is about baby products, but it is not a service for children. It is designed for parents and caregivers, accounts are for adults, and BundleProof is not directed to children.
We do not knowingly collect personal information from children. The records you keep are about products — a stroller's model number, a car seat's expiration date — and BundleProof does not ask for a child's name, birth date, photograph, or any other information about a child. Please do not enter information about a child in the notes fields. If you believe a child has provided us with personal information, contact us at support@bundleproofapp.com and we will delete it.
Changes to this policy
We will update this policy as BundleProof changes — this is a beta, and it changes often. Each version carries an effective date and a version identifier at the top of this page. If a change materially affects how we handle your information, we will take reasonable steps to let testers know rather than changing it quietly.
Contact us
Email support@bundleproofapp.com with any question, problem, or request about privacy or anything else. Support during beta is best effort — we read everything, but we cannot promise a response time.
The Terms of Service describe the rest of the agreement between us, including what BundleProof does and does not promise about recall information.