Bump Privacy Policy

Your privacy matters to us

Effective Date: May 18, 2026

Bump ("we," "us," or "our") operates the Bump mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

1.2 Bluetooth Low Energy (BLE) Data

Bump uses Bluetooth Low Energy to detect nearby users. We collect:

BLE proximity detection only determines whether another Bump user is nearby, not your geographic coordinates. BLE scanning runs only when you have explicitly enabled the Bump toggle and is paused automatically during Quiet Hours and any time you disable the toggle.

1.3 Precise Location

Bump can show your own position on the campus map when you tap the "Locate" button. We collect precise location only when you actively press this button; we automatically disable location sharing after 60 seconds and do not access location in the background. Your location is rendered on your own device for navigation purposes only — it is never sent to other users, never shared with third parties, and never written to our servers.

1.4 Chat and Message Data

Ephemeral one-to-one conversations leave the active chat list after 30 hours without activity. Unless both users become friends, the server permanently deletes the conversation after its 60-hour hard expiry plus a 14-day safety-report grace period.

1.5 Sage AI Chat

Bump includes "Sage," an AI assistant powered by Claude (from Anthropic, PBC). When you send a message to Sage, the message and conversation context are transmitted to Anthropic's API to generate a response, and the response is returned to your device. We do not store Sage conversations on our servers — your conversation history lives on your device only, and you can clear it at any time from the Sage chat's settings menu. Anthropic does not retain your Sage messages for AI model training. By opening a conversation with Sage you consent to your messages being transmitted to Anthropic for the sole purpose of generating a response. For more information about Anthropic's data handling, see Anthropic's Privacy Policy.

1.6 Device Information

Our first-party product analytics measure actions such as sessions, screens viewed, bumps, messages sent, group activity, and feature use. Analytics events do not include message text, names, email addresses, precise location, Bluetooth payloads, or another user's identifier.

2. How We Use Your Information

We use the information we collect to:

3. Information Sharing and Disclosure

We do not sell your personal information. We may share information in the following circumstances:

4. Data Retention

5. Privacy Controls

You control your privacy through:

6. Community Safety, Block, and Report

Bump is designed around safeguards that exist before any user opens the app:

7. Security

We use industry-standard measures to protect your data, including Firebase Authentication, Firestore security rules, encrypted communication in transit, and server-side access restrictions. If we become aware of a data breach affecting your account, we will notify you within 72 hours by email and on this page. No method of electronic transmission or storage is 100% secure.

8. Bluetooth and Background Permissions

Bump requires Bluetooth permissions to function. On Android, the App may run a foreground service to maintain BLE scanning in the background. You can disable this at any time through the App settings or your device settings. We only use Bluetooth for proximity detection — never for tracking your location.

On Android 12 and later, Bump asks for the Nearby devices permission only. It does not ask for location permission in order to find people. This is enforced by the operating system, not just promised here: the App declares Bluetooth scanning with Android’s neverForLocation flag, a formal declaration that we do not derive your location from Bluetooth scan results. Location permission is requested separately, and only if you tap “Locate” on the campus map — see section 1.3. Declining it does not affect Bump’s ability to detect people nearby. On Android 11 and older the operating system itself requires location permission before it will return any Bluetooth scan result; on those devices the permission is unavoidable, and we still never read your coordinates for proximity detection.

9. Children's Privacy

Bump is intended for university students aged 18 and older. We do not knowingly collect information from anyone under the age of 18. If we learn we have collected personal information from someone under 18, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy in the App or on our website. Your continued use of the App after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Email: support@uwobump.ca