Overview
BinderSafe is built and operated by Tembrion LLC, a limited liability company based in Sacramento, California, USA ("we", "us"), which also operates this marketing and support website (www.bindersafe.com). This policy explains how the BinderSafe mobile app and this website handle your information and the choices you have.
In short: BinderSafe is local-first. By default, your files, notes, and their metadata stay on your device. Information reaches us only when you choose to sign in, turn on cloud backup, subscribe, or contact us.
Who we are
The data controller is Tembrion LLC, located in Sacramento, California, USA. To contact us about this policy or your personal data, use the form on our Support page.
Data that stays on your device
BinderSafe is local-first. Your binders, files, note bodies, tags, and settings are stored by default in the app sandbox on your device. If you do not sign in and do not enable cloud backup, we do not receive, transmit, or store this content.
Uninstalling the app deletes this on-device data, unless your operating system keeps its own backups (for example iCloud or Google device backup), which are governed by those platform policies.
Account and sign-in
Signing in is optional and enables cloud backup, cross-device sync, and subscriptions. We offer only Sign in with Apple and Sign in with Google; there is no email-and-password login, and we do not create or store a login password for you.
When you sign in, we receive a stable account identifier from Apple or Google, along with your name and email address; with Google we may also receive an avatar URL. With Sign in with Apple you may choose to hide your real email, in which case Apple provides us a private relay address (@privaterelay.appleid.com). We use this to create and recognize your account, display your name in the app, and identify you to others when you use sharing.
We generate an in-app account identifier and a random username (handle) for you, and store the sign-in information above in our cloud database.
Cloud backup and sync
Cloud backup is an optional feature. When you sign in and enable it, the binder metadata, files, and notes you choose to back up are uploaded and stored under your account in our cloud infrastructure, so you can restore them on a new device or sync across devices.
You choose whether to turn this on. When it is off, that content stays only on your device.
Subscriptions and purchases
Premium features such as cloud backup are offered through auto-renewing subscriptions. Payment is processed by the Apple App Store or Google Play — we do not receive or store your full card number or payment credentials.
We use RevenueCat, a third-party service, to manage subscriptions and entitlements. To link a subscription to your account, we share your account identifier with RevenueCat and receive subscription status from it, such as your current tier, whether you are in a trial, and renewal and expiry dates. We use this to unlock the features you have purchased.
What the support form collects
When you submit the support form on the website, we collect the subject, your email address, an optional company name, and your message, so our support team can read and reply.
With each submission we also record limited, non-identifying technical information such as your IP address, used only to prevent spam and abuse (for example, rate limiting). These submissions are emailed to our support inbox and stored in a database accessible only to our support team. They are never displayed publicly.
Device permissions
To let you add and work with content, the app may ask the operating system for access to your photo library, camera, or files (to import documents and images), and to use biometrics or your device passcode (for on-device locking). Content accessed through these permissions is processed on your device or backed up to your account according to your choices. You can manage or revoke these permissions in your device settings.
How we use information
We use the information above to provide and maintain your account, cloud backup, and sync; manage your subscription and unlock purchased features; respond to support requests; keep the service secure and free of spam and abuse; and comply with legal obligations.
We do not use your information for third-party advertising, we do not sell your personal data, and we do not use it for model training. The app currently integrates no third-party advertising SDK; if we introduce ads for free users in the future, we will update this policy first and explain the practice.
Sharing and service providers
We do not sell your personal data. We share information only with third-party service providers that process data on our behalf as needed to provide the service, including: our cloud infrastructure provider, Amazon Web Services (AWS), for account, backup, sync, and file storage; RevenueCat for subscription and entitlement management; Apple and Google for sign-in; and an email service for delivering support messages.
These providers process data under our instructions and not for their own purposes. We may also disclose information where required by law or to protect the rights and safety of us and our users.
Where your data is processed
Our cloud providers process and store your account and backup data on servers located in the United States. If you use the service from outside the United States, your information is transferred to and processed there.
Data retention
Account and cloud-backup data are retained for the life of your account; after you delete your account, we delete or anonymize the associated data within a reasonable period, except where the law requires retention. Support-form messages are retained for up to 12 months and then deleted automatically; anti-abuse rate-limit records expire within minutes. On-device app data remains until you delete it or uninstall the app.
Security
We use HTTPS for the website and all APIs. We isolate each user’s cloud data, follow least-privilege access for our infrastructure, and restrict access to stored data. No system can guarantee absolute security, but we take reasonable technical and organizational measures to protect your information.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or restrict processing of your personal data, or to object to processing. You can sign out at any time, or delete your account to remove your cloud data (see below). On-device data can be cleared by deleting content or uninstalling the app.
Deleting your account: you can request deletion of your account and the associated cloud data. When you do, we remove your account record and cloud-backup content (except where the law requires retention); your subscription must still be cancelled separately in the App Store or Google Play, as described below. To exercise your rights or delete your account, use the relevant option in the app or contact us through the Support page form; we may need to verify your identity using the email address you used.
Children privacy
BinderSafe is not directed at children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child sent us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected in the effective date below and, where appropriate, highlighted in the app. Continued use after an update means you accept the revised policy.
Contact
For any privacy question, or to exercise your rights, contact Tembrion LLC through the form on our Support page.