Privacy Policy

Last updated October 1, 2026

Bulletin is an app for finding out what is actually happening on campus. This page explains what we collect, why, and what we never do with it.

We do not sell your data, we do not run ads, we do not track you across other apps or websites, and your location stays on your phone unless you choose to share your spot with friends.

What we collect

Your account

To sign in, we collect your email address and a password you choose, and we confirm the address with a one-time code. Your password is never stored in a readable form. It is kept only as a scrambled hash that cannot be turned back into the original, so nobody at Bulletin can see what you picked. You can also sign in with an emailed code instead of your password any time. When you set up your profile you also give us a username, a display name, and optionally a profile photo.

What you tell us during setup

Onboarding asks which interests and clubs you care about. We use this only to decide which events to show you first. You can change or clear these at any time in the app.

When you swipe through events in the match deck, we save which ones you saved and which you skipped, along with each event's category and tags, so the match percentages you see fit you. Only you can read your swipes, nobody else ever sees them, and they go when you delete your account.

If you tell us you are faculty or staff, we store the department you type and the fact that you asked; someone on our team approves it and the label shows on your profile. If a business applies through this website, we store the application (name, category, contact email, and the optional phone, Instagram handle and description) and, once we promote it onto an account, the business name and category on that account with a verified mark.

What you create and post

Notifications

If you turn on notifications, we store a push token for your device so we can deliver them. It identifies the device, not you personally, and turning notifications off removes it.

Product analytics

We record which screens you open, how long you stay on them, and which of about sixteen named buttons you tap. If the app hits an error or crashes, we also record what broke and where in the app, so we can fix it. That is the entire list. Not what you type, not what you read, not who you message.

We do this to learn which parts of Bulletin are worth building on. We do not sell it, there are no ads in Bulletin, and none of it follows you into other apps or websites.

It goes to two places. The first is our own database, where your account ID is never stored. We keep a scrambled stand-in instead. It stays the same for you over time so we can tell whether people come back, which means it is still connected to you, and we declare it that way on our App Store privacy label rather than call it anonymous.

The second is an outside analytics provider that processes this for us under contract and is not permitted to use it for its own purposes. It never receives your name, your email, or your account ID. What it sees is a different, random identifier created on your device, along with your device model, operating system, and app version. We have switched its location lookup off and told it to discard IP addresses, so it cannot work out where you are either.

You can turn all of this off any time in Settings under Share usage data, which stops both copies at once. Deleting your account erases our own copy. The provider's copy carries no link to your account at all, which is deliberate, and it also means we cannot pick your records out of it to delete them, and neither can they.

What we do not collect

How we use what we collect

That is the whole list. We do not use your content to build advertising profiles, and we do not share it with data brokers.

Who else touches your data

We use a small number of service providers to run the app. They process data only on our behalf, are not permitted to use it for their own purposes, and must protect it at least as carefully as this policy describes. These are the kinds of providers we use and what each receives:

We will also disclose information if the law genuinely requires it, or if we need to address a real threat to someone's safety.

Do Not Track

Bulletin does not track you across other apps or websites, and it does not let any other company do so through Bulletin. Because nothing like that happens, a browser's Do Not Track signal has nothing to switch off; we treat every visitor as if it were on.

Public campus events

Some events in Bulletin are not posted by users. They are gathered from publicly available University of Florida sources. That is public institutional information about events, and it contains no personal data about you.

Safety and moderation

Every image uploaded to the app is screened automatically before it becomes visible, and so is every piece of text you type: messages, event and club descriptions, names, and feedback. Screening is done automatically by the third-party AI services described above and is used only to catch unsafe content, never to profile you. You can report any message, event, or person, and you can block anyone, which immediately stops them from contacting you. Reports are reviewed by a human. We keep records of reports and enforcement actions so repeat behavior does not get a clean slate.

Keeping and deleting your data

We keep your information for as long as your account exists.

You can delete your account at any time from Settings in the app. Deletion works like this:

Messages you sent to other people may remain visible in their copy of a conversation, the same way a text message you sent still sits on someone else's phone. Reports and safety records may be kept longer where we need them to protect other people.

Your choices

If you want a copy of your data or need help with any of this, email us and we will take care of it.

Age

Bulletin is built for university students and is not intended for children under 13. We do not knowingly collect information from anyone under 13. If you believe a child under 13 has created an account, email us and we will remove it.

Security

Data is encrypted in transit and at rest, and access to it is restricted at the database level so one account cannot read another's private information. No system is perfect, but we do not cut corners here.

Changes

If we change this policy in a way that meaningfully affects you, we will update the date at the top and let you know in the app before the change takes effect.

Contact

Questions about privacy, or want your data removed? Email privacy@downloadbulletin.com.