Privacy Policy

Last updated: July 22, 2026

1. Introduction

Welcome to PeersBridge. This Privacy Policy is the single, canonical privacy notice for PeersBridge across all of the ways you use it — the native iOS app, the Telegram bot and Mini App, and this website. It explains how we collect, use, disclose, and safeguard your personal data. Our goal here is full transparency: we describe exactly what we collect and how it is protected, and we do not overstate our protections. Your use of the Service, together with a separate User Agreement (Terms of Use), governs your relationship with us.

2. Information We Collect

We collect the categories of information below, and we use every category solely to provide and operate PeersBridge. Unless a category has a longer statutory retention (see "Data Retention & Deletion"), we keep each category only while your account is active:

  • Account information: your name, email address, profile photo, and a unique account identifier (your Telegram user ID or app account ID). Used to create and secure your account. Retained while your account is active.
  • Profile & professional information: age, gender, city, bio, company, position, interests, professional background, and any other content you add to your profile or share with other users. Used to build your profile and match you. Retained while your account is active.
  • Messages & photos: the direct messages you send to other users and any photos you attach to them, and messages you post in shared spaces such as game-table chat. Used to deliver your conversations. Direct messages are end-to-end encrypted (see "Data Security & Encryption" below); messages in shared/group spaces such as game tables are not end-to-end encrypted.
  • Voice audio & interview responses: if you use voice input or the AI-assisted onboarding interview, we process the audio you record and the resulting text transcript. Used to build your profile and let you dictate content. Retained while your account is active; see "AI processing" below for how it is processed.
  • Identity verification (KYC) data: when you verify your identity, we process LinkedIn profile information you choose to share and, where identity/document verification is used, identity-document data and a selfie/video. Document and biometric verification is performed by our verification processor, Sumsub, which captures and holds the identity documents; we receive the verification result and status. Used to confirm your identity and prevent fraud. Verification records may be retained for a statutory period (see "Data Retention & Deletion").
  • Contacts & business cards: contacts you choose to import from your address book, and business cards you scan — used only to build your personal network map and to prepare meeting briefs for you. This can include the personal data of other people who are not PeersBridge users. By importing contacts or scanning a card, you confirm that you have a lawful basis to share that person's data with us for this purpose. See "Third-party (non-user) data" below.
  • Precise location: your precise location when you use location-based features — the StreetPoly game and the in-person meeting/event planner. Used only to run those features. Retained while your account is active.
  • Voice/video calls: when you place a 1:1 call with a match, we process the connection metadata needed to set up and route the call (WebRTC signalling data such as session and network-candidate information). Call media is relayed through our own, self-hosted relay (TURN) server when a direct connection is not possible; we do not record the audio or video of your calls. Used only to connect your calls. Signalling/connection logs are retained briefly for reliability and abuse-prevention.
  • Financial information (budget planner): if you use the budget planner, we process the bank-statement files you upload and the transaction data in them (amounts, dates, categories). Used only to produce your personal spending insights. See "AI processing" below for how insights are generated. Retained while your account is active or until you delete the data.
  • Company research (Company Mirror): when you use Company Mirror, we process the name of your company and publicly available information about it to generate insights for you. Used only to prepare those insights.
  • Subscription & purchase data: your subscription status and purchase history. On iOS, subscriptions are billed through Apple In-App Purchase and Apple processes your payment; on the Telegram/web product, payments are processed by our payment provider. We do not receive or store your full card details. Payment/transaction records may be retained for a statutory period (see "Data Retention & Deletion").
  • Push-notification tokens: the device push token (e.g. Apple Push Notification service token) needed to deliver notifications to your device. Used only to send you notifications you have enabled.
  • Referral & invite data: if you invite others or join via an invite/referral, we process the referral link, who invited whom, and the IP address associated with the referral event (used to prevent abuse and fraud). Retained for a limited period for anti-fraud purposes.
  • Activity & match history: how you interact with the service, including your match history and the feedback you give about meetings and other users. Used to operate the matching and Trust Score features and to improve the Service. Retained while your account is active.
  • Technical & log data: IP address, device/browser type, in-app usage events (first-party product analytics), access times and error logs. Used to operate, secure, and improve the Service.

No ads, no third-party tracking in the app. The PeersBridge app contains no advertising, no advertising identifiers, no third-party analytics or tracking SDKs, and no data-broker integrations. We do not sell your personal data. Every category above is collected only to make the app's features work. (Note: this public marketing website, peersbridge.org, uses standard web-analytics tools — Google Analytics and Microsoft Clarity — to understand aggregate website usage. Those run on the website only, never inside the app.)

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account
  • Match you with compatible professionals and enable 1:1 meetings, messages, and calls
  • Calculate and maintain your Trust Score
  • Verify your identity and keep the community safe (fraud- and abuse-prevention)
  • Process your subscription and payments
  • Provide the features you use (contacts & cards, location features, budget insights, company research)
  • Send notifications about matches and updates
  • Improve our services and develop new features
  • Respond to your inquiries and comply with our legal obligations

4. Legal Basis for Processing

We process your personal data on the following legal bases under the personal-data law of the Republic of Kazakhstan (Law "On Personal Data and Their Protection" No. 94-V):

  • Your consent — for example, to process your profile data, to carry out identity verification, to receive notifications, and (where applicable) for cross-border processing. You may withdraw consent at any time (see "Your Rights").
  • Performance of a contract — where processing is necessary to provide the Service under the User Agreement.
  • Compliance with our legal obligations — for example, accounting, tax, and record-keeping requirements.
  • Our legitimate interests — for example, keeping the Service secure and preventing fraud and abuse — to the extent permitted by law.

5. Information Sharing & Sub-processors

We may share your information in the following situations, and we do not sell your personal data:

  • With your matches: when you are matched with another user, we share limited profile information to facilitate your connection.
  • Legal requirements: we may disclose information if required by law or in response to valid legal requests from the authorities of the Republic of Kazakhstan or other competent bodies.

We use the following categories of sub-processors and service providers to operate the Service. Each acts under contractual confidentiality and data-protection obligations:

  • Sumsub (identity/KYC verification) — captures and holds identity documents and biometric selfie/video during verification and returns the result to us.
  • Payment providers — Apple In-App Purchase (for iOS subscriptions) and our payment provider for the Telegram/web product process your payments; we do not receive your full card details.
  • Apple — for Sign in with Apple, App Store distribution, In-App Purchase, and push notifications on iOS.
  • Telegram — as the messaging platform for the Telegram bot and Mini App.
  • Hosting & cloud infrastructure providers — used to store data and run the Service.
  • OpenAI (United States) — a third-party AI processor used only for three features: the AI onboarding interview (your text answers), voice-message transcription, and moderation of content you report for abuse. No other data is sent to OpenAI; in particular, your budget/financial data is not sent to OpenAI, and our professional-matching model runs on our own local infrastructure.
  • Website analytics — Google Analytics and Microsoft Clarity run on this marketing website only (aggregate website-usage statistics and session analytics), never inside the app.

6. Cross-Border Data Processing

Some of our service providers and infrastructure may process your personal data on servers located outside the Republic of Kazakhstan. By using the Service, you consent to such cross-border processing of your personal data to the extent necessary to provide the Service. We apply contractual and technical safeguards to protect your data wherever it is processed.

7. Data Security & Encryption

We take specific, concrete measures to protect your data. We describe them precisely, and we are equally clear about what our encryption does not do:

  • Encryption in transit: all traffic between your device and our servers is protected with TLS/HTTPS.
  • End-to-end encrypted direct messages: direct messages between users are end-to-end encrypted using industry-standard cryptography — AES-256 for message content and an elliptic-curve (ECDH) key exchange. Only your device and the recipient's device hold the keys; our servers relay and store only encrypted ciphertext and cannot read your message contents.
  • What our encryption does not do (honest limits): the current end-to-end implementation uses a static key exchange, so it does not provide forward secrecy, and the encrypted messages are stored on our servers in encrypted form. We do not claim "perfect", "unbreakable", "forward-secret", or "zero-knowledge" encryption — only what is described here.
  • On-device & local AI: the app's AI writing assistance runs on your device, and our professional-matching model runs on our own (non-third-party) infrastructure. These do not send your content to any third-party AI provider.
  • Third-party AI processing: exactly three features send the relevant content to OpenAI, a third-party AI provider in the United States, and only these three: (1) the AI onboarding interview — your text answers; (2) voice-message transcription — the audio of a voice message you record; and (3) abuse-report moderation — the content you report when you flag another user. Nothing else is sent to a third-party AI provider. Your budget/financial data is analyzed by a built-in, deterministic method and is not sent to OpenAI or any third-party AI, and our professional-matching model runs on our own local (non-third-party) infrastructure.
  • Credential storage: your login credentials are stored in your operating system's secure keychain.
  • Export classification: because the app uses encryption, it is self-classified as a mass-market product under U.S. export regulations (ECCN 5D992.c).

No method of transmission over the Internet or method of electronic storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security.

8. Data Retention & Deletion

We keep your personal data only for as long as your account is active or as needed to provide the Service. You can delete your account at any time — directly in the app's account settings, or by contacting us — and we do not hold your account behind a hidden recovery window. When you delete your account, we delete your personal data from our active systems, except for records we are required to retain by law. Those exceptions are kept only for the minimum period the law requires and only for the stated purpose, then deleted or anonymized. They include: transaction, payment, and accounting/tax records; identity-verification (KYC) records; evidence relating to abuse reports, safety, and fraud-prevention; and any other records we are legally obliged to keep.

9. Your Rights

Under the personal-data law of the Republic of Kazakhstan, and depending on your location, you have the right to:

  • Access your personal data and obtain information about how it is processed
  • Correct inaccurate or incomplete data
  • Delete your account and personal data at any time — from within the app or by request — subject to the legal-retention exceptions above
  • Withdraw your consent (which may mean you can no longer use the Service)
  • Object to, or ask us to restrict, certain processing
  • Data portability where applicable
  • Lodge a complaint with the authorized personal-data-protection body of the Republic of Kazakhstan

10. Third-Party (Non-User) Data

Some features let you bring in information about other people — for example, importing contacts from your address book or scanning a business card. When you do this, you may be sharing the personal data of people who are not PeersBridge users. You confirm that you have a lawful basis to share that data with us for the purpose of building your personal network map and preparing meeting briefs, and that you will not use the Service to collect other people's data without a proper basis. If you are a non-user and believe your data was imported, contact us and we will handle your request and, where required, delete the data.

11. Children's Privacy

Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

12. Data-Protection Contact & Breach Notification

You can reach our data-protection contact for any privacy request or concern at privacy@peersbridge.org. If a personal-data breach affecting you occurs, we will notify the authorized body and affected users as required by applicable law and within the legally-required timeframe.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

Contact Us & Operator

If you have questions about this Privacy Policy or our practices, please contact us:

Email: privacy@peersbridge.org

Telegram: @Peersbridge_bot

For general help and frequently asked questions, see our Support & FAQ page. Your use of the Service is also subject to our User Agreement (Terms of Use).

Operator: NEKSA IKS TI, TOO

BIN: 230940021527

Registered address: 050013, Republic of Kazakhstan, Almaty, Almaly district, Sharipova A street, building 145, block 5, apt. 87

Phone: +7 (777) 320-00-71

Back to Home