Privacy Policy
Last updated: July 7, 2026
Bulletin Bored is a community bulletin board for local events. This policy explains what we collect, why we collect it, and the choices you have. We've tried to keep it in plain English β if anything is unclear, write to us at support@bulletinbored.io.
Who we are
Bulletin Bored is a US-based service operated from Illinois, currently in beta. Our boards, and the data behind them, are hosted in the United States. When this policy says "we" or "us," it means Bulletin Bored.
What we collect
Account and profile. When you sign up we collect your name, email address, and either a password (stored hashed by our authentication provider β we never see it in plain text) or your Google sign-in. Your profile also holds your home city and, if you add them, an avatar photo and a phone number. Business accounts additionally have a business name, logo, bio, and the contact details you choose to publish on your business page.
Content you post. Event notes (title, description, date and time, venue and address, images and flyers, itineraries, bring lists, pricing details, and any payment handles you type in), post-event recaps and reviews, photos, chat messages on private events, and feedback you send us through the footer forms (along with the reply-to email you provide).
Guest emails.Hosts can invite people to private events (and cohosts to any event) by email address. We use that address only to deliver the invitation, connect it to an account registered under the same email, and record the RSVP. Guest emails are visible only to the event's host β never to other guests or the public.
Usage analytics.When a note is shown or opened, or its ticket link or "going" button is clicked, we log an event with the note, the board it appeared on, and a viewer id: your profile id if you're signed in, or the anonymous bb_anoncookie id if you're not. These logs power the aggregate view counts promoters see, the "hot" badge, and event recommendations. Raw event rows are deleted after about a week; only per-note hourly totals are kept longer (see Retention below).
Device and log data. Like most websites, our hosting infrastructure keeps standard server logs (IP address, browser type, pages requested) for security, rate-limiting, and debugging.
How we use it
- Running the boards β placing your notes on the city boards you chose, ordering the rails, picking the hourly featured note, and showing accurate view and RSVP counts.
- Promoter stats β event owners see aggregate counts of impressions, opens, ticket clicks, and RSVPs for their own notes. They never see who the individual viewers were.
- Recommendationsβ a simple points system uses your recent opens, clicks, and RSVPs (last 90 days), plus the tags and promoters you follow, to suggest events you might like. There's no advertising profile β it never leaves the service.
- Emails you controlβ invitations and cohost requests, RSVP confirmations, note milestones ("your note is live," post-event summaries), and optional digests. Notification emails respect your per-type toggles and quiet hours in Settings β Notifications; transactional emails (invites, sign-in codes, password resets) are sent when the action calls for them.
- Safety and moderation β note text is automatically scanned when you post, links are checked, and our admins can review and remove content that breaks the Terms & Conditions.
- Account security β optional two-factor login codes, remembering trusted devices, and the encrypted account switcher.
We do not sell your personal information, and we don't use it for third-party advertising.
Cookies
We only set first-party cookies β no advertising or cross-site tracking cookies.
| Cookie | What it does | Lifetime |
|---|---|---|
| Supabase auth cookies (sb-β¦) | Keep you signed in. Set by our auth provider when you log in; hold your session tokens. | For your session, refreshed while you use the site |
| bb_anon | A random anonymous id for signed-out visitors, so view counts can be de-duplicated without knowing who you are. Never linked to an account. | 1 year |
| bb-trusted-devices | If you turn on two-factor authentication, remembers browsers that already passed an email code so you aren't asked on every login. Signed; holds no personal data beyond account ids. | ~90 days |
| bb-saved-sessions | Powers the account switcher β an encrypted list of the logins you chose to save on this browser. Unreadable without our server key. | 1 year |
Services we rely on
A handful of providers process data on our behalf, under their own security commitments:
- Supabase β database, authentication, and file storage (hosted in the US).
- Vercel β application hosting and server logs.
- Resend β delivers the emails we send you.
- Mapboxβ map tiles and address search. When you use a map or look up a venue, your request ( including your IP address) is processed by Mapbox; we don't store your device location.
- Googleβ only if you choose "Continue with Google" to sign in.
Who can see what
- Public events are visible to everyone, including signed-out visitors.
- Private events β the event page, guest list, chat, and bring lists β are visible only to the host and invited guests. Guest email addresses are visible only to the host.
- Personal accounts stay anonymous on public notes. Your profile name is not shown to other users as the poster of a public note; only the host names you type into the note itself appear. Business accounts post publicly under their business name and logo.
- Friend activityβ whether friends can see that you're going to events is controlled by your activity-sharing setting; set it to "Nobody" and your RSVPs are never surfaced to others or used for their recommendations.
- Recap photos shared by guests appear publicly only after the host approves them.
Retention and deletion
You can delete your account yourself at any time in Settings β Security. Deletion is immediate: after re-confirming with your password (or an emailed code for Google-only accounts), your profile, notes, messages, and uploaded files are removed.
Raw analytics events are deleted after about seven days and rolled up into hourly per-note totals β counts with no viewer ids attached β which we keep so promoters' historical stats stay accurate. Feedback you email us lives in our support inbox for as long as we need it to help you.
Children
Bulletin Bored is not directed at children under 13, and you must be at least 13 to use it. If you believe a child under 13 has created an account, contact us and we'll remove it.
Your choices
- Turn each notification type on or off β and set quiet hours β in Settings β Notifications.
- Control who sees your event activity in Settings β Friends.
- Edit or delete your notes, recaps, and photos anytime.
- Delete your account in Settings β Security (immediate, no waiting period).
- Block or clear cookies in your browser β signed-out browsing works without the
bb_anoncookie; you just may be counted more than once in view totals. - Ask us anything about your data at support@bulletinbored.io.
Changes to this policy
We're in beta, so this policy will evolve with the product. When we make meaningful changes we'll update the date at the top and, for significant changes, let you know in the app or by email. Continuing to use Bulletin Bored after a change means you accept the updated policy.
Contact
Questions, requests, or concerns: support@bulletinbored.io. Ideas for the product are always welcome at suggestions@bulletinbored.io.
Looking for the rules of the road? Read our Terms & Conditions.