BedPost
BedPost
Privacy Policy Get the app

Privacy Policy

Stetty Ventures LLC is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how we use it, who we share it with, and your rights — in plain language.

Contents

  1. Data Controller & Contact
  2. Data We Collect
  3. Legal Basis for Processing (GDPR)
  4. How We Use Your Data
  5. AI-Powered Features (Bex)
  6. Cookies & Tracking Technologies
  7. Third-Party Sub-Processors
  8. Health & Sensitive Data
  9. BedPost Connect Data
  10. Data Sharing & Disclosure
  11. International Data Transfers
  12. Automated Decision-Making & Profiling
  13. Data Retention
  14. Data Security
  15. Children's Privacy
  16. Your Rights — EU, EEA & UK (GDPR / UK GDPR)
  17. Your Rights — California (CCPA / CPRA)
  18. Your Rights — Other US States
  19. Data Breach Notification
  20. Changes to This Policy
  21. Contact & Complaints

Last updated: May 13, 2026  ·  Effective date: May 13, 2026  ·  Stetty Ventures LLC, registered in Wyoming, USA

1. Data Controller & Contact

Data Controller: Stetty Ventures LLC, registered in Wyoming, United States of America.

Privacy contact: privacy@getbedpost.com

EU/EEA Representative (Article 27 GDPR): We are in the process of designating an EU representative. Until designated, EU/EEA users may contact us directly at privacy@getbedpost.com. We respond within 30 days.

UK Representative: UK users may exercise their rights under the UK GDPR by contacting privacy@getbedpost.com.

Data Protection Officer: Given the nature and scale of our processing of special-category health data, we are evaluating the appointment of a DPO. In the interim, our privacy team handles all data protection enquiries at the address above.

2. Data We Collect

We collect only the data necessary to provide and improve our service.

Account Data

Health & Wellness Data Special Category — GDPR Art. 9

Profile Data

BedPost Connect Data

Subscription & Payment Data

Device & Technical Data

Usage Data (Anonymized)

4. How We Use Your Data

We never sell your personal data. We never use your health or wellness data for advertising. We never share individually identifiable data with third parties without your explicit consent.

5. AI-Powered Features (Bex)

BedPost includes an AI coaching assistant called Bex. When you use Bex:

If you are in the EU/EEA and we rely on automated processing that produces significant effects on you, you have the right to request human review — see Section 12.

6. Cookies & Tracking Technologies

Mobile App

The mobile app does not use browser cookies. We use:

Web App & Website

Our web app and landing page use:

We do not use advertising cookies, third-party tracking pixels, or cookie-based retargeting. The web app uses a strictly necessary session cookie plus an analytics cookie (Mixpanel) that requires your consent.

Do Not Track

We respect browser-level Do Not Track (DNT) signals for our website. Our app does not respond to DNT signals because it uses no cross-site tracking by default.

7. Third-Party Sub-Processors

We engage the following sub-processors to deliver the service. Each operates under a Data Processing Agreement where required by applicable law.

Sub-Processor Purpose Data Shared Location
Stripe Payments Inc. Web subscription billing & payment processing Email, billing country, payment-method token, subscription status. No health data. USA / EU
RevenueCat Mobile in-app purchase management (iOS & Android) Anonymous app user ID, subscription status. No health data. USA
Apple / Google App distribution, in-app purchases, Sign In with Apple/Google Per their own policies. We receive identity tokens only. USA
Sentry Crash reporting & error monitoring Device type, OS version, app version, stack traces. No personal or health data. USA
Mixpanel Anonymized product analytics Anonymized usage events only. IP anonymization enabled. No personal or health data. USA
Neon, Inc. Managed PostgreSQL database (via Replit-managed Postgres) All persisted application data. Encrypted at rest (AES-256) and in transit (TLS 1.2+). USA
Replit, Inc. Application hosting & deployment infrastructure All data the application processes (encrypted at rest and in transit). USA

Sub-processor privacy policies: Stripe · RevenueCat · Sentry · Mixpanel · Google · Neon · Replit

Canonical sub-processor list: The full, up-to-date list of sub-processors — including legal entity names, data categories, processing region, and links to each provider's DPA — is published on our Sub-processor List. We give existing customers at least 30 days' notice before adding a new sub-processor. For the contractual framework that governs these relationships, see our Data Processing Addendum.

8. Health & Sensitive Data

Your cycle data, wellness logs, and personal notes constitute special-category personal data under GDPR Article 9 and sensitive personal information under the CCPA/CPRA. We treat this data with the highest level of protection.

9. BedPost Connect Data

BedPost Connect matches you anonymously with compatible users based on derived behavioral signals — not your raw wellness logs.

10. Data Sharing & Disclosure

We do not share your personal data with third parties except:

We never sell personal data. We never share health or wellness data for advertising purposes.

11. International Data Transfers

Stetty Ventures LLC is based in the United States. If you use the app from the EU, EEA, UK, or other jurisdictions with data transfer restrictions, your data will be transferred to and processed in the United States.

EU/EEA users: Transfers to the United States are made on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, or where a sub-processor participates in an adequacy framework recognized by the EU. We conduct transfer impact assessments for key sub-processors.

UK users: Transfers from the UK are made under the UK International Data Transfer Agreement (IDTA) or UK addendum to EU SCCs.

Swiss users: Transfers are made pursuant to the Swiss Federal Act on Data Protection (revFADP) and applicable SCCs.

To request a copy of the applicable transfer mechanisms, contact privacy@getbedpost.com.

12. Automated Decision-Making & Profiling

BedPost uses automated processing to deliver its core features. We are transparent about where automated decisions affect you.

Connection Score

Your Connection Score is calculated algorithmically from your wellness and activity data. This score is for your personal insight only — it is never shared with other users, employers, or insurers, and does not affect your access to the service.

BedPost Connect Matching

Connect uses an algorithm to derive anonymized compatibility signals and rank potential matches. This constitutes automated profiling under GDPR Article 22. The matching algorithm produces a compatibility signal used to suggest connections — it does not make legally significant or similarly significant decisions about you.

Cycle & Fertility Predictions

Cycle phase predictions and fertile window calculations are generated algorithmically. These are informational estimates — they are not medical advice and should not be used as the sole basis for any health decision.

Your Rights Regarding Automated Processing

If you are in the EU/EEA or UK, you have the right to request human review of any automated processing that produces significant effects on you. Contact privacy@getbedpost.com to make such a request.

13. Data Retention

Data Type Retention Period
Account & profile dataFor the account lifetime; deleted within 30 days of a verified deletion request
Health & wellness logsFor the account lifetime; permanently deleted within 30 days of account deletion
Connect anonymous messagesHard-deleted 365 days after the message was sent (nightly sweep)
Waitlist signups (pre-launch)Hard-deleted after 180 days of inactivity (nightly sweep)
Webhook event log (Stripe / RevenueCat)Hard-deleted after 90 days (nightly sweep)
Subscription & billing recordsRetained for 7 years as required by applicable tax and financial law
Crash logs30 days then automatically deleted
Anonymized analytics dataUp to 24 months; irreversibly anonymized before storage
Inactive accountsAccount is deleted after 24 months of inactivity. We send an advance notice 30 days before deletion so you can keep your account by simply opening the app.

After deletion, data may persist in encrypted backups for up to 90 additional days before being permanently overwritten. Backup data is inaccessible during this period.

Erasure cascade across our processors

When you request account deletion (Settings → Privacy & Security → Delete Account), we run a coordinated cascade against every processor that holds data under your identity, tracked in an internal audit log:

Each provider call is retried with a 6-hour back-off up to 5 attempts. Once every provider has confirmed (or returned "no data held"), you receive a confirmation email itemizing what happened with each. If a provider remains unreachable after the final attempt, our team is alerted and completes the deletion manually within 7 days. Sentry crash reports are not listed because they only ever held anonymous identifiers.

14. Data Security

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to security@getbedpost.com.

15. Children's Privacy

BedPost is intended exclusively for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we discover we have received data from a minor, we will delete it promptly.

If you believe a minor has created an account, please contact privacy@getbedpost.com immediately.

BedPost is not directed at children and is not subject to the Children's Online Privacy Protection Act (COPPA) as we take active steps to prevent access by minors.

16. Your Rights — EU, EEA & UK (GDPR / UK GDPR)

If you are located in the EU, EEA, or UK, you have the following rights under the GDPR and UK GDPR. These rights apply to all personal data we process about you.

To exercise any right, email privacy@getbedpost.com. We will respond within 30 days (extendable to 90 days for complex requests, with notice). We do not charge a fee for legitimate requests. We may ask you to verify your identity before processing sensitive requests.

18. Age Verification & Encrypted Date of Birth

BedPost is an 18+ product. At signup we ask for your full date of birth and apply a region-aware age check before creating the account:

The date you provide is encrypted at rest with AES-256-GCM (the same versioned-key scheme we use for proxy credentials — see our security overview) and stored separately from your profile so administrators cannot read it casually. We retain it solely to verify your age, satisfy law-enforcement requests where legally compelled, and demonstrate compliance with the regional minimums above. We never display it back to you in cleartext outside of a verified data-export request.

17. Your Rights — California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights.

Categories of Personal Information Collected (Last 12 Months)

Your CCPA / CPRA Rights

To exercise these rights, email privacy@getbedpost.com or use the in-app Data & Privacy settings. Authorized agents may submit requests with written authorization. We will respond within 45 days (extendable to 90 days with notice).

18. Your Rights — Other US States

Residents of the following states have privacy rights similar to California's under their respective laws. In all cases, contact privacy@getbedpost.com to exercise any right.

State Law Key Rights
VirginiaVCDPAAccess, correction, deletion, portability, opt-out of sale/profiling
ColoradoCPAAccess, correction, deletion, portability, opt-out of sale/profiling
ConnecticutCTDPAAccess, correction, deletion, portability, opt-out of sale/profiling
TexasTDPSAAccess, correction, deletion, portability, opt-out of sale/profiling
OregonOCPAAccess, correction, deletion, portability, opt-out of sale/profiling
Montana, Iowa, Indiana, Tennessee, Delaware, New Hampshire, New Jersey, Nebraska, Maryland, MinnesotaVariousAccess, correction, deletion, opt-out of sale — contact us to exercise

We honor privacy rights requests from all US states regardless of whether a specific state law currently applies to us. We do not sell or share personal information, so opt-out-of-sale rights are already in effect for all users.

19. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

Our breach response team conducts regular drills and maintains an incident response plan. To report a potential security incident, email security@getbedpost.com.

20. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via in-app notification and/or email at least 30 days before changes take effect. The "last updated" date at the top of this page reflects the most recent revision.

For non-material changes (e.g., clarifications, correcting typos), we will update the date and post the revised policy without prior notice. Continued use of BedPost after the effective date of material changes constitutes acceptance of the updated policy.

21. Contact & Complaints

Privacy Enquiries & Rights Requests
Security Vulnerabilities
General Support
Company
Stetty Ventures LLC
Registered in Wyoming, USA

Supervisory Authority Complaints

If you are in the EU/EEA and believe we have not handled your data lawfully, you have the right to lodge a complaint with the data protection supervisory authority in your Member State. A full list of EU supervisory authorities is available at edpb.europa.eu.

UK users may complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint

We encourage you to contact us first so we can address your concern directly.