Privacy Policy
Last updated October 8, 2026
This policy covers hosted Bridge (the dashboard at dashboard.bridge.kroszborg.co and its API) and the Bridge Android app. Bridge is open source, so everything below can be checked against the code. If you run Bridge on your own server, your data stays on that server and this policy does not apply; whoever operates it is responsible for it.
What we collect
- Your account: email address, name (optional), and your password, which is stored only as an Argon2id hash.
- Messages you send and receive: phone numbers, message text, delivery status and which phone handled each message. You put this data in Bridge to have it delivered; we process it only to do that.
- Paired phones: model, Android and app version, battery level, network type and SIM details needed to route messages. The app never reads your SMS history, contacts, photos or location.
- Technical logs: IP addresses and API request details, to secure the service, rate-limit abuse and help you debug your integration.
- Billing: your plan and subscription status. Card and payment details go straight to our payment provider and never reach Bridge.
How long we keep it
- Message text is erased after 30 days; numbers and statuses stay for your history.
- API request logs are deleted after 14 days.
- Account data stays until you delete your account under Account settings, which removes it along with workspaces where you are the only member.
Who processes it for us
- Amazon Web Services hosts the servers and database, in Mumbai, India.
- Dodo Payments takes payments as merchant of record and handles invoices and tax.
- Your email provider and ours deliver account email such as password reset links.
- SMS providers you connect (MSG91, Twilio, Vonage or Plivo) receive the messages you route through them, under their own policies.
- Google Firebase Cloud Messaging, only in the Play build of the Android app, wakes the app when a message is waiting. The F-Droid and GitHub builds use UnifiedPush or a persistent connection instead.
We do not sell personal data, show ads, or use analytics or tracking scripts.
Cookies
The dashboard sets a session cookie to keep you signed in and a cookie that remembers your last project; your light or dark theme is kept in your browser. There are no advertising or third-party cookies.
The Android app and SMS permissions
Bridge turns your phone into an SMS gateway. It needs permission to send SMS so it can deliver the messages you queue, and to receive SMS: while the phone is paired, every SMS it receives is forwarded to its Bridge project, so replies and incoming messages appear in your dashboard and webhooks. Pair a phone whose incoming messages you are happy to share with your project. It stops when you unpair it or uninstall the app.
Your rights
You can see, export through the API, correct and delete your data. To ask a question or make a request you cannot do in the dashboard, contact Abhiman Panwar. We answer within 30 days.
Changes
If this policy changes in a way that matters, we will say so in the dashboard before it takes effect. Earlier versions are in the public repository's history.