The short version:
- Both apps store your information on your own device by default. Nothing is uploaded anywhere unless you explicitly choose to.
- Sharing a document between the two apps ("Pairing") is end-to-end encrypted — our server only ever sees scrambled data, never names, contracts, or pay.
- The optional Cloud Backup is also end-to-end encrypted, protected by a password and a 12-word recovery code that only you hold.
- We don't run ads, don't sell data, and don't track you across other apps or websites.
Who this policy covers
This policy applies to the Bonakala Worker and Bonakala Employer apps (iOS, Android, and web), run by Jakobo-Maria Bartusch. Where the two apps handle something differently, it's called out below.
What stays on your device
By default, everything you enter — your record of hours and pay, contracts, payslips, notes, photos of documents, your name, and any other detail — is stored locally on your own phone, in the app's own private storage. It is never sent to us or to anyone else automatically. If you turn on the app's PIN lock or use "Erase everything" in Settings, that's a purely on-device action too.
Secure Pairing (sharing between Worker and Employer)
When a worker and employer link their apps ("Pairing"), each device generates a random, meaningless mailbox ID — no name, phone number, or address is ever attached to it on our server. When a document (a contract, a payslip, a letter) is shared, it is encrypted on the sending device before it ever leaves it. Our server stores only that encrypted blob, briefly, until the other device retrieves and decrypts it — we cannot read its contents, and we don't try to.
To let each side know when something new has arrived even while the app is closed, we send a content-free push notification ("Something new is here — open the app") through Apple's or Google's notification service. That notification never contains the document, its title, or who sent it.
Push notifications
If you allow notifications, your device registers a notification token with our server, linked only to your random mailbox ID — never to your name. We use it solely to trigger the content-free alert described above. You can turn notifications off at any time in your device's system settings.
Cloud Backup (optional)
Cloud Backup is off by default. If you turn it on, your data is encrypted on your device before it's backed up — using a 12-word recovery code that only you have. Our server stores only that encrypted backup and the account details needed to sign you in (a username and a password, stored using standard secure hashing, never in plain text). We cannot read your backed-up data, and if you lose your recovery code, neither can we recover it for you.
About account deletion: turning Cloud Backup off, or using "Erase everything," removes the backup connection and all data from your device, but does not yet automatically delete the account and encrypted backup from our server. If you'd like your Cloud Backup account fully deleted, contact us at the email below and we'll do it by hand. We're working on making this a self-service action.
Analytics
Bonakala Worker uses a small amount of privacy-first, cookie-free analytics (via Umami) to understand which screens are used and whether the app was installed — never what you write, save, or who you are. Bonakala Employer currently collects no analytics at all.
What we never do
- We never run advertising, and we never sell or share your data with advertisers or data brokers.
- We never ask for, infer, or store anything about a worker's immigration or residence status — there is no field for it, anywhere.
- We never contact your employer, a worker, the government, or anyone else on your behalf. Sharing only ever happens when you explicitly choose it.
- We never require an account to use the core features of either app.
Your rights
If you're in the EU/EEA or another jurisdiction with similar protections, you have the right to access, correct, or request deletion of any personal data we hold about you (in practice, this is limited to a Cloud Backup account and its encrypted contents, plus any push-notification token, since we hold nothing else). Write to the email below for any of these requests, or to lodge a complaint with your local data protection authority.
Children
Bonakala is intended for adults in employment relationships and is not directed at children.
Changes to this policy
If how either app handles data changes meaningfully, we'll update this page and change the date at the top.
Site owner / data controller: Jakobo-Maria Bartusch
Contact: bonakala@tutamail.com
This page describes, in plain language, how Bonakala actually works from a technical standpoint. It is not a substitute for legal advice.