Bhrmn — Privacy Notice
Last updated: 29 August 2026
Applies to: the Bhrmn private beta (invite-only)
Who we are
Bhrmn is a travel identity platform operated by Yash Thakur, an individual based in India. Under the DPDP Act we are the Data Fiduciary for the personal data described here. You are the Data Principal.
Contact for any privacy question, request or complaint: hello@bhrmn.in
You must be 18 or over
Bhrmn is not for anyone under 18. The DPDP Act treats every person under 18 as a child and requires verifiable parental consent plus a ban on profiling — obligations this beta is not built to meet. You confirm you are 18 or over when you create an account. If we learn an account belongs to someone under 18, we will delete it and its data.
What we collect, and why
We collect only what a travel identity needs to work. Each item below is listed with the specific purpose it serves — we do not collect anything "just in case".
| What | Why | Basis |
|---|---|---|
| Email address | To sign you in, and to send the one-time codes that do it | Consent |
| Display name and handle | To identify you to other travellers | Consent |
| Home city | To show you travellers passing through your city | Consent |
| Travel DNA (traveller types you pick) | To describe how you travel on your profile | Consent |
| Trips: places, dates, notes, companions, visibility | This is your travel record — the product itself | Consent |
| Travel documents you upload (tickets, boarding passes, booking confirmations) | To read the dates and route off them so a trip can be marked verified | Consent |
| Data read from those documents (route, dates, carrier, booking reference, the name printed on the ticket) | To propose a trip for you to confirm, and to keep an auditable record of what backed a verified trip | Consent |
| Which of the app's five screens you open, and when | To find out whether the beta actually works — which parts people come back to, and how many people get a trip verified | Consent |
| Who you follow, and who you have blocked | To build your feed, and to keep blocked people apart | Consent |
| Reports you file: the reason, any note you add, and who it is about | To act on rule-breaking and keep the record trustworthy | Legitimate use |
| Check-ins: the city you name, when, and whether you chose to be seen | To show people who follow you that you are somewhere now | Consent |
| Photos you add to a trip, and any caption on them | To build your travel record and the portfolio book made from it | Consent |
| Photos you post, their captions, and any place you tag | To share where you have been with people who follow you | Consent |
| Trails: short videos you post (up to a minute), a still frame from each, the caption and any place you tag | To share trips as video with the people you choose. Same Everyone / Followers / Only me choice as a photo | Consent |
| "Been there" and saves on trails | "Been there" is shown to whoever can see that trail; a save is visible only to you | Consent |
| Likes and comments you leave, and who left them on your posts | To make posts a conversation rather than a broadcast | Consent |
| Trip spending you record in a portfolio | To show others what a trip actually cost, if you choose to share it | Consent |
| Which Magazine stories you have already seen, and when | To show you new stories first instead of the same ones every time you open the app | Consent |
| Magazine stories you save | To keep them for you after they leave the feed. Only you can see them | Consent |
| A profile photo and a short bio, if you add them | So other travellers recognise you. Visible to signed-in Bhrmn users, never to anyone signed out; the photo's location data is removed on your phone before upload, and removing the photo deletes the file | Consent |
| When you last opened Activity | To show what is new since then. Nothing else about your reading is recorded | Consent |
| Your answer when someone says you were on their trip | A companion only appears on a trip once that person confirms it. Until then they see only whose trip it is, where and when | Consent |
| Waitlist sign-ups on our website: your email, and optionally your city and where you heard of us | To send you one invitation when there is a place for you. Not readable by any Bhrmn user, signed in or not, and never used for marketing | Consent |
We do not collect government identity documents (Aadhaar, PAN, passport data pages), payment card details, precise location, contacts, or your device's photo library. Bhrmn never reads your camera roll — you choose individual files to upload.
About that last row
It was added on 29 August 2026 and it is the only thing in this table that exists for our benefit rather than yours, so it is worth being precise about its limits.
- It records the name of a screen and a timestamp, nothing else. There is no free-text field it could hold anything else in: the database physically rejects any value outside a fixed list of five screen names and seven event names.
- It records no content — not which trip, which card, which document, or which person you looked at.
- There is no third-party analytics service. No Google Analytics, no Firebase, no advertising or attribution SDK. It is our own database table, and no new company gets your data because of it.
- There is no device identifier, advertising ID or fingerprint.
- It is not collected when you are signed out.
- It is deleted with your account, like everything else.
We are telling you this because a private beta is an experiment, and you are entitled to know you are in one.
About photos and portfolios
A photo is attached to a trip, and a portfolio is a book assembled from that trip's photos and notes. Three things follow:
- Nobody else sees a trip photo until it is in a book you published. A photo you add to a trip is yours alone until it appears in a published book — on the cover or on a page. Photos left out of the book, and photos in a draft, stay private. Even then, a photo is never more visible than its trip: Followers means followers only, Only me means nobody else.
- Location and camera metadata are stripped before upload. Bhrmn does not read where a photo was taken, and does not keep the EXIF that would say.
- A book is private until you publish it. Assembling one changes nothing for anyone else. Publishing is a separate, deliberate press: it puts the book in the Following feed of people who can see that trip. Unpublishing takes it back out.
Photos live in private storage. They are never served from a public URL — each one is fetched through a link that expires within minutes.
Photos, and the record
They are two different things, and Bhrmn keeps them apart on purpose.
Your travel record — the timeline, verified trips, skills, Travel DNA — is evidence. It is backed by documents and Bhrmn will not let it be self-declared.
Photos and comments are not evidence. A post earns no verification, counts towards no skill, and changes nothing about your record. That is what lets it be ordinary: post what you like, or nothing at all.
Posts carry their own visibility — Everyone, Followers or Only me — set when you post and changeable after. Comments are visible to whoever can see the post. You can delete your own comments anywhere, and anyone's comments on your own posts.
Money in a portfolio
A portfolio can record what a trip cost — flights, stays, food, entries. It is there so someone reading can work out what their own version would cost, which is one of the more useful things a traveller can tell another one.
It is yours until you say otherwise. Expenses in a book default to hidden, and sharing them is a switch you flip on that book. Bhrmn asks for no account details, no card, and no payment information of any kind — only the numbers you choose to type.
About check-ins
The Live Rail shows people who follow you that you are in a city right now. Three things about it are worth stating plainly, because presence features are where privacy notices usually get vague:
- It is a city, never a location. Bhrmn does not ask for device location, does not receive it, and stores no coordinates. A check-in is a row pointing at a city in our own list — the same list trips use.
- You are hidden unless you say otherwise. Every check-in starts private. It is visible to nobody, including us in any practical sense, until you turn on "Show me on the rail" — and you can turn it off again at any moment, without checking out.
- It dies within a day. A check-in expires 24 hours after you make it, and this is a database constraint rather than a habit: no code we write later can extend one. Expired check-ins are deleted a day after that. They are not part of your travel record, never become a trip, and are not counted towards any skill.
A visible check-in is shown only to people who follow you, and never to anyone either of you has blocked. That rule is enforced in the database, alongside the one for trips.
About reports
A report is the one place you can write free text about another person, so it gets its own limits.
- The person reported is never told who reported them. Not when we act, not when we dismiss it.
- Nobody can read reports about themselves, or find out one exists. The database has no read access for users at all — only the operator can see the queue. Being able to discover who reported you is how reporting becomes retaliation.
- A note is optional and capped at 500 characters.
- Reports are kept while the account they concern exists, because a pattern across time is usually the only way to tell a mistake from a habit.
- Blocking is not reporting. Blocking is private to you, needs no approval, and is undone at Profile → Blocked people. We are told nothing about why.
What is and is not allowed, and what happens after a report, is set out in MODERATION.md.
Your travel documents
These get the strictest handling in the product, because a boarding pass carries your name and booking reference.
- Stored in private cloud storage, partitioned per user. Access rules are enforced at the database level, so another Bhrmn user cannot read your documents even in error.
- Never shown on your profile, in the feed, or to anyone you travel with.
- Sent once to an AI model operated by Anthropic to extract the travel facts. The model is not trained on your document. It is processed to produce a result and not retained by us for any other purpose.
- Kept while the trip they verify exists, so a verified badge can be substantiated. Delete the trip or your account and they are deleted with it.
Who else sees your data
- Other Bhrmn users see only what you choose: your profile, and trips you set to Everyone or Followers. Private trips are yours alone. "Everyone" means every signed-in Bhrmn user — Bhrmn has no public website, and nothing here is readable without an account. New trips default to Followers.
- Discover shows other signed-in users the portfolios you published from trips set to Everyone, and photos you posted for Everyone. Nothing set to Followers or Only me, and never your trips or check-ins.
- Nobody who is not signed in can read any of it. Signed-out access reaches our city list and nothing else — not a profile, not a trip, not who follows whom.
- Companions you tag see that trip, and must confirm before it appears on their profile.
- People who follow you see a check-in only if you turned it on, only as a city, and only while it is live.
- People who follow you and live in a city you are visiting may see you in their "In your city" list — but only from a trip or check-in they could already see on your profile. Strangers in that city never get a list of who is there.
- Supabase hosts our database, authentication and file storage.
- Anthropic processes uploaded documents to extract travel facts.
- Resend delivers your sign-in emails.
We do not sell your data. We do not share it with advertisers. We run no behavioural advertising and no third-party ad tracking.
Where your data lives
Our database and file storage are currently hosted in Singapore (Supabase, ap-southeast-1). Document processing and email delivery may involve providers outside India. The DPDP Act permits transfers outside India except to countries the Government restricts; we will comply with any such restriction if one is notified.
How long we keep it
- Your account data: until you delete your account.
- Trips and documents: until you delete the trip, or your account.
- Verification records: for as long as the verified trip exists, because they are what a verified badge stands on.
- Failed or discarded upload drafts: deleted with your account.
- Check-ins: 24 hours live, deleted 24 hours after that — at most two days, whatever else happens.
- Photos and portfolios: until you delete the photo, the trip, or your account.
- Trails: until you delete the trail or your account. Deleting a trail removes the video file.
- Waitlist sign-ups: until you are invited and create an account, or ask us to remove you — whichever comes first. An invited address that never signs up is deleted 90 days after the invitation.
When you delete your account we erase your profile, trips, documents, uploaded files and verification records. We do not keep a shadow copy.
Your rights under the DPDP Act
You can, at any time:
- Access a summary of the personal data we hold about you and what we do with it
- Correct anything inaccurate, and complete anything incomplete — most of it is editable directly in the app, including who can see each trip, from your timeline
- Erase your data by deleting your account, in Profile → Delete account
- Withdraw consent, which for a consent-based service means deleting your account
- Nominate another person to exercise your rights if you die or become incapacitated
- Complain to us at hello@bhrmn.in, and if unsatisfied, to the Data Protection Board of India
We aim to answer any request within 30 days.
Security
- All traffic is encrypted in transit.
- Access to your rows and files is enforced by database-level row security, not by application code alone, so a bug in the app cannot expose another user's data.
- Verification cannot be self-declared: the app is structurally unable to mark a trip verified, which prevents both fraud and accidental corruption of the record.
- We use one-time email codes rather than passwords, so there is no password of yours to leak.
If a breach affecting your data occurs, we will notify you and the Data Protection Board as required.
Changes
If this notice changes in a way that affects what we collect or why, we will tell you in the app before the change takes effect and ask for consent again where the law requires it.