Bhrmn.← BACK TO BHRMN

Bhrmn — Privacy Notice

Last updated: 29 August 2026
Applies to: the Bhrmn private beta (invite-only)

Who we are

Bhrmn is a travel identity platform operated by Yash Thakur, an individual based in India. Under the DPDP Act we are the Data Fiduciary for the personal data described here. You are the Data Principal.

Contact for any privacy question, request or complaint: hello@bhrmn.in

You must be 18 or over

Bhrmn is not for anyone under 18. The DPDP Act treats every person under 18 as a child and requires verifiable parental consent plus a ban on profiling — obligations this beta is not built to meet. You confirm you are 18 or over when you create an account. If we learn an account belongs to someone under 18, we will delete it and its data.

What we collect, and why

We collect only what a travel identity needs to work. Each item below is listed with the specific purpose it serves — we do not collect anything "just in case".

WhatWhyBasis
Email addressTo sign you in, and to send the one-time codes that do itConsent
Display name and handleTo identify you to other travellersConsent
Home cityTo show you travellers passing through your cityConsent
Travel DNA (traveller types you pick)To describe how you travel on your profileConsent
Trips: places, dates, notes, companions, visibilityThis is your travel record — the product itselfConsent
Travel documents you upload (tickets, boarding passes, booking confirmations)To read the dates and route off them so a trip can be marked verifiedConsent
Data read from those documents (route, dates, carrier, booking reference, the name printed on the ticket)To propose a trip for you to confirm, and to keep an auditable record of what backed a verified tripConsent
Which of the app's five screens you open, and whenTo find out whether the beta actually works — which parts people come back to, and how many people get a trip verifiedConsent
Who you follow, and who you have blockedTo build your feed, and to keep blocked people apartConsent
Reports you file: the reason, any note you add, and who it is aboutTo act on rule-breaking and keep the record trustworthyLegitimate use
Check-ins: the city you name, when, and whether you chose to be seenTo show people who follow you that you are somewhere nowConsent
Photos you add to a trip, and any caption on themTo build your travel record and the portfolio book made from itConsent
Photos you post, their captions, and any place you tagTo share where you have been with people who follow youConsent
Trails: short videos you post (up to a minute), a still frame from each, the caption and any place you tagTo share trips as video with the people you choose. Same Everyone / Followers / Only me choice as a photoConsent
"Been there" and saves on trails"Been there" is shown to whoever can see that trail; a save is visible only to youConsent
Likes and comments you leave, and who left them on your postsTo make posts a conversation rather than a broadcastConsent
Trip spending you record in a portfolioTo show others what a trip actually cost, if you choose to share itConsent
Which Magazine stories you have already seen, and whenTo show you new stories first instead of the same ones every time you open the appConsent
Magazine stories you saveTo keep them for you after they leave the feed. Only you can see themConsent
A profile photo and a short bio, if you add themSo other travellers recognise you. Visible to signed-in Bhrmn users, never to anyone signed out; the photo's location data is removed on your phone before upload, and removing the photo deletes the fileConsent
When you last opened ActivityTo show what is new since then. Nothing else about your reading is recordedConsent
Your answer when someone says you were on their tripA companion only appears on a trip once that person confirms it. Until then they see only whose trip it is, where and whenConsent
Waitlist sign-ups on our website: your email, and optionally your city and where you heard of usTo send you one invitation when there is a place for you. Not readable by any Bhrmn user, signed in or not, and never used for marketingConsent

We do not collect government identity documents (Aadhaar, PAN, passport data pages), payment card details, precise location, contacts, or your device's photo library. Bhrmn never reads your camera roll — you choose individual files to upload.

About that last row

It was added on 29 August 2026 and it is the only thing in this table that exists for our benefit rather than yours, so it is worth being precise about its limits.

We are telling you this because a private beta is an experiment, and you are entitled to know you are in one.

About photos and portfolios

A photo is attached to a trip, and a portfolio is a book assembled from that trip's photos and notes. Three things follow:

Photos live in private storage. They are never served from a public URL — each one is fetched through a link that expires within minutes.

Photos, and the record

They are two different things, and Bhrmn keeps them apart on purpose.

Your travel record — the timeline, verified trips, skills, Travel DNA — is evidence. It is backed by documents and Bhrmn will not let it be self-declared.

Photos and comments are not evidence. A post earns no verification, counts towards no skill, and changes nothing about your record. That is what lets it be ordinary: post what you like, or nothing at all.

Posts carry their own visibility — Everyone, Followers or Only me — set when you post and changeable after. Comments are visible to whoever can see the post. You can delete your own comments anywhere, and anyone's comments on your own posts.

Money in a portfolio

A portfolio can record what a trip cost — flights, stays, food, entries. It is there so someone reading can work out what their own version would cost, which is one of the more useful things a traveller can tell another one.

It is yours until you say otherwise. Expenses in a book default to hidden, and sharing them is a switch you flip on that book. Bhrmn asks for no account details, no card, and no payment information of any kind — only the numbers you choose to type.

About check-ins

The Live Rail shows people who follow you that you are in a city right now. Three things about it are worth stating plainly, because presence features are where privacy notices usually get vague:

A visible check-in is shown only to people who follow you, and never to anyone either of you has blocked. That rule is enforced in the database, alongside the one for trips.

About reports

A report is the one place you can write free text about another person, so it gets its own limits.

What is and is not allowed, and what happens after a report, is set out in MODERATION.md.

Your travel documents

These get the strictest handling in the product, because a boarding pass carries your name and booking reference.

Who else sees your data

We do not sell your data. We do not share it with advertisers. We run no behavioural advertising and no third-party ad tracking.

Where your data lives

Our database and file storage are currently hosted in Singapore (Supabase, ap-southeast-1). Document processing and email delivery may involve providers outside India. The DPDP Act permits transfers outside India except to countries the Government restricts; we will comply with any such restriction if one is notified.

How long we keep it

When you delete your account we erase your profile, trips, documents, uploaded files and verification records. We do not keep a shadow copy.

Your rights under the DPDP Act

You can, at any time:

We aim to answer any request within 30 days.

Security

If a breach affecting your data occurs, we will notify you and the Data Protection Board as required.

Changes

If this notice changes in a way that affects what we collect or why, we will tell you in the app before the change takes effect and ask for consent again where the law requires it.