Updated: 18 September 2026
Surf City Apps LLC is the controller responsible for Bubblz's website, mobile app and related support. This notice covers all website languages. Website consent does not control app data processing. Features and providers can vary by version and platform.
Contact: privacy@bubblz.ai; Surf City Apps LLC, 440 N Barranca Ave #2975, Covina, CA 91723, USA. Our EU representative is BizLegal Ltd (EU Rep), 27 Cork Road, Midleton, Co. Cork, Ireland, company 635921; https://www.eurep.ie.
We obtain information from you, your browser/device, identity providers and app stores. Providers receive the information relevant to their function, not necessarily every category below.
PostHog session replay is enabled on supported devices with text/image masking configured. Sentry error reports may include screenshots, thread information and technical context. Some audio-format failures send the failed recording in a diagnostic report through Amazon SES. When diagnostic API logging is enabled, request/response content may be stored. Masking in one service does not mean all other diagnostic content is masked.
App analytics and other SDKs may initialize without a separate in-app consent gate. Website rejection does not stop them. Device microphone, notification and tracking permissions are separate controls; a tracking permission is not consent to every processing activity. Manage available app/device settings, unsubscribe from marketing messages, or contact us. Account deletion is available in app settings; deleting the app does not cancel an app-store subscription.
Necessary storage supports security, language and consent. Google Analytics and AppsFlyer website attribution remain blocked until their respective categories are accepted. Reject allows browsing with necessary functions. The floating privacy icon lets you change or withdraw consent. The choice lasts 90 days across Bubblz language pages in the same browser, not across devices or other company domains.
Global Privacy Control blocks optional website tracking. We do not separately respond to the older Do Not Track header. The site displays no ads and loads no advertising/remarketing tags. Providers may receive connection information when delivering permitted content or assets. The Cookie policy identifies storage and providers. Withdrawal stops future optional loading and clears accessible tracking storage; it does not erase information already received by providers.
Where GDPR or similar law applies, requested account, learning and purchase functions rely on contract performance; security, troubleshooting, support and proportionate service improvement on legitimate interests; required records on legal obligations; and optional website tracking or marketing on consent where required. Without information necessary for a requested feature, we may be unable to provide it.
You may object to processing based on legitimate interests, including our interests in reliable services and understanding their use. You may withdraw consent without affecting earlier lawful processing. Providing this policy or continuing to use the app does not itself supply any legally required consent. AI generates learning responses; we do not use it to make solely automated decisions with legal or similarly significant effects on you.
AWS hosts our website/consent service in the United States; Firebase/Google Cloud and the providers above support the app. Website delivery/security also uses CloudFront, Optimole, Google Fonts, unpkg, Wordfence and TranslatePress. Authorized personnel and providers may access information for their functions. We may disclose relevant records to advisers, to comply with law, protect rights/security, or in a business transfer subject to applicable safeguards.
Information may be processed in the US and other provider countries. AWS and Google include Standard Contractual Clauses for covered transfers. Other applicable safeguards depend on provider terms and the transfer, such as SCCs, UK transfer terms or an applicable adequacy framework. Contact us for the safeguards relevant to your data and how to obtain a copy. Provider privacy links appear below; their separate notices also explain their processing.
AWS · Google · Firebase · Apple · OpenAI · Lemonfox · PostHog · Sentry · AppsFlyer · RevenueCat · Superwall · Customer.io · Zoho · SendGrid / Twilio · Optimole · Wordfence
We keep account/history information while needed to provide the service or until deletion, subject to legal and operational exceptions. The account-deletion workflow removes Firebase account/profile history and requests Customer.io suppression. It does not automatically erase every analytics, attribution, purchase, support or diagnostic record. Contact us for those requests. Suppression identifiers may remain to prevent unwanted re-creation or messaging.
Purchases may be retained for restoration, accounting and disputes. Support/diagnostic/security records are kept for resolving requests, recurring failures, abuse and legal claims. Analytics, AI and other provider records follow their service/account settings; there is no single 24-month rule. Backups expire through their recovery cycles, and legal holds can extend retention. Uninstalling does not delete provider-side records.
Website choices expire after 90 days; consent evidence is kept up to 1,095 days and separate daily database backups up to 30 days. Full-server backups follow separate cycles. Cookie expiry differs from server-side retention.
Depending on applicable law, you may request access, correction, deletion, a portable copy, restriction, objection, withdrawal of consent, or opt-out of sale/sharing, targeted advertising or certain profiling. Email privacy@bubblz.ai or write to the address above, stating the service and request. We may ask for proportionate identity/authority verification, including for an authorized agent; no new account is required. Do not send passwords or full payment-card numbers.
We respond within applicable deadlines, explain lawful exceptions/extensions and do not discriminate for exercising rights. Requests are normally free. Where an appeal right applies, reply to our decision with “Privacy appeal.” You may complain to your privacy regulator: an EEA supervisory authority, the UK ICO, Swiss FDPIC, or relevant US state authority.
The categories in section 2 include identifiers/contact records, commercial information, internet/electronic activity, approximate location and content such as audio or support attachments. Sources, purposes and recipient categories are described there and above. Where CCPA applies, rights include knowing categories/specific information and disclosures, correction, deletion and opting out of sale or sharing, with applicable sensitive-information rights. Use the request methods above, including for the preceding 12 months. CCPA applicability depends on statutory business thresholds; other privacy protections may apply independently.
Bubblz is not intended for children under 16 in the EU or under 13 in the US. Contact us if a child has provided information so we can investigate. We use protected connections and access controls, but cannot guarantee absolute security. Material changes are reflected here with a revised date and additional notice or consent where required.