message in aBOTTL
TermsPrivacyCookiesLegal

Privacy Policy

Last updated: 19 September 2026 · Prepared under the EU GDPR (we are established in Bulgaria).

1. Who we are (Data Controller)

YDA Ltd (UIC 206471089), established in Bulgaria, is the data controller for your personal data.

  • Address: Drujba, bl. 170, ent. B, fl. 7, apt. 67, 1592 Sofia, Bulgaria
  • Privacy requests: hello@bottl.world
  • Data Protection Officer: not appointed

2. What data we collect

a. Account data — email address, username, password (stored hashed by our authentication provider), the fact that you confirmed being old enough and when, your country (suggested from your connection, which you can change), your language and display preferences, your email notification choices, and the profile details you add: avatar, bio, answers to profile questions.

b. Content you create — the messages and photos you put in bottles, your replies (emoji, short answers, letters), and the reports you file.

c. Location data — Bottl is built on real places, so location is involved in several ways:

  • Your device's location, only with your permission: to set where a bottle departs from, to place a pin where you stand (you can also choose the spot on the map), to list the bottles around you and check that you are close enough to open one, and to guide you towards a bottle you are walking to. You control this in your device or browser settings; some features won't work without it.
  • An approximate location from your connection, which our hosting provider derives from your IP address: to centre the map, and to suggest your country, units and language. If your device cannot give a position when you launch a bottle, we offer this approximate spot as the departure instead; it is only used if you accept it.
  • What we keep: the exact departure point of each of your bottles; the place you were when you wrote a reply or a letter (it sets how long the carrier pigeon takes to fly); and, if you turn on push notifications or let the app guide you to a bottle, your last known position — updated at most once a minute, overwritten each time, and used only to tell you when a bottle washes up near you (positions older than 30 days are ignored). The position you send when opening a bottle is used for the distance check and is not stored.

How precisely any of this is shown to other people is explained in §4.

d. Payment data — Bottl has no paid features today and processes no payment data.

e. Technical & usage data — IP address, device and browser type, the pages you open and a few in-app events (see PostHog, §5a), server logs, and error reports.

f. Cookies / local storage — see our Cookie Policy.

3. Why we use it and our legal basis (GDPR Art. 6)

Where the table says contract, the contract is our Terms of Service, which you agree to when you create an account: we need that data to provide the service they describe.

PurposeLegal basis
Create and manage your accountContract
Carry bottles, let them be found, deliver replies and lettersContract
Show bottles on the map, simulate their journey by wind and currentContract
Translate a message, when you ask for itContract
Emails about your bottles (found, landed, replies, the Sunday recap) — each can be switched offContract; legitimate interest
Use your device's locationConsent (device permission)
Push notificationsConsent (browser permission)
Approximate location from your connectionLegitimate interest (sensible defaults)
Moderation, safety, preventing abuseLegitimate interest; legal obligation
Security, diagnostics, error monitoringLegitimate interest
Product improvement / analyticsLegitimate interest (anonymous, cookieless audience measurement)

We send no marketing emails. You may withdraw consent at any time; this does not affect processing done before withdrawal.

4. Sharing and who can see your content

Other users: the essence of Bottl is that a bottle you release can be read by another user (a stranger). Do not put sensitive personal information in a message. Your username, avatar and bio are visible to others. We do not sell your personal data.

Opening a bottle is not anonymous. When you unseal someone else’s bottle, the person who sent it is told that you opened it, and is shown your username; so are the people following that bottle, in their weekly recap. That happens whether or not you write back, and it cannot be undone by staying silent — sealing in silence withholds what you thought of the message, not who read it. The sender also learns where the bottle was lying when you opened it — a spot already shown on the map — never the position of your device.

A bottle never departs, in public, from where you were standing. The spot you launch from is often enough your own doorstep. So wherever your bottle's departure appears to anybody else — the map, the trail of its journey and its milestones, a replay, the list of bottles nearby, a link preview, an email — it is replaced by a decoy point several kilometres away. We do not publish how far, or in which direction, and the decoy is the same on every request, so it cannot be averaged back to the truth by reading a bottle repeatedly. The person who finds your bottle sees the decoy too. Your exact coordinates stay on our servers, where the flight and the drift are computed from them; you still see the real departure on your own bottles.

The departure is also named in words: “near” the nearest town of 15,000 inhabitants or more to where you launched (or the town itself, if you picked it from the list) — or, far from any such town, as coordinates rounded to the whole degree. The places a bottle crosses are named by sea, country or landmark, and no landmark within 30 km of its departure is ever named.

Replies and letters. The place you write from is shown to the other person the same way — as a decoy point, never the real one.

Pinned bottles are different. They stay at the exact spot you choose, and that spot is shown precisely to anyone looking at the map — that is the point of a pin, and the app says so on the screen where you drop one. Only pin public places, never a private home, yours or someone else's. You can report a pin from the bottle itself, without opening it: the report withholds its message immediately and puts it in front of a human, who takes it off the map if it should not be there. You can take one of your own pins off the map at any time, from the bottle itself.

5. Third-party processors and services

We rely on the following providers, who process data on our behalf or receive data to make features work. Data may be processed outside the EU; where so, we rely on appropriate safeguards (e.g. Standard Contractual Clauses).

a. Processors acting on our behalf

  • Application hosting: Vercel Inc. (United States) — serves the application, receives request data including IP, and provides the approximate location described in §2c.
  • API hosting: Railway Corp. (United States) — runs our backend; receives request data including IP.
  • Database, authentication & storage: Supabase Pte. Ltd. (Singapore) — stores account data, content, photos, coordinates and IP.
  • Email delivery: Resend (United States) — sends our emails; receives your email address and the email itself (usernames, where a bottle is — never a message's text).
  • Translation: Anthropic, PBC (United States) — when you ask for a message to be translated, its text is sent on its own, with no account, name or location attached. Translations are kept on our servers so the same text is not sent twice.
  • Error monitoring: Sentry (Functional Software, Inc., United States) — we use its EU region, hosted in Germany. It receives technical details of errors on our servers. We strip IP addresses, coordinates and request contents before anything is sent.
  • Analytics: PostHog, Inc. (United States) — we use its EU Cloud instance, hosted in Frankfurt, Germany. It receives the pages you open and a few events (a bottle sent or opened, a reply or letter sent, whether locating your device worked), together with the IP address inherent in any request. It is cookieless and anonymous by design: no cookie, no local storage, no persistent identifier, no session recording, no heatmaps, and we never link a session to your account. Message content and coordinates are never sent to it.
  • Place names: Komoot (Photon, Germany) — our server asks it which country a bottle's resting place is in, to write it in an email, and which town is nearest to your welcome bottle (placed about 150 m from you). Coordinates are sent on their own, with no account, name or email address attached.
  • Push notifications: if you turn them on, your browser's own push service (Google, Apple, Mozilla or Microsoft, depending on your browser) delivers them. It receives an anonymous subscription address and the notification, encrypted so that it cannot read it.

b. Third-party calls made from your browser

  • Map tiles: OpenFreeMap — receives your IP and the map area you are viewing, to serve map tiles.

Nothing else is loaded from a third party: fonts are served from our own servers, and searching the map or naming a town uses a list of towns that ships inside the app.

c. Public data sources (no user data shared)

Weather, wind, wave, ocean-current and tidal data are downloaded on a schedule (wind roughly every 6 hours, the rest less often) from public scientific sources onto our own infrastructure, and served to you from there. The list of towns the app uses to name a place and to answer the search box is built the same way, and ships inside the app. No user data, coordinates or IP are sent to these sources. They are not processors of your personal data.

One public source is queried live rather than on a schedule. When a drifting bottle comes ashore, our server asks OpenStreetMap — through the Overpass API — for the coastline around the point the simulation put it at, so the bottle comes to rest on a real shore instead of in open water. What leaves our server is that computed drift position: a point the engine arrived at from wind and currents, not anyone's location, sent on its own with no account, name or address attached.

6. How long we keep data

  • Account data: while your account is active. When you delete your account the erasure is immediate, not deferred — see §7.
  • Content: until you delete your account; a bottle already opened by another user stays with them (see §7).
  • Your last known position: overwritten at each update, erased with your account.
  • Logs and error reports: up to 12 months.

7. Your rights (GDPR)

You have the right to access, correct, delete ("right to be forgotten"), restrict or object to processing, data portability, and to withdraw consent. To exercise these, contact hello@bottl.world. You may also complain to your supervisory authority — in Bulgaria, the Commission for Personal Data Protection (cpdp.bg).

Deleting your account

You can delete your account yourself, at any time, from your profile panel ("delete my account", at the bottom). No email required, and there is no waiting period — the deletion happens when you confirm it.

What is erased immediately and for good:

  • your sign-in identity: email address and password;
  • your username, avatar, bio, country, preferences and email choices, and your last known position;
  • your notifications, the bottles you followed or were walking towards, and the push subscriptions of your devices;
  • every bottle of yours that nobody has opened, entirely — message, photo, departure point and journey. Those bottles leave the map at once.

What remains: a bottle someone has already opened, with its journey, and the replies and letters exchanged about it. That content is part of another person's experience of the Service, and it stays under the name “someone”, with no link to you. The reports you filed stay too, without your name. If you want any of it removed as well, write to hello@bottl.world and we will handle it case by case.

8. Minors

You must be at least 16 to create an account. Sign-up asks you to confirm it, and we store only that you did and when — we do not ask for your date of birth. We do not knowingly collect the data of anyone under 16, and if we learn we have, we will delete it.

9. Security

We use reasonable technical and organizational measures (encryption in transit, hashed passwords, access controls). No system is perfectly secure; we cannot guarantee absolute security.

10. International users

We are based in Bulgaria and process data under EU law. If you use Bottl from outside the EU, your data may be transferred to and processed in the EU and by the providers listed above.

11. Changes

We may update this policy. Material changes will be notified in-app or by email. The "Last updated" date shows the current version.

12. Contact

YDA Ltd · hello@bottl.world · Drujba, bl. 170, ent. B, fl. 7, apt. 67, 1592 Sofia, Bulgaria

TermsPrivacyCookiesLegal notice
© 2026 BOTTL · message in a bottle, for the whole world.