BelongTo.

Communities

Privacy Policy

Effective 26 August 2026 · Last updated 26 August 2026

The short version

1. Who this is

BelongTo Communities is a private, invite-only group-chat app for iOS and the web, operated by 4Brunch LLC ("BelongTo", "we", "us"). This policy covers the iOS app, the web app at communities.belongto.ai, and the backend behind them. It is written to be read, not to be survived. Our Terms of Service cover the rules of the road.

2. What we collect, and where it comes from

All of it comes from you or from your device as you use the app. We do not buy data, we do not receive data about you from data brokers, and we do not scrape anything.

What Where it comes from Why we have it
Email address You type it when you sign up, or Sign in with Apple provides it (which may be a private relay address). It is your login and the only way we can reach you about your account or a password reset.
Password You choose it. It is handled and stored by Firebase Authentication (Google), hashed. We never see it. Authentication.
Display name and avatar You choose them at the door, and can change them later. So people know who is talking. Visible to every member of every community you are in.
Account identifier (UID) and your member numbers (M, C) Generated by us when your account is created. To attach your messages, memberships, and settings to you.
Messages — community chat, thread replies, direct messages, votes and ballots, and anything you send the AI assistant You write them. They are the product. We store them so the community has a history.
Photos and images you upload, including any embedded EXIF metadata Your camera or photo library, with your permission, at the moment you attach one. To show them in the chat. See section 4.
Community and membership data — which communities you are in, when you joined, who invited you, your invite codes, who you have blocked Generated as you join, found, invite, and block. Access control and the roster.
Push notification token (a device identifier issued by Apple/Firebase) Your device, only if you allow notifications. To send you a notification when you are mentioned or someone replies to you.
Agreement timestamps — when you accepted these terms and consented to AI processing Recorded when you tap "Agree and continue". Proof of consent, which we are required to keep.
Reports you file or that are filed about you — the reason you wrote, a copy of the reported message, and who was involved Created when someone taps Report. Safety and moderation. See section 8.
Server logs — request timestamps, error traces, and technical diagnostics generated by our backend Generated automatically by Google Cloud when the app talks to the server. Keeping the service up and debugging it when it breaks.

What we do not collect

3. How we use it

We use what we collect only for these purposes:

We do not use your data for advertising, for sale to anyone, for training our own models, or for any purpose that is not on this list. If that ever changes, we will tell you in the app and ask first.

If you are in the EEA or the UK, our legal bases are: contract (running the app you signed up for), consent (AI processing and push notifications, both of which you grant explicitly and can withdraw), legitimate interests (safety, moderation, security, and keeping the service running), and legal obligation (records we must retain).

4. Photos, and a straight answer about EXIF

When you attach a photo, the app uploads the file you selected to our storage and posts it to the community. Two things happen to it: it is screened by an automated image-safety check, and it is described in words by the AI assistant so that the photo can be found in search and read by a screen reader. That description is stored alongside the message.

EXIF metadata is not stripped. Photos from a phone often carry hidden metadata — the camera model, the date and time, and, if your camera had location services enabled, the GPS coordinates where the photo was taken. BelongTo does not currently remove that metadata before storing and sharing the file. Anyone who can see the photo and downloads the original can read it.

If that matters for a particular photo, strip the metadata before you upload it, or turn off location for your camera app. We intend to strip EXIF on upload in a future release and will update this section when we do.

The app asks for photo-library access only at the moment you tap to attach something, and only the photo you pick is read. It never browses your library.

5. AI processing — Google Gemini, named

BelongTo Communities uses a third-party artificial-intelligence service. We are telling you exactly which one, exactly what we send it, and exactly what it does with it. You are asked to agree to this before you can use the app, on a screen that names the provider.

The provider

Google LLC, through the Gemini API (ai.google.dev/gemini-api/terms). No other AI provider receives any of your data.

What we send to Google

We do not send your email address, your password, your account identifier, your push token, your payment information (we have none), or your device location.

What Google does with it

We use the paid tier of the Gemini API. Google's Gemini API Additional Terms of Service (last updated 28 April 2026) say, for paid services:

"Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products."

Google does keep a short-lived log of what is sent — in its words, it "logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy to maintain the safety and security of the Services." So: your messages and photos are not used to train Google's models, but they do pass through Google's systems and are briefly retained there for abuse prevention. Google's own terms govern that retention, not ours. Read them at ai.google.dev/gemini-api/terms.

Consent, and why it is all-or-nothing

The AI assistant is not a bolt-on feature — it reads the room in order to answer, search, and recap, and it is present in every community. There is no version of BelongTo Communities that works without sending community content to Google. That is why consent to AI processing is asked for once, up front, on the same screen as the terms, and why declining means not using the app.

To withdraw your consent, delete your account (Your profile → Delete account). That stops all further processing and removes your content. We record the date and time you consented so we can prove we asked.

Note the practical consequence of a shared room: if you post in a community, your message may be sent to Google as context when another member asks the assistant something later. The same is true of every group chat with an assistant in it. It is the reason we tell you before you post rather than after.

6. Who else sees your data

We share your data with a small number of service providers who process it on our behalf, under contracts that require them to protect it at least as well as this policy requires us to, to use it only for the services they provide to us, and not for their own purposes. That is the whole list:

Provider What they handle Their terms
Google LLC — Firebase Authentication Your email address and password (hashed), and your sign-in sessions. firebase.google.com/support/privacy
Google LLC — Cloud Firestore Your profile, messages, memberships, votes, reports, and settings. As above
Google LLC — Cloud Storage for Firebase Your uploaded photos and avatars. As above
Google LLC — Cloud Functions The server code that joins you to communities, sends notifications, filters content, and deletes your account. As above
Google LLC — Firebase Cloud Messaging Your push token and the notifications sent to it. As above
Google LLC — Gemini API Community message text and uploaded photos, for the AI features. See section 5. ai.google.dev/gemini-api/terms
Apple Inc. Sign in with Apple (if you use it) and the Apple Push Notification service, which delivers notifications to your device. apple.com/legal/privacy

Beyond those providers, we disclose data only when we are legally required to (a valid subpoena, court order, or equivalent), when it is necessary to protect someone's safety or investigate a violation of our terms, or if the app is ever acquired or merged — in which case we would tell you before your data moved, and this policy would continue to apply until you were given notice of a new one.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We never have.

7. What other members can see

This is a chat app, so a lot of it is the point — but it is worth being explicit:

8. How long we keep it, and how to delete it

We keep your data while your account exists, because that is what a chat history is. When you delete your account, we delete it.

Deleting your account

In the app: Your profile → Delete account. You will be shown what is about to be deleted and asked to type delete to confirm. There is no waiting period and no dark pattern — it happens immediately, and it cannot be undone. Deletion completes within 24 hours at the outside.

What deletion removes

What survives, and why

One known gap, stated plainly. If you signed up with Sign in with Apple, we delete your account and all of its content, but we are not currently able to revoke the Apple sign-in token on Apple's side — the tool we use to receive that sign-in does not give us what we would need. You can revoke it yourself at any time on your device: Settings → [your name] → Sign in with Apple → BelongTo → Stop using Apple ID. We are working on doing it automatically.

If you leave a community instead

Leaving a community (or being removed from one) takes away your access immediately and removes you from the roster. Your past messages stay in that room, because deleting them would tear holes in a conversation other people are still having. If you want them gone, delete them individually before you leave, or delete your account.

9. Your choices and your rights

We do not charge for any of this and we will not make you jump through hoops. We answer within 30 days.

10. Notifications

Push notifications are off until you allow them. If you do, your device registers a token with Firebase Cloud Messaging, and we store it under your profile so we can send you a notification when someone mentions you or replies to your thread. Notification content may include the sender's name, the community name, and a preview of the message — so it can appear on your lock screen. Signing out deletes the token for that device; tokens that stop working are pruned automatically.

11. Children

BelongTo Communities is rated for ages 13 and up and is not intended for children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that an account belongs to someone under 13, we delete it and its content. If you are a parent or guardian and believe your child has an account here, email support@belongto.ai and we will remove it.

12. Security

Traffic between the app and our servers is encrypted with TLS. Data at rest in Google Cloud is encrypted. Access to your data is enforced by server-side security rules: membership in a community is the access key, and a rule engine — not the app — decides what any given account can read or write. Sensitive operations (joining, inviting, reporting, ejecting, deleting) run as server code, never on your device. Passwords are hashed by Firebase and are not visible to us.

No system is perfect. Messages are not end-to-end encrypted: we can technically read what is stored, and we do so only when a report or a legal obligation requires it. If a breach ever affects your data, we will tell you and the relevant authorities as required by law.

13. Where your data lives

Our Firebase project is hosted in the United States, and the Gemini API may process and transiently cache data in any country where Google or its agents maintain facilities. If you use the app from outside the United States, your data is transferred to and processed in the U.S. and potentially elsewhere. Our providers rely on Standard Contractual Clauses and equivalent safeguards for those transfers.

14. Changes to this policy

We will update this policy as the app changes — and when something material changes, especially anything about the AI provider or what we send it, we will tell you in the app and ask you to agree again before it takes effect. The "last updated" date at the top always reflects the current version.

15. Contact us

A human reads this inbox.

Email: support@belongto.ai
Web: communities.belongto.ai
In the app: Your profile → Contact us

Privacy requests, data exports, deletion questions, and anything else about this policy go to the same place. Put "PRIVACY" in the subject line and we will answer within 30 days — usually the same day.