Privacy Policy

Pre-launch draft · Updated September 10, 2026

Age eligibility

Bari is intended for people aged 18 and older. People under 18 should not create an account or use Bari. We do not knowingly collect personal information from children.

Your account

We use your email address to authenticate and identify your account. Google shares basic account information with Bari if you choose Google sign-in. Authentication cookies keep you signed in. Your first name creates a readable referral link. Date of birth and self-described gender are required before using placements and can be updated in account settings. Bari stores these details for account eligibility and possible future audience features; demographic targeting is not currently enabled.

Mac connection and placements

The Mac app creates independent one-time approval and device credentials. Bari stores only hashes of those secrets, the Mac name, connection state and the device and delivery records needed to validate placements. Placement records can include the assigned promotion, timing, completion or interruption, funding type, locked rate, reward and destination clicks. Bari does not collect screenshots, keystrokes, files, app names, window titles or browsing history.

Promotions and preferences

Signed-in promotion drafts, prepared logos, review decisions, campaign settings and delivery reports are stored with the advertiser’s account. The separate preview route keeps its unfinished design draft in the browser session and does not submit it. Selecting “Recommend brands like this” records an advertiser preference; that preference does not currently alter delivery.

Referrals

A valid referral visit sets an HTTP-only cookie for up to 30 days. If the visitor creates an account in that window, Bari retains the attribution, reward status and review evidence needed to administer the program. Public referral names can change under Bari’s limits, while prior names remain reserved and continue to resolve to the same account.

Approximate network location

When the Mac app requests a sponsor, Vercel can derive an approximate country from the request’s IP address. Bari uses the two-letter country to apply paid campaign targeting and retains it with private delivery evidence. VPNs, travel and routing can change that result. For connection-request abuse protection, Vercel’s trusted client address is transformed into an opaque HMAC bucket before it reaches the database; Bari does not store the raw address in application records. Infrastructure providers may process or retain network data under their own policies.

Payments and payouts

Stripe processes advertiser payments, refunds, recipient onboarding and payouts. Bari stores the provider identifiers, account readiness, amounts and outcomes needed to reconcile those operations. Stripe collects and handles bank, identity and payment-method details under its own privacy terms; Bari does not use those details for advertising.

Retention

Detailed eligibility diagnostics remain until at least 60 days of data exist, then cleanup removes the oldest 30-day tranche while preserving the newest 30 days. This cycle is separate from delivery reports and financial records. Expired Mac connection requests retain hash-only replay protection for seven days; connected or canceled request records are removed after seven days, and anonymous rate-limit buckets after 24 hours. Financial, campaign, referral and aggregated reporting records are retained separately for reconciliation, disputes and legal obligations; Bari’s final financial retention period has not yet been published.

Before the pilot

This draft accurately describes the current application design, but it is not the final launch policy. Bari’s legal business identity, privacy contact, request and deletion process, exact financial retention period and final provider list must be added and reviewed before an authorized public pilot.