目录
- 1What we process and why
- 2What never reaches us
- 3How long we keep data
- 4Account deletion and destruction
- 5Sharing with third parties
- 6Processors and international transfers
- 7Cookies and browser storage
- 8Your rights and how to use them
- 9How we protect your data
- 10Children under 14
- 11Changes to this policy
- 12Privacy officer and contact
- 13Other places to get help
Bridge Code (bridge-code.com, the Mac, Windows and iPhone apps, and the web app) is operated by Aside. This policy explains what personal data we process while you use a Bridge Code account and the service, why, when we delete it, and who processes it on our behalf.
In this policy, “we” means Aside, and “the service” means the Bridge Code website and accounts, the device network and the relay servers.
1What we process and why
We only process what the service needs. Processing for your account and the service is necessary to perform our contract with you (Personal Information Protection Act of Korea, Article 15(1)4), and security records are kept in our legitimate interest in protecting the service and its users (Article 15(1)6).
| Category | Data | Purpose |
|---|---|---|
| Email sign-up | Email address, password (stored only as an irreversible hash) | Sign-up, sign-in, verifying it’s you, confirmation and password reset emails |
| Sign in with Google | Google account ID, email address, name, profile picture URL (as provided by Google) | Sign-up and sign-in. Admins see your name to tell accounts apart. |
| Account status | Approval status (pending, approved, suspended), plan, role (user or admin), approval time, sign-up and update times | Running approvals, providing plan features, checking admin rights |
| Device network (Pro, once you connect devices) | Device network name (one per account), names and public device keys of connected devices, addresses inside the device network, public IP addresses and ports used to connect devices, online status and last seen time | Letting your devices find and reach each other, enforcing device limits, disconnecting devices on suspension or deletion |
| PCs used from the website (Pro) | PC name, operating system, device ID, public key for encrypted connections, registration and update times | Listing your PCs on the website, authenticating end-to-end encrypted connections |
| Activity log | Actions such as sign-up, approval, rejection, suspension, plan or role changes, connecting devices, adding or removing website PCs and account deletion, with their time, the acting and target accounts (email), and related device names and IDs | Security, preventing abuse, reviewing admin actions, handling disputes |
| Generated automatically | IP address, browser and device information (User-Agent), access times and requested URLs, sign-in session data, cookies | Keeping you signed in, running and securing the service, troubleshooting |
| Support requests | Your email address and what you send us | Answering you |
If you use the app on a single PC without an account, no personal data reaches us. When the apps check for updates or you download them from our server, the server processes your IP address and request details to deliver the files.
2What never reaches us
- Your code, Claude Code conversations, files, terminal input and output, and remote screen contents never reach the service. The Bridge Code app on each PC handles them on that PC.
- Your devices talk to each other with end-to-end encryption (WireGuard for the device network, X25519 and AES-256-GCM for using your PCs from the website). When a direct connection isn’t possible, traffic passes through our relay servers, which only forward encrypted data and cannot decrypt it.
- Claude Code talks to Anthropic directly from each PC using your own account. That processing follows Anthropic’s policies, and we don’t receive it.
- We never receive your PC passwords or the sign-in details of your Claude or Anthropic account.
- We don’t charge for the service right now, so we don’t process payment data.
3How long we keep data
| Data | Retention |
|---|---|
| Account, account status, device network, website PCs | Until you delete your account. We delete them right away when you do. |
| Activity log | When you delete your account, we remove the email addresses from the log and unlink it from your account. The remaining entries (type and time of action, related device names and IDs) are kept for security and dispute handling. |
| Sign-in sessions | End when you sign out or delete your account. |
| Server access and error logs | Logs at Vercel, Supabase and Microsoft Azure are deleted when each provider’s retention period ends. |
| Support emails | Kept for as long as needed to handle your request. |
If a law requires us to keep certain data, we keep it for the period that law sets.
4Account deletion and destruction
You can delete your account at any time from Delete account after signing in. We delete data in this order:
- If you are the only one using your device network, the control server deletes that network and its devices. If this step fails, nothing is deleted and you can try again a little later.
- Your list of website PCs and your device network link are deleted.
- Email addresses are removed from the activity log.
- Your account status and sign-in account (email, password hash, Google link) are deleted and you are signed out.
A device network shared with other accounts is not deleted; only your account is removed from it. Electronic records are deleted so they cannot be restored, and we keep no personal data on paper.
The Bridge Code app and your conversations and files on each PC stay on that PC regardless of your account. To remove them, uninstall the app or delete its data on that PC.
If you can’t sign in, email contact@aside.ai.kr to request deletion. We’ll verify it’s you and delete your data the same way.
6Processors and international transfers
We use the companies below to run the service. They use the data only for the work we give them, under their terms of service and data processing terms.
| Company | What they do | Where |
|---|---|---|
| Supabase Inc. | Accounts and sign-in (authentication), database, sending confirmation and password reset emails | Stored in Seoul, Republic of Korea (AWS ap-northeast-2). Company based in the United States |
| Vercel Inc. | Website hosting, running server functions, access logs | Server functions run in the Seoul region. Website delivery and logs use Vercel’s network, including the United States |
| Microsoft Corporation (Microsoft Azure) | Device network control server, encrypted relay server, app download and update server | Republic of Korea (Korea Central, Seoul) |
International transfers
The data below may be transferred outside the Republic of Korea, or accessed from outside it, while you use the service. These transfers are processing and storage needed to perform our contract with you, disclosed here under Article 28-8(1)3 of the Personal Information Protection Act.
Vercel Inc.
- Countries
- United States and other countries where Vercel runs servers
- Data
- IP address, browser information, requested URLs and times, sign-in cookies
- When and how
- Each time you use the website, over encrypted connections
- Purpose
- Website hosting, access logs
- Retention
- Vercel’s log retention period
Supabase Inc.
- Countries
- United States (data is stored in Seoul and may be accessed from the United States and elsewhere for operations and support)
- Data
- Account, account status, device and activity log data from the table in section 1
- When and how
- Each time you use the service, over encrypted connections
- Purpose
- Authentication, database, sending emails
- Retention
- Until you delete your account (access logs follow Supabase’s retention period)
- Contact
- supabase.com/privacy
If you don’t want your data transferred abroad, don’t create an account, or delete it. You then can’t use the features that need an account (such as using your other devices remotely or from the website), but you can still use the app on a single PC without an account.
Sign in with Google
If you sign in with Google, Google LLC (United States) sends us your email address, name, profile picture URL and Google account ID. The sign-in page loads Google’s sign-in button, so when you open it Google processes connection data under its own policy (policies.google.com/privacy). You can sign up with your email instead.
8Your rights and how to use them
You can ask to access, correct or delete your personal data, or to stop processing it, at any time.
- Access: My account shows your email, approval status, plan, role, sign-up date, connected devices and website PCs.
- Deletion: delete your account right away from Delete account, or remove website PCs one by one in My account.
- Anything else (a copy of your data, correction, stopping processing, withdrawing consent): email contact@aside.ai.kr. Once we’ve verified it’s you, we’ll reply within 10 days with the result or the reason we can’t act on it.
- A legal representative or someone you authorize can also make these requests for you.
Sign-up approvals are decided by an administrator. We don’t approve or reject accounts by automated decisions alone.
9How we protect your data
- All connections are encrypted with HTTPS (TLS).
- Passwords are never stored in plain text; Supabase Auth stores only an irreversible hash.
- Row-level security in the database lets each account read only its own data. Changes happen only on the server after a permission check.
- Admin rights are limited to admin accounts, and every admin action is recorded in the activity log.
- Secrets such as database admin keys and signing keys live only on our servers, never in browsers or source code.
- Traffic between your devices is end-to-end encrypted, and relay servers only forward encrypted data.
If we learn of an incident such as a data breach, we notify affected users and take the necessary steps as the law requires.
10Children under 14
People under 14 may not create an account. If we learn that an account belongs to a child under 14, we delete it right away.
11Changes to this policy
If we change this policy, we post what changes and when it takes effect on this page at least 7 days in advance. For changes that matter to your rights, we give 30 days’ notice and also email you. If the Korean and English versions differ, the Korean version prevails.
- October 2, 2026: first version
12Privacy officer and contact
- Privacy officer
- Aside Privacy Officer
- contact@aside.ai.kr
- Operator
- Aside
Send questions, complaints or requests for redress about personal data to contact@aside.ai.kr.
13Other places to get help
For advice or dispute resolution about a privacy infringement, you can also contact these Korean authorities:
- Personal Information Infringement Report Center (KISA): privacy.kisa.or.kr, phone 118 (within Korea)
- Personal Information Dispute Mediation Committee: www.kopico.go.kr, phone 1833-6972 (within Korea)
- Supreme Prosecutors' Office, Cyber Investigation Division: www.spo.go.kr, phone 1301 (within Korea)
- Korean National Police Agency, Cyber Bureau: ecrm.police.go.kr, phone 182 (within Korea)