Privacy Policy
Last updated: May 24, 2026
Knightian Labs Pte Ltd (“we”, “us”, or “our”) is the data controller for the Bridge Town platform and website at https://bridgetown.builders (the “Service”). This Privacy Policy describes how we collect, use, and protect your information when you use the Service.
1. Information We Collect
Account Information
When you sign up for Bridge Town, we collect:
- Auth0 profile data: your name, email address, and profile picture as provided via Auth0 or your OAuth provider (Google).
- Organisation information: your company or team name if provided during onboarding.
Financial Model Data
Bridge Town is a financial planning and analysis platform. When you use the Service, we store:
- Financial models and plans you create or import, including any data you upload (CSV, spreadsheets, etc.).
- Model code and version history stored in your tenant’s versioned project storage.
- Query results and snapshots generated by the DuckDB query engine from your data.
You retain ownership of all financial data you upload or create. We process it solely to provide the Service.
Usage Analytics
We collect anonymised usage data to improve the Service using PostHog and Google Analytics. This includes:
- Pages visited and features used within the platform.
- Session duration and interaction patterns.
- Error logs and performance metrics.
PostHog and Google Analytics use cookies and similar tracking technologies to recognise returning visitors and understand page usage. This data does not include the content of your financial models. PostHog’s data processing is governed by PostHog’s Privacy Policy, and Google Analytics data processing is governed by Google’s Privacy Policy.
2. How We Store Your Data
Encryption and Security
- At rest: All data stored in our PostgreSQL database is encrypted at rest using AWS RDS encryption (AES-256).
- In transit: All communication between your browser and our servers uses TLS 1.2 or higher.
- Object storage: Files and snapshots stored in Amazon S3 use server-side encryption.
Tenant Isolation
Bridge Town enforces strict tenant isolation using PostgreSQL Row-Level Security (RLS). Your data is logically separated from other tenants’ data at the database level. Every query is automatically scoped to your organisation.
3. Third Parties We Share Data With
We use the following third-party services to operate the platform:
| Provider | Purpose | Data shared |
|---|---|---|
| Auth0 | Authentication and identity management | Email, name, OAuth tokens |
| Google OAuth | Social login | Email and profile, per your Google account settings |
| Google Analytics | Website analytics | Page views, browser/device metadata, approximate geography |
| PostHog | Product analytics and usage insights | Anonymised usage events, session data, browser/device metadata |
| Stripe | Payment processing and billing | Billing contact details, payment method (card details handled by Stripe directly) |
| Resend | Transactional email | Email address, for service notifications |
| Amazon Web Services | Cloud infrastructure (compute, storage, database) | All data at rest and in transit |
We do not sell your personal data to third parties. We do not use your financial model data to train AI models.
For a complete list of third-party services and subprocessors, see our Subprocessors page.
Bridge Town does not call LLMs on your behalf
Bridge Town is a Bring Your Own Agent (BYOA) platform. You connect your own AI agent — Claude (Anthropic), Codex, Gemini, or any MCP-compatible agent — to Bridge Town’s MCP server. Your prompts travel from your AI client directly to your chosen LLM provider; they do not pass through Bridge Town’s infrastructure.
Bridge Town receives only structured MCP tool calls: typed inputs such as model names, Python code to store, or SQL query strings. We do not have access to the conversational context between you and your AI agent.
If you choose to use an AI agent that processes data on your behalf, your relationship with that AI provider is governed by their own terms and privacy policy, not ours.
PostHog Analytics
We use PostHog to understand how users interact with Bridge Town. PostHog collects anonymised event data (page views, feature clicks, session replays where enabled) using cookies stored in your browser. No financial model content is included in analytics events. PostHog may process data outside your jurisdiction; see PostHog’s Privacy Policy for details. You can opt out of analytics tracking by enabling “Do Not Track” in your browser settings.
Google Analytics
We use Google Analytics to understand public website traffic and content performance. Google Analytics collects page views, browser/device metadata, and approximate geography using cookies and similar technologies. No financial model content is included in analytics events. See Google’s Privacy Policy for details.
4. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that inaccurate data be corrected.
- Deletion: Request deletion of your account and associated personal data. Financial model data will be deleted within 30 days of account closure.
- Data export: Export your financial models and data in standard formats (CSV, JSON, versioned project archive) via the account settings page.
- Objection: Object to certain processing activities.
To exercise any of these rights, contact us at privacy@bridgetown.builders.
5. Data Retention
- Account data: Retained for the duration of your subscription and for 90 days after account closure (to allow recovery).
- Financial model data: Deleted within 30 days of account closure upon request.
- Usage analytics: Retained in aggregated, anonymised form for up to 2 years. PostHog and Google Analytics cookies persist according to each provider’s configured retention period.
- Billing records: Retained for 7 years as required by law.
6. Children’s Privacy
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
7. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice within the Service at least 14 days before the change takes effect. The updated “Last updated” date at the top of this page will always reflect the most recent revision.
8. Contact Us
For privacy-related questions or to exercise your rights, contact:
Knightian Labs, LLC (trading as Bridge Town) Email: privacy@bridgetown.builders
For DPA requests or security review enquiries, see our Security and Compliance page.