BucketSave

Privacy Policy

Last updated 21 August 2026

The short version. BucketSave stores the links you save and the account you save them under. There are no analytics, no tracking SDKs, and no advertising identifiers in the app. Your saved library is private to your account, is never sold, and is never shared with data brokers. The only things other people see are the ones you choose to share: your username, and posts you save into a group.

Who this is from

BucketSave is an iOS and Android app made by Lorik Kastratii. Questions about this policy, or about data held about you, go to lorik.kastrati@bk-solutions.info.

What the app collects

Account information

To create an account you provide an email address, a username and a password. The email is stored so you can sign in and so we can contact you about your account. The username is the handle other people use to find you. The password is never stored — it is put through a one-way bcrypt hash, and the original cannot be recovered from what is saved.

The things you save

When you save a post, BucketSave stores:

Friends, groups and shared saves

Your username is visible to anyone using the app, because that is how people find each other to send a friend request. BucketSave also stores who your friends are, which groups you belong to, and the invitations you have sent or received.

A post you save into a group is visible to every member of that group, shown with the handle of whoever saved it. Posts saved to your own stash are not visible to anyone else. A post saved to the Vault is hidden behind a PIN of your choosing and stays out of your library, your search and your tag counts; the PIN itself is stored only as a one-way bcrypt hash.

What the app does not collect

How a saved link gets its preview

After you save a URL, the BucketSave server visits that page to read its Open Graph tags, which is where the title, description and thumbnail come from. For YouTube, TikTok and X it also calls those services' public oEmbed endpoints to get a more reliable author name and thumbnail.

This means the site you saved from receives a request from the BucketSave server. That request does not carry your identity, your email or your account — the destination site learns that someone asked about that public URL, nothing more.

Where the data is kept

Account and item data are stored in a PostgreSQL database hosted on Railway, a cloud hosting provider, which processes it on our behalf in order to run the service. Traffic between the app and the server is encrypted with HTTPS. On your device, the sign-in token is kept in the iOS Keychain or the Android Keystore, which is encrypted by the operating system.

Who the data is shared with

BucketSave does not sell your data, does not share it for advertising, and does not hand it to data brokers. It is disclosed only in these cases:

How long it is kept, and how to delete it

Your data is kept for as long as your account exists. Deleting an item or a collection removes it. Deleting your account removes your saved items and collections along with it.

You can delete your account from inside the app at any time: open the You tab, then Delete account. That removes your account and every item, tag and collection saved under it immediately and permanently.

If you have already uninstalled the app you can still have everything removed: email lorik.kastrati@bk-solutions.info from the address you signed up with and ask for your account to be deleted. No reinstall is needed, and the account and everything in it is deleted within 30 days.

To ask for a copy of the data held about your account, email lorik.kastrati@bk-solutions.info from the address you signed up with.

Children

BucketSave is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has created an account, contact us and it will be removed.

Changes to this policy

If this policy changes, the date at the top of this page changes with it. Material changes affecting how your data is handled will also be announced in the app or by email.

Contact

lorik.kastrati@bk-solutions.info