Bridgewire
How it works Features Blog FAQ Contact
Sign in

Legal

Privacy Policy

Last updated: 27 July 2026

This is a working draft written to accurately describe what Bridgewire actually does and what data it actually handles. It has not been reviewed by a solicitor. Given this service connects to people's private messaging accounts, that review is genuinely worth getting before relying on this as your final published policy.

On this page

1. Who we are 2. Information we collect 3. How we use your information 4. Our legal basis for processing 5. About your WhatsApp connection specifically 6. Who we share information with 7. International data transfers 8. How long we keep your data 9. Security 10. Your rights 11. Cookies 12. Children 13. Changes to this policy 14. Contact us

1. Who we are

Bridgewire is operated by Michael Alexander Radford, trading as Bridgewire, currently operating as a sole trader based in the United Kingdom. For the purposes of UK data protection law, Michael Alexander Radford is the data controller for the personal data described in this policy.

This policy covers www.bridgewire.cloud (this marketing site) and dashboard.bridgewire.cloud (the Bridgewire application itself).

2. Information we collect

Account information

When you register, we collect your name, email address, a password (which we never store in readable form — see Security below), your timezone, and language preference. If you're approved and use the service, we also store your assigned plan, account status, and the date you signed up and were approved.

Connected messaging accounts

To bridge messages, Bridgewire needs to connect to the Telegram and/or WhatsApp accounts you choose to link. This involves storing session credentials that let Bridgewire act on your behalf for the specific chats you configure — this is sensitive information and is treated as such. We do not see or store your Telegram or WhatsApp login password itself; connection happens through each platform's own authentication method (a login code for Telegram, a QR code scan for WhatsApp).

Message content that passes through your bridges

When a bridge you've configured forwards a message, we necessarily process that message's content, media (images, videos, documents), and metadata (which chat it came from, its type, the time) in order to deliver it to the destination you specified. This is stored as message history within your account so you can review it on the Messages page.

Logs

We keep system logs of bridge activity — connection status changes, errors, and delivery outcomes — to help diagnose problems and support you if something goes wrong.

Technical information

Like most web services, our servers automatically log IP addresses and basic request information as part of normal operation and security (for example, to apply rate limiting against abuse).

Communications with us

If you email us or message our support bot on Telegram, we keep a record of that conversation so we can respond and follow up.

3. How we use your information

  • To provide the core service — connecting your messaging accounts and forwarding messages according to the bridges you configure.
  • To manage your account, including the approval process new accounts currently go through before becoming active.
  • To send you service emails: confirming your request was received, notifying you when your account is approved, password reset links, and alerts if a message fails to deliver.
  • To maintain and secure the service, including detecting misuse and enforcing plan limits.
  • To respond to you when you contact support.

We do not sell your data, and we do not use the content of your messages for advertising or profiling.

4. Our legal basis for processing

Where UK/EU data protection law applies, we rely on:

  • Performance of a contract — processing your account details and message data is necessary to actually provide the bridging service you've signed up for.
  • Legitimate interests — for things like security logging, fraud prevention, and improving the service, balanced against your rights.
  • Consent — specifically for connecting a WhatsApp or Telegram account, which you actively initiate and can disconnect at any time.

5. About your WhatsApp connection specifically

This section matters, so we're stating it plainly rather than burying it in general terms.

Bridgewire's Telegram integration uses Telegram's own official API. Its WhatsApp integration does not use Meta's official WhatsApp Business Platform — it connects as a linked device, similar to WhatsApp Web. This method is not officially sanctioned by Meta/WhatsApp for this kind of use, and connecting your WhatsApp account through Bridgewire carries a real risk that WhatsApp may restrict, limit, or ban the connected number, independently of anything Bridgewire does wrong. This isn't a hypothetical disclaimer — it's a documented, real risk of this connection method generally, for any account connected this way.

By connecting a WhatsApp account, you're accepting this risk for that specific number. We take reasonable steps to reduce it (details of which aren't published here for obvious reasons), but we cannot eliminate it or guarantee against it, because it depends on decisions made by Meta, not by us.

6. Who we share information with

We share data with a small number of service providers who help us run Bridgewire, each only for the purpose described:

  • Hosting — our servers and database are hosted with Hetzner, in Germany.
  • Email delivery — account, approval, and password-reset emails are sent through Resend.
  • Business email — our own support and admin email accounts run on Google Workspace.
  • Telegram and WhatsApp — by the nature of the service, message data you choose to bridge is necessarily sent to and from Telegram's and WhatsApp's own systems, governed by their own respective terms and privacy policies.

We don't share your data with anyone else, and we don't sell it. If we introduce payment processing (for example, Stripe) or additional infrastructure providers in future, we'll update this section and this policy accordingly.

7. International data transfers

Our hosting is within the EU (Germany). Some of our service providers (such as Resend and Google) may process data outside the UK/EEA, including in the United States, under their own standard data protection safeguards. If you'd like more detail on any specific provider's safeguards, contact us and we'll do our best to point you to it.

8. How long we keep your data

We keep your account and message data for as long as your account is active. If you or an administrator deletes your account, this is permanent and immediate: your profile, connections, bridges, message history, and logs are all removed at that point — not just hidden or marked inactive. There is no recovery window after deletion, so this is a genuinely final action.

9. Security

We take real, concrete steps to protect your data, including:

  • Passwords are hashed (never stored in plain, readable form) using industry-standard bcrypt hashing.
  • All traffic to the dashboard is encrypted in transit (HTTPS).
  • Session security protections against common web attack patterns (including cross-site request forgery protection and rate limiting on login attempts).
  • Administrative access to user accounts is restricted to approved administrator accounts only.

No system is perfectly secure, and we can't guarantee absolute security, but we treat this seriously given the sensitivity of what's being handled.

10. Your rights

Depending on where you're based, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (most of this you can already do yourself, in Settings).
  • Request deletion of your account and data (also available directly to you, or by asking us).
  • Object to or restrict certain processing.
  • Receive a copy of your data in a portable format.

To exercise any of these, contact us using the details below. If you're in the UK and believe we haven't handled your data properly, you also have the right to complain to the Information Commissioner's Office (ico.org.uk).

11. Cookies

The Bridgewire dashboard uses a single essential session cookie to keep you signed in. It is not used for advertising, tracking, or analytics, and isn't shared with any third party. We don't currently use analytics or marketing cookies on this site.

12. Children

Bridgewire is not intended for use by anyone under 18, and we don't knowingly collect data from children.

13. Changes to this policy

We may update this policy as the service changes — for example, when we introduce payment processing. We'll update the date at the top of this page when we do, and for significant changes, we'll make a reasonable effort to let active users know directly.

14. Contact us

Questions about this policy or your data can be sent to support@bridgewire.cloud.

© 2026 Bridgewire. All rights reserved. Connect. Route. Deliver.