Skip to content
BoloBots

Legal

Privacy policy

Plain-language summary for BoloBots. Draft for review by counsel before general availability.

Who this covers

Agency users who sign up, their teammates, and the client contacts and leads that agencies store. The agency is the controller of its client and lead data; we process it on the agency's instructions.

What we collect

Account data: name, email, password hash, sessions, and preferences.

Workspace data the agency enters: clients, brands, content, approvals, inbox items, leads, outcomes, reports, and media.

Approval and portal visits: the decision, name, version, and time. We do not store IP addresses for approvals or tracked-link clicks; clicks keep a daily salted hash for counting.

Operational logs with correlation IDs, kept for 30 days.

What we don't collect

Card numbers (handled by the payment provider), social network passwords, or clinical records. Healthcare templates are for marketing only.

How it is used

To run the service, send transactional emails, publish content the agency approves, secure accounts, and produce reports. No data is sold. AI features send redacted text to the configured AI provider only when an organization enables AI.

Subprocessors

Database hosting (Neon), application hosting (Vercel), worker hosting, email delivery, optional AI provider, and payment provider. The current list is kept in the vendor inventory.

Retention and deletion

Account deletion stops sign-in immediately and removes personal details after 30 days. Organization records such as approvals and audit entries are retained with the person's name removed. Agencies can export leads and reports at any time.

Your rights

Request access, correction, export, or deletion from Settings → Your account, or by writing to support@bolobots.com.