Legal
Privacy policy
Plain-language summary for BoloBots. Draft for review by counsel before general availability.
Who this covers
Agency users who sign up, their teammates, and the client contacts and leads that agencies store. The agency is the controller of its client and lead data; we process it on the agency's instructions.
What we collect
Account data: name, email, password hash, sessions, and preferences.
Workspace data the agency enters: clients, brands, content, approvals, inbox items, leads, outcomes, reports, and media.
Approval and portal visits: the decision, name, version, and time. We do not store IP addresses for approvals or tracked-link clicks; clicks keep a daily salted hash for counting.
Operational logs with correlation IDs, kept for 30 days.
What we don't collect
Card numbers (handled by the payment provider), social network passwords, or clinical records. Healthcare templates are for marketing only.
How it is used
To run the service, send transactional emails, publish content the agency approves, secure accounts, and produce reports. No data is sold. AI features send redacted text to the configured AI provider only when an organization enables AI.
Subprocessors
Database hosting (Neon), application hosting (Vercel), worker hosting, email delivery, optional AI provider, and payment provider. The current list is kept in the vendor inventory.
Retention and deletion
Account deletion stops sign-in immediately and removes personal details after 30 days. Organization records such as approvals and audit entries are retained with the person's name removed. Agencies can export leads and reports at any time.
Your rights
Request access, correction, export, or deletion from Settings → Your account, or by writing to support@bolobots.com.