Legal
Privacy Policy
Effective July 8, 2026
What information BoundOS handles, why, and the choices you have.
1. Overview and our role
This policy explains how BoundOS, Inc. (“BoundOS”, “we”, “us”) handles information across boundos.app and the Services. Our role depends on the data:
- For Customer Data that an agency uploads about its End Clients, the agency decides why and how the data is used (the “controller” / “business”), and BoundOS acts as its service provider / processor, handling the data only to provide the Services on the agency’s instructions.
- For account and website information (e.g., agency and agent contact details, site usage), BoundOS acts as the controller.
2. Information we collect
Account information
Agency name, Authorized Users’ names and email addresses, agency contact email, and plan details.
Uploaded documents and their contents (Customer Data)
Insurance quotes, declarations pages, and claim documents submitted through the dashboard or the website widget. These may contain personal information about End Clients — such as names, mailing addresses, property or vehicle details, coverage limits, deductibles, premiums, and claim descriptions — together with the structured data we extract from them and any comments added to a shared brief.
Website-widget / lead information
When a visitor uses an agency’s embedded widget: the email address they provide, the documents they upload, an optional marketing opt-in, and the originating website.
Technical information
Standard log and device data (e.g., IP address, timestamps, request metadata) and a session cookie used to keep authenticated users signed in. We do not use advertising or cross-site tracking cookies.
3. How we use information
- to provide the Services — extract data from documents, generate briefs, comparisons, answers, and draft materials, and deliver them;
- to send transactional and notification emails (e.g., a proposal link, a “new comment” or “new lead” alert);
- to authenticate users, enforce tenant isolation and usage limits, and secure the Services;
- to operate, maintain, debug, and improve the Services; and
- to comply with legal obligations.
We do not sell personal information, and we do notuse Customer Data to train foundation models — our own or our providers’.
4. AI processing and subprocessors
The Services use trusted third parties to function. Each receives only the data needed for its role, under confidentiality and data-protection terms:
- Anthropic — provides the large language models that BoundOS’s analysis pipeline builds on. Anthropic processes data only to return results and does not use it to train its models.
- Google — provides the embedding models used to index document text for in-product search.
- Supabase — database, authentication, and vector storage for account data and extracted document data.
- Resend — delivery of transactional and notification emails.
- Railway and Vercel — hosting for the application backend and website.
We update this list as our providers change. Questions: privacy@boundos.app.
5. Data retention
- Uploaded document files (PDFs) are processed transiently and deleted from processing storage shortly after a brief, answer, or claim is generated — they are not retained as files.
- Extracted data and Output (the brief/claim records) are retained in the account until the Customer or BoundOS deletes them or the account is terminated.
- Shareable links to briefs and claims expire automatically (currently 30 days).
- Lead records from the widget are retained for the agency until deleted. Widget-uploaded documents are not added to the searchable BoundChat store.
- Pilot submissions (documents you upload through the “One-Renewal Pilot” on our website) are received by email and used solely to prepare and return your sample brief. They are not added to any agency workspace, not used to train models, and not used for any other purpose. We delete these submission emails and their attachments within 30 days of delivering the brief.
- Logs and backups are kept for a limited period for security and reliability.
6. How information is shared
We share information with the subprocessors above to run the Services; with an agency’s own authorized users (each agency’s data is isolated to that agency); as required by law or to protect rights and safety; and in connection with a merger, acquisition, or asset sale (subject to this policy). We do not sell or rent personal information.
7. Your choices and rights
Because BoundOS processes End-Client information on behalf of agencies, End Clients should direct privacy requests to the agency they worked with; we assist agencies in responding. Depending on your location — for example, under the California Consumer Privacy Act — you may have rights to access, correct, delete, or limit the use of your personal information, and to not be discriminated against for exercising them. Account holders can update or request deletion of their information by contacting privacy@boundos.app.
8. Cookies, children, international, and changes
We use a strictly necessary session cookie for authentication; no advertising cookies. The Services are for business use by insurance professionals and are not directed to children. BoundOS operates in the United States; if you access the Services from elsewhere, you consent to processing in the U.S. We may update this policy and will post changes here with a new effective date.
9. Contact
Privacy questions or requests: privacy@boundos.app. BoundOS, Inc. is a Delaware corporation.