Legal01 / 04

Privacy Policy

Last updated · August 13, 2026 · v1.5
The short version

We collect what we need to run your workspace and your agents — nothing we can sell, because we don't sell your data. We use your connected-tool credentials only to perform the actions your agents take, and you can export or delete your data at any time.

01

What we collect

We keep this to what the product needs:

  • ·Account — your name, email, and organization, handled through our authentication provider.
  • ·Marketing enquiries — the email and optional details you submit, plus bounded referral and campaign parameters from the link you followed; we derive the email's domain to route company enquiries.
  • ·Usage — app interactions, agent run metadata, and diagnostic logs.
  • ·Session security — IP address, browser details, and approximate IP-derived location (city, region, country, timezone, coordinates, and Cloudflare data center) recorded when you sign in.
  • ·Webhook diagnostics — when an external service calls an agent's webhook, we retain a limited request snapshot (IP address, browser/client details, approximate location and network, Cloudflare request ID, connection details, and whether the webhook secret or signature verified) so authorized workspace members can identify and troubleshoot the caller. We do not retain the secret, signature value, authorization credentials, cookies, or the full request-header set.
  • ·Content you provide — agent instructions, saved memory, and files you upload.
  • ·Integration data — the OAuth grants for tools you connect, and the data an agent reads or writes in those tools while a run is executing.
02

How we use it

To run and improve Boring:

  • ·operate, secure, and support the service, and run your agents and show their history;
  • ·improve the product using aggregated, de-identified usage — never your private content;
  • ·communicate with you about your account, security, and product updates.
  • ·We do not sell personal data, and we do not use your content to train foundation models.
03

Your tools & credentials

Connections to your tools are governed by you:

  • ·credentials Boring stores directly use an encrypted workspace vault; OAuth grants handled by an integration provider are subject to that provider's security controls;
  • ·workspace owners govern connections and the tools assigned to agents, and can revoke a connection;
  • ·every action an agent takes in a connected tool is written to your run audit trail.
04

Subprocessors

We rely on a small set of vendors to operate the service:

  • ·Composio — tool integrations; Cloudflare — edge & hosting;
  • ·Model providers (e.g. Anthropic, OpenAI) — inference for agent reasoning; and an email provider for transactional mail.
  • ·PostHog — product analytics on our website and app (see Cookies & analytics below).
05

Cookies & analytics

On the marketing site we measure which pages earn their keep, and what that means for you depends on where you are:

  • ·In the EU, EEA, and UK we ask first. Until you answer the cookie banner our analytics (PostHog) runs without setting anything on your device — measurement is in-memory and ends with the page. Choosing Allow sets analytics cookies so we can tell visits apart; choosing Decline turns analytics off. The only thing we store either way is your answer, so we don't ask again.
  • ·Everywhere else we don't show the banner, and a first-party analytics cookie is set when you arrive.
  • ·Either way it's the same measurement: pageviews, conversions, which calls-to-action get clicked, and non-PII campaign tags from the link you followed — never the email or company domain as an event property.
  • ·We don't use advertising cookies or cross-site trackers, and we don't sell or share this data, on any answer or in any region.
  • ·Strictly necessary items (like the bot-protection challenge on our forms) are separate from analytics and don't depend on this.
  • ·To determine which of the above applies, we read the country your network resolves to from the request — we don't store it. If you'd rather not be measured at all, your browser's cookie controls or a blocking extension will stop it, and you can email privacy@boringaico.com to have your data deleted.
06

Data retention

  • ·We keep your data while your workspace is active. Bulky run replay payloads, generated artifacts, and webhook caller diagnostics are pruned after 90 days; run summaries and step history remain until the workspace is deleted.
  • ·Deleting your account removes its active workspace data through the product deletion flow; residual provider backups expire under the provider's retention schedule.
07

Your rights

Depending on where you live (including under GDPR and CCPA), you can:

  • ·access, correct, export, or delete your personal data;
  • ·object to or restrict certain processing, and withdraw consent.
  • ·To exercise any of these, email privacy@boringaico.com.
08

How we protect it

Data is encrypted in transit and at rest, access is least-privilege, and sensitive agent actions pause for human approval. See our Security & Disclosure policy for details.

09

Changes

We'll post any material changes here and update the date above. Continued use after a change means you accept the revised policy.

Boring AI, Inc.legal@boringaico.comQuestions about your data? privacy@boringaico.com — we reply within 30 days.