Privacy Policy
Last updated: 2026-03-31
Table of contents
1. Who we are
Bao Agent (referred to as "Bao", "we", "us", or "our") provides AI-assisted product and marketing workflows. For personal data processed through this service, Bao is the data controller unless otherwise stated in a customer agreement.
2. Information we collect
We may collect the following categories of personal information:
- Account data: email address, authentication provider ID, session metadata.
- User-submitted data: prompts, project inputs, generated workflow context.
- Usage and diagnostics: feature interactions, timestamps, logs, crash events.
- Technical data: IP address, browser/device data, approximate location from IP.
3. Why we process data
- To provide account login, authorization, and core product functionality.
- To maintain security, prevent abuse, and investigate incidents.
- To monitor performance, debug errors, and improve product quality.
- To communicate service updates and support responses.
- To comply with applicable legal and regulatory requirements.
We do not sell personal information and do not process personal data for unrelated, deceptive, or incompatible purposes.
4. Legal basis (GDPR)
For users in the EEA/UK/Switzerland, we process personal data based on:
- Contractual necessity (providing the service you request).
- Legitimate interests (security, product reliability, fraud prevention).
- Consent (where required for optional cookies or communications).
- Legal obligation (record-keeping, legal compliance requests).
6. International transfers
Your information may be processed in countries other than your own. Where required, we apply appropriate safeguards (such as standard contractual clauses) to protect transferred personal data.
7. Data retention
We retain personal data for as long as needed to provide the service, maintain security, resolve disputes, and satisfy legal obligations. Retention periods vary by data type, account status, and legal requirements.
8. Security
We use reasonable technical and organizational safeguards to protect personal data, including access controls, encryption in transit, and operational security practices. No system is perfectly secure, and we continuously improve protections.
10. Your privacy rights
Depending on your jurisdiction, you may have rights to:
- Access, correct, delete, or export your personal data.
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent.
- Appeal or lodge a complaint with a data protection authority.
California residents may also have rights under CCPA/CPRA, including the right to know, delete, correct, and opt out of sale/share (Bao does not sell personal information).
11. Children's privacy
Bao is not directed to children under 13 (or the applicable age in your jurisdiction), and we do not knowingly collect personal information from children.
12. Policy changes
We may update this Privacy Policy periodically. If material changes are made, we will update the "Last updated" date and provide additional notice where required by law.
13. Contact us
For privacy requests or questions, contact privacy@buildbao.com.