Privacy Policy

Last updated: 2026-07-28

This Privacy Policy explains what information Bool (“Bool,” “we,” “us”) collects, how we use and share it, and the choices you have. It covers the Bool website and editor, the apps you build and publish with Bool (each, a “Bool”), and the infrastructure that hosts and serves them. It works alongside our Terms of Service.

1. Who This Policy Covers

Three different kinds of people interact with Bool:

  • Builderspeople who sign in to Bool to create, host, and share apps. For builder data, Bool decides how the data is used and this policy describes those practices in full.
  • End users of a published Boolpeople who sign up for or sign in to an app that a builder made. Their accounts live in Bool's infrastructure, isolated per app, but the builder decides what their app collects and what it does with it. For that data Bool acts on the builder's behalf as a service provider (a “processor” under laws that use that term); the builder is responsible for their app's own notices and consents.
  • Visitorsanyone who loads a published Bool without signing in, or who browses our marketing site and documentation.

Sections 2 and 4–12 apply to everyone. Section 3 describes the data that flows through published apps specifically.

2. Information We Collect From Builders

  • Account informationname, email address, and either a password (which we store only as a salted hash) or the basic profile your identity provider returns when you sign in with Google. Optional profile details such as an avatar, plus the workspaces, teams, and invitations you belong to.
  • What you buildthe prompts you send, the chat history of a project, files you upload as attachments, the project files and code generated for you, deployment records, and screenshots or previews of your apps.
  • Usage and diagnosticsfeature and model usage, credit and plan activity, error and performance logs, and records of administrative actions taken on your account.
  • Billing informationplan, subscription status, invoices, purchase history, and the identifiers our payment processor returns. Card numbers and bank details are collected and stored by our payment processor, not by Bool.
  • Connected accountswhen you connect an outside tool to Bool, the access and refresh tokens that connection needs, the scopes you granted, and the tool's name. Tokens are encrypted at rest and are used only to make the calls you or your project ask for.
  • Domainsdomain names you connect or purchase through Bool, the DNS and certificate records needed to serve them, and the registration details a registrar requires (which may be published in public registry records for domains you buy).
  • Communicationssupport requests, feedback, and messages you send us, and our replies.

3. Information Collected Through Published Bools

When a builder publishes an app, Bool hosts it and runs its backend. That means the following data passes through — and is stored in — our infrastructure:

  • App datawhatever the app itself stores: records its users create, files they upload, and any personal information the builder chose to collect. Each app's data is kept in its own isolated space and is reachable only through that app's server-side credentials. Bool does not use app data to build profiles of a builder's users and does not sell it.
  • End-user accountsif an app has sign-in, we store the account directory for it: email address, a salted password hash (or the identity provider used instead), display name, whether the email has been verified, sign-up and last-sign-in times, and any per-user details the app records. Password hashes are held apart from the rest of the account record and are never shown to the builder. An account is scoped to the single app it was created in; the same email in two different Bools is two unrelated accounts. Sessions are kept in a cookie that scripts on the page cannot read.
  • Traffic measurementfor pages served by Bool we record the path visited, the referring site, an approximate location (country, region, and city) derived from the network request, and coarse device, operating-system, and browser categories. We do not store raw IP addresses for this purpose; visitors are counted using a one-way, salted fingerprint we cannot reverse into an IP address. We do not use this data for advertising and do not share it with ad networks.
  • Request logsan operational record of requests to a published app: timestamp, method, path, the resource touched, response status, how long it took, and the signed-in end user's identifier when the request carried one. These logs let a builder debug their own app and let us investigate abuse, outages, and security incidents.
  • Abuse preventionrate-limit counters and similar short-lived signals, which may be keyed on a hashed IP address.

A builder can see and export the data their own app holds, including its account directory (minus credentials) and its traffic and request logs. Builders are responsible for what their apps collect, for telling their users about it, and for honoring requests those users make.

4. How We Use Information

We use the information described above to:

  • Provide, operate, host, and serve Bool and the apps built on it;
  • Generate code and other output in response to prompts, which requires sending prompt and project content to the AI providers described in Section 5;
  • Authenticate people, keep sessions active, and enforce access to private projects and apps;
  • Meter plans, credits, and usage, process payments, and prevent billing abuse;
  • Send transactional messages — email verification, password resets, invitations, share notifications, receipts, and important service notices;
  • Debug, monitor, and improve reliability, performance, quality, and safety;
  • Detect, investigate, and stop fraud, abuse, security incidents, and violations of our Terms; and
  • Comply with legal obligations and enforce our rights.

We do not sell personal information, and we do not use it for third-party advertising or cross-context behavioral advertising.

5. AI Models and Your Prompts

Bool generates code and other output using large language models operated by third parties, reached through a model-routing provider. Producing output requires sending them the relevant content — your prompt, and the project context needed to answer it, which can include file contents and attachments.

Apps you publish can also call AI features that Bool provides at runtime. Where an app does that, the content its users submit to that feature is likewise sent to a model provider to produce a response, and Bool records the fact and cost of the call for metering.

Bool does not train models on your prompts, code, or app data. Content we send to a model provider is handled under that provider's terms, which may allow it to retain the content for a limited period for abuse monitoring.

6. Cookies and Similar Technologies

We use cookies and local browser storage for purposes that are necessary to run the service: keeping you signed in, keeping an end user signed in to a published app, protecting requests against cross-site forgery, remembering interface preferences such as theme, and gating access to private apps. We do not use advertising or cross-site tracking cookies. Blocking essential cookies will prevent sign-in from working.

7. How We Share Information

We do not sell personal information. We share it only in these situations:

  • Service providerswho run parts of Bool on our behalf, under contracts that limit them to that purpose. They currently include: cloud hosting and serverless compute; managed Postgres, authentication, file storage, and realtime messaging; isolated sandbox environments that run and build your app's code; AI model providers and the model-routing layer in front of them (including Anthropic, OpenAI, and Google); a payment processor (Stripe); a transactional email provider; a domain registrar and DNS and certificate providers; error-monitoring and analytics tooling we operate for Bool itself; and a managed cache used for queues and rate limits.
  • Other people you choosecollaborators you invite, workspace members and administrators, and anyone you share a project or published app with. Publishing an app makes what you put in it available to whoever can reach its URL.
  • Buildersif you sign up for an app built on Bool, that app's builder can see the account and app data it holds about you (never your password).
  • Legal and safetywhen we believe disclosure is required by law or legal process, or is needed to investigate abuse or protect the rights, property, or safety of Bool, our users, or the public.
  • Business transfersin connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred data.

8. Data Retention

We keep information for as long as we need it to provide the service and for the purposes described above. In general:

  • Account, project, and app data are kept while your account is active.
  • Traffic measurement and request logs for published apps are kept for a limited operational window and then deleted or aggregated.
  • Billing and tax records are kept as long as applicable law requires.
  • Backups persist for a short period after deletion before they age out.

When you delete a project or your account, we delete or de-identify the associated data, including a published app's account directory and stored data, within a reasonable period, except where we must keep something to meet a legal obligation, resolve a dispute, or enforce our Terms. Export anything you want a copy of before you delete it.

9. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, encryption of connected-account tokens at rest, salted password hashing, server-side-only database credentials so that no app ships a credential capable of reading data, per-app isolation of app data, scoped access controls, and audit logging. No system is perfectly secure; if we become aware of a breach affecting your personal information we will notify you and any regulator as required by law.

10. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising these rights. You can change your account details and delete your projects or your account from the app at any time.

To make a request, email hello@bool.com. We may need to verify your identity before acting, and you can use an authorized agent where the law allows. If you are an end user of an app built on Bool, send your request to that app's builder first — they control the data. If you contact us instead, we will forward it to them or act on their instructions.

11. Children

Bool is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, email hello@bool.com and we will delete it. Builders who direct an app at children are responsible for complying with the laws that apply to that audience.

12. International Transfers

Bool is operated from the United States, and our service providers may process and store data in the United States and other countries. If you use Bool from outside the United States, you understand that your information will be processed there, where privacy laws may differ from those in your country.

13. Changes to This Policy

We may update this policy as the service evolves. The “Last updated” date above reflects the most recent revision, and for material changes we will provide reasonable notice (for example, an in-product banner or an email).

14. Contact Us

Questions about this policy or how we handle your information? Email hello@bool.com.