Privacy Policy ← Back to Chat

At BundleAI, your privacy matters. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your personal data. By using BundleAI, you agree to the practices described in this policy.

1 Information We Collect

We collect information in the following ways:

Information you provide directly:

Information collected automatically:

2 How We Use Information

We use the information we collect to:

We do not sell your personal data to third parties. We do not use your chat content to train AI models. Your conversations are processed in real time to generate responses and are not retained beyond what is technically necessary for session continuity.

3 Data Storage

Your account data, session memory, and uploaded documents are stored in a SQLite database hosted on our servers. We implement the following safeguards:

Session Memory: If you enable Session Memory, a summary of your conversations may be stored to improve continuity across sessions. You can clear this data at any time via your account settings.

4 Cookies

BundleAI uses only essential cookies required for the service to function. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

Because we only use strictly necessary cookies, no cookie consent banner is required. You can delete cookies through your browser settings at any time, but doing so will log you out of your account.

5 Third-Party Services

BundleAI integrates with the following third-party services. Each has its own privacy policy governing how they handle data:

💳 Stripe

Processes card payments. Stripe handles all card data directly and is PCI-DSS compliant. BundleAI never receives or stores your full card number.

stripe.com/privacy →

₿ Cryptomus

Processes cryptocurrency payments. Cryptomus handles wallet and transaction data. BundleAI receives only a payment confirmation status.

cryptomus.com/privacy-policy →

When you use the Web Search (Tools) feature, your query may be sent to a search API provider to retrieve results. Search queries are not associated with your account in logs retained by third-party providers beyond their standard usage policies.

6 Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

7 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us via the details in Section 10. We will respond to verifiable requests within 30 days. Note that some data may need to be retained for legal or legitimate business purposes even after a deletion request.

8 Security

We implement reasonable technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you discover a security vulnerability, please report it to us responsibly rather than publicly disclosing it.

9 Children's Privacy

BundleAI is not directed to children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately so we can delete that information.

If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take steps to delete that information as quickly as possible.

10 Contact

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

BundleAI Privacy Team
Website: bundleai.cloud
For data requests or privacy concerns, use the in-app contact form or email us through the address on our website.

For users in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data in accordance with applicable law.

We will respond to all privacy inquiries within 30 days. For urgent security matters, please indicate "URGENT" in your subject line.