LEGAL
Privacy Policy
Last updated: September 13, 2026
1. What we collect
Account data: your email address, name, and workspace metadata when you sign up.
Email content: emails and attachments sent to your BounceBox inbound addresses, stored so they can be processed and so you can review results.
Extraction results: the structured data produced from your emails, plus delivery logs and usage counters.
Billing data: handled by our merchant of record, Polar. We receive subscription status and customer identifiers, not card numbers.
2. How email content is processed
Received emails are processed by machine-learning models (OpenAI GPT-5.6 via Vercel AI Gateway or OpenRouter) to extract the fields you configured. PDF attachments are sent to the model for reading; spreadsheets are parsed by our own code. Only the content needed for your configured extraction is transmitted to the model provider.
3. Retention
Raw received emails and attachments are retained for 14 days on Starter and 30 days on Pro and above, then deleted automatically. You can delete all raw emails immediately from Settings → Data & retention. Extracted results, delivery logs, and SKU catalogs are kept until you delete them or close your workspace.
4. Sub-processors
Supabase (database, authentication, file storage; default region us-east-1, eu-central-1 available on request for Custom plans), Resend (email receiving and sending), Vercel (application hosting, workflow execution, AI Gateway), OpenRouter (model routing), OpenAI (the model that reads your emails), Polar (billing, merchant of record).
5. Your rights
You can access, export, and delete your data from the dashboard at any time: extracted results are downloadable as JSON, raw emails can be purged instantly, and closing the workspace deletes its data. For GDPR/CCPA requests that you cannot fulfil from the dashboard, contact support@bubblav.com. A DPA is available on Custom plans.
6. Security
Data is encrypted in transit and at rest. Inbound webhooks are signature-verified; outbound webhooks are signed with HMAC-SHA256. Access to your workspace is authenticated and row-level-scoped in the database. No employee access to email content except to resolve a support incident you report.
7. Cookies
We use the minimum cookies required for authentication (session cookies set by Supabase). We do not use advertising or third-party analytics trackers.
8. Contact
Privacy questions: support@bubblav.com.