Skip to content

Privacy Policy

Last updated: May 26, 2026

BossMode is local-first: the CLI, daemon, and agent harnesses run on your machine, and the control plane at bossmode.ing is the synchronized mirror. We process customer account data, operational telemetry, connected-system metadata, customer-provided business context, and opt-in records in order to deliver the service. Where GDPR applies, we act as processor for customer content and as controller for account, billing, security, communications, and product-improvement data.

Categories of data and legal basis

Account and identity
Names, emails, roles, WorkOS identifiers, and session events. Used to authenticate users, manage seats, and secure the workspace. Legal basis: contract performance and legitimate interests in security.
Billing and subscription
Stripe customer IDs, subscription status, invoices, and plan entitlements. Used to provision paid access and handle support. Legal basis: contract performance and legal compliance.
Operational workspace data
Directives, work packets, execution runs, artifacts, audit logs, routines, knowledge entries, and memories. Used to run BossMode and preserve a consistent operator trail. Legal basis: contract performance.
Support and diagnostics
Request IDs, error events, traces, and monitoring metadata. Used to diagnose reliability issues and protect the service. Legal basis: legitimate interests.
SMS consent and delivery
Mobile phone numbers, SMS consent selections, opt-in source, timestamps, message status, and STOP/HELP handling records. Used only to provide requested BossMode text messages, support, confirmations, reminders, service follow-up, and optional marketing messages when separately selected.

SMS and mobile messaging privacy

BossMode collects mobile numbers and SMS consent when you submit a form, request AI demo access, book or confirm an appointment, ask for service follow-up, or separately choose to receive marketing texts. SMS consent is optional and is not required to buy or use BossMode. The opt-in form presents marketing and non-marketing SMS choices separately, and both choices are unchecked by default.

The marketing consent language shown at opt-in is: “I consent to receive marketing text messages, about special offers, discounts, and service updates, from BOSSMODE (BossMode) at the phone number provided. Message frequency may vary. Message & data rates may apply. Text HELP for assistance, reply STOP to opt out.

The non-marketing consent language shown at opt-in is: “I consent to receive non-marketing text messages from BOSSMODE (BossMode) about my requested AI demo access, appointment confirmations, reminders, and service follow-up. Message frequency may vary, message & data rates may apply. Text HELP for assistance, reply STOP to opt out.

You can get help by replying HELP to a BossMode text message or by emailing support@bossmode.ing. You can opt out of SMS messages at any time by replying STOP to any BossMode text message from +1 404-383-0061 or any other BossMode sending number.

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Additional messaging terms are available in the BossMode Terms of Service.

Retention

Standard retention keeps customer operational records for up to one year unless a shorter verified deletion request applies. Enterprise customers may negotiate a custom retention profile. Verified deletion requests trigger a 30-day grace period before hard deletion. SMS opt-in and opt-out records may be retained as needed to honor consent, prove compliance, suppress future messages after STOP, and resolve disputes.

Cookies and tracking technologies

BossMode may use first-party cookies, local storage, pixels, and similar tracking technologies for authentication, security, fraud prevention, preferences, diagnostics, attribution, and consent-gated product analytics. We do not use SMS opt-in data, mobile numbers, or text messaging consent records for third-party advertising or affiliate lead sharing.

Data security practices

BossMode uses administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encrypted transport, least-privilege operational workflows, audit logging, vendor review, and monitored infrastructure. No system can be guaranteed perfectly secure, but we limit access to personal information to personnel and subprocessors who need it to operate, secure, support, and improve BossMode.

Your rights

Subject to applicable law, you may request access, correction, export, deletion, restriction, or objection. BossMode supports NDJSON export and account deletion workflows for owner users. Additional processing details are described in the DPA.

Subprocessors

We rely on infrastructure providers including Convex, Vercel, Stripe, Resend, Sentry, Cloudflare, WorkOS, GoHighLevel/LeadConnector for customer communication workflows, and LLM providers (Anthropic, OpenAI, Google, xAI) selected by the customer. See the live list at /subprocessors.

Product analytics

We use consent-gated PostHog product analytics to understand feature adoption, Pilot Training progress, approval actions, connection setup, and Trust Pack outcomes. Autocapture of keystrokes, input values, rage clicks, and session recording is disabled by default.

Contact

Privacy requests can be sent to privacy@bossmode.ing.