Privacy Policy
Last updated 2026-07-06.
1. What we collect
Account data you provide directly (name, email, workspace name), the messages and customer records your connected channels and bots generate, and operational data (audit logs, login activity) needed to run and secure the platform. We don’t collect more than the feature you’re using requires.
2. How it's protected
Credentials and channel/connector secrets are encrypted at rest (AES-256-GCM) and all traffic is encrypted in transit (TLS). Every action is checked against workspace-scoped role-based access control before it runs, and privileged actions are recorded in an audit log that’s outside the reach of any installed module. See our security page for the full model.
3. Who can see your data
Your workspace’s data is isolated from every other workspace on the platform — this is enforced at the data-access layer, not just the UI. Within your workspace, visibility follows the roles you assign to your team. BotForge staff do not access workspace data except to provide support you’ve requested or investigate abuse.
4. Third parties we use
Payments are processed by Stripe and, where enabled, PayPal — we don’t store raw card numbers. AI features call the provider you configure (Claude, OpenAI, Groq, or Gemini) with only the context needed to answer that request. Connector integrations (e.g. email delivery) only run when you install and configure them.
5. Data retention
Retention today is whatever the underlying database retains — nothing is silently deleted. Workspace owners can delete a workspace and its data from the workspace danger-zone settings at any time. Organizations can declare target retention windows for audit and message data as part of their compliance configuration.
6. Your rights
You can export your customer and audit data from within your workspace, and request deletion of your account or workspace data at any time by using the in-app deletion tools or by contacting support.
7. Compliance posture
BotForge’s architecture is built to support GDPR, SOC 2, and ISO 27001-style controls (encryption, access control, audit logging, deprovisioning) — this is a readiness posture, not a certification claim. We’ll update this page if that changes.
8. Changes to this policy
We’ll update the “last updated” date above when this policy changes and, for material changes, notify workspace owners in advance.
9. Contact
Privacy questions or requests: contact us.