AIBOS

Legal

Privacy Policy

Plain language, because you should be able to read it. Last updated 14 July 2026.

See also our Trust Center for the promises behind these mechanics.

What we collect

  • Account details you give us: your name, email, business name, industry, currency, and (if you choose) a WhatsApp number for your brief.
  • Business data you record or upload: sales, expenses, inventory, customers, suppliers, invoices, schedules, and any spreadsheets you import.
  • Payroll data, if you use it: employee names, pay, and statutory figures (PAYE, NAPSA, NHIMA).
  • Hospitality data, if you use it: guest names, contact details, and — encrypted at the field level before it is stored — guest ID numbers.
  • Usage events: which features you open, so we can improve the product. Never the content of your records for advertising.

How we use it

  • To run the product for you: compute your P&L, cashflow, forecasts, briefs and recommendations from your own recorded data.
  • To answer your questions: when you use the AI chat, the relevant figures are sent to our AI provider (Groq) solely to generate your answer. They are not used to train any model.
  • To keep you informed: deliver the brief you asked for, by email or WhatsApp, if you opt in.
  • We do NOT sell your data, and we do NOT use your business records to train AI models or to advertise to you.

Where it lives and how it is protected

  • Your data is stored on Supabase (PostgreSQL) with row-level security, so one business can never read another’s records.
  • Access to the database uses a server-side key held only by our backend; the browser never holds it.
  • Sensitive identifiers (guest ID numbers) are encrypted with a per-deployment key before they are written, so a database leak alone does not expose them.
  • Connections use HTTPS/TLS. We apply security headers (HSTS, CSP, frame protection) to the web app.

Your team and roles

  • If you invite staff or an accountant, they act inside your business with the role you grant. Staff record entries that you confirm; accountants have read-only access. You can change or revoke their access at any time from your profile.

Your rights

  • Export: download your full history at any time, on any plan, including after you cancel.
  • Deletion: you can start fresh (which archives then removes recorded events, recoverable for 30 days) or ask us to delete your account entirely.
  • Correction: edit any recorded event; the change is kept in an audit trail.
  • To exercise any right, or ask a question, contact us at the address below.

Retention

  • We keep your data for as long as your account is active. Reset/“start fresh” archives are retained for 30 days for recovery, then purged. If you delete your account, your data is removed within 30 days, except where we must retain records to meet a legal obligation.

Third parties we rely on

  • Supabase (authentication and database), Groq (AI question answering), Resend (email brief delivery, if enabled), and Meta WhatsApp Cloud API (WhatsApp brief and recording, if enabled). Each receives only what is needed to perform its function.

Data processing (for business customers)

  • When you record your customers’, suppliers’ or guests’ personal details in AIBOS, you are the data controller and AIBOS is your data processor. We process that data only on your instructions — to run the features you use — and never for our own purposes.
  • We keep it confidential, apply the security measures described above (RLS isolation, field encryption for guest IDs, TLS), and do not transfer it to anyone except the sub-processors listed below, each bound to equivalent terms.
  • On request we will help you meet your own obligations to the people whose data you hold — including access, correction, export and deletion — and we return or delete the data when you close your account. For a signed Data Processing Agreement, contact us.

Benchmarks and anonymised insights

  • In future, AIBOS may offer benchmark insights — e.g. “restaurants like yours run a 62% food margin.” Any such benchmarks are built ONLY from data that has been aggregated and anonymised so no individual business can be identified, and only from businesses that have explicitly opted in.
  • This is off by default. We will ask for your clear consent before your (anonymised) figures ever contribute to a benchmark, and you can withdraw at any time. We never sell your data, benchmarked or otherwise.

Changes and contact

  • We will give notice before any material change to this policy. Questions or requests: reach us at the support address shown in the app, or via the business you signed up with.