Privacy policy

Last updated September 27, 2026

This policy explains what information Baleybots, Inc. (“Baleybots”, “we”, “us”) collects when you use baleybots.com, the Baleybots app at app.baleybots.com, the Baleybots apps for your devices, our API and MCP server, and the messaging channels you link to Baleybots (together, the “Services”). It also covers how we use and share that information, how long we keep it, and the choices you have.

The short version:

  • We use your information to run the Services for you. We don’t sell it, and we don’t use it for advertising.
  • The data you connect or send through Baleybots stays yours. We process it only to do what you set up, and we don’t use it to train AI models.
  • To do that work, some of it goes to service providers, including the AI model providers that run the steps you configure. Section 6 names them.
  • Data from Google accounts is used only for the features you use, under Google’s Limited Use requirements (Section 5).
  1. Who we are
  2. Information we collect
  3. How we use information
  4. AI processing
  5. Google user data
  6. How we share information
  7. How long we keep information
  8. Security
  9. Your choices and rights
  10. Cookies and similar technologies
  11. Where we process information
  12. Children
  13. Changes to this policy
  14. Contact us

1. Who we are

Baleybots, Inc. is a Delaware corporation. You can reach us about anything in this policy at hello@baleybots.com.

Much of what flows through Baleybots is information you bring: rows in a spreadsheet, emails, transactions, documents. Some of it may be about other people, such as your customers. For that content, you decide what to connect and what to do with it, and we process it on your behalf. If you are one of those other people and have a question about your information, please contact the business that uses Baleybots. We will help them respond.

2. Information we collect

Information you give us

  • Account information: your email address, your password (stored by our authentication provider as a salted hash), and any passkeys you register.
  • Waiting list: the email address you submit, which we use to contact you about access.
  • Payment information: when you buy credits, you enter your card details on Stripe’s checkout page. Card numbers go to Stripe and never reach our systems. We keep a record of your purchases, your credit balance and a reference to your Stripe customer.
  • Messages to us: feedback you send in the app (with your browser’s user agent) and emails you send us.
  • Linked phone numbers: if you link iMessage or WhatsApp to Baleybots, your phone number and the messages you exchange with Baleybots.

Content you create or connect

  • What you build: pipelines, instructions, boards, reports and chats with Baley, including the tool calls Baley makes and their results.
  • Data from sources you connect: files you upload, databases, webhooks, spreadsheets, email, calendars, your X username and posts, and other accounts you choose to connect. For bank, card, loan and investment accounts you link through Plaid: account names and masked numbers, balances and credit limits, transactions and, if you choose, loan details (including loan account numbers and a mortgage’s property address) and investment holdings.
  • Run records: when a pipeline runs, we keep each row it read, what each step produced and any errors, so you can inspect every record and step.
  • Browser sessions: if you use a browser agent, the sites and pages it visits and the requests it asks you to approve. Website logins you enter are stored by our browser provider, encrypted, and not in our database (see Section 6).

Credentials

To reach the accounts you connect, we store access tokens, refresh tokens, API keys and database connection strings, encrypted in a secrets vault. One exception: when you start connecting a Supabase account, its access and refresh tokens are held in an access-controlled table in our database while you pick a project, and stay there if you don’t finish. The API keys we issue to you are stored only as one-way hashes, so we cannot recover them.

Information collected automatically

  • Usage analytics: on baleybots.com and in the app we use PostHog to record page views, clicks and other interactions, your browser and device type, and an approximate location derived from your IP address. We may record sessions to see how the product is used. In the app, recordings and click events mask all text on the screen, everything you type, and page details that can hold your data, such as links, labels, images and charts, and don’t record network requests, so they don’t capture your content or the data you connect. On baleybots.com, recordings mask what you type. When you are signed in to the app, these events are linked to your account and email address. You can turn analytics off for your browser at baleybots.com/analytics.
  • Logs: our servers log requests, including IP address, time, the route requested and errors, to operate and secure the Services.
  • Usage and billing records: which models and resources your runs used, how much, and what they cost.
  • Devices: if you use a Baleybots app that syncs conversations, the device’s name and platform and when it last synced.

3. How we use information

We use information to:

  • provide the Services: run your pipelines, answer your chat requests, sync your sources and show you the results;
  • carry out actions you set up or approve, such as writing to a destination you connected;
  • measure usage and bill for it;
  • keep the Services secure, prevent abuse and fraud, and debug problems;
  • understand how the product is used, in aggregate, so we can improve it;
  • communicate with you about your account, access, security and changes to the Services; and
  • comply with the law and enforce our Terms of Service.

We do not sell your personal information, we do not use it or your content for advertising, and we do not use your content to train AI models.

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases: performing our contract with you (running the Services), our legitimate interests (security, improving the product, communicating with you), your consent where we ask for it, and legal obligations.

4. AI processing

Baleybots uses AI models to do the work you ask for. When a pipeline step, a board or a chat request runs, the content it needs, such as the rows it processes and your instructions, is sent to the AI model provider that performs that step. The provider returns a result and we store it with your run or chat.

Depending on the model, the provider may be Anthropic, OpenAI, Google, xAI, Sakana or Ollama, or a provider reached through OpenRouter, which routes requests to the company that serves the chosen model. TypeSafe, a service that helps our agents choose their next step, receives the conversation so far. When you build a pipeline or a board, schema details, totals and, for some sources, sample rows can go to TypeSafe and an AI model to design it. Tavily, a web search service, receives the search queries an agent writes.

These providers process the content to produce results for you. Their handling of it is also governed by their own terms. If you use your own provider API key, your agreement with that provider applies to those requests.

AI output can be wrong. See the Terms of Service for what that means for how you use results.

5. Google user data

You can connect a Google account to Baleybots. Here is exactly what we access, why, and what happens to it.

What we access

  • Google Sheets: only the spreadsheets you pick in the Google Picker (the drive.file permission), and the email address of the Google account, so you can tell your connections apart. We read the cells in the range you choose and check the file’s version to notice when it changes. We don’t write to your spreadsheets, and we can’t see other files in your Drive.
  • Gmail: if you connect Gmail, Baley reads the messages it looks up to answer your requests, and the messages a pipeline step you set up asks for: their headers (from, to, cc, subject, date), text and attachment names. Baley acts on your mailbox, such as drafting and sending email from your account, only when you ask it to in a conversation or set up a pipeline step that does.
  • Google Calendar: if you connect Calendar, Baley reads your list of calendars and your events when it needs them to do what you asked. Baley can create, change or delete events, and invite attendees, when you ask it to in a conversation.

How we use it

We use Google user data only to provide and improve the features you use in Baleybots: running your pipelines over it, answering your chat requests and showing you the results. We store the rows, messages and events your pipelines and chats read, and what they produced, as part of your run and chat history, until you delete them (Section 7).

When you use Google data with AI, the parts that task needs are sent to AI model providers and TypeSafe (Section 4). Building a pipeline over Gmail sends field names and the name of the label it reads, without message text. Building a board tile over Gmail sends field names, the label’s name and a row count, without message text, to TypeSafe. A web search Baley runs for your task sends its query to Tavily. If you talk to Baley over iMessage or WhatsApp, replies that include it pass through Sendblue or Meta (Section 6).

What we don’t do

  • We don’t use Google user data to serve ads, including personalized or retargeted ads.
  • We don’t sell it, and we don’t transfer it to data brokers or information resellers.
  • We don’t use it to determine creditworthiness or for lending.
  • We don’t use Google Workspace data to develop, improve or train generalized AI or machine-learning models.
  • We don’t let people read it unless you ask us to (for example, to help with a support request), it is needed for security or to comply with the law, or it has been aggregated and anonymized for internal operations.

Baleybots’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting

You can delete a Google connection in the app at any time, and Baleybots stops using it. Deleting it also asks Google to revoke our access, unless another of your Baleybots connections may still be using the same Google account: Google ends all of our access to an account at once, so revoking then would break that connection too. You can end our access at Google yourself at any time by removing Baleybots from your Google Account at myaccount.google.com/permissions. To delete the data we already read, delete the pipelines, chats and connections that hold it, or ask us to (Section 9).

6. How we share information

We share information only in these ways.

Service providers

These companies process information for us, to run the Services:

Cloudflare
Hosting, networking, request processing, queues and logs.
Supabase
Our database, authentication, file storage and encrypted secrets vault. Sends account emails such as invitations and password resets.
AI model providers
Anthropic, OpenAI, Google, xAI, Sakana, Ollama, OpenRouter and the providers it routes to, TypeSafe and Tavily, as described in Section 4.
Stripe
Payment processing for credit purchases and saved cards.
PostHog
Product analytics and session recordings, as described in Section 2.
Kernel
Cloud browsers for browser agents. Stores the website logins you save, encrypted, and your sessions’ sign-in state.
Sendblue and Meta (WhatsApp)
Delivering iMessage and WhatsApp messages between you and Baleybots, if you link a phone number.
Plaid
Connecting bank, card, loan and investment accounts you choose to link. Plaid’s own privacy policy applies to the information you give Plaid.

Your browser also loads fonts from Google Fonts, the sign-in page for MCP clients loads a script from jsDelivr, and, when you use those features, the Google Picker and Plaid Link load directly from Google and Plaid. Those companies receive your IP address and browser details when that happens.

Services you connect and destinations you choose

When you connect an account (such as Google, X, Plaid, Supabase, Neon, or a database or MCP server) or send results to a destination (such as a webhook, a database, or a post on X), we exchange data with that service as you directed. What that service does with it is governed by your agreement with it. When a link appears in your data, we may fetch that page from our servers to show a preview.

Other reasons

  • Shared workspaces: if a workspace is shared with others at your request, they can see its pipelines, runs, credit balance and usage.
  • Legal requirements: when we believe in good faith that the law requires it, or to protect the rights, property or safety of Baleybots, our users or others.
  • Business transfers: as part of a merger, acquisition, financing or sale of assets, subject to this policy.
  • With your consent or at your direction.

7. How long we keep information

We keep your information while your account is open, until you delete it, or as long as we need it for the purposes in this policy. In particular:

  • What you can delete yourself: pipelines (with all their runs, rows and outputs), connections (with the rows and events we stored from them), chats, boards, saved cards, passkeys, linked phone numbers and saved website logins. You can also revoke the API keys we issued you.
  • Deleting a connection stops Baleybots from using it, and removes the rows and events we stored from it. It does not delete results that pipelines already produced from that data; delete those pipelines too. Deleting a Google connection also asks Google to revoke our access, except in the case Section 5 describes. For other providers, to end our access at the provider itself, also remove Baleybots in that account’s settings.
  • Gmail in pipelines: we remove a polled message’s event copy after no pipeline subscription or run needs it. A run can keep its own copy of the message and its results until you delete the run or pipeline. A chat can keep a Gmail tool result until you delete the conversation.
  • Messages over iMessage and WhatsApp: we remove message text and your phone number from our message-handling records 30 days after we handle each message. A copy of the conversation is kept in your Baleybots conversation history until you delete it in a Baleybots app that syncs conversations or ask us to, and deleted conversations are permanently removed 30 days later. Updates Baley sends you about work it did in the background are kept until you ask us to delete them.
  • Browser sessions end after six hours idle. Saved website logins are deleted when you disconnect the site.
  • Anything else, such as files you uploaded, we delete when you ask.
  • Closing your account: email us and we will delete your account and its content, except what we must keep for legal, tax, accounting, security or fraud-prevention reasons, such as billing records.

Copies may remain in backups for a limited period before they are overwritten. Deleting content from Baleybots does not delete copies already held by services you connected or sent results to, or by AI model providers under their own retention terms.

8. Security

We protect information with encryption in transit, an encrypted vault for credentials, one-way hashes for the API keys we issue, access controls that limit each account to its own data, and restricted internal access. No system is perfectly secure, and we can’t guarantee the security of information sent over the internet. If we learn of a breach affecting your personal information, we will notify you as the law requires.

9. Your choices and rights

  • Access, correction, deletion and export: much of your information is visible and deletable in the app. For anything else, or to close your account, email hello@baleybots.com.
  • Analytics: turn off analytics and session recording for your browser at baleybots.com/analytics.
  • Connected accounts: disconnect them in the app, and revoke our access at the provider.
  • Messaging: reply STOP to end a linked iMessage or WhatsApp conversation, or unlink it in the app.

Depending on where you live, including California and other US states, the European Economic Area and the United Kingdom, you may have the right to know what personal information we hold about you, to get a copy of it, to correct it, to delete it, and to object to or restrict certain processing. You can also withdraw consent you gave us. To make a request, email us. We will verify your request and respond within the time the law allows. You may use an authorized agent. We will not discriminate against you for exercising these rights. If you are in the EEA or the UK, you may also complain to your local data protection authority.

We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined in California law.

10. Cookies and similar technologies

We use cookies and browser storage for these purposes only:

  • Signing in: session cookies that keep you signed in to the app.
  • Preferences: your light or dark theme, your analytics choice, and settings in the app.
  • Analytics: PostHog’s cookie and browser storage, which recognize your browser between visits. You can turn these off at baleybots.com/analytics.

We don’t use advertising cookies, and we don’t allow advertising networks to track you on our sites.

11. Where we process information

We are based in the United States, and we and our service providers process information in the United States and other countries. Those countries’ laws may differ from yours. Where the law requires it, we use appropriate safeguards for international transfers, such as standard contractual clauses.

12. Children

The Services are for adults and are not directed to children. We don’t knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.

13. Changes to this policy

We will update this policy as the Services change. We will post the new version here and change the date at the top. If a change is material, we will also tell you by email or in the app before it takes effect.

14. Contact us

Baleybots, Inc. — hello@baleybots.com

BaleybotsPrivacy policyTerms of servicehello@baleybots.com