Privacy Policy
Effective date: 20 August 2026
1. Introduction
This Privacy Policy explains how Whitestone Labs, Inc. d/b/a Boski, a company incorporated under the laws of the State of Delaware, United States, with an address at 1111B S Governors Ave Suite 90298, Dover, DE 19904, United States, e-mail: contact@boski.com (hereinafter: the "Controller"), collects, uses, discloses and protects personal data in connection with Boski.
Boski is a personal artificial intelligence service available through its websites, web and mobile applications, supported messaging and e-mail channels, and integrations with third-party services (collectively, the "Service"). This Privacy Policy applies whenever a person creates an account, uses the Service, communicates with the Controller or otherwise interacts with Boski (hereinafter: the "User").
The Controller reviews this Privacy Policy periodically and updates it when the Service, the Controller's practices or applicable law changes. The current effective date appears at the top of this page.
For purposes of this Privacy Policy:
- "Account Data" means information used to create, authenticate, configure and administer a User account;
- "User Content" means messages, prompts, responses, files, media, voice transcripts, notes, contacts, tasks, journal entries and other content a User provides, creates or receives through the Service;
- "Connected Service Data" means information obtained from or sent to a third-party service or communication channel at the User's direction; and
- "Technical and Usage Data" means device, network, event, performance and diagnostic information generated through use of the Service.
2. Information the Controller collects
The categories of personal data collected depend on how the User uses the Service and may include:
- Account and profile information, such as name, e-mail address, username, profile image, website, telephone number, locale, time zone, approximate city, region or country, signup channel and onboarding answers;
- authentication and integration information, such as login provider identifiers, authorisations, scopes, access or refresh tokens, and identifiers assigned by connected services;
- User Content and conversation information, including prompts, AI-generated responses, tool calls, actions, approvals, reactions, read state, attachments, images, audio and transcripts;
- memory and personal-organisation information used to provide continuity and requested features, including profile details, preferences, relationships, notes, contacts, to-do items, journal entries, news collections, nutrition or calorie records, saved content and related metadata;
- scheduling and notification information, including reminders, recurring tasks, planned executions, delivery preferences and channel settings;
- Connected Service Data, such as calendar lists, event details, availability, attendees and other information the User asks Boski to read, create, change or transmit through an integration;
- communication-channel information, such as telephone number, e-mail address, messages, attachments, sender and recipient identifiers, timestamps, delivery or read receipts and other metadata generated when Boski is used through WhatsApp, Apple Messages, XChat, e-mail or another supported channel;
- transaction information, such as subscription status, plan, billing country, payment status and transaction identifiers. Full payment-card details are processed by payment providers and are not stored by the Controller;
- communications with the Controller, including support requests, complaints, feedback and related correspondence; and
- Technical and Usage Data, such as IP address, approximate location derived from IP address, device and browser type, operating system, page paths, referring page, installation or session identifier, timestamps, feature events, error reports, security logs and performance diagnostics.
The Controller receives information directly from the User, automatically from the User's device or use of the Service, from connected services and communication channels authorised by the User, from payment and authentication providers, and from service providers acting on the Controller's behalf.
When a User creates or enriches a profile, the Controller may use information from the User's account to search publicly available professional or social sources and use automated matching to identify likely information about that User. Boski stores only results reasonably believed to relate to the User and uses them to personalise the Service. A User may ask the Controller to correct or delete this information.
The Controller uses privacy-conscious product analytics. Product analytics may include page paths, sanitised URLs or referrers, pseudonymous installation or session identifiers, authenticated User identifiers, event names and limited scalar properties. The Controller does not intentionally place User Content, prompts, AI outputs, telephone numbers, e-mail addresses, credentials, raw provider identifiers or media in product-analytics events and does not use device fingerprinting. Product analytics is separate from the advertising technologies described below.
When a User visits Boski's public website, signup or checkout flows, or other surfaces on which advertising technologies are enabled, the Controller may use cookies, pixels, tags, mobile advertising identifiers and similar technologies supplied by Google Ads and Meta Ads. The resulting advertising and attribution data may include online identifiers, IP address, device and browser information, pages viewed, interaction and conversion events, campaign or referral information, and subscription or purchase events. If an advertising matching feature is enabled and the User has provided any consent required by law, it may also include contact information transformed by hashing before transmission. The Controller does not intentionally send User Content, prompts, AI outputs, Connected Service Data, credentials, files, media or sensitive personal data to advertising partners.
Because Boski accepts free-form User Content, a User may choose to provide information that applicable law regards as sensitive, including health, financial, relationship or other private information. Users should provide only information necessary for the feature they request and must not provide another person's sensitive information without lawful authority. Where applicable law requires a specific notice or explicit consent for particular processing, the Controller will request it before carrying out that processing.
3. How the Controller uses personal data
The Controller uses personal data to:
- create, authenticate, maintain and administer User accounts;
- provide conversations, memory, personalisation, files, applications, integrations, communication channels, scheduled or recurring tasks and other requested Service features;
- understand and carry out User instructions, generate responses and invoke tools or connected services chosen by the User;
- build and maintain User-specific memory, indexes, embeddings, classifications and other derived representations needed to retrieve context and provide the Service;
- process transactions, administer subscriptions and provide billing records;
- respond to questions, feedback, complaints and support requests and send operational or security communications;
- personalise the Service, including by enriching the User's profile from public sources as described in §2;
- secure, maintain, troubleshoot and improve the Service, prevent fraud and abuse, and investigate incidents;
- produce aggregated or de-identified statistics and privacy-conscious analytics about Service performance and feature use;
- measure advertising and campaign performance, attribute visits, signups and subscriptions, create or measure audiences, and deliver or personalise advertising where the User has consented or applicable law otherwise permits it;
- send product news, offers or other marketing communications where the User has consented or applicable law otherwise permits them. Creating an account does not by itself constitute marketing consent where separate consent is required, and each marketing e-mail includes a way to unsubscribe;
- comply with tax, accounting, consumer-protection and other legal obligations; and
- establish, exercise or defend legal claims and enforce the Terms of Service.
Boski uses artificial intelligence systems to provide features requested by Users. The Controller may send the information needed for a request to AI model providers acting on its behalf. AI-generated responses may be inaccurate, and Users remain responsible for reviewing outputs and approving actions before relying on them where the Service presents an approval step.
Relevant portions of User Content may be processed by AI systems to produce responses, reports, actions and other outputs at the User's direction. The Controller does not use User Content for advertising, does not train its own or third-party foundation models on User Content, and does not permit AI providers acting on its behalf to use User Content to train or improve their general-purpose models.
The Controller may use User Content to develop or improve narrowly scoped, internal systems used only to operate and improve Boski, such as a model-selection router that determines which AI provider or model should handle a request. These service-specific systems are not general-purpose AI models, do not generate content independently, and are not made available to third parties. User-specific memory, embeddings, indexes, classifications and other representations are likewise created only to provide Boski to the relevant User and are not used to train a foundation model.
For Users in the European Economic Area or the United Kingdom, the Controller relies on the following legal bases, as applicable:
- performance of a contract or steps requested before entering into a contract, for account administration, provision of the Service and payment handling (Article 6(1)(b) GDPR);
- the User's consent, for optional connected services, non-essential device storage, advertising technologies, ads personalisation or analytics where consent is required, marketing communications requiring consent and other processing presented as optional (Article 6(1)(a) GDPR);
- compliance with legal obligations, including tax, accounting and lawful disclosure duties (Article 6(1)(c) GDPR); and
- the Controller's legitimate interests in operating, securing, supporting and improving the Service, including narrowly scoped internal quality systems, communicating with Users, preventing abuse, analysing limited Service usage and establishing or defending claims, balanced against the User's rights and expectations (Article 6(1)(f) GDPR).
A User may withdraw consent at any time without affecting processing that took place before withdrawal. When the Controller relies on legitimate interests, a User may object as described in §7.
4. How the Controller discloses personal data
The Controller does not sell personal data for monetary consideration. The Controller may disclose online identifiers, advertising and attribution data, and limited usage or conversion data to advertising, measurement and attribution partners. Depending on the User's jurisdiction, this disclosure may be considered a "sale," "sharing," targeted advertising or cross-context behavioural advertising, and the User may have a right to opt out. The Controller does not disclose User Content, Connected Service Data or sensitive personal data for these purposes.
The Controller may disclose personal data to the following recipients, only as reasonably necessary for the purposes described in this Privacy Policy:
- hosting, storage and database providers, including Vercel and managed PostgreSQL infrastructure providers such as Neon;
- AI and machine-learning infrastructure providers, including Vercel AI Gateway and, depending on the selected feature and configuration, Anthropic, OpenAI and Google;
- communication providers, including Resend and AgentMail for e-mail and, depending on the channel used, Meta or WhatsApp, Twilio, Apple, LINQ or X;
- payment providers and app-store operators, including Stripe, Apple and Google;
- analytics, monitoring and observability providers, including ClickHouse and Logfire;
- advertising, measurement and attribution providers, including Google Ads and Meta Ads;
- web search, research and browser-automation providers, including Exa, Apify and Browserbase;
- professional advisers, auditors, insurers and contractors subject to appropriate confidentiality obligations; and
- corporate affiliates that support the operation of Boski.
The providers listed above are examples and may change as the Service develops. Depending on the context, they act as processors or service providers on the Controller's instructions, or as independent controllers for their own activities. The Controller requires processors to protect personal data and use it only for contracted services.
Google and Meta may use cookies, pixels, tags and related information to provide campaign measurement, conversion attribution, audience creation and personalised advertising. Depending on the service and jurisdiction, the Controller and the advertising provider may act as independent or joint controllers for parts of this processing. Information subsequently processed by Google or Meta is also governed by that provider's privacy policy and advertising controls.
AI providers receive only the information needed to process the relevant request. Data sent through business or API services may be retained temporarily for security and abuse-prevention purposes under the provider's applicable terms, but it is not made available to other Boski Users and may not be used by those providers for general-purpose model training on the Controller's behalf.
Boski discloses information to recipients, connected services or the public when a User asks it to send a message, create or update an external record, share a file, publish a note or collection, or perform another outward-facing action. The recipient's own privacy practices apply after it receives the information.
The Controller may also disclose personal data when reasonably necessary to comply with law or legal process, protect the rights, safety or property of Users, the Controller or others, investigate fraud or security threats, or establish, exercise or defend legal claims.
If the Controller is involved in a merger, financing, reorganisation, acquisition, sale of assets, insolvency or similar transaction, personal data may be disclosed to advisers, counterparties and a successor, subject to appropriate confidentiality and data-protection safeguards.
The Service may contain links to, retrieve content from or perform actions on third-party services. This Privacy Policy does not govern an independent third party's processing, and Users should review that party's privacy notice.
5. Data storage and security
The Controller is established in the United States. Personal data may be stored or processed in the United States, the European Economic Area and other countries in which the Controller or its providers operate. Transfer safeguards for EEA and UK personal data are described in §9.
The Controller applies technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the system, these measures include encrypted network transport, encryption at rest supplied by managed infrastructure, access controls and least-privilege practices, protected credentials, encrypted provider payloads where applicable, signed-webhook verification, security logging and monitoring, backups and incident-response procedures.
Access to User Content by authorised personnel is limited to what is reasonably necessary to respond to a User request, investigate a security or abuse issue, maintain the Service, or comply with law. More restrictive conditions apply to Google user data as described in §10.
Users are responsible for protecting their login credentials, securing devices used to access Boski and reviewing recipients before approving an external action. A User should notify the Controller promptly if the User suspects unauthorised account access.
No method of transmission or storage is completely secure. Although the Controller works to protect personal data, it cannot guarantee absolute security. If a personal data breach requires notice, the Controller will notify the competent authority and affected Users in accordance with applicable law.
6. Data retention
The Controller retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, taking account of the nature of the data, the User's choices, security needs and legal, tax, accounting and limitation-period requirements.
The following retention principles ordinarily apply:
- Account Data and User Content are retained while the account is active and as needed to provide the Service. When a User deletes the account, the Controller begins deletion from active systems without undue delay and ordinarily completes provider cleanup within 30 days, subject to backup, security and legal exceptions;
- Connected Service Data is retained while the relevant connection is active and the data is needed for the requested feature. After disconnection, the Controller deletes retained Connected Service Data within 30 days, except where a limited copy must remain temporarily in backups or for security or legal compliance;
- when a User deletes individual User Content, the Controller removes it from active systems as part of normal processing. Residual copies may remain temporarily in backups until normal rotation;
- support requests and other correspondence may be retained for three years after the communication;
- marketing records are retained until consent is withdrawn or the User opts out, with a limited suppression record retained to honour the choice;
- product-analytics data is retained for no more than one year from collection;
- advertising and attribution records are retained only as long as needed to measure campaigns, maintain suppression or consent records, prevent fraud and comply with law. Advertising providers may retain data under their own settings, terms and privacy policies;
- security and diagnostic logs are retained for no more than 12 months unless a longer period is necessary to investigate an incident or abuse; and
- transaction, tax, accounting and claims records are retained for the period required by applicable law or until the relevant claims expire.
User-specific memory, indexes, embeddings and other derived representations are deleted or disassociated when the associated content or account is deleted, subject to the same limited backup, security and legal exceptions.
Providers may keep temporary security, transaction or backup copies under their applicable terms. The Controller does not keep personal data indefinitely merely because storage is technically possible.
7. User rights and choices
Subject to applicable law, a User may have the right to:
- obtain confirmation of whether the Controller processes the User's personal data and access a copy of it;
- correct inaccurate data and complete incomplete data;
- request deletion of personal data;
- request restriction of processing;
- receive data provided by the User in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests, including objection at any time to direct marketing;
- withdraw consent at any time; and
- lodge a complaint with the competent data-protection authority.
A User may exercise available rights through account or integration settings, or by contacting contact@boski.com. The Controller may ask for information reasonably necessary to verify identity and authority. For GDPR requests, the Controller responds without undue delay and ordinarily within one month, subject to lawful extensions.
A User may disconnect a connected service or revoke its authorisation at any time through Boski or the connected service. Disconnection stops new collection from that service but does not by itself delete the Boski account or information that must be retained under §6. A User may unsubscribe from marketing through the link in an e-mail or by contacting the Controller.
Where applicable law requires consent, non-essential Google Ads and Meta Ads technologies are activated only after the User has made the required choice. A User may reject or withdraw advertising consent through the privacy controls presented by the Service and may also use browser or device controls. Where applicable U.S. state law provides a right to opt out of sale, sharing or targeted advertising, the User may exercise it through the Service's advertising privacy controls or by contacting the Controller.
The Controller does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects concerning Users. Boski may automate tasks at a User's direction, but the User remains able to configure, review or stop those tasks through the Service.
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies, a California resident may have the rights to know and access, correct and delete personal information, receive information about its collection and disclosure, opt out of sale or sharing, limit certain uses of sensitive personal information and receive non-discriminatory treatment. The Controller does not sell personal information for monetary consideration, but its disclosure of advertising and attribution data to Google or Meta may constitute "sharing" or cross-context behavioural advertising. The Controller does not use or disclose sensitive personal information for advertising purposes.
Residents of other U.S. states may have analogous rights, including rights to access, correct, delete or obtain a copy of personal data and opt out of sale, targeted advertising or profiling that produces legal or similarly significant effects. Because advertising technologies may process personal data for targeted advertising, eligible Users may opt out as described above. If the Controller denies a request, the User may appeal by replying to the Controller's decision.
U.S. state privacy requests may be sent to contact@boski.com and may be submitted by an authorised agent where the law permits. The Controller will verify the request and ordinarily respond within 45 days, subject to lawful extensions.
Providing personal data is generally voluntary. However, certain Account Data and User Content are necessary to create an account, provide requested features, process a subscription or respond to the User. If the User does not provide them, the relevant feature may not be available.
8. Children's privacy
The Service is intended for people who are at least 16 years old. The Controller does not knowingly collect personal data from a person under 16. If the Controller learns that such data has been collected, it will take appropriate steps to delete the data and related account without undue delay. A parent or guardian who believes a child has provided personal data may contact the Controller.
9. International users and data transfers
Whitestone Labs, Inc. d/b/a Boski is the controller of personal data processed through Boski. Although it is established outside the European Union, it applies the GDPR to processing within the GDPR's territorial scope.
The Controller's representative in the European Union under Article 27 GDPR is Whitestone Labs sp. z o.o. with its registered office in Warsaw, Poland, address: Świeradowska 47, 02-662 Warsaw, Poland, e-mail: contact@boski.com.
When personal data is transferred from the EEA to a country that is not recognised as providing adequate protection, the Controller uses an applicable safeguard, such as the European Commission's Standard Contractual Clauses, and supplementary measures where appropriate. Transfers may also be made to recipients covered by an adequacy decision or, where applicable, the EU-U.S. Data Privacy Framework.
For transfers governed by the UK GDPR, the Controller uses an applicable UK transfer mechanism, such as the UK Addendum to the Standard Contractual Clauses or the UK International Data Transfer Agreement, or relies on applicable UK adequacy regulations.
Users in the EEA may lodge a complaint with the supervisory authority in the country where they live, work or believe an infringement occurred. In Poland, this is the President of the Personal Data Protection Office. Users in the United Kingdom may complain to the Information Commissioner's Office. The Controller encourages Users to contact it first so it can try to address the concern.
10. Google API services
If a User connects a Google service, Boski accesses Google user data only after the User grants the requested permissions through Google's consent screen. Depending on the feature, this may include account identifiers, calendar lists, calendar events, availability, attendees and information needed to perform an action selected by the User.
The Controller's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve prominent, user-facing Boski features. It is not sold, used for advertising, used for creditworthiness or lending decisions, or used to train general-purpose AI or machine-learning models.
Google user data obtained through Google APIs is kept separate from Google Ads processing. Google Ads may receive only the advertising and attribution data described in §2; it does not receive Google Calendar data, other Connected Service Data or User Content for advertising purposes.
Humans do not read Google user data unless the User gives affirmative permission for a specific interaction, access is necessary for security or abuse investigation, access is required by law, or the data has been aggregated and anonymised for internal operations in a manner permitted by Google's policies.
A User may revoke Boski's Google access through Google account permissions or disconnect the integration in Boski. The Controller then stops collecting new Google data and deletes retained Google user data within the period described in §6, subject to the stated backup, security and legal exceptions.
11. Messaging channels and connected services
When a User communicates with Boski through WhatsApp, Apple Messages, XChat, e-mail or another third-party channel, messages and associated metadata pass through that provider's infrastructure. The provider may process information as an independent controller under its own privacy notice and terms. Boski receives and stores the information necessary to maintain the conversation, associate it with the User and deliver requested responses or actions.
When a User signs in through Google or Apple, pays through Stripe or an app store, or connects another third-party service, that provider may separately process authentication, payment, account or usage information for its own purposes. The Controller does not control those independent activities.
Connected services receive information when the User asks Boski to take an action, such as sending a message, creating a calendar event, searching the web or publishing content. Users should review the instruction, intended recipient and destination before approving an action and should not use Boski to disclose information they are not authorised to share.
Revoking or disconnecting a channel or service prevents future access through that connection but may not delete information already sent to an external recipient or retained by the provider under its own rules. Boski's retention of Connected Service Data is described in §6.
12. Changes to this Privacy Policy
The Controller may update this Privacy Policy to reflect changes to the Service, data practices, providers or applicable law. The Controller will post the revised version on this page and update its effective date.
The Controller will provide advance notice of material changes when reasonably practicable, for example by e-mail, within the Service or through a communication channel used by the User. If a change materially expands the use of Google user data or otherwise requires consent, the Controller will obtain that consent before the new use begins.
13. Contact
Questions, complaints and privacy-rights requests may be sent to Whitestone Labs, Inc. d/b/a Boski, 1111B S Governors Ave Suite 90298, Dover, DE 19904, United States, e-mail: contact@boski.com, telephone: +1 (302) 257 1852.