Privacy and your files
Last updated: 25 September 2026.
Bosonoo Pty Ltd, ACN 699 900 019, ABN 60 699 900 019, NSW, Australia, operates Bosonoo. For privacy questions, access or correction requests, deletion requests and complaints, contact admin@bosonoo.com.
Bosonoo is being introduced in stages. The sections below apply when you use the relevant feature. They do not mean that every account, AI, sharing or Store integration has been enabled.
Temporary files on your device
Files opened or created in a temporary browser-local workspace are intended to be processed and retained within your browser, rather than uploaded to your Library merely by opening them. This can include working copies, thumbnails, file names, editor state, recovery data and a reference to a file or folder you selected. Browser storage can include IndexedDB, Cache Storage, localStorage, sessionStorage and an origin-private file system.
Website and editor software still needs to load from our services. These requests expose ordinary connection information, such as your IP address, browser information and requested resources. Public search sends the search query. Following an external link or explicitly using a remote feature is different from local editing.
Signing in does not automatically upload temporary files. An available “Import a copy to Library” action uploads the particular copy and destination you confirm, while leaving the temporary original in browser storage. A failed or interrupted transfer may need its server receipt checked; do not assume an error means no copy reached the Library.
Browser-local storage is tied to the profile and device and may be accessible to someone using them. It can disappear when site data is cleared, storage is evicted, private browsing ends or the device fails. Bosonoo cannot promise to recover it remotely. Export important work before clearing site data or changing profiles.
Accounts and access requests
When you create an identity or sign in, Clerk processes authentication and session information. Bosonoo can receive identity identifiers, email address, name or profile image where supplied, verification and account status, and session or security information needed to validate access. We use these to provide sign-in, associate your account correctly and protect the service.
Workspace approval is separate. Access requests, their status and the owner’s decisions are recorded so we can assess, grant, reconcile or revoke workspace access. Signing in or having a Store account does not automatically authorise a workspace.
Library content, activity and public sharing
When you upload or save content to the Library, Bosonoo and its hosting/storage services process the file contents and associated information. This can include file names, folder structure, size, type, previews, revisions, dependencies, save and transfer receipts, and recovery data. These records support editing, storage, search, conversions, recovery and access control.
We also process operational and security records such as account and request identifiers, timestamps, routes, device/browser information, errors, usage, reservations and billing records. Public search and discovery can process queries and engagement, such as views, opens or clicks. Where available, the My Data and personalization settings let you inspect or delete supported signals or pause new personalization collection. Pausing personalization does not disable records needed to provide, bill for or secure a service.
Saving a private Library file is not public publication. If you deliberately publish or share content through an available feature, the selected file, included assets, description, attribution or other publication metadata may become available to its audience, including public visitors and search engines where publication is public. Other people may retain copies; unpublishing cannot recall those copies.
Remote AI, tools and memory
If you use remote AI, the chosen service receives the information needed for the request. Depending on the feature, this can include your prompt, conversation history or summaries, selected attachments, images or other reference media, permitted file contents or excerpts, tool results and task instructions. Files can contain personal or confidential information even when you did not type it into the prompt.
Available model integrations can include OpenAI, Anthropic, Google, xAI, DeepSeek and Moonshot/Kimi. Audio integrations can include ElevenLabs or other separately enabled services. This is not a statement that all integrations are active. The provider used depends on the model or service made available and selected for your request.
An AI task may retrieve more information through its enabled tools and pass the resulting context to the model. Scope and permission checks limit tool access, but you should review the task and its capabilities before submitting confidential material. Do not submit passwords, API keys or sensitive personal information unnecessarily, or another person’s information without an appropriate basis.
Chat content, generated results, tool records, task checkpoints and usage or charge records can be stored by Bosonoo. When agent memory is enabled, AI may write notes into visible Library memory files associated with the chat’s folder; chats in that same folder can use that memory. You can inspect, edit or delete those files. Disabling memory does not by itself delete existing notes, conversation history or provider records.
Provider retention, logging, training practices and processing locations depend on the provider, product and account configuration. Bosonoo does not make a blanket promise that every provider has zero retention or never uses submitted information to improve models. Ask us about the applicable service before sending information that requires a particular contractual or residency restriction. Review AI output: it can contain inaccurate personal information or unintended disclosures.
Store and payments
The Store processes the customer, contact, order, cart and transaction information needed for shopping and order administration. Checkout and payment services may receive information required for the transaction under the notices shown there. An order or invoice may need to be retained independently of workspace access or sign-in status.
Where Bosonoo identity sign-in is enabled for the Store, the Store receives verified identity identifiers and permitted profile/email information and links them to a Store customer record. It is not intended to grant the Store access to your workspace files. Existing accounts are not automatically merged solely because an email address matches. Store sign-out and global identity sign-out are separate. A remaining shared sign-in session can sign you in again; check the sign-out instructions offered by the service.
Cookies and similar storage
Authentication, security, preferences, local recovery and Store cart/session functions can use cookies or similar browser storage. Clerk and the Store maintain their own relevant session state. Clearing or blocking storage can sign you out, affect checkout or remove local work. Sign-out alone should not be treated as clearing saved browser-local files.
Checkout, identity and Store pages can have their own cookies and similar technologies. Refer to the notices and controls on those surfaces. This policy does not promise that every third-party cookie is strictly necessary or that those services never use tracking technologies.
The Store has Google Analytics connected through Site Kit. Its current settings insert the Analytics snippet, enable conversion tracking and exclude logged-in WordPress users from that Analytics measurement. Google Analytics uses cookies and processes visitor identifiers, browser/device information and page interactions to report how the site is used. See Google’s explanation of Analytics data handling.
The Store also uses Jetpack Stats to measure visits and page views. Automattic processes visitor information for these statistics, which can include IP address, browser/device information, referring pages and activity on the site. Its services can use cookies and similar technologies. See Automattic’s privacy notice for visitors. The Google Analytics exclusion for logged-in users is not a promise that all Store services stop collecting information when you sign in.
Service providers and overseas processing
We use service providers to operate the relevant services, including Cloudflare for network delivery/security, Render for hosted services, Clerk for identity, and WordPress.com/Automattic for the Store. Selected AI services, payment services and communications providers can also receive information necessary for the functions you use. Providers may use subprocessors.
Information may be processed outside Australia; Bosonoo does not promise Australian-only storage or processing. The countries and arrangements depend on the selected provider and deployed service. Contact us if you need information about a particular service’s processing locations before using it. We may also disclose information where required or authorised by law, or as reasonably necessary to investigate abuse, protect rights or address a security incident.
Security and encryption
We use access controls and security measures appropriate to the services we operate, but no system is risk-free. Ordinary Library storage, hosted editing and remote AI require server-side access to relevant content; they are not a general end-to-end encrypted service.
Where supported, a Vault’s explicit “Encrypt contents” option is different from hiding a folder or protecting it with a PIN. It encrypts eligible contents in the browser; it does not cover all file types, all metadata or all pre-existing files. Do not assume a lock icon means every file is encrypted. Follow the feature’s limitations and keep the means needed to unlock or export your files. See our Security policy.
Retention, deletion and recovery
Different records have different lifecycles. Active files support your work; revisions, Trash, recovery copies and backups can outlast a change or deletion in the interface. Security, billing, orders and dispute records may need to be kept for their respective purposes or legal obligations. Disabling access, deleting an identity or signing out is not proof that every associated file, log, backup or provider record has been erased.
Library Trash or Empty Trash actions and available recovery tools affect the records they describe. Physical deletion may be staged, delayed or unavailable while integrity or recovery checks remain unresolved. There is no single guaranteed deletion deadline across all systems. Browser-local data is controlled separately by your browser. A completed AI result retained for recovery can remain pending until it is saved, exported and discarded, or otherwise removed through the applicable process; recovery is not available for every failure.
Contact us to request deletion or clarification of what remains. We will assess the request, verify identity where needed, explain relevant limits and identify records that must be retained. We do not treat a technical limitation as permission to retain personal information indefinitely without a valid purpose.
Your choices and complaints
You can choose whether to create an account, upload a local file, use remote AI or publish content. Withholding information can prevent the associated feature from working. Use available account, file and My Data controls to inspect, correct, export or remove supported information. These controls are not a complete export or deletion guarantee for every system.
For other access, correction or privacy requests, email admin@bosonoo.com with enough information to identify the issue. Do not send your password or unnecessary identity documents. We may ask for proportionate verification before releasing or changing information.
If you are dissatisfied with our response, you can ask us to review it and contact the Office of the Australian Information Commissioner or another relevant regulator about your available options. Any statutory access, correction and complaint rights apply according to the law; this policy does not remove them.
We will date material updates to this policy and update notices when processing materially changes.