Privacy Policy
Last updated: 21 September 2026
1. Who we are and how to reach us
Bordet (bordet.ai) is operated by Gensight.AI Limited, a company registered in England and Wales (company number 17110761) with its registered office at Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ. In this policy "Bordet", "we", "us" and "our" mean Gensight.AI Limited.
We are the data controller for the personal data described here. We are registered with the UK Information Commissioner's Office (ICO), registration reference ZC208381.
For any privacy question or to exercise your rights, email contact@bordet.ai. For legal notices, email legal@bordet.ai. We do not have a statutory Data Protection Officer; our founder is responsible for data protection.
2. What this policy covers
This policy applies to the bordet.ai website and application, the Bordet command-line tool, the Bordet connector for external AI tools (MCP), and the emails we send. It explains what personal data we process, why, who we share it with, how long we keep it, and what rights you have. It applies to visitors, people who try Bordet anonymously, account holders, people invited into a room, and people who connect their own AI tools.
3. The personal data we process
Account data. Your email address and either a hashed password or a Google sign-in identity (we receive your email address and Google account identifier only). If you start without an account, we hold a temporary anonymous identifier instead.
Profile data. The username and avatar options you choose, shown to other people in your rooms.
Room content. Everything that goes into a room: your messages, images you attach or generate, sources you add (links we fetch, files you upload such as PDF or Word documents, notes you type), deliverables the AI members produce (artifacts and workspace files), and the room's board (objective, status, open questions and decisions). From this content the service derives a shared memory for the room: short written facts and their numerical representations (embeddings), plus a versioned summary of the project state. Room content can contain personal data about you and about anyone you write about.
Collaboration data. Which rooms you belong to, your display name in each room, invitations you create or accept, and when you last viewed a room.
Connected AI seats. If you connect your own AI tool (for example claude.ai, ChatGPT or Claude Code), we store a hashed access token, the name and description you give the seat, its scopes and spend cap, and the messages it posts.
Bring-your-own-key and GitHub credentials. Provider API keys and GitHub tokens you supply are stored encrypted with a key held outside the database. They are never displayed back, logged or shared.
Billing and usage data. For paid use: a Stripe customer identifier, your credit balance and ledger, and per-turn usage records (model, tokens, cost). We do not receive or store card numbers.
Technical data. An authentication cookie to keep you signed in, a small number of browser-storage entries for your preferences, and a random first-party visitor identifier used for product statistics. Our hosting and database providers keep short-lived server logs that include IP addresses for security purposes. We do not build profiles from technical data, do not fingerprint devices, and do not use third-party advertising or analytics trackers.
Emails. If you own a room, we may send you a transactional "where your boardroom left off" email containing the room name, objective, recent decisions and open questions.
4. Where the data comes from
Most of it comes from you. Some comes from other people: someone who invites you provides your email or a link, and other participants may mention you in a room. Google provides your email address and account identifier when you sign in with Google. The rest is generated by the service itself (usage records, memory facts, the project board).
5. Why we process it and our lawful bases
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Creating your account, running your rooms, generating AI responses, keeping shared memory and the board in sync, delivering emails about your rooms | Performance of a contract with you |
| Letting the people you invite collaborate with you, and letting connected AI seats take part | Performance of a contract; legitimate interests of the room's participants in collaborating |
| Metering usage, applying spend caps, preventing abuse, securing the platform, investigating errors | Legitimate interests (running a safe, reliable, affordable service); legal obligation where fraud or crime is involved |
| Billing and keeping financial records | Performance of a contract; legal obligation (tax and accounting law) |
| First-party product statistics (which pages and features are used) | Legitimate interests (understanding and improving the product). We do not use third-party trackers and you can object at any time |
| Communicating with you about the service, its terms and security | Performance of a contract; legitimate interests |
| Marketing emails | Consent. We do not currently send any |
Sensitive ("special category") data. We never ask for health, sexuality, religious, political, biometric, ethnic or similar data, or data about criminal offences. Because a room is a free-text space, you may choose to include such information. If you do, we process it only to provide the service you asked for, on the basis of your explicit consent given by submitting it, and you can delete it at any time. Please think before putting sensitive information about yourself or other people into a room, because it will be sent to the AI model providers described below.
6. How room content is processed by AI model providers (please read)
Bordet works by sending room content to third-party AI models to generate responses. In plain terms:
- What is sent. For each AI turn we send the relevant messages and recent conversation, the names of the humans in the room, the room's board, relevant memory facts and source passages, attached images, and, when you ask for it, the artifact being revised. We do not send your email address, account identifier, IP address or billing data to any model provider.
- Managed mode. Requests go through our model gateway, OpenRouter (United States), which routes them to the model provider for the member you chose: OpenAI, Anthropic, Google or xAI. Our OpenRouter account is configured so that prompts and completions are not logged for training and are not routed to providers that would train on them. Providers may keep inputs and outputs for a short period to detect abuse (OpenAI, for example, states up to 30 days).
- Bring your own key. If you supply your own provider key, the same content goes directly to that provider under your account and their terms.
- Memory. To keep a room's shared memory searchable we send extracted facts (short sentences derived from room content) to OpenAI to compute embeddings. OpenAI does not use API data to train its models.
- Web search and images. If a turn uses live web search, a search query derived from your message is sent through OpenRouter to its search partner. If a turn generates an image, the prompt is sent to an image model at the same providers.
- Connected AI seats. If you or another participant connects a personal AI tool (claude.ai, ChatGPT, Claude Code, Cursor and similar), that tool reads the room content it is allowed to see and posts back. Content read this way is processed by that tool's provider under that provider's terms and privacy policy, not ours, and under the account of the person who connected it.
- We do not train models on your content, and we do not allow our providers to do so.
7. Who we share personal data with
We share personal data only with the service providers below (our "sub-processors"), with the people you share rooms with, and where the law requires it. We do not sell personal data and we do not share it with advertisers.
| Provider | What they do for us | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account, profile, room and billing records; uploaded files | Frankfurt, Germany (EU) |
| Vercel | Application hosting and delivery | All data in transit; short-lived request logs | Functions in Frankfurt, Germany; global edge network including the US |
| OpenRouter | AI model gateway (managed mode) | Room content sent for AI turns, web search queries | United States |
| OpenAI, Anthropic, Google, xAI | AI model inference (via OpenRouter, or directly with your own key) | Room content sent for AI turns | United States |
| OpenAI | Embeddings for room memory | Extracted memory facts | United States |
| Stripe | Payment processing | Email address, payment details you enter on Stripe's pages, transaction records | United States and EU. Stripe is an independent controller for its own regulatory purposes |
| Resend | Sending transactional email | Your email address and the email content | United States |
| Sign in with Google (only if you use it) | Email address, Google account identifier | United States. Google is an independent controller for the sign-in itself | |
| GitHub | Repository connection (only if you connect one) | Encrypted access token, file changes you approve | United States |
We have data processing terms in place with each processor. We will update this table when it changes.
People in your rooms. Bordet is a collaboration product. Everyone in a room can see the messages, names, images, sources, artifacts and board shared in that room. Anyone with a room's invite link can join until the link is revoked, so share links only with people you intend to admit. Guests who join without an account can read and write in that room only.
Legal requirements and business changes. We may disclose data where the law requires it, to protect our rights or the safety of others, and to a successor if our business is sold or reorganised, in which case this policy continues to apply.
8. International transfers
Our database and file storage are in Germany and our application runs in Germany. The UK government has found the EU to provide adequate protection, so those transfers need no further safeguard. Model providers, OpenRouter, Stripe, Resend and GitHub process data in the United States. For those transfers we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, as set out in each provider's data processing terms. You can ask us for details of the safeguard used for any provider.
9. How long we keep data
| Data | Retention |
|---|---|
| Account, profile, credentials | Until you delete your account |
| Rooms you own, including messages, sources, artifacts, files, memory and board | Until you delete the room or your account |
| Your messages in rooms owned by other people | Kept as part of that room's record, but your identity is detached when you delete your account |
| Anonymous (no account) sessions and their rooms | Deleted after 30 days of inactivity |
| Connected AI seat tokens | Until you revoke them or delete the room |
| Usage and credit records | Retained while your account exists, and financial records for six years after the transaction as required by UK tax law |
| First-party product statistics | 24 months, after which they are deleted |
| Transactional email records | Kept by our email provider for a short period for delivery diagnostics |
| Database backups | Rolling short-term backups that are overwritten automatically |
Copies held by model providers for abuse monitoring are deleted on their timetable (typically within 30 days). Where we must keep something for legal reasons after you delete your account, we keep only that and nothing else.
10. Security
We protect data with encryption in transit (TLS) and at rest, application-level encryption for provider keys and GitHub tokens, row-level access rules in the database so that each person can only reach the rooms they belong to, server-only handling of all secrets, private file storage served through short-lived signed links, hashed access tokens for connected tools, spend caps and rate limits, and least-privilege administrative access. No system is perfectly secure. If a breach is likely to put people at risk we will notify the ICO within 72 hours and inform affected users without undue delay.
11. Your rights
Under the UK GDPR (and the EU GDPR if you are in the EEA) you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete your data ("right to erasure");
- restrict or object to processing based on legitimate interests, including our product statistics;
- port your data to another service in a machine-readable format;
- withdraw consent at any time where consent is the basis;
- not be subject to automated decisions with legal or similarly significant effects. We do not make such decisions; AI members reply in a chat, they do not decide anything about you.
You can do most of this yourself. Profile → Delete my account permanently deletes your account, every room you own and everything in them, and detaches your identity from messages in other people's rooms. Workspace → Export room downloads a room as Markdown. For anything else, or if you are not an account holder (for example, you were mentioned in someone's room), email contact@bordet.ai. We respond within one month, and may ask you to verify your identity first. There is no charge unless a request is clearly unfounded or excessive.
If you are unhappy with how we handle your data you can complain to the ICO at ico.org.uk or on 0303 123 1113. If you are in the EEA you can complain to your local supervisory authority. We would appreciate the chance to resolve it first.
12. Cookies and browser storage
We set one strictly necessary cookie to keep you signed in. We use browser local storage for a few preferences (for example which panels you collapsed, when you last viewed a room) and a random visitor identifier used only for our own first-party statistics, which is never shared with anyone. We do not use third-party cookies, advertising cookies or cross-site tracking. Clearing your browser's site data for bordet.ai removes all of these. To object to the statistics identifier, email us and we will delete the events linked to it.
13. Children
Bordet is a work tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We will update this policy as the product evolves, change the date at the top, and for material changes tell account holders by email or with a notice in the app before the change takes effect.
15. Contact
Privacy questions and rights requests: contact@bordet.ai. Legal notices: legal@bordet.ai. Post: Gensight.AI Limited, Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ.