Privacy Policy

Last updated: 4 June 2026

Draft pending legal review. This policy is a working draft prepared to describe how the product handles data; it should be reviewed by qualified counsel before public launch.

1. Who we are

Bordet ("Bordet", "we", "us") operates the Bordet platform at bordet.ai, an AI collaboration platform where multiple large language models (LLMs) and human teammates work together in shared rooms ("boardrooms"). This policy explains what personal data we process and why.

For privacy questions or to exercise your rights, contact us at privacy@bordet.ai.

2. The data we collect

Account data. When you create an account we store your email address and an encrypted (hashed) password. You can also start anonymously, in which case we hold only a temporary anonymous identifier until you sign up.

Profile data. A display name (username) and avatar preference you choose, shown to others in your rooms.

Content you provide. The messages you write, files you create in a room's workspace, and images you upload or paste. This is the core content you choose to share with your AI team and any human collaborators you invite.

Collaboration data. Room membership, invitations you create, and the display names of people in your rooms.

Usage and metering data. Records of AI turns and token/cost usage, used to show your usage and to meter and bill managed usage.

Provider credentials (if you use "bring your own key"). API keys you supply are stored encrypted and are never displayed back to you or logged. Connected GitHub tokens are likewise stored encrypted.

Technical data. Standard request metadata (e.g., IP address, browser type) and an essential authentication cookie/token to keep you signed in. We do not currently run third-party advertising or analytics trackers; if we add product analytics we will update this policy and, where required, ask for consent.

3. How we use your data

  • To provide the service: run your boardrooms, generate AI responses, and keep shared memory in sync.
  • To enable collaboration with people you invite.
  • To meter usage, prevent abuse, enforce spend limits, and bill (for paid/managed usage).
  • To secure the platform and debug issues.
  • To communicate with you about the service.

We rely on the legal bases of performance of a contract (providing the service you request), legitimate interests (security, abuse prevention, product improvement), and consent where required (e.g., optional analytics).

4. How your content is processed by AI providers (important)

To generate responses, Bordet sends the relevant content of a turn, your messages, recent conversation context, and any attached images, to the AI model providers you choose to use in a room. In managed mode this is routed through our model gateway (OpenRouter) to the underlying model providers (which may include OpenAI, Anthropic, Google, and xAI). In "bring your own key" mode, content goes directly to the provider whose key you supplied.

These providers process your content as our (or your) sub-processors solely to produce responses. We configure no-training / limited-retention options with our gateway and providers where available; their handling of data is also governed by their own terms and privacy policies. Please do not paste content you are not permitted to share with third-party AI providers.

5. Service providers / sub-processors

We use the following processors to run Bordet:

  • Supabase, database, authentication, and file storage.
  • Vercel, application hosting and delivery.
  • OpenRouter, AI model gateway (managed mode).
  • AI model providers, OpenAI, Anthropic, Google, xAI (via the gateway, or directly in BYOK mode).
  • Stripe, payment processing (when paid plans are enabled).

We will keep an up-to-date sub-processor list and update it as this changes.

6. Storage, security & retention

We protect data with measures including encryption of sensitive secrets (provider API keys and GitHub tokens) at rest. Uploaded images are stored in a private store and served only to room participants via short-lived signed links.

We retain your data for as long as your account and rooms exist, and as needed to provide the service and meet legal obligations. Deleting a room deletes its associated content. You can request deletion of your account and associated personal data (see "Your rights").

7. Sharing within rooms

Bordet is a collaboration product: people you invite to a room can see the messages, names, and images shared in that room, and the shared decisions log. Anyone with a room's invite link can join that room until the link is revoked. Only share rooms and links with people you intend to give access.

8. Your rights

Depending on your location (e.g., the EEA/UK under GDPR, or California under CCPA/CPRA), you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. To exercise any of these, contact privacy@bordet.ai. You also have the right to lodge a complaint with your local data protection authority.

We do not sell your personal data.

9. International transfers

We and our providers may process data in countries outside your own, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers.

10. Children

Bordet is not directed to children and is not intended for use by anyone under the age required by their local law (e.g., 16 in parts of the EEA, 13 in the US). We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy as the product evolves. We will revise the "last updated" date and, for material changes, provide a more prominent notice.

12. Contact

Questions, requests, or complaints: privacy@bordet.ai.