Privacy Policy
Last updated: September 1, 2026
1. Introduction
BOB AI Holdings Corp (“we”, “us”, or “our”) operates BOB, an AI-powered financial operations platform for small businesses — an assistant that helps you track spending, manage invoices, and move money with your approval. BOB is a financial technology company and is not a bank. Bank deposit services provided by Erebor Bank NA, Member FDIC. This Privacy Policy describes how we collect, use, and protect your information when you use our Service. The Service is available on the web and as an iOS app. This policy covers both.
2. Information We Collect
2.1 Information You Provide
- Account information: email address, name (for KYC-verified operators)
- Identity and business verification: information submitted through our verification, banking, or payments providers for operators who opt into account setup or regulated money movement
- Workspace configuration: business names, handles, team members, and profile settings
- Finance workflow data: invoices, counterparties, approval requests, payment proposals, limits, policies, and audit records you create or import
2.2 Information Collected Automatically
- Payment and provider records: provider resource identifiers, account-readiness states, transaction metadata, amounts, timestamps, and reconciliation status
- Usage data: API request logs, IP addresses, and browser information for security and rate limiting
- Site analytics: on public marketing and sign-in pages, anonymous page views and page departures, the page and referring page, campaign parameters, coarse browser or device information, and limited waitlist-funnel steps. On the public
joinbob.ailanding page, PostHog also records interactions such as clicks and scrolling, the page layout and public page copy, and sanitized browser error diagnostics. The waitlist modal is blocked from replay and all form inputs are masked; those recordings and error diagnostics do not include network headers, request or response bodies, console logs, replay URL query strings, or dynamic error messages. When you successfully submit the public waitlist form, PostHog also receives the submitted first name, email address, selected business category, employee range, and revenue range so it can trigger a useful internal signup notification - Advertising and attribution data: on public marketing pages, Meta Pixel receives page-view and waitlist-conversion events, page URLs, IP address, browser or device information, and Meta cookie or ad-click identifiers. When you submit the waitlist form, Meta Conversions API also receives the conversion event, landing-page URL, browser user agent, IP address, Meta cookie or ad-click identifiers, a hashed internal lead identifier, and a normalized, SHA-256-hashed email address and phone number (when provided) to measure campaigns and avoid counting the same conversion twice
- Reliability analytics: for an internal BOB-staff pilot on authenticated pages, canonical internal operator and workspace identifiers, a coarse product area, release and environment information, bounded web performance measurements, and sanitized error diagnostics
Production session replay is limited to the public joinbob.ai landing page under the masking and collection limits described above; authenticated product pages are not recorded in production. Except for the first name, email address, and bounded business category, employee range, and revenue range on a successful public waitlist submission described above, we do not send PostHog names, email addresses, detailed business or financial records, conversation or other form contents, raw authenticated URLs, or other free-form customer content through these analytics paths.
2.3 Information From Third Parties
- Verification and banking providers: application status, account status, provider resource identifiers, and transaction or webhook events needed to operate account and payment workflows
3. How We Use Your Information
- Operate your financial workflows, including accounts, invoices, approvals, spending policies, and audit trails
- Initiate, track, and reconcile provider-backed payment or account actions you approve through the Service
- Verify your business identity (KYC/KYB) through our banking provider
- Authenticate your identity and protect account security
- Enforce rate limits and prevent abuse
- Measure use of our public site and diagnose the performance and reliability of the Service
- Manage public waitlist submissions and notify our internal team when someone joins
- Communicate service updates and security notices
- Improve the Service and develop new features
Where applicable, we rely on our legitimate interests to operate, secure, measure, and improve the Service for the limited analytics described in this policy. For PostHog analytics, safeguards include data minimization, discarded client IP data, memory-only public analytics, supported browser Do Not Track signals, and masked replay limited to the public landing page. Separately, Meta advertising attribution is limited to public marketing pages and waitlist conversions and uses the data described above.
4. Data We Do NOT Collect
We do not collect or store:
- Bank login passwords or raw card credentials
- Identity documents unless a provider returns a record we are legally required to retain
- The contents of your conversations with BOB beyond what is needed to provide the Service
5. Data Sharing
We do not sell personal information for money. We disclose data only as described in this policy. Some privacy laws may define the Meta advertising attribution described below as “sharing” or “targeted advertising.” Where applicable, you may opt out of that use by contacting contact@joinbob.ai.
We may disclose data to:
- Verification, banking, and payments providers: identity, business, account, counterparty, transaction, and webhook data needed to provide approved account or payment workflows
- Infrastructure providers (AWS, Vercel, Cloudflare): hosting, data storage, content delivery, security, and network diagnostics. These providers may process ordinary request metadata such as IP address, browser information, requested URL, and timing data
- Analytics and reliability provider (PostHog): PostHog processes the limited site-usage and reliability data described above for us as a service provider in its US Cloud environment
- Advertising and attribution provider (Meta): Meta receives the limited public-site and waitlist conversion data described above through Meta Pixel and Conversions API to measure advertising performance and deduplicate browser and server conversion events. Meta handles that data under its applicable business terms and privacy policy
- Font delivery provider (Google Fonts): public web pages request font files from Google, which receives ordinary request metadata such as IP address, browser information, the requested font resource, and request time
- AI assistant connectors: when you connect BOB to a third-party AI assistant (Claude.ai, ChatGPT, etc.) via our Model Context Protocol (MCP) server, that assistant's provider receives the data you ask the assistant to act on — see Section 10 below
- Law enforcement: if required by law, court order, or legal process
6. Data Retention
We retain account data for as long as your account remains active and as needed to provide the Service, enforce our terms, and comply with legal obligations. We may retain limited records (including security and fraud-prevention logs) after deletion requests where required by law or legitimate security interests.
Unless deleted earlier, the current PostHog project configuration permits analytics and reliability data to be retained for up to 84 months. We periodically review that period and delete or aggregate data earlier when it is no longer needed to measure product performance, investigate reliability, or meet legal obligations.
You may request deletion of your account and associated data by contacting us at contact@joinbob.ai.
7. Data Security
We use commercially reasonable administrative, technical, and organizational safeguards to protect data, including encryption in transit (TLS) and at rest, API key authentication with per-key rate limiting, and HMAC-verified webhook signatures.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected users as required by applicable law.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export your personal data, and to opt out of sale, sharing, or targeted advertising.
To submit a request, contact contact@joinbob.ai. We will verify your request and respond within the timeframe required by applicable law.
9. Cookies and Tracking
We use essential session cookies for authentication. We use PostHog as our analytics and reliability service provider. On public marketing and sign-in pages, PostHog runs without analytics cookies or local/session storage, does not create person profiles, and honors supported browser Do Not Track signals. PostHog does not track visitors across unrelated websites on our behalf. The internal authenticated pilot uses session-scoped browser storage and is limited to BOB staff accounts. Production session replay is used only on the public joinbob.ai landing page and applies the masking and collection limits described in Section 2.2; authenticated product pages remain excluded.
Public marketing pages use Meta Pixel and Meta Conversions API for advertising attribution. Meta Pixel may set or read the _fbp browser identifier and the _fbc ad-click identifier, and the waitlist form passes those identifiers to our server so the corresponding browser and server conversion events can be deduplicated. Meta may process this information under its own privacy policy.
10. AI Assistant Connectors
BOB offers an opt-in Model Context Protocol (MCP) connector that lets third-party AI assistants (such as Claude.ai or ChatGPT) read and act on your BOB data on your behalf. You install the connector by signing in with OAuth from inside the assistant — the assistant receives a scoped access token from us, and uses it to call a defined set of tools (for example, listing invoices, drafting an invoice, or sending one).
What the AI assistant's provider receives:
- The prompts you write inside the assistant (these reach the assistant's provider, not us)
- The arguments the assistant chooses to pass to each tool — typically derived from your prompts (e.g. a recipient name, an email address, a dollar amount, an invoice ID)
- The responses our server returns to each tool call — invoice details, line items, payment status, customer names and amounts, and similar structured records
What we receive: the tool name, the tool arguments, the response we returned, and the access token's scoped identity. We do not receive the raw prompts you write inside the AI assistant — only the structured tool calls the assistant makes on your behalf.
What we store as audit records: the tool name, the access token's scoped identity, the status of the call (ok / error / denied), an error message when relevant, the latency in milliseconds, a request identifier, and a SHA-256 hash of the tool arguments. We retain a hash rather than the raw arguments so that repeat calls with the same inputs can be grouped during security review without us persisting customer-identifying fields like email addresses or invoice amounts. Tool responses we returned to the assistant are not stored. Audit data is retained per Section 6.
Provider privacy policies apply. Each AI assistant provider has its own privacy policy governing what they collect, how they use your prompts (including potentially for model training), and how long they retain conversation history. Review your assistant's privacy policy before connecting — for example, Anthropic's Privacy Policy covers Claude.ai usage.
Scope and revocation. Each connector token is scoped to a specific set of capabilities (for example, invoices:read or invoices:write), shown on the consent screen at install time. To revoke a connector, disconnect it from inside the AI assistant's connector settings; most AI assistant clients will, in addition, call our standard RFC 7009 revocation endpoint to invalidate the token on our side, but we cannot guarantee third-party client behavior. For a guaranteed server-side revocation — for example, if you have lost access to the AI assistant account or want to be certain the token cannot be used — email contact@joinbob.ai and we will revoke it directly. Access tokens also expire automatically after one hour; if the assistant did not refresh the token via offline_access, it will lose access at that point regardless.
Money-moving actions. Tools that send invoices, void invoices, or mark invoices paid are flagged to the assistant as destructive operations; the assistant is expected to (and Claude.ai does) present a confirmation prompt before executing them.
11. Mobile App
Push notifications. If you enable notifications, we store a device push token so we can alert you to approval requests, held payments, and other account activity. Notifications are delivered through Apple and Expo. You can turn them off in iOS Settings.
Face ID and passkeys. You can sign in with a passkey protected by Face ID or Touch ID. Your biometric data stays on your device. We only receive confirmation that your device approved the sign-in.
Camera. The camera is used only to scan the pairing code when you link your phone. Nothing is recorded or stored.
12. Children
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date and, where required by law, provide additional notice. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
14. Contact
For privacy-related questions or requests, contact us at contact@joinbob.ai.