Privacy Policy

Version 2026-08-24 (closed beta)

1. Who we are and what this covers

BuroWise is a bureaucracy assistant that helps you draft consumer complaint correspondence. This policy explains what information we collect, why, how it is handled, and what rights you have over it.

2. What we collect

We do not ask for or store information beyond what is needed to provide and protect the service.

3. How we use it

We do not use your case information to contact any third party on your behalf. We do not verify or investigate the facts you provide.

4. Lawful basis for processing (EU/UK users)

The per-case acknowledgement shown before you enter case information is a product safeguard and an audit record of what BuroWise explained to you. It does not, by itself, replace the lawful basis or transparency requirements that apply to each processing activity.

5. Audit record of accepted drafts

When you accept a draft, we retain a non-personal activity record of that acceptance. The audit record stores only the action type, timestamp, and a version hash of the tool's instructions at the time of generation. It contains no case text, correspondence, document content, or any other personal information.

The purpose of this record is to ensure BuroWise can account for which version of its instructions produced an accepted draft if that is ever in question. The lawful basis is legitimate interests.

This record may be retained after a general deletion request under Article 17(3)(e) of the GDPR/UK GDPR, which permits retention where necessary "for the establishment, exercise or defence of legal claims." If we rely on this exception in response to a deletion request, we will tell you clearly.

Audit records are retained for 3 years from the date of acceptance. This is the operating default for closed beta; it will be confirmed or replaced before public launch.

6. Third-party data processors

OpenAI: When you use AI features, case text and uploaded files are sent to OpenAI's API for processing. OpenAI does not train on API data submitted through the API by default. Data is transferred to the United States under Standard Contractual Clauses (SCCs) as the transfer mechanism under GDPR Chapter V. OpenAI acts as a processor under its API terms. Formal DPA documentation is a public-launch item.

Supabase: Case data, documents, and account information are stored in Supabase, hosted in the EU (Frankfurt, Germany). Supabase acts as a data processor. Data residency remains within the EEA. Supabase is used under its standard terms. Formal DPA documentation is a public-launch item.

Resend: If you set reminders, BuroWise sends notification emails to your address via Resend. No case content or documents are sent — only the reminder title and date. Resend processes this data as a sub-processor.

We do not sell your information. We do not share it with businesses you are in dispute with, or with other third parties, except as described here or as required by law.

7. Data retention

8. Your rights

If you are located in the EU or UK, you have rights under the GDPR/UK GDPR, including the right to: access your data, correct inaccurate data, request deletion, restrict processing, and object to processing based on legitimate interests.

Deletion requests: You can delete individual cases in the app. To delete your account, email support@theboat.dev from the address on the account. We will delete case data, documents, and the account. The hash-only audit record of accepted drafts may be retained under Article 17(3)(e); we will tell you if we rely on this.

To exercise any other right, use the same address.

9. Data location

Case data and documents are stored in Supabase's EU (Frankfurt) region. AI processing uses OpenAI's US-based API under Standard Contractual Clauses.

10. Security

Document storage uses private access controls; files are accessible only to the authenticated account holder. No method of storage or transmission is completely secure.

11. Changes to this policy

We may update this policy. Material changes will be presented to you at next sign-in. Continued use after accepting an updated policy means you accept it.

12. Contact

Privacy questions and rights requests: support@theboat.dev.

Closed beta. Retention periods and processor documentation above are operating defaults; they will be confirmed before a public launch. See Terms of Service.