BumbleB Privacy Policy
What this policy covers. This policy explains how BumbleB handles personal data where we decide how and why it’s used — as a “controller” or, in India, a “Data Fiduciary”. That means your Account Data, information from our own website, the creation of Usage Data, and your own personal data in an individual account (one you hold yourself, not through a company). In an individual account, Visitor Data and any data you upload about other people are yours to control: we process them for you under our Data Processing Agreement, as we do for a company.
What it doesn’t cover. When a company uses BumbleB, we process its Customer Content — including Visitor Data about people who visit its website — on that company’s behalf and only on its instructions. That processing is governed by our Data Processing Agreement with the company and by the company’s own privacy notice. If you visited a website that uses BumbleB, or you use BumbleB through your employer, please contact that company about your data. We’ll help them answer you.
Previous versions of this policy, with a short change log, are available at https://bumbleb.co/legal/archive.
Who we are
In short: BumbleB Technologies Pvt Ltd, an Indian company, runs BumbleB and is responsible for the data this policy covers.
BumbleB is an analytics service. You connect your data or add our tracking tag to your website, ask questions in plain language, and BumbleB answers with explanations, charts and tables (the “Service”). “We”, “us” and “BumbleB” mean BumbleB Technologies Pvt Ltd, registered office 581, Second Floor, 1st Main Rd, Sector 6, HSR Layout, Bengaluru, Karnataka 560102, India. “You” means the person reading this — an account holder, a user, or a visitor to our website.
The three kinds of data
In short: your content, your account, and our record of how the Service ran are kept apart and treated differently.
We sort everything we handle into three kinds, and we never mix them.
- Customer Content means Inputs, Outputs and Visitor Data. Inputs are what you or your users type, upload or connect. Outputs are what the Service writes back: answers, charts, tables and generated queries. Visitor Data is what our tracking tag collects about your website visitors.
- Account Data is who you are and how you use your account.
- Usage Data is our identity-free record of how the Service ran.
| Customer Content | Account Data | Usage Data | |
|---|---|---|---|
| What it is | Your questions, files and connected data; what our tag collects from your website visitors; and every answer, chart and table we produce for you. | Names, work emails, organisation, logins, seats, plan, invoices and payment records, feature-level activity counts, support tickets and notes from calls with us. | Which tools the Service called, in what order, the types of arguments (never the values), the kind of question, errors, retries, timing, and whether the answer was accepted — with no names, account identifiers or data values. |
| Who controls it | You | Us | Us |
| What we use it for | Answering your questions; keeping the Service secure; support you ask for | Running and billing your account; security; customer success; telling you about your account and the product | Operating, securing, measuring and improving the Service |
| Contains personal data? | Often | Yes | No. We create it from your sessions as they run, and that step uses personal data. The record we keep is designed so it can’t identify anyone |
Two more defined terms. A Submitted Conversation is a conversation a user chooses to send us, by pressing “Report a bug”. Before it is sent, you see how we will use it. Feedback means suggestions and ideas about the product, which you send us however you like. They’re different: Feedback is about BumbleB; a Submitted Conversation contains Customer Content and has its own rules, set out below.
Our three promises
In short: we don’t train on your content, we learn only from an identity-free record of how the Service ran, and our staff don’t read your content to improve the product.
No training. BumbleB will not use Customer Content to train, retrain or fine-tune any AI model, and will not allow any sub-processor to do so. The only exception is a Submitted Conversation, which a user chooses to send us.
Usage Data. BumbleB records how the Service runs — which tools were called, in what order, and whether they worked — without names, account identifiers or the values in your data. We use Usage Data only to operate, secure, measure and improve the Service.
No human reading. BumbleB staff do not read Customer Content to improve the Service. Staff read it only to provide support you ask for, to investigate security or abuse, or when you send us a conversation.
These apply to every customer: individuals and companies, on every plan, in every country. The same words appear in our Terms of Service, our Data Processing Agreement and our How we use your data page.
What we collect and why
In short: each purpose is listed separately below, with the data it uses and the legal basis we rely on.
What we collect.
- From you: your name, work email, organisation, role, password or single sign-on details, billing details, support requests, Feedback, and anything you tell us on calls.
- Automatically, when you use the Service: login records, IP address and device information, feature-level activity counts (for example, how many questions an account ran this month), and Usage Data.
- From your organisation: if your employer adds you to its workspace, it gives us your name and email.
- On our website: anything you submit in a form. Only if you choose “Accept all” in our cookie banner, our own analytics also records the pages you view, your clicks and scrolling, your device and browser, and a random identifier stored in your browser. We use no third-party advertising or analytics tags. If you choose “Necessary only”, or your browser sends a Global Privacy Control signal, we record none of this. You can change your choice at any time from “Cookie settings” at the foot of each page.
- In an individual account: your Customer Content, which we process as described in this policy.
Why we use it. The legal basis column applies to the “Everywhere else” baseline. India has its own rules — see the India section below.
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver the Service — answer your questions, run your workspace, show your history | Customer Content (individual accounts); Account Data | Contract |
| Billing — meter usage, invoice, collect payment, keep tax records | Account Data (plan, usage counts, invoices, payment records) | Contract; legal obligation |
| Security and abuse prevention — detect misuse, investigate incidents, keep access logs | Account Data; access and security logs; Customer Content when investigating a specific incident | Legitimate interests (keeping the Service and its users safe); legal obligation |
| Support — fix a problem you report | The Account Data and Customer Content involved in your request, read in place | Contract; your request |
| Improve the Service using Usage Data — find which tool sequences fail and fix them, tune our own service components | Usage Data, created from each session as it runs | Company accounts: on our customer’s instruction, under the DPA. Individual accounts: legitimate interests (a working, improving Service), with your right to object; in India, consent by ticking a box that starts unticked |
| Automated re-check of recent sessions — machines re-scan sessions less than 90 days old to add a new label or verdict; output is labels only and no person reads the sessions | Customer Content from the last 90 days (excluding Visitor Data) | Company accounts: on our customer’s instruction, under the DPA. Individual accounts: legitimate interests, with your right to object; in India, consent by ticking a box that starts unticked |
| Submitted Conversations — our team reads the conversation you send and uses it to improve BumbleB, including to train our models | That one conversation, with Visitor Data hidden first | Consent — you choose to send it, and can withdraw it |
| Customer success and account communications — onboarding help, renewal, notices about your account, invoices, security and changes to our sub-processors | Account Data, including feature-level activity counts — never what you asked or what the answers said | Contract; legitimate interests (looking after the account) |
| Marketing — news about features, events and offers | Name, email, organisation, your marketing preferences | Consent where the law requires it, otherwise legitimate interests with an opt-out. Every marketing email has an unsubscribe link |
What we never do. We don’t build profiles of individual people. We don’t use Visitor Data to improve BumbleB. We don’t make automated decisions about you that have legal or similarly significant effects. Our sales and customer-success team sees which features an account uses and how often — never what you asked or what the answers said.
How we learn whether BumbleB got it right
In short: machines check our work and keep only labels; a person reads real content for improvement only when you send it to us.
BumbleB answers by calling a series of tools — filter the data, compare two periods, draw a chart. To tell whether it chose well, without anyone reading your conversations:
- Live labelling. While answering, a classifier gives the question a type, such as “period comparison”. We keep the type, not your words.
- Automatic signals. Did a tool fail? Did BumbleB retry? Did you rephrase, or accept the answer?
- Automated checking. A separate model compares your question with the steps BumbleB took and records a verdict from a fixed list, such as “right tool, wrong time period”. It stores the verdict only.
- Re-checking recent sessions. For up to 90 days, automated tools may re-check recent sessions for a new kind of problem. They output labels only. No person reads the sessions. Individual users in India are asked first.
- Submitted Conversations. If you send us a conversation, our team may read it and use it to improve BumbleB, including to train our models. Visitor Data is hidden before anyone reads it. You can withdraw it at any time: we delete it and stop using it, but we can’t undo training that has already finished. If your company’s admin has turned this off for your workspace, you won’t see the option.
When you delete your account, we delete your Customer Content and your personal data on the schedule below. We keep Usage Data, because it identifies no one and can’t be traced back to you. We’d rather tell you that now than have you find out later.
How we use AI providers
In short: OpenAI generates answers for us, directly or through OpenRouter; they may not train on your data.
To answer a question, we send the relevant Inputs to a large language model provider — currently OpenAI, directly or through OpenRouter, which routes a request to the model provider that serves it — for inference only: they generate a response and send it back. From 8 November 2026 at the earliest, we may also send text to OpenAI to create embeddings that power search. Our contracts with them prohibit training any model on your data or using it for their own purposes, other than limited abuse monitoring, as described below and on our sub-processor list. OpenAI may keep prompts for up to 30 days to monitor for abuse, under its own terms. Requests through OpenRouter use zero retention: the provider that serves them doesn’t store them, apart from brief retention the law may require. Our sub-processor list shows each provider’s retention terms and zero-retention status.
Who we share data with
In short: only companies that help us run BumbleB, and otherwise only where the law requires it or in a business sale.
- Sub-processors and service providers — hosting, email delivery, AI providers and payments — who process data only on our instructions, under written data-protection contracts. Our sub-processor list names every vendor that processes Customer Content, and the vendors, such as payment and email providers, that handle Account Data only. We give 30 days’ notice before adding one to the list.
- Your organisation. If you use BumbleB through a company workspace, its administrators can see your account details and the content in that workspace.
- Legal requests. We disclose data when the law requires it — for example, a valid court order — and only what is required. Where we’re allowed to, we tell you first.
- Business transfers. If BumbleB is merged, acquired or sells its assets, data may pass to the new owner, who must honour this policy. We’ll tell you before that happens.
- Professional advisers, such as lawyers and auditors, under a duty of confidentiality.
- Anyone else, only with your consent.
We never sell your personal data, and we don’t share it for targeted advertising.
International transfers
In short: we host in the United States; some processing, such as email delivery, happens elsewhere, under contracts that protect it.
We host the Service on Microsoft Azure in the United States (East US), with our databases on MongoDB Atlas in Azure East US 2 (Virginia), and send transactional email through Amazon Web Services (SES) in Mumbai, India. Our AI providers process Inputs in the United States. Wherever data goes, the same contractual protections apply. Where data about people in the European Economic Area, the United Kingdom or Switzerland is transferred, we use the European Commission’s Standard Contractual Clauses and the UK Addendum. Details of each sub-processor’s location are on our sub-processor list.
How long we keep data
In short: concrete numbers, deleted automatically. We keep data longer only when the law requires it.
| Data | How long |
|---|---|
| Your conversations — questions and answers | 90 days, then deleted; backup copies within a further 90 days |
| Records of who accessed what (access and security logs — no content) | 12 months |
| Submitted Conversations | 12 months, or until you withdraw them |
| Visitor Data, uploaded files and connected data in an individual account | While your account is open, or until you delete them |
| Account Data | While your account is open, then as long as the law requires |
| Usage Data | As long as it’s useful. It identifies no one, so it isn’t deleted with your account. |
| Prompts held by our AI providers | OpenAI: up to 30 days for abuse monitoring under its terms. Through OpenRouter: served only by OpenAI, with zero data retention required on every request |
We keep data longer only when the law requires it, for example during a legal dispute. When a company account ends, we offer the company an export and then delete its Customer Content as set out in our Data Processing Agreement.
How we protect data
In short: encryption, tight access controls, logged staff access and fast breach notice.
We encrypt data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent). Access is role-based and limited to the people who need it. Staff can open a conversation only for support you asked for or to investigate security or abuse; that access is tied to a ticket or incident, read in place, never copied into our improvement work, and recorded in an access log we keep for 12 months. We also test for vulnerabilities, train our staff and review our sub-processors’ security.
No system is perfectly secure. If a breach affects your personal data, we’ll tell you without undue delay, and tell regulators where the law requires. We notify affected business customers within 24 hours of becoming aware.
Your rights
In short: you can see, correct, delete and take your data, object to how we use it, and complain to a regulator.
Everywhere else. Wherever you are, you can ask us to:
- Access — confirm whether we hold your personal data and give you a copy.
- Correct — fix data that’s wrong or incomplete.
- Erase — delete your personal data, unless we must keep it by law.
- Restrict — pause our use of your data while a question about it is resolved.
- Port — give you your data in a machine-readable format.
- Object — stop processing based on legitimate interests, including creating Usage Data from your sessions and re-checking them. If you object, we stop doing so for your future sessions, where we can identify your sessions when they happen. Usage Data already created identifies no one, so we can’t find it to remove it. You can always object to marketing.
- Withdraw consent — at any time, as easily as you gave it, without affecting what we did before.
- Complain to your data protection regulator. We’d appreciate the chance to fix things first.
Usage Data isn’t covered by access or erasure requests, because nothing in it links to you. Your rights apply to the step that creates it, which is why you can object to it or, in India, withdraw consent to it.
How to ask. Email privacy@bumbleb.co, or use the settings in your account. We may need to confirm your identity first. We reply within 1 month, or sooner where the law requires; if a request is complex we may extend this as the law allows, and we’ll tell you why. If you use BumbleB through a company, or your data reached us through a website’s tracking tag, the company is responsible for your request — contact it, and we’ll help it answer you.
The sections that follow add the rights and details that apply in India and in the United States.
India
In short: under India’s Digital Personal Data Protection Act, 2023, you get an itemised notice, consent you can withdraw as easily as you gave it, a named Grievance Officer who resolves complaints within one month, and the right to nominate someone to act for you.
This section applies to personal data we process in India or in connection with offering the Service to people in India, under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Some of the Act’s duties begin later, during 2026 and 2027; we follow everything in this section from the day this policy takes effect.
Our role. We are the Data Fiduciary for Account Data, for the personal data we use to create Usage Data, and for your own personal data in an individual account. Visitor Data and any data you upload about other people are yours to control, even in an individual account: you are their Data Fiduciary and we are your Data Processor, under our Data Processing Agreement. When a company uses BumbleB, the company is the Data Fiduciary for its Customer Content, including Visitor Data, and we are its Data Processor: we process that data only on the company’s instructions, under a contract. If your data reached us through a company, send requests to that company; we’ll help it respond.
Until the Act’s main duties begin. Until then, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 also apply. Your password and payment details are sensitive personal data under those Rules. We collect them only to run your account and take payment, with the consent you give when you sign up; we transfer personal data outside India only to recipients bound to protect it to at least the standard of those Rules; and our Grievance Officer resolves grievances within one month.
What we use your data for — each purpose separately.
- Delivering the Service — answering your questions and running your account. Uses your Inputs, Outputs and Account Data.
- Billing — metering usage, invoicing and keeping tax records. Uses Account Data.
- Security and abuse prevention — protecting the Service and investigating incidents. Uses Account Data and access logs, and Customer Content only for a specific investigation.
- Support — fixing a problem you report. Uses the data involved in your request, read in place.
- Improving the Service using Usage Data — learning which tool sequences work. Uses an identity-free record of how the Service ran, created as each session runs. Only if you tick the box described below.
- Re-checking recent sessions — automated re-checks of sessions less than 90 days old, producing labels only. Only if you tick the box described below.
- Submitted Conversations — reading and learning from a conversation you choose to send us, including to train our models. Only when you send one.
- Account communications — invoices, security notices, renewal and changes to our terms or sub-processors. Uses Account Data.
- Marketing — news about features and events. Only if you opt in, with a box that starts unticked. Every marketing email has an unsubscribe link.
At signup we show you this list. Purposes 1 to 4 and 8 use the data you choose to give us in order to use the Service, which the Act treats as a “legitimate use”; keeping records the law requires is also a legitimate use. You can tell us at any time that you no longer want this, and we’ll explain what that means for your account. Purposes 5, 6, 7 and 9 happen only with your consent, which you give separately for each.
Improving the Service — your choice. If you hold an individual account in India, you’ll see these at signup, both unticked:
☐ Let BumbleB learn from an identity-free record of how its tools ran in my sessions.
☐ Let BumbleB automatically re-check my recent sessions to improve answers.
If you leave the first unticked, we don’t create Usage Data from your sessions. If you leave the second unticked, our automated re-checks skip your sessions. Live labelling and automated checking still run while BumbleB answers you, because they’re part of answering. You can tick or untick either at any time in your account settings.
Withdrawing consent. You can withdraw any consent as easily as you gave it — in your account settings, by withdrawing a Submitted Conversation, through the unsubscribe link, or by emailing privacy@bumbleb.co. We then stop that processing and delete the data used for it, unless the law requires us to keep it. Usage Data already created identifies no one, so we can’t find it to delete it; we stop creating more. Withdrawal doesn’t affect processing that happened before. If you ask us to stop purposes 1 to 4, we may no longer be able to provide the Service, and we’ll tell you what that means before closing anything.
Consent Managers. Once Consent Managers registered with the Data Protection Board of India are operating, you may give, review, manage and withdraw your consent to us through one, and we’ll act on it in the same way.
Your rights. You can ask us for:
- Access — a summary of the personal data we hold about you, what we do with it, and the other Data Fiduciaries and Data Processors we’ve shared it with, with a description of what was shared.
- Correction, completion and updating of data that’s inaccurate, incomplete or out of date.
- Erasure of data we no longer need for the purpose you gave it for, unless the law requires us to keep it.
- Grievance redressal — see below.
- Nomination — you can name another person to exercise your rights if you die or become unable to do so. Tell us who, through your account settings or by emailing grievance@bumbleb.co.
Grievance Officer. Our Grievance Officer is Chinmaya Reddy, grievance@bumbleb.co, 581, Second Floor, 1st Main Rd, Sector 6, HSR Layout, Bengaluru, Karnataka 560102, India. We acknowledge every grievance and resolve it within one month. If you’re not satisfied with our answer, you can complain to the Data Protection Board of India.
Language. This notice is available in English or, on request, in any language listed in the Eighth Schedule to the Constitution of India. Ask at grievance@bumbleb.co.
Children. We don’t offer individual accounts to anyone under 18, and we don’t onboard websites directed at children. If we learn that a website is directed at children, we stop collecting from it and offboard it.
Data breaches. If a breach affects your personal data, we’ll tell the Data Protection Board of India and you without delay — what happened, what it means for you and what you can do — and send the Board a detailed report within 72 hours.
Transfers outside India. We host the Service in the United States, and our AI providers process Inputs there, so your personal data is transferred outside India. Indian law allows this except to countries the Central Government restricts by notification. None has been notified yet; if one is, we won’t transfer personal data there.
Retention. We erase personal data once the purpose it was collected for is served, on the schedule in “How long we keep data” above. Access and security logs, which contain no content, are kept for 12 months.
United States
In short: if you live in a US state with a privacy law, you can access, delete and correct your data and opt out of sale, sharing and targeted advertising — though we don’t do any of those.
This section applies to residents of US states with comprehensive privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act. Where we process personal data on behalf of a business customer — its Customer Content, including Visitor Data — we act as its service provider or processor. That customer handles your request; send it to them, and we’ll assist.
Your rights. Depending on your state, you can ask us to:
- Know and access — tell you what personal data we’ve collected about you, where it came from, why we use it and who we disclose it to, and give you a copy in a portable format.
- Delete the personal data we’ve collected from you.
- Correct inaccurate personal data.
- Opt out of the sale or sharing of your personal data, and of targeted advertising. We don’t sell or share personal data, and we don’t use it for targeted advertising, so there is nothing to opt out of — but you can still ask, and we’ll record your choice.
What we collect, why, and who we disclose it to. We collect the categories below. We collect them from you, automatically when you use the Service or our website, and from your organisation if it adds you to its workspace. We keep each for the periods in “How long we keep data” above.
| Category | Examples | Purpose | Disclosed to | Sold or shared? |
|---|---|---|---|---|
| Identifiers | Name, work email, account ID, IP address | Delivering the Service; billing; security; support; account communications; marketing | Hosting, email delivery and support providers | No |
| Commercial information | Plan, seats, invoices, payment records | Billing; account management | Hosting and payment providers | No |
| Internet or other electronic network activity | Login records, feature-level activity counts, pages viewed on our website | Delivering the Service; security; customer success | Hosting provider | No |
| Professional information | Job title, organisation | Account management; account communications | Hosting and support providers | No |
| Customer Content in an individual account | Your questions, uploads, connected data, answers and charts | Delivering the Service; support you ask for; security | Hosting and AI providers | No |
| Account login credentials (sensitive) | Password or single sign-on details | Letting you sign in; security | Hosting provider | No |
Usage Data is deidentified. We keep it in a form that can’t reasonably be linked to you, we don’t try to re-identify it, and we don’t disclose it to anyone.
Sensitive personal information. We use your login credentials, and any sensitive information in an individual account’s content, only to provide the Service, keep it secure and meet legal obligations. We don’t use sensitive personal information to infer characteristics about you.
Global Privacy Control. Our website honours the Global Privacy Control signal as a request to opt out of sale and sharing for that browser.
No discrimination. We won’t deny you the Service, charge you a different price or give you a different quality of service because you exercised these rights.
How to make a request. Email privacy@bumbleb.co or use the settings in your account. To protect you, we verify your identity before acting — usually by asking you to confirm the request from the email address on your account, or to sign in. We’ll confirm receipt within 10 business days and respond within 45 days, or tell you if we need up to 45 more.
Authorised agents. Someone else can make a request for you if you give them signed, written permission. We may still ask you to verify your identity directly with us.
Appeals. If we decline your request and your state gives you a right to appeal, reply to our decision with “Appeal” in the subject line. We’ll respond within the time your state’s law sets and explain our reasons. If you’re still not satisfied, you can contact your state’s Attorney General.
Children
In short: BumbleB is for adults and for businesses that don’t target children.
We don’t offer individual accounts to anyone under 18. We don’t knowingly collect personal data from children, and we don’t onboard websites or apps directed at children. If we learn that a website is directed at children, we stop collecting from it, delete the data and offboard it. If you think a child’s data has reached us, contact privacy@bumbleb.co.
Changes to this policy
In short: 30 days’ notice before any material change, and every past version stays available.
If we make a material change — one that reduces your rights or expands how we use your data — we give you 30 days’ notice by email and in the product before it takes effect. Other changes, such as adding a section for a new country, are recorded in the change log with a new version number and take effect on the date shown, which is never earlier than the day we publish them. Each version shows its effective date and last-updated date, and previous versions are archived at https://bumbleb.co/legal/archive.
Contact us
In short: one address for each kind of question.
- Legal — legal@bumbleb.co
- Privacy — privacy@bumbleb.co
- Security — security@bumbleb.co
- India Grievance Officer — Chinmaya Reddy, grievance@bumbleb.co
By post: BumbleB Technologies Pvt Ltd, 581, Second Floor, 1st Main Rd, Sector 6, HSR Layout, Bengaluru, Karnataka 560102, India.