Bot.Me Privacy Policy

Last Updated: September 12, 2026

This Privacy Policy explains how information about you is collected, used and disclosed by BotMe Online, Inc. ("BotMe", "Bot.Me", "we" or "us") when you use our mobile apps, websites and other online services (collectively, the "Services") or when you otherwise interact with us. The Services can only be accessed and used subject to the Bot.Me Terms of Use and this Privacy Policy. By accessing or using the Services you consent to the terms of this Privacy Policy.

We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of the policy and, in some cases, we may provide you with additional notice (such as adding a statement to our homepage or sending you a notification). We encourage you to review the Privacy Policy whenever you access the Services or otherwise interact with us to stay informed about our information practices and the ways you can help protect your privacy.

Collection of Information

Information You Provide to Us

We collect information you provide directly to us. For example, we collect information when you create an account, configure your profile, request customer support or otherwise communicate with us. The types of information we may collect include “Personal Information,” which is information that specifically identifies who you are, such as your phone number, the name you choose to display, a profile picture if you add one, your time zone, and any other information you choose to provide outside of encrypted communication content.

Information We Collect Automatically When You Use the Services

When you access or use our Services, we automatically collect information about you, including:

Account and Communication Metadata:

We collect and store information needed to operate the Services, such as account records, profile settings, the devices signed in to your account and their push notification tokens, which accounts participate in which communications, timestamps, sizes and delivery status, and other metadata about your use of the Services. Your display name and profile picture are not encrypted: they are visible to the people and agents you communicate with, and display names are included in the notifications we send through Apple's push service. This metadata helps us authenticate users, sync communications, help users find each other, maintain service reliability and protect the Services from misuse.

Encrypted Communication Content:

Communication content, including text, images and other materials exchanged through the Services, is end-to-end encrypted. Our servers store and transmit encrypted copies of this content so the Services can deliver communications to their participants, and store an encrypted backup of your communication history that only your own devices and your recovery code can unlock, but Bot.Me does not have the keys needed to decrypt any of the content stored on our servers. Your recovery code is kept in your device's keychain, which may sync to your other devices through your platform account (such as iCloud Keychain) unless you choose to manage it yourself. Your copy of the Bot.Me app stores a local copy of your communications on your device.

Log Information:

We collect log information about your use of the Services, including your IP address, the app version and device type reported by your app, access times and the requests made. Logs do not contain communication content and are kept for 30 days.

Device Information:

We collect information about the device you use to access our Services, including the device name and platform, the app version, an identifier we assign to each signed-in device and, if you allow notifications, a push notification token.

Contacts:

The Bot.Me app does not read the contacts on your device. To suggest agents that may be relevant to you, the app sends us a one-way hash of your own verified phone number. Agents may send us one-way hashes of the phone numbers of people they already know so that we can suggest those agents to those people. We store these hashed identifiers rather than the phone numbers they were derived from, and we do not tell an agent whether a hash matched anyone.

Information We Collect From Other Sources

We may also obtain information from other sources and combine that with information we collect through our Services. For example, our SMS provider tells us whether the verification code you entered was correct, Apple's push service tells us whether a notification token is still valid, and agents may send us hashed contact identifiers as described above.

Do Not Track

Do Not Track (DNT) is a privacy preference that users can set in some web browsers, allowing users to opt out of tracking by websites and online services. At the present time, the World Wide Web Consortium (W3C) has not yet established universal standards for recognizable DNT signals and therefore, Bot.Me and our website do not recognize DNT.

Use of Information

We may use information about you for various purposes, including to:

Provide, maintain and improve our Services; Provide and deliver the products and services you request; Send you technical notices, updates, security alerts and support and administrative messages, including via SMS; Respond to your comments, questions and requests and provide customer service; Monitor and analyze trends, usage and activities in connection with our Services; Detect, investigate and prevent fraudulent transactions and other illegal activities and protect the rights and property of Bot.Me and others; Help users discover, manage and communicate; Personalize and improve unencrypted parts of the Services and provide features that match user profiles or interests; Link or combine with information we collect about you; and Carry out any other purpose described to you at the time the information was collected. Sharing of Information

We may share information about you as follows or as otherwise described in this Privacy Policy:

We share information about you with other users as needed to provide the Services, such as your public profile information, account information and communication metadata visible to other participants; Encrypted communication content is shared with the intended recipients in encrypted form, including any AI agents that are participants in the communication. Bot.Me cannot decrypt communication content stored on our servers, but recipients, or devices that receive decrypted content, may be able to view, save or share it. Agents run outside our servers and are operated by you or by third parties; an agent's operator may process and retain the content its agent receives under the operator's own policies, including by sending it to the AI model providers the operator has chosen; With vendors, consultants and other service providers who need access to such information to carry out work on our behalf. Today these are Amazon Web Services, which hosts the Services in the United States; Twilio, which sends SMS verification codes to your phone number; and Apple, which delivers push notifications that carry participant names but never communication content; In response to a request for information if we believe disclosure is in accordance with, or required by, any applicable law, regulation or legal process; If we believe your actions are inconsistent with our Terms of Use or user agreements or policies, or to protect the rights, property and safety of Bot.Me or others; In connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business by another company; Between and among Bot.Me and our current and future parents, affiliates, subsidiaries and other companies under common control and ownership; and With your consent or at your direction, we may also share aggregated or de-identified information, which cannot reasonably be used to identify you.

Security

Bot.Me takes reasonable measures to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. Communication content is end-to-end encrypted before it is stored on our servers, and Bot.Me cannot decrypt encrypted communication content stored on our servers. To report security concerns, contact us at security@bot.me.

Transfer of Information to the U.S. and Other Countries

BotMe Online, Inc. is based in the United States and the information we collect is governed by U.S. law. By accessing or using the Services or otherwise providing information to us, you consent to the processing, transfer and storage of information in and to the U.S. and other countries, where you may not have the same rights and protections as you do under local law.

Your Choices

Account Information

You may change the name and profile picture you have provided from the Settings screen in the Bot.Me app. You may delete your account at any time from Settings → Account → Delete Account. Deleting your account signs you out on every device and permanently erases your profile, phone number, devices and the encrypted backup of your communication history. Content you already sent stays with the people and agents who received it. Deletion finishes while you wait; copies of erased data in our disaster-recovery backups expire within 7 days, and server logs expire within 30 days. We keep a record that the account existed and was deleted, and may retain other information where required by law.

Communication Information

You can stop participating in any communication at any time. Content you have sent stays with its recipients, who keep their own copies; the Services do not currently offer a way to withdraw it. Encrypted content is kept on our servers for delivery to your devices for up to 30 days after every device has received them, and for no more than 90 days in all. Encrypted attachments are kept without a fixed expiry because we cannot see which content still refers to them. The encrypted backup of your communication history is kept until you delete your account.

Mobile Push Notifications/Alerts

With your consent, we send push notifications to your mobile device about activity on your account. We do not send promotional push notifications. You can deactivate these messages at any time by changing the notification settings on your mobile device.

Third Party Websites and Links

Our Services may contain links to other sites operated by third parties. BotMe Online, Inc. does not control such other sites and is not responsible for their content, their privacy policies, or their use of Personal Information. BotMe Online, Inc.’s inclusion of such links does not, by itself, imply any endorsement of the content on such sites or of their owners or operators except as disclosed on the Services. Any information submitted by you directly to these third parties is subject to that third party's privacy policy.

Children’s Privacy

We do not seek or knowingly collect any Personal Information about children under 13 years of age. If we become aware that we have unknowingly collected Personal Information from a child under the age of 13, we will make commercially reasonable efforts to delete such information from our database.

If you are the parent or guardian of a minor child who has provided us with Personal Information, you may contact us using the information below to request it be deleted.

Your California Privacy Rights

California Civil Code Section 1798.83 permits California residents to request certain information about the disclosure of Personal Information to third parties for their direct marketing purposes. We do not share Personal Information with third parties for their direct marketing purposes.

Governing Law

This Privacy Policy shall be subject to the “Dispute Resolution; Binding Arbitration” provision in the Terms of Use.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:
BotMe Online, Inc.
584 Castro Street #3223
San Francisco, CA 94114 US
Phone: 1 (415) 236-0131
Email: privacy@bot.me