Last updated: September 11, 2026
How Botchi collects, uses, and protects your information.
Botchi is an AI assistant that helps you chat, organize files, manage memories, create documents, schedule tasks, and connect to services you choose to use. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
This notice covers Botchi's website, applications, chat, dashboard, and API or MCP access. It describes personal data processing under articles 13 and 14 GDPR. Reading this notice or accepting the Terms does not constitute general consent to processing; legal bases are described in section 3.
Sealo S.r.l., Strada Trossi 41, 13871 Verrone (BI), Italy, VAT number IT 02777410024, REA BI-310965, is the controller for processing it determines to administer the Service, contractual relationships, security, legal obligations, and the analytics described here. Contact hello@botchi.ai or the registered office for privacy matters and rights.
When an organization uses Botchi to process data for its own purposes, it may act as controller and Sealo as processor, within the instructions and data processing agreement, or DPA. The organization supplies its own notice and identifies the legal basis for processing on its behalf. Sealo retains controller obligations for processing it determines independently. Choosing a model or provider does not automatically change these roles.
Business administrators and authorized Users may access business data, executions, and usage information according to their permissions. Account membership does not automatically grant access to all of a member's personal content.
We receive data directly from you, from organizations inviting or authorizing you, from connected services, and from sources consulted for requested operations, including public web sources. We also generate technical and usage data while operating the Service. Content may concern people other than the submitting User; its source depends on the request and sources used.
### Account and identity
When you create or sign in to an account through WorkOS AuthKit, we receive your email address, a unique user identifier, session identifiers, email verification status, and any profile information made available by the sign-in method you use. We may also store your timezone, preferred language, referral state, terms acceptance timestamp, and account or team membership information.
### Chat content and attachments
Messages you send to Botchi, assistant responses, uploaded files, images, generated documents, generated images, voice recordings, contact cards, location attachments, reactions, tool results, and related metadata are stored on our backend so conversations can be resumed across devices, files can be opened later, and future replies can use relevant context.
### Memory and personalization
Botchi can remember facts, preferences, communication style, account context, assistant profile settings, app settings, tool permissions, approvals, tasks, calendar items, and other context you share so it can be more useful over time.
### Connected services
If you connect a third-party service, we store OAuth tokens, refresh tokens, account identifiers, email address or profile identifiers returned by that provider, selected scopes, and connection settings needed to call the service on your behalf. Tokens and custom credentials are encrypted at rest. We call connected services when you ask Botchi to do something, when you approve an action, or when you configure an automation that requires that provider.
Connected services can include productivity, communication, file, calendar, social, health, fitness, music, location, email, MCP, API, and custom workspace integrations. Depending on what you connect and ask Botchi to do, provider data may include emails, drafts, attachments, calendar events, tasks, contacts, files, spreadsheets, presentations, notes, health or fitness summaries, music library information, social media metadata, messages, comments, and place or routing information.
### Subscription and billing
Available web purchases, including business subscriptions, seats, and Sparks top-ups, are processed through Stripe. We receive customer identifiers, billing details, addresses, supplied tax information, payment status, invoices, subscriptions, top-ups, and related events. Automatic top-ups generate additional authorization and charge records.
Mobile purchases are processed by Apple App Store or Google Play. RevenueCat supports purchase and access verification. We receive transaction and product identifiers, subscription status and duration, and reconciliation data. We do not store full card numbers or security codes; payment services may provide limited payment-method information such as type and last digits.
### Device and technical information
We collect basic device and app information needed to deliver the Service: app version, runtime version, operating system, device model, manufacturer or brand, language, timezone, network status, push notification tokens if you enable notifications, and approximate request metadata such as IP address, timestamps, headers, and backend request identifiers.
### Usage analytics
We use PostHog to understand how the app is used and to monitor reliability and cost. Analytics events may include account identifiers, feature usage, onboarding and purchase events, tool connection events, tool approval events, message and attachment workflow events, performance metrics, and AI usage telemetry such as model name, input tokens, output tokens, total tokens, and estimated cost. Optional browser analytics and conversion attribution on the public website remain disabled until you consent through the cookie settings. See our Cookie Policy for details. We do not sell analytics data. After consent, PostHog also captures clicks and form interactions, scrolling, page exits, browser errors and loading performance. Heatmaps aggregate clicks and scrolling. Session replay reconstructs navigation from the public page, mouse movements and interactions, with form values and editable text masked. We do not record console logs, request headers or bodies, or third-party iframe contents. Withdrawing consent stops recording and clears optional analytics storage.
### Support and feedback
If you submit a feature request, contact support, or report a problem, we collect the details you submit, your account identifier, your email address if needed for a reply, and relevant technical context.
### Device permissions
With your explicit permission, the mobile app may access photos, camera, microphone, speech recognition, location, contacts, notifications, and files/documents for the features you choose to use. You can revoke permissions from your device settings.
This table concerns processing for which Sealo acts as controller. The contractual basis applies where the data subject is a contracting party and processing is necessary for performance or requested pre-contractual steps. For content processed on a business customer's behalf, that customer determines purposes and legal basis; Sealo acts under the DPA.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Create and manage accounts, provide assistants, memory, files and requested features, synchronize devices, and send service notices | Identity, content, settings, sessions, and operation data | Contract performance or pre-contractual steps, GDPR art. 6(1)(b). For contacts and administrative management of business customer users, legitimate interest in managing the relationship, art. 6(1)(f). |
| Manage purchases, seats, Sparks, renewals, and contractual support | Billing, transactions, support requests, and usage | Contract performance; legitimate interest for business contacts. |
| Meet tax, accounting, and legally binding requirements | Accounting records and necessary compliance data | Legal obligation, art. 6(1)(c). |
| Protect accounts and infrastructure, prevent abuse, identify failures, and verify usage and costs | Logs, technical metadata, identifiers, operational events, and AI telemetry | Legitimate interest in security, continuity, and accurate Service accounting, art. 6(1)(f), respecting data subjects' rights. |
| Analyze authenticated product usage and improve features and reliability | Usage events, metrics, and technical data |
### Model and provider choices
Botchi uses multiple AI providers to offer a choice of models and features. Where supported, you can choose among available options; business choices also depend on permissions and administrator settings. Otherwise the feature's defaults apply.
Each option shows the conditions Botchi enforces for that route: retention, training use, and inference region where the provider reports it. Choices available to Users or administrators require assessing suitability for the purpose and data, based on that information. They are not general consent to sharing or a waiver of rights. Automatic provider selection within a route is limited to providers meeting the route's stated conditions. Sealo configures each request according to those conditions, relies on the providers' declarations and agreements, and remains responsible for its own configuration and security measures.
One task may involve multiple services. Audio transcription or document reading may use a provider different from the one selected for the chat response.
### Data sent and recipients
To complete requests or automations, we send the necessary conversation content, attachments, memories, profile settings, tool results, and connected-service context to the providers involved. AI functions may generate responses and images, transcribe audio, read and summarize documents, search the web, create memories, and produce structured output.
Requests may reach the service running the model directly or pass through a routing service. Model developers and inference providers may be different entities. Data is shared with providers involved in that operation, not every provider in the catalog. The subprocessor page lists services and roles.
### Retention and training
Retention and training use depend on the service, model, endpoint, and applicable agreements. Botchi applies provider selection controls, zero data retention, and training restrictions where specified by configuration. See Security and service-specific details in Subprocessors.
Zero data retention concerns inference content within the provider's scope. It does not mean operational or billing metadata is absent or remove content Botchi stores to provide the Service, as described in section 7. Where that protection does not apply, providers may temporarily retain content or metadata for security, abuse prevention, reliability, or legal requirements under applicable policies and agreements. We record tokens and estimated cost to manage usage and billing.
### Sensitive information
Do not submit sensitive personal information to AI functions unless a specific feature or written agreement expressly permits it and legal requirements are met, including an article 9 GDPR condition where necessary. Technical availability of an integration does not automatically authorize special-category processing. This includes health information, financial account numbers, government identifiers, identity documents, credentials, private keys, GDPR special-category data, and similar regulated information.
We do not sell your personal information. We share necessary data with providers that help us deliver the Service, under agreements that limit its use. Their activities include authentication, hosting, databases and storage, AI and media processing, payments and subscriptions, analytics, diagnostics, and notifications. Provider names, purposes, and data categories are listed on the subprocessor page.
When you connect an external service, Botchi calls it on your behalf within the permissions granted and the feature requested or configured. These services may operate under their own terms and privacy notices, including in a role other than Botchi's subprocessor.
We do not sell connected-service data or use it for advertising. Our use and transfer of Google user data received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide or improve Botchi features requested or configured by the user; we do not use it to train generalized AI or machine-learning models.
We may also disclose information when required by law, to protect rights and safety, or in connection with a corporate transaction, respecting applicable legal bases, minimization, and information obligations. A corporate transfer does not automatically authorize incompatible new purposes.
Botchi is a global service. Data may be processed in the European Union, the United States, or other countries, depending on the feature and providers involved. Choosing a model or regional endpoint does not, by itself, determine the location of all Service processing.
Where required, transfers are protected by appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, and supplementary technical and organizational measures, within the applicable agreements. Requirements for EU-only processing must be evaluated and agreed separately. You may request information about applicable safeguards and a copy of relevant clauses, with any necessary redaction of unrelated confidential information, at hello@botchi.ai. An EU endpoint does not automatically exclude access or separate metadata processing from other countries. Service-specific notes are available on the subprocessor page.
Duration depends on category and purpose. We retain only necessary data and distinguish Service data, legally required records, and residual copies. Account deletion is not instantaneous removal of every record from every provider.
| Category | Retention period or criterion |
|---|---|
| Accounts, chats, files, memories, and settings | For the requested service's duration, until applicable content or account deletion, allowing for processing time. Business customer instructions and the DPA also apply. |
| Tokens and connections | Until revocation, expiry, disconnection, or account termination, except minimum records needed to document the operation or handle revocation errors. |
| Accounting and tax data | For the legally required period; documents subject to Italy's ten-year requirement are retained for ten years, with extensions required by investigations or disputes. |
| Logs, security, and operational records | As necessary to identify and resolve incidents, reconcile operations, and prevent unlawful replay; dispute-related retention is limited to relevant data and the dispute's duration. |
| Support and communications | To handle the request and subsequent documentary, contractual, or legal-claim needs, according to the issue's nature and conclusion. |
| Optional browser analytics identifiers | Periods in the Cookie Policy, up to six months for the specified persistent identifiers. This is not automatically the retention period for events already received by analytics services. |
| Server-side analytics data | As necessary for the stated analysis, reliability, and accounting purposes; personal data deletion procedures and legal exceptions apply. Pseudonymization alone does not make data anonymous. |
We use practical technical and organizational measures to protect your information, including TLS in transit, access controls, encryption at rest for sensitive OAuth tokens and custom credentials, secure token storage on device, least-privilege service access, and monitoring for reliability and abuse. No method of transmission or storage is fully secure; we cannot guarantee absolute security, but we work to protect your data and respond quickly to incidents.
Under GDPR conditions, you may obtain access and copies, rectification, erasure, restriction, objection, and portability of data processed automatically on consent or contract grounds. You may withdraw consent at any time without affecting prior lawful processing. Each right has statutory conditions and exceptions.
Write to hello@botchi.ai or Sealo's registered office, identifying the request and account. Additional identity information is requested only where necessary and proportionate. We respond without undue delay, normally within one month; complexity or request volume may justify a further two months, with notice and reasons within the first month. Refusals are explained. Charges or refusals for manifestly unfounded or excessive requests are permitted only as provided by law.
For data processed on your organization's behalf, you may contact the relevant controller; if we receive the request, we cooperate and forward it under the DPA without affecting rights exercisable directly against us.
You may complain to the Italian data protection authority or the competent authority where you habitually reside, work, or consider an infringement occurred, and seek judicial remedies. A prior complaint to Sealo is not required.
Botchi is restricted to people aged 18 or over under the Terms. Minor access is not authorized, including through business accounts. If you report data collected in breach of this rule, we investigate and take appropriate measures, including required deletion and minimum retention necessary to handle the report.
Botchi automatically processes prompts, context, and memories to generate outputs and personalize responses. Automations may affect connected services within instructions and permissions. Subscription, balance, and permission checks may prevent new operations; contact support to report errors and request review.
The standard service is not intended for solely automated decisions producing legal or similarly significant effects on people. Customers cannot activate such uses merely because a model is available: prior assessment, legal basis, safeguards, and express agreement for uses requiring specific support are necessary. Actual roles and obligations depend on processing, not the automation's name.
Connected external services may process data under their own notices. Revoking a Botchi connection does not automatically delete data or actions already held by those services.
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, when appropriate, notify you in the app or by email.
For any privacy question or request, contact us at hello@botchi.ai.
| Legitimate interest in understanding and improving the Service, with minimization and a balancing assessment. This does not cover access to tracking technologies requiring consent. |
| Optional public-site analytics and conversion measurement, including heatmaps and replay | Pseudonymous identifiers, navigation, and interactions | Consent, art. 6(1)(a), and applicable cookie rules. |
| Establish, exercise, or defend rights | Relevant contracts, communications, transactions, and records | Legitimate interest in protecting rights, art. 6(1)(f), or legal obligations where applicable. |
Data necessary for contractual or legal obligations is required for the corresponding services; without it we may be unable to activate an account, invoice, or complete an operation. Connections, device permissions, and optional analytics are optional: refusal limits only dependent features. Device permission or OAuth connection does not, by itself, replace a GDPR legal basis.
You may object to legitimate-interest processing on grounds relating to your particular situation. We assess the request under GDPR and stop processing unless compelling overriding legitimate grounds or legal-claim needs apply.
| Backups and provider-held data | Subject to the relevant service's retention cycles and procedures; residual copies remain protected and use-restricted. Immediate deletion of third-party backups or logs is not promised. |
Effectively anonymous data, with no reasonable means of identifying a person, may be retained for statistical analysis. Merely de-identified or pseudonymized data continues to be treated as personal data.
The account deletion procedure distinguishes receipt, processing, and completion. Mandatory retention and minimum records preventing replay from recreating deleted data may remain.