Legal

Privacy Policy

Effective July 21, 2026 · Version 1.0

This Privacy Policy describes how File Business Inc. [confirm exact legal entity name], doing business as "BosAI" ("BosAI," "we," "us"), collects, uses, and shares information in connection with the BosAI websites, web application, and mobile applications (collectively, the "Service"). It does not cover third-party services you connect to BosAI, which are governed by those providers' own policies. Where you use BosAI on behalf of a business, much of the data we process belongs to that business; our Data Processing Addendum governs processing we perform as a processor or service provider on the business's behalf.

1. Who We Are; Scope

For information about visitors to our websites and account holders (such as registration and billing data), BosAI acts as a controller. For Customer Content processed at a customer's direction (such as the contents of a connected inbox), BosAI acts as a processor/service provider for the customer, and the customer is responsible for its own privacy obligations to its contacts. If you are a customer, employee, or contact of a business that uses BosAI, please direct requests about that business's data to the business; we will assist the business in responding as required by law and contract.

2. Information We Collect

2.1 Information you provide. Account registration data (name, email address, password or single-sign-on identifier), business profile data (business name, industry, preferences, tone settings), Seat information for team members you add, communications with us (support requests, survey responses), and content you type into the Service (questions, instructions, edits, templates).

2.2 Payment information. Paid subscriptions are processed by our payment processor. We receive limited billing metadata (such as plan, card brand, last four digits, billing address, and transaction status); we do not store full payment card numbers.

2.3 Connected Services data. When you connect a third-party service, we access only the data made available under the permission scopes you approve, which may include, depending on the connection: email messages and metadata; calendar events; contacts; invoices, estimates, customers, and payment status from accounting software; and transaction records from payment platforms. We access this data to perform the tasks you have configured (for example, reading an invoice's status to draft a payment reminder).

2.4 Information collected automatically. Log and device data (IP address, browser type, operating system, device identifiers, app version, timestamps, pages viewed, feature interactions, crash data), and approximate location derived from IP address. See our Cookie Policy for cookie-level detail.

2.5 Information from other sources. Referral partners, service providers that help us prevent fraud, and publicly available business records (for example, to prefill your business profile).

3. How We Use Information

We use information to: (a) provide, operate, and maintain the Service, including executing the tasks and autonomy levels you configure; (b) prepare your daily Brief and Receipts; (c) authenticate users and secure the Service, including fraud and abuse detection; (d) process billing and manage subscriptions; (e) provide support and respond to requests; (f) send transactional and administrative communications, and, with your consent where required, product news you can opt out of at any time; (g) analyze usage in aggregate to improve the Service; (h) enforce our terms and policies; and (i) comply with legal obligations. Legal bases for EEA/U.K. processing are described in Section 12.

4. Artificial Intelligence and Your Data

4.1 Model providers. The Service uses large-language-model and other machine-learning technology, including models operated by third-party AI infrastructure providers acting as our subprocessors under contractual confidentiality and data-use restrictions [current list available in the DPA subprocessor annex].

4.2 No foundation-model training on your content. We do not use Customer Content to train generalized AI foundation models, and we contractually require our AI subprocessors not to use Customer Content submitted through the Service to train their generalized models, in each case absent your explicit opt-in consent.

4.3 Service improvement. We may use de-identified, aggregated usage signals (for example, which suggestions are accepted or edited) to evaluate and improve Service quality. Where we use human review to debug a specific failure, access is limited, logged, and subject to confidentiality obligations.

4.4 Automated activity. Actions the Service takes automatically are governed by the autonomy settings you choose and are logged in Receipts. The Service does not make legal or similarly significant automated decisions about consumers without human involvement within the meaning of applicable privacy laws; you (the customer) direct and supervise its operation.

5. Google User Data (Limited Use)

BosAI's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data (such as Gmail and Google Calendar data) only to provide and improve user-facing features of the Service that are visible and prominent to you; we do not transfer it except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice; we do not use it for advertising; and we do not permit humans to read it except with your consent, for security purposes, to comply with law, or where the data has been aggregated and anonymized.

6. How We Share Information

We share information only as follows: (a) Service providers and subprocessors that host and support the Service (cloud infrastructure, AI model providers, payment processing, email delivery, customer support tooling, analytics), bound by contracts limiting use to our instructions; (b) Connected Services, at your direction, when the Service performs an action in your connected account; (c) recipients of your communications, when the Service sends a message on your behalf under your settings; (d) legal and safety, when we believe in good faith that disclosure is required by law or legal process or is necessary to protect the rights, safety, or property of BosAI, our users, or the public; (e) corporate transactions, in connection with a merger, financing, acquisition, or sale of assets, subject to this Policy and with notice of any material change in practices; and (f) with your consent or at your direction. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. The Service displays no third-party advertising.

7. Cookies and Similar Technologies

We use strictly necessary cookies and a limited set of functional and first-party analytics technologies, described in our Cookie Policy, which also explains your controls, including our treatment of Global Privacy Control signals.

8. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy: account data for the life of the account; Customer Content synced from Connected Services for the shorter of the period needed to provide the feature or your configured retention; Receipts for the life of the account (they are your audit trail) unless you delete them; billing records as required by tax and accounting law (generally 7 years); and support communications for up to 3 years. Following account deletion, we delete or de-identify personal information within 30 days, and residual copies in encrypted backups are overwritten in the ordinary course within 35 additional days, except where longer retention is required by law, needed to resolve disputes, or to enforce agreements.

9. Security

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS 1.2+) and at rest (AES-256), OAuth-scoped connections rather than credential storage wherever supported, role-based access on a least-privilege basis, logging and monitoring, and vendor security review. No system is perfectly secure; please use a strong, unique password and protect your devices. See our Security Overview. We will notify affected customers of a personal-data breach as required by applicable law and, for processor data, per the DPA.

10. Your Rights and Choices

Subject to applicable law, you may: access, correct, or delete your personal information; export your data (Receipts and account data are exportable in-product or on request); object to or restrict certain processing; withdraw consent at any time where processing is based on consent; and opt out of marketing communications via the unsubscribe link or your settings. To exercise rights, use in-product controls or contact info@file.business. We will verify your request using your account email and respond within the time required by law. You may authorize an agent to act for you; we will require proof of authorization. We will not discriminate against you for exercising your rights.

11. U.S. State Privacy Notices (California and Others)

11.1 Categories. In the preceding 12 months we have collected the following categories of personal information as defined by the California Consumer Privacy Act (as amended): identifiers (name, email, IP address); customer records (billing metadata); commercial information (plan and transaction history); internet activity (usage and device data); professional information (business role); geolocation (approximate, from IP); and inferences limited to product preferences. Sources, purposes, and recipients are as described in Sections 2, 3, and 6.

11.2 No sale or sharing. We do not "sell" personal information and have not done so in the preceding 12 months, and we do not "share" personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit under California law. We do not knowingly collect personal information of consumers under 16.

11.3 Your California rights. California residents have the rights to know/access, delete, correct, and port their personal information, and the right not to receive discriminatory treatment. Submit requests as described in Section 10; we honor Global Privacy Control signals as an opt-out where applicable. If we deny a request, you may appeal by replying to our decision; residents of states providing an appeal right (including Colorado, Connecticut, and Virginia) will receive appeal instructions with our response.

12. EEA, U.K., and Swiss Notices (GDPR)

Where the EU or U.K. General Data Protection Regulation applies to our processing as a controller, our legal bases are: performance of a contract (providing the Service you request); legitimate interests (securing and improving the Service, preventing abuse, business administration), balanced against your rights; consent (optional marketing, optional AI-training opt-in), which you may withdraw at any time; and legal obligation (tax, accounting, lawful requests). You additionally have the rights to lodge a complaint with your supervisory authority and, where processing is based on legitimate interests, to object. [EU/U.K. representative details to be inserted if and when appointed.]

13. International Data Transfers

We are based in the United States and process data there and in other countries through our subprocessors. Where we transfer personal data from the EEA, U.K., or Switzerland to countries without an adequacy determination, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the U.K. International Data Transfer Addendum, copies of which are available on request.

14. Children

The Service is a business tool for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.

15. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a revised effective date and, for material changes, provide additional notice (such as email or in-Service notice) at least 30 days before the changes take effect where required.

16. Contact Us

Privacy questions and requests: info@file.business (Attn: Privacy) · File Business Inc. d/b/a BosAI, [registered address]. If you have an unresolved concern, you may also contact your local data protection authority or state attorney general.