Privacy Policy
Operator and contact
Data controller/operator: [LEGAL_ENTITY_NAME], [BUSINESS_ADDRESS]. Privacy inquiries: support@noboundsai.com. Effective date: [LAUNCH_DATE]. Regions and legal bases: [COUNSEL/OPERATOR TO COMPLETE].
Data we process
We process your email, authentication records, adult affirmation and terms version, billing identifiers and subscription status, saved chat history, normalized images and extracted text from file attachments, project names and instructions, usage counts, generation timing, and limited abuse-prevention records. Stripe processes card details; our app does not receive full card numbers. Authentication and database services are provided by Supabase. The operator must identify the chosen web host, GPU host, safety-classifier operator, Redis provider, email provider, and their processing locations before launch.
How conversations are handled
Messages pass through our backend to privately configured inference and safety services. Servers process the text; this is not end-to-end encryption or anonymity. Saved conversations are available in your account. Uploaded images are resized and stored with saved messages. We retain extracted document text rather than original documents. Attachments follow the conversation’s deletion and retention rules. Projects organize saved conversations and store optional instructions that are sent with future requests in that project. Serious policy blocks create a category, version, timestamp, account reference, and salted fingerprint rather than the blocked prompt.
Operational logs and product analytics do not contain full prompts or responses. We do not use conversations to train our model. We do not sell chat text. Administrators can review operational metrics and enforce account policy; the dashboard does not offer conversation browsing.
Retention and deletion
Default saved-chat retention is 90 days since the last conversation update, enforced by scheduled maintenance. Deleting a chat removes the live database content immediately. Projects and their instructions remain until you delete the project or your account. Deleting a project keeps its chats in your general history. Policy fingerprints default to 365 days. Account deletion removes saved conversations, the login, and owned account tables; remaining accounting/audit records lose their account reference. Billing and accounting retention must be configured with professional review for the operator’s jurisdiction.
Backups may contain older content until the infrastructure provider’s backup window expires. [OPERATOR: publish the actual backup, billing, audit, and log retention windows before launch.] We do not promise immediate erasure from backups. Configure inference and safety services to disable request-body logs and prompt caches; the application cannot control a provider’s independent retention by itself.
Cookies and choices
Essential HTTP-only cookies maintain your session. Saved-chat composer drafts are stored in your browser so failed navigation does not lose your text. Pending attachments and project/conversation context are stored with drafts so you can return to your work. Product analytics is disabled by default and any optional sink must honor consent. No advertising trackers are included.
Use Account to export data or delete your account. Contact support for access issues, correction requests, appeals, and region-specific privacy requests. [COUNSEL: complete response deadlines, lawful bases, cross-border safeguards, applicable rights, and regulator information.]