Privacy Policy

Last updated: July 2026

1. Overview

This Privacy Policy explains what information BoltLynx collects, how we use it, and the choices you have. It applies to the BoltLynx web application, the local client, and related services.

2. Information we collect

We collect:

  • Account information, such as your name, email, and organization;
  • Usage information, such as feature usage and request volume, used for billing and to improve the Service. We may create de-identified or aggregated behavioral data from how the Service is used, such as workflow patterns, performance signals, and error rates, for product optimization and service improvement;
  • Content you send to the Service so the agent can act on a task;
  • Execution results and diagnostic logs sent back by the local client about the actions it runs;
  • Technical information, such as device and log data needed to operate and secure the Service.

3. Your files and local environment

The local client runs on your machine and works inside the directories and permissions you configure. Local file access happens on your device. Structured file actions are checked against BoltLynx access controls, allowing precise read and write boundaries without relying on shell commands. Shell commands can require approval and can be governed by user-configured allowlists or blocklists. We do not mirror your local workspace to our servers or scan and upload unrelated files. Content may be transmitted when needed for model reasoning, included in action results needed to continue the work, or sent to an online service you choose, such as web search. The client may also send operational diagnostic logs needed to coordinate, secure, and operate the Service.

4. How we use information

We use information to:

  • provide, maintain, and secure the Service;
  • process requests and run the actions you approve;
  • handle billing and account management;
  • communicate with you about the Service;
  • improve reliability, performance, usability, and safety, including by analyzing de-identified or aggregated behavioral data.

5. We do not train on your content

We do not use Your Content to train our own or shared AI models. This applies to any models we may develop in the future. We also do not use de-identified or aggregated behavioral data to train general-purpose large language models. We may use de-identified or aggregated behavioral data only for product optimization, reliability, usability, safety, and performance improvement.

6. Third-party model providers

To carry out your requests, the Service sends prompts and related content to third-party model providers (for example, the large language model providers whose models you use). These providers process that content under their own terms and privacy policies, which are outside our control and may differ from ours. Some providers may retain or use the data they receive according to their own policies, including for their own processing or model training. We do not control, and are not responsible for, how third-party providers handle data once it reaches them. Review their terms before submitting sensitive content.

7. Sharing and subprocessors

We do not sell your personal information. We share information only with service providers who help us operate the Service under appropriate confidentiality terms, or when required by law. A list of the model providers and other subprocessors we use is available on request.

8. Data retention and deletion

We keep Your Content while your account is active and as needed to provide the Service. When you delete content or close your account, we remove it from active systems promptly and purge residual copies from backups within 30 days. We may retain limited records, such as billing and transaction records, for longer where required by law.

9. Restricted data

Please do not submit regulated data such as protected health information (PHI), full payment card numbers, government classified information, or special categories of personal data under the GDPR, unless we have agreed otherwise in writing. You are responsible for the data you submit and for complying with the laws that apply to it.

10. Security

We use technical and organizational measures to protect information, including access controls and encryption of data in transit. No system is perfectly secure, but we work to limit access and respond quickly to issues. Where required by law, we will notify affected users of a data breach.

11. Data protection roles and international transfers

Where you use the Service to process personal data, you act as the data controller and BoltLynx acts as the data processor, processing that data on your instructions to provide the Service. You are responsible for having a lawful basis and any required consents for the personal data you submit, and for responding to data-subject requests relating to it.

We and our providers may process data in different countries. Where required, we rely on appropriate safeguards for cross-border transfers. If you require a Data Processing Agreement (DPA), one is available on request.

12. Your choices

You can access and update your account information, and you can request export or deletion of your data. Contact us using the address below to make a request.

13. Contact

Questions about this Policy or your data can be sent to the address below.

Questions about this page? Reach us at support@boltlynx.com.