Privacy Policy
Last updated: July 2026
1. Overview
This Privacy Policy explains what information BoltLynx collects, how we use it, and the choices you have. It applies to the BoltLynx web application, the local client, and related services.
2. Information we collect
We collect:
- Account information, such as your name, email, and organization;
- Usage information, such as feature usage and request volume, used for billing and to improve the Service. We may create de-identified or aggregated behavioral data from how the Service is used, such as workflow patterns, performance signals, and error rates, for product optimization and service improvement;
- Content you send to the Service so the agent can act on a task;
- Execution results and diagnostic logs sent back by the local client about the actions it runs;
- Technical information, such as device and log data needed to operate and secure the Service.
3. Your files and local environment
The local client runs on your machine and works inside the directories and permissions you configure. Local file access happens on your device. Structured file actions are checked against BoltLynx access controls, allowing precise read and write boundaries without relying on shell commands. Shell commands can require approval and can be governed by user-configured allowlists or blocklists. We do not mirror your local workspace to our servers or scan and upload unrelated files. Content may be transmitted when needed for model reasoning, included in action results needed to continue the work, or sent to an online service you choose, such as web search. The client may also send operational diagnostic logs needed to coordinate, secure, and operate the Service.
4. How we use information
We use information to:
- provide, maintain, and secure the Service;
- process requests and run the actions you approve;
- handle billing and account management;
- communicate with you about the Service;
- improve reliability, performance, usability, and safety, including by analyzing de-identified or aggregated behavioral data.
5. We do not train on your content
We do not use Your Content to train our own or shared AI models. This applies to any models we may develop in the future. We also do not use de-identified or aggregated behavioral data to train general-purpose large language models. We may use de-identified or aggregated behavioral data only for product optimization, reliability, usability, safety, and performance improvement.
6. Third-party model providers
To carry out your requests, the Service sends prompts and related content to third-party model providers (for example, the large language model providers whose models you use). These providers process that content under their own terms and privacy policies, which are outside our control and may differ from ours. Some providers may retain or use the data they receive according to their own policies, including for their own processing or model training. We do not control, and are not responsible for, how third-party providers handle data once it reaches them. Review their terms before submitting sensitive content.
7. Sharing and subprocessors
We do not sell your personal information. We share information only with service providers who help us operate the Service under appropriate confidentiality terms, or when required by law. A list of the model providers and other subprocessors we use is available on request.
8. Data retention and deletion
We keep Your Content while your account is active and as needed to provide the Service. When you delete content or close your account, we remove it from active systems promptly and purge residual copies from backups within 30 days. We may retain limited records, such as billing and transaction records, for longer where required by law.
9. Restricted data
Please do not submit regulated data such as protected health information (PHI), full payment card numbers, government classified information, or special categories of personal data under the GDPR, unless we have agreed otherwise in writing. You are responsible for the data you submit and for complying with the laws that apply to it.
10. Security
We use technical and organizational measures to protect information, including access controls and encryption of data in transit. No system is perfectly secure, but we work to limit access and respond quickly to issues. Where required by law, we will notify affected users of a data breach.
11. Data protection roles and international transfers
Where you use the Service to process personal data, you act as the data controller and BoltLynx acts as the data processor, processing that data on your instructions to provide the Service. You are responsible for having a lawful basis and any required consents for the personal data you submit, and for responding to data-subject requests relating to it.
We and our providers may process data in different countries. Where required, we rely on appropriate safeguards for cross-border transfers. If you require a Data Processing Agreement (DPA), one is available on request.
12. Your choices
You can access and update your account information, and you can request export or deletion of your data. Contact us using the address below to make a request.
13. Contact
Questions about this Policy or your data can be sent to the address below.
Questions about this page? Reach us at support@boltlynx.com.