← Back to Boardroom

Privacy Policy

Last updated: September 13, 2026

1. What this covers

This policy explains what Boardroom (“we,” “us”) collects when you use the Boardroom application at boardroomops.com, and how that information is used, stored, and shared.

2. What we collect

  • Account information: your name, email address, and authentication credentials.
  • Business context you provide: your business name, offers, pricing, standard operating procedures, and any other material you add to your shared knowledge base.
  • Content you generate: briefs, project goals, agent outputs, approvals, and decision-log entries.
  • Billing information, handled directly by Stripe — we do not store your card number.
  • If you connect an integration (GitHub, Gmail, Google Calendar, Slack), the OAuth tokens needed to act on your behalf within the scopes you approved, and the minimum data those integrations return (e.g. recent email subject lines for context, not full mailbox archives, unless the connector explicitly says otherwise).

3. How we use it

We use your data to run the agents you brief, generate the deliverables you request, enforce your plan’s usage limits, and improve reliability. Your business content is used to give your AI agents context — it is not used to train shared or third-party models, and it is not sold.

4. Third parties we use

  • Supabase — database and authentication hosting.
  • Vercel — application hosting.
  • Stripe — subscription billing.
  • Anthropic and OpenAI — the language models that power your agents receive the content of your briefs and knowledge base as needed to generate responses, under those providers’ own data-handling terms.
  • Any integration you explicitly connect (GitHub, Google, Slack) — only the scopes you approve are requested, and you can disconnect at any time from Connectors.

5. Data retention & deletion

Your data is retained for as long as your account is active. You can request full account and data deletion at any time by emailing privacy@boardroom-app.com. We will delete your organization’s records, knowledge base, and connector tokens within 30 days of a verified request, except where we are required to retain billing records by law.

6. Your rights

You can access, export, or delete your data from Settings, or by contacting us directly. If you are in a jurisdiction with statutory data rights (e.g. GDPR, CCPA), those rights apply and we will honor verified requests.

7. Security

Data is encrypted in transit and at rest through our infrastructure providers. Row-level security scopes every database query to your own organization. No system is perfectly secure, and we do not guarantee absolute security.

8. Changes to this policy

We will update the date at the top of this page when this policy changes and, for material changes, notify active accounts by email.

9. Contact

Questions about this policy: privacy@boardroom-app.com