Privacy Policy
Last updated: April 2026
1. Overview
This Privacy Policy describes how Kairos Software AI ("we", "us", "our") collects, uses, and protects information when you use Boule Board ("the Service"). The Service is intended for users who are 18 years of age or older. We do not knowingly collect information from children under 18.
2. Information We Collect
When you create a Boule Board account, we collect:
- Account information: first name, last name, email address, and password (stored as a hashed value)
- Business information: the answers you provide during onboarding, including company details, opportunity framing, solution details, and business-model inputs
- Session content: the questions you ask during board sessions and the Advisor responses generated for you
- Payment information: handled directly by Stripe; we do not store full card numbers on our systems
- Usage data: session activity, feature interactions, and technical logs (such as IP address and browser type) used for security and product improvement
3. How We Use Your Information
We use your information to:
- Provide and personalize the Boule Board advisory experience
- Generate your Boule Audit and session responses
- Produce Boule Records for your sessions
- Send transactional emails such as account confirmations, session summaries, and billing receipts
- Operate, maintain, secure, and improve the Service
- Comply with legal obligations and enforce our Terms of Service
4. Data Security
Your data is encrypted in transit (TLS) and at rest. We use Supabase with row-level security, meaning only you can access your business information, sessions, and records. Your data is never shared with other users of the Service. No system is perfectly secure, but we continue to invest in safeguards appropriate to the sensitivity of the data we handle.
5. AI Model Training
Your business data is never used to train our AI models or those of our providers. Session inputs and outputs are processed through the Anthropic API under terms that prohibit the use of your data for model training.
6. Third-Party Services
We use the following providers to operate Boule Board:
- Supabase — database, authentication, and row-level security
- Stripe — payment processing
- AWS Amplify — application hosting
- Anthropic — large language model provider for Advisor responses
- HeyGen — video hosting and playback for onboarding video content
Each provider has its own privacy policy governing its handling of data. We select providers that offer security and privacy standards appropriate to the Service.
7. Data Storage and Location
Our application and database are hosted on Amazon Web Services infrastructure in the United States. Your data is processed and stored primarily in the United States. If you access the Service from outside the United States, you understand that your data will be transferred to and processed in the United States.
8. Cookies and Analytics
We use cookies and similar technologies strictly necessary to operate the Service, such as authentication cookies that keep you signed in. We do not sell your data, and we do not use advertising or cross-site tracking cookies. If we add analytics or measurement tools in the future, we will update this policy to describe what is collected and provide controls where required.
9. Data Retention
We retain your account data and session history for as long as your account is active. If you delete your account, all associated data will be permanently removed within 30 days, except where we are required to retain information to comply with legal obligations (such as tax or financial records).
10. Your Privacy Rights
Depending on where you live, you may have the following rights regarding your personal data:
- The right to access the personal data we hold about you
- The right to correct inaccurate personal data
- The right to delete your personal data
- The right to data portability (to receive your data in a portable format)
- The right to object to or restrict certain processing
- The right to withdraw consent where processing is based on consent
- The right to opt out of the sale or sharing of personal data (we do not sell or share personal data for advertising)
- The right to non-discrimination for exercising any of these rights
To exercise any of these rights, email us at support@bouleboard.com. We respond within the timeframes required by applicable law.
11. Do Not Track and Global Privacy Signals
Some browsers offer "Do Not Track" or Global Privacy Control signals. Because we do not sell personal data or engage in cross-site tracking for advertising, these signals do not change how we process your data.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
If you have questions about this Privacy Policy or want to exercise any of your privacy rights, contact us at support@bouleboard.com.
