Privacy Policy

A clear account of the data used to provide and improve Bondi

Last Updated: August 3, 2026

This Privacy Policy describes how Bondi Labs, Inc. (“Bondi,” “we,” “us,” or “our”) handles personal information when you visit our website, create or use a Bondi account, contact us, apply for a role, or otherwise interact with us.

Bondi Labs, Inc. is a Delaware corporation located at 2803 Philadelphia Pike, Suite B #356, Claymont, DE 19703, United States. Privacy questions and requests can be sent to privacy@heybondi.com.

1. Scope and customer roles

For account, website, sales, billing, and support information, Bondi generally acts as the business or controller. For personal data that a customer places in its Bondi Workspaces, Bondi generally acts as a service provider or processor on the customer’s instructions. The customer determines why that Customer Data is collected and who may access it. Our Data Processing Agreement provides additional processor terms.

This policy does not govern third-party services that a customer connects to Bondi or external Portals whose owner provides a separate privacy notice.

2. Information we collect

Depending on how you use Bondi, we may collect:

  • Account and identity data: name, email, profile image, organization, role, authentication events, verification state, and account preferences.
  • Customer Data: records, files, forms, messages, prompts, workflow inputs and outputs, integration data, Portal data, and other content submitted to a Workspace.
  • Product and device data: IP address, browser and device information, session identifiers, pages or features used, timestamps, diagnostics, audit events, and security signals.
  • Billing data: plan, seat count, tax address and Tax ID, invoices, transaction identifiers, usage, add-ons, Wallet activity, and payment status. Stripe processes full payment-card details; Bondi does not need to store the full card number.
  • Communications: support, sales, Partner, security, survey, and other messages you send to us.
  • Marketing-site data: page visits and campaign or referrer information when analytics consent is enabled.
  • Applicant data: information submitted when applying for a role.

We also receive information from the organization that invited you, authentication providers you choose, verified Partners, payment and fraud-prevention providers, and services a customer connects to Bondi.

3. How we use information

We use personal information to:

  • provide, secure, support, and administer the Service;
  • authenticate users and enforce tenant, workspace, role, record, field, and action permissions;
  • run customer-requested automations, integrations, exports, Portals, MCP access, and AI features;
  • calculate seats and usage, process payments and taxes, prevent abuse, and maintain financial records;
  • monitor reliability, investigate incidents, debug failures, and improve product quality;
  • communicate about the account, Trial, subscription, security, support, or requested sales activity;
  • comply with law and enforce our agreements; and
  • analyze the marketing site when the visitor permits analytics.

Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the Service, consent, and compliance with legal obligations. A customer is responsible for choosing an appropriate legal basis for Customer Data it controls.

4. AI and automated processing

When a user invokes Chat, Builder, AI Agents, OCR, parsing, image generation, or AI inside an Automation, the relevant prompt, selected context, files, and output may be processed by the configured AI provider. Bondi currently supports processing through Google Cloud/Vertex AI and may route eligible requests to Anthropic or OpenAI depending on the selected capability, availability, and configuration.

AI output can be inaccurate. Customers are responsible for reviewing generated systems, decisions, communications, and automations before relying on them, especially where a person could be materially affected.

5. Service providers and disclosures

We disclose information only as needed to operate Bondi, follow customer instructions, complete a transaction, protect the Service, or comply with law. Current core provider categories include:

ProviderPurpose
Google CloudApplication runtime, secrets, monitoring, archives, and selected AI/document processing
CloudflareDNS, edge delivery, Workers, realtime services, abuse protection, and object storage
NeonManaged PostgreSQL databases
StripeSubscription billing, payments, invoicing, fraud controls, and tax calculation
ResendTransactional and customer-configured email delivery
Google AnalyticsConsent-based marketing-site analytics
Anthropic and OpenAIAI processing when the applicable model or fallback is used
ContentfulPublication of careers content

Customer-configured integrations send data to the provider selected by the customer under that provider’s terms. We may also disclose information to professional advisers, authorities when legally required, and a successor in a merger, financing, reorganization, or sale subject to appropriate protections.

Bondi does not sell personal information. Bondi does not use Customer Data for third-party advertising. If applicable law treats consent-based analytics as “sharing,” you can decline analytics through the cookie controls and we honor applicable opt-out signals where required.

6. International transfers

Bondi and its providers operate in multiple countries. Product data may be processed in the region configured for the Service and in other locations needed for support, security, billing, integrations, or AI processing. We do not promise that all data remains in one country unless that commitment appears in a signed Enterprise agreement.

Where data-protection law requires a transfer mechanism, Bondi uses an applicable mechanism such as adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK addendum, or another lawful safeguard.

7. Retention and deletion

We retain information for as long as needed to provide the Service, maintain security and audit records, process billing, comply with law, resolve disputes, and enforce agreements.

  • A Trial begins when the first Workspace is created. After Trial expiry, read-only and export access remain for 30 days before the account is queued for deletion.
  • A canceled subscription remains active through its paid period, followed by 30 days of read-only and export access before deletion.
  • An account restricted after a payment failure remains in view-only mode while collection or recovery continues. The deletion period begins only if the subscription is canceled or the account is terminated.
  • Billing, tax, fraud, security, referral, and legal records may be kept longer where required or reasonably necessary.
  • Provider-level backups and recovery copies expire under their lifecycle policies and are not restored for ordinary product use after deletion.

Customer-purchased Wallet balance does not expire while the account remains available, but is not redeemable for cash. A customer should export records it must retain before its access period ends.

8. Security

Bondi uses tenant isolation, authenticated services, permission controls, managed secrets, audit records, HTTPS/TLS, provider storage encryption, monitoring, and backup and restore processes. No internet service is completely secure. See Security at Bondi and our Responsible Disclosure Policy for more detail.

9. Your privacy rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection, to withdraw consent, or to appeal a decision. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive-information uses, and receive equal service when exercising a right.

Send requests to privacy@heybondi.com. We may need to verify your identity and authority. If Bondi processes the information only for a customer, we may direct the request to that customer. Rights are subject to legal exceptions, and you may contact the relevant supervisory authority if you believe a request was handled improperly.

10. Cookies and analytics

The website uses essential storage for security, preferences, and consent choices. Google Analytics is enabled only after analytics consent. You can change the choice using the cookie control on the site or clear the saved site data. See our Cookie & Consent Policy.

11. Children

Bondi is a business service and is not directed to children under 18. Do not submit a child’s personal information unless your organization has a lawful basis and has configured appropriate protections. Contact us if you believe a child submitted account information directly to Bondi without authorization.

12. Changes and contact

We may update this policy as the Service or law changes. We will update the date above and provide additional notice where required for a material change.

Bondi Labs, Inc.

2803 Philadelphia Pike, Suite B #356

Claymont, DE 19703, United States

privacy@heybondi.com