Privacy Policy
This Privacy Policy explains how Open Session Inc. ("Open Session", "we", "us" or "our") collects, uses and shares personal information through bos.live and through BOS, the brand operating system we build and run. It also explains the choices and rights you have. "Personal information" means information that identifies you or could reasonably be linked to you.
Please read it together with our Terms of Service. To the extent the law allows, any dispute about this policy or about how we handle personal information is subject to the Terms of Service, including their limitation of liability and dispute resolution sections.
1. Who we are
BOS is provided by Open Session Inc., a Delaware corporation based in San Diego, California. For the personal information this policy describes, Open Session decides how and why it is used, which makes us the "controller" under EU and UK law, except where section 2 explains that we act for a customer.
You can reach us about anything in this policy at hello@opensession.co.
2. What this policy covers, and our role
This policy covers:
- bos.live, our public website for BOS, including the BOS waitlist;
- the BOS app at app.bos.live;
- our API and the BOS MCP server at api.bos.live, and our sign-in service at auth.bos.live;
- the emails we send about BOS.
It does not cover opensession.co, the website of our design studio, which has its own Privacy Policy (opens in a new tab). That includes the contact form on opensession.co, which the "Contact us" button on bos.live leads to, and email sign-ups on opensession.co, even when those emails are about BOS. It also does not cover services you connect to BOS or AI tools you allow to read your brand. Their own policies apply.
Workspaces and customers. BOS is a tool for businesses. Each workspace belongs to a customer, usually a company or a team. The customer's admins invite members, assign roles and decide what goes into the workspace.
Workspace content means everything you and your colleagues upload to, create in or submit to a workspace, such as brand assets, documents, chats with the assistant, AI inputs and outputs and generated files, plus what BOS derives from them, such as embeddings, extracted text, thumbnails and previews. Our Terms of Service call this "Customer Content".
We handle personal information in two roles:
- For our own purposes. We decide how we use account and profile information, sign-in information, usage and device information, analytics and session recordings, security logs, waitlist answers, and your communications with us. This policy describes that use.
- For the customer. We process workspace content on behalf of the customer that owns the workspace, to provide BOS to it. If you use BOS through your organization's workspace, your organization controls that content, and we may act on its admins' instructions, for example to remove a member or to answer a request about workspace content.
There is one exception to the second role. Our session recordings (section 9) can capture workspace content that appears on your screen, and we use those recordings for our own purpose: to understand and improve BOS.
If your organization needs data processing terms, contact us at hello@opensession.co.
3. Our commitments at a glance
- We do not sell your personal information for money, and we do not show ads in BOS or on bos.live. On bos.live, the Google Analytics settings described in section 9 may allow Google to use some information for its own purposes, including advertising-related purposes. You can turn them off at any time through Cookie settings.
- We do not use workspace content, or information we receive from Google, for advertising.
- Open Session does not use your workspace content, or anything derived from it, to train or improve AI models. The AI model providers that power BOS's AI features handle requests under their own terms, as section 7 explains.
- BOS's use of information received from Google APIs will adhere to Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements.
- Open Session Inc., not the services you connect, is responsible for the data BOS collects or accesses from those services.
- We tell you in advance about material changes to this policy, as section 15 explains.
4. Information we collect
When you visit bos.live
- Technical information. Your browser sends standard information with each request, such as your IP address, browser and device type, the page you asked for and the time. Our hosting provider processes it to deliver pages and protect the site.
- Analytics. Depending on where you are and the choices you make, Google Analytics collects information such as the pages you view, how you arrived, how you interact with pages, your device and browser type, and your approximate location, which Google works out from your IP address (section 9).
- Your cookie choices. Each time a page loads, your browser contacts Inth, which runs our cookie consent service. Inth uses your IP address and browser details to work out which privacy rules apply where you are. If you make a choice about cookies, Inth keeps a record of it for us (section 9).
The animated Remi character on bos.live runs entirely in your browser. It does not send anything you do or type to us or to any AI provider.
When you join the waitlist
The waitlist asks for:
- your email address, which is required, and your name, which is optional;
- whether you would use BOS for your own brand or for clients' brands, and what you would like to use it for;
- the names of your workspace and your brand;
- where your brand files live today, such as Figma, Google Drive, Dropbox or Notion.
Choosing where your files live only tells us about your setup. It does not connect BOS to those services or give us access to them. Your answers stay in your browser until you submit the form on the last step, when they are sent to us together.
When you use BOS
- Account information. Your email address and password, if you create an account with them. Our sign-in provider stores your password in hashed form, not as readable text.
- Google sign-in information. If you sign in with Google: your name, email address, profile photo and Google account ID (section 6).
- Profile information. Details you choose to add, such as a display name, username, first and last name, photo, job title, phone number, website, short bio, time zone, language and an alternate email address, and your notification settings.
- Workspace information. The workspaces you belong to, your role in each, and invitations. If a colleague invites you, they give us your email address, and our sign-in provider emails you the invitation.
- Workspace content (section 2).
- Derived information. What BOS creates from workspace content, such as embeddings (numerical representations used for search), extracted text, thumbnails and previews, and suggested names, descriptions and tags.
- Usage and device information. Your IP address, browser and device details, the pages and screens you use, what you click, errors in your browser, request and security logs, and session recordings (section 9).
- AI tool authorizations. Records of the AI tools you allow to read your brand through the BOS MCP server (section 6).
- Records. Records of your acceptance of our Terms of Service, including the organization, the version and the time.
- Communications. Messages you send us, such as support or privacy requests.
To create an account, you need to give us an email address and a password, or sign in with Google. Other profile details are optional.
Files you upload may contain metadata, such as the time and place a photo was taken, and that metadata may be stored with the file.
Your profile photo, whether you add it in BOS or it comes from your Google account, can be viewed by anyone who has its link.
We do not buy personal information from data brokers.
5. How we use information
We use personal information to:
- provide and operate bos.live and BOS, including accounts, sign-in, workspaces, invitations and AI features;
- run the waitlist, and contact you about early access to BOS and about BOS generally;
- send service messages about your BOS account, such as email address verification, password resets and invitations;
- answer your questions and requests;
- understand how bos.live and BOS are used and improve them, through analytics, measurement and session recordings;
- keep bos.live and BOS secure, prevent abuse, and find and fix errors;
- enforce our Terms of Service and protect our rights and the rights and safety of others;
- comply with the law.
On a customer's behalf, we also store workspace content, show it to the right members, and run AI features on it when you use them (section 7).
If we send you news about BOS by email, you can ask us to stop at any time by writing to hello@opensession.co.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you.
6. Google sign-in and other services you connect
Open Session Inc. is responsible for the privacy, security, and integrity of the data BOS collects or accesses from services you connect.
We do not sell information we receive from services you connect, use it for advertising or to decide anyone's creditworthiness, or use it to train AI models.
Signing in with Google
What we receive. When you choose to sign in with Google, Google asks you to share your name, email address and profile photo with BOS. We receive those and your Google account ID. When you sign in, BOS does not request access to your Gmail, Calendar, Google Drive or contacts, and BOS does not store the access token Google issues at sign-in.
How we use it. To create your account, sign you in, show your name and photo in BOS, and keep your account secure. We also send your BOS account ID, email address and role to our product analytics provider, PostHog, so we can understand how BOS is used (section 9).
Where it is stored and who sees it. We store it with your account in our database and sign-in service, run by Supabase. Members of your workspaces can see your name, email address and photo, and anyone who has the link to your photo can view it (section 4). Otherwise, we share it only as section 8 describes.
How long we keep it. For as long as your account exists (section 10). Your email address and BOS account ID may also stay in our product analytics records for the period section 10 describes for analytics.
Removing access. You can remove BOS's access to your Google account at any time at https://myaccount.google.com/permissions (opens in a new tab). That does not delete your BOS account. To delete your account, contact us (section 10).
Our commitment under Google's policies
BOS's use of information received from Google APIs will adhere to Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy (opens in a new tab), including the Limited Use requirements. (See also Google's Workspace API User Data and Developer Policy (opens in a new tab).)
Open Session does not use data obtained through Google Workspace APIs, or anything derived from it, to develop, improve, or train non-personalized AI or machine-learning models.
AI tools you connect to BOS
You can allow a third-party AI tool, such as Claude or Cursor, to read a brand in BOS through the BOS MCP server. The tool can then read that brand's guidelines, documents and brand assets.
- Access tokens last one hour, and refresh tokens up to 30 days.
- You can revoke a tool's access at any time in your BOS settings.
- We delete the authorization record 30 days after it is revoked or expires.
The tool is run by its provider, not by us. Its own terms and privacy policy govern what it does with the information it receives.
Figma
Open Session Inc., and not Figma, is responsible for the privacy, security, and integrity of any Figma data (Integration Data) that BOS processes.
BOS does not index your Figma files, enumerate your team's files, or bulk-copy file content. Open Session does not use Figma data to train AI models. BOS does not currently import files through Figma's API.
New connections
Before you can connect any other service to BOS, for example to import files, we will describe in this policy what BOS accesses from it and how we use that information.
7. AI features
BOS includes AI features, including an assistant called Remi. Remi is an AI system, and its outputs can be inaccurate. Check anything important before you rely on it.
Open Session does not use your workspace content, or anything derived from it, to train or improve AI models. That includes your inputs, the assistant's outputs and the files you upload.
How your content reaches AI models. BOS sends AI requests through OpenRouter, our AI gateway. OpenRouter passes each request to a third-party provider that runs the model. That provider may be the company that made the model, or another company that hosts it. The model picker in BOS shows which model you are using. When a model is chosen automatically, including for some background tasks, OpenRouter chooses the model and the provider. The models available in BOS include models made by Anthropic, OpenAI, Google, DeepSeek, Alibaba (Qwen), Meta (Llama) and Moonshot AI (Kimi).
Provider terms. OpenRouter and these providers process requests under their own terms. Those terms may allow them to keep requests for a period of time and, for some providers, to use them to improve their models.
What we send to AI models. Depending on the features you use:
- Chat. Your messages, the conversation so far, attachments and images, the brand context the assistant needs, and the results of the tools it runs.
- Automatic descriptions. When you add assets such as logos, images, colors or typography, or a document, an AI model may read them to suggest names, descriptions and tags.
- Color and theme tools. When you use them, the images you choose are sent to an AI model.
- Search. To make your workspace searchable, BOS creates embeddings of content such as chat messages, document text, search queries and images, using Google's Gemini embedding model through OpenRouter.
- Document import. When you add a document, an AI model may read its text to organize it.
- Text extraction. When BOS needs to read the text in a PDF or image you upload, it may send the file directly to Mistral AI. BOS then deletes the file from Mistral on a best-effort basis. Mistral may keep information under its own terms.
- Web search. If you turn on web search, the assistant's search queries, which are based on your messages, are sent through OpenRouter to the search service it uses, and the results are added to your chat.
- Other helper tasks. BOS may send parts of your content, such as the start of a chat or a request you make, to an AI model for smaller tasks, such as suggesting a title or working out which assets a request refers to.
Monitoring. To find and fix problems, we may record AI requests and responses, together with account, workspace and brand identifiers, in a monitoring tool run by a service provider.
Session recordings. Our analytics provider may use AI models to summarize and analyze session recordings, which can show workspace content (section 9).
8. How we share information
We share personal information only as this policy describes. We do not sell it for money.
Service providers
These companies process personal information to provide their services to us. OpenRouter, the AI model providers and Mistral AI also handle what they receive under their own terms, as section 7 explains.
- Vercel hosts bos.live and the BOS app, and measures page views and performance in the BOS app without cookies (Vercel Web Analytics and Speed Insights).
- Railway hosts our API and background jobs.
- Cloudflare delivers and protects traffic to the BOS app and API.
- Supabase runs our database, sign-in service and file storage in the United States. It also sends BOS account emails, such as email address verification, password resets and invitations, directly or through an email delivery service.
- OpenRouter routes AI requests to the model providers described in section 7, which process them to generate responses, descriptions and embeddings.
- Mistral AI may extract text from PDFs and images (section 7).
- PostHog provides product analytics and session recording for the BOS app, and may use AI models, including Google's Gemini models, to summarize and analyze recordings for us (section 9).
- Inth runs our cookie consent service for bos.live (section 9).
- Other service providers may help us monitor errors and performance, record AI requests for troubleshooting (section 7), and manage mailing lists, including the waitlist.
Other recipients
- Your workspace. Members see workspace content according to their roles, and can see your name, email address and photo. Admins manage membership.
- AI tools you authorize receive the brand information you allow them to read (section 6).
- Google. Google Analytics on bos.live collects information as section 9 describes. In the BOS app, font previews load from Google Fonts, and website icons in the chat's links and sources views load from Google. With these requests, Google receives your IP address and browser details, and your browser may send Google's own cookies.
- Legal and safety. Authorities or others, where we believe in good faith that the law requires it, or where it is needed to protect people, bos.live, BOS, or our rights.
- Business transfers. Another company, if we are involved in a merger, acquisition or sale of assets. Where Google's policies require it, we will ask for your consent before we transfer information we received from Google APIs in such a transaction.
- Professional advisers, such as lawyers, accountants and auditors, under duties of confidentiality.
- Others, with your consent or at your direction.
We may also use and share information that has been aggregated or de-identified so that it can no longer reasonably identify you, for example statistics about how many workspaces use a feature.
9. Cookies and similar technologies
Cookies are small files a website stores in your browser. Your browser's local storage works in a similar way. This section explains how bos.live and the BOS app use them.
Analytics on bos.live
We use Google Analytics to understand how people use bos.live. Google's tag loads on every page. What happens next depends on where you are, which Inth works out from your IP address:
- Where we ask first, including the EU, the EEA and the UK. We show a cookie notice. Google Analytics sets no cookies until you accept.
- California. We show a cookie notice. Analytics cookies are set unless you turn them off.
- Elsewhere, including Switzerland and US states other than California. Analytics cookies are set by default, and we do not show a cookie notice unless you open Cookie settings.
Whenever analytics cookies are off (where we ask first and you have not accepted, after you turn them off, or because your browser sends a GPC signal), Google's tag still loads and may send Google limited measurement requests without cookies. Like any web request, these include your IP address and browser details. To stop Google Analytics on bos.live entirely, use Google's opt-out add-on (see Your choices below).
In California and everywhere else analytics cookies are set by default, the consent settings we send to Google also allow Google's advertising-related storage and signals. In those places, if your browser sends a Global Privacy Control (GPC) signal, we treat it as a choice to turn off analytics cookies and these advertising settings. To learn how Google uses information from sites that use its services, see How Google uses information from sites or apps that use our services (opens in a new tab).
Cookies and storage on bos.live
- _ga and _ga_KZNB7CM5CD (set by Google Analytics, only when analytics cookies are allowed): distinguish visitors and sessions. Up to 2 years. Some browsers limit them to a shorter period.
- c15t (a cookie and a local storage entry): remembers your cookie choice, when you made it, and a random identifier for your choice. Set only when you make a choice. Lasts 1 year.
- Temporary local storage entries beginning with c15t: briefly hold a choice that could not yet be sent to Inth, until it can be sent.
Your consent record. When you make a choice, Inth keeps a record of it for us. The record includes your choice, a random identifier, the time, the privacy rules that applied in your region, and a reference to the consent settings in force at the time. It may also include your country or region and your browser's language. We use it to show that we respected your choice.
The PostHog cookie. If you use the BOS app, the PostHog cookie described below is set for the whole bos.live domain, so your browser may also send it when you visit bos.live. Nothing on bos.live uses it.
Cookies and storage in the BOS app
- bos_access_token, bos_refresh_token and bos_expires_at (set by api.bos.live): keep you signed in. 7 days. Strictly necessary.
- bos_csrf_token (set by api.bos.live): protects against cross-site request forgery. 7 days. Strictly necessary.
- bos_oauth_verifier (set by api.bos.live): completes Google sign-in securely. 10 minutes. Strictly necessary.
- bos_session_hint (set by app.bos.live): tells the app you are signed in. 24 hours. Strictly necessary.
- locale (set by app.bos.live): remembers your language. 1 year. Functional.
- A PostHog cookie whose name starts with ph_ and ends with _posthog: an analytics identifier and session ID. 1 year. Analytics.
The app also uses your browser's local storage to remember your active workspace and its theme and your interface preferences, such as panel widths and dismissed tips, to keep unsaved changes to documents on your device until you save them, and to hold PostHog's analytics state.
Analytics and session recording in the BOS app
The BOS app runs PostHog for every visitor, signed in or not. PostHog collects:
- the pages you visit;
- what you click, including the text of the element you click;
- errors in your browser;
- device and browser details, and your IP address, which PostHog receives with each request and may use to estimate your approximate location.
PostHog may also record your sessions: what appears on your screen and how you move through the app. Recordings can include the text on screen, including documents you write or read and chat messages. Only text you type into form fields, such as passwords and search boxes, is hidden. When you sign in, we link this information to your BOS account ID, email address and role. PostHog stores it in the United States. PostHog may use AI models, including Google's Gemini models, to summarize and analyze recordings for us.
Vercel Web Analytics and Speed Insights count page views and measure performance in the app without cookies.
Tracking across websites
When you use the BOS app, we do not allow third parties to collect personal information about your online activities over time and across different websites, except that Google receives the requests described in section 8. Our analytics providers for the app, PostHog and Vercel, collect information only on BOS, for us. On bos.live, Google may collect information about your online activities over time and across different websites through Google Analytics, as described above. You can limit this through Cookie settings, a GPC signal or Google's opt-out add-on.
Your choices
- Cookie settings on bos.live. Use the Cookie settings link in the footer of the bos.live home page and legal pages to review or change your choice at any time.
- Global Privacy Control. bos.live treats a GPC signal as a choice to turn off analytics cookies and Google's advertising settings, as described above. The BOS app does not currently respond to GPC. In the app we do not sell or share personal information, as California law defines those terms, so there is nothing for a GPC signal to opt you out of.
- Analytics in the BOS app. The app does not offer a setting to turn off analytics or session recording, and we cannot yet turn them off for one person while they use the app. You can object, or ask us to delete the analytics information and recordings linked to your account, by emailing us (section 13).
- Browser settings. You can block or delete cookies and local storage in your browser. Blocking the BOS sign-in cookies will sign you out, and when you sign in again, PostHog links your activity to your account again.
- Google's opt-out tool. Google offers a browser add-on (opens in a new tab) that stops Google Analytics from collecting information about your visits.
- Do Not Track. Neither bos.live nor the BOS app responds to "Do Not Track" signals.
10. How long we keep information
We keep personal information for as long as we need it for the purposes in this policy, and then delete it or de-identify it. In particular:
- Account and profile information: for as long as your account exists.
- Workspace content: until you or your workspace delete it.
- Items deleted in BOS, such as messages, chats, assets, documents, projects and brands: permanently deleted about 30 days after deletion, except for the related data described below.
- Earlier versions of documents and assets: we keep the 20 most recent versions. Older versions are deleted once they are more than 12 months old.
- Records of tools the assistant runs: their inputs and outputs are cleared after 90 days.
- Uploads you start but do not finish: moved to the trash after 24 hours, then permanently deleted about 30 days later.
- Temporary files BOS generates for rendering: 24 hours.
- AI tool authorizations: access tokens last one hour and refresh tokens up to 30 days. Authorization records are deleted 30 days after they are revoked or expire.
- A deleted workspace: its content is permanently deleted about 30 days after the workspace is deleted, except for the related data described below.
- Waitlist answers: until you ask us to remove them, or until we no longer need them to manage early access to BOS. Copies in our hosting provider's logs are deleted automatically on its schedule.
- Analytics and session recordings: for as long as we need them to understand and improve bos.live and BOS, within the retention settings of our analytics providers.
- Cookie consent records: for as long as we need them to show that we respected your choices.
- Hosting and security logs: for limited periods set by our hosting providers.
- Information sent to OpenRouter, AI model providers and Mistral AI: kept by those companies under their own terms (section 7).
- Records of AI requests in our monitoring tool (section 7): for as long as we need them to find and fix problems, within that provider's retention settings.
- Your communications with us: for as long as we need them to answer you and keep a record of what we did.
Some data related to deleted items and workspaces can take longer to remove than the periods above, and some is not removed automatically. Examples are images attached to deleted chats, workspace logos, and information derived from deleted content, such as search data. You can ask us to remove it (section 13).
We may keep information for longer where the law requires it, or where we need it to resolve disputes, enforce our agreements or protect our rights. Deleted information may also remain in backups until those backups expire on their regular schedule.
Deleting your information
- Items in a workspace. Delete them in BOS. They are permanently deleted about 30 days later, except for the related data described above. Your workspace's admins may control what you can delete.
- Your account. BOS does not currently offer self-service account deletion. Email hello@opensession.co from the address on your account and ask us to delete it. Content you added to a workspace is workspace content that belongs to that workspace's customer, and it may stay in the workspace until the customer deletes it.
- A workspace. The workspace owner can ask us to delete it by emailing hello@opensession.co.
- AI tools you authorized. Revoke them in your BOS settings.
- Google sign-in. Remove BOS at https://myaccount.google.com/permissions (opens in a new tab). This does not delete your BOS account.
- Your waitlist entry. Email hello@opensession.co and ask us to remove it. Copies in our hosting provider's logs are deleted automatically on its schedule.
11. Security
We use technical and organizational measures designed to protect personal information. They include:
- encryption in transit (TLS) for information sent to and from bos.live and BOS;
- encryption at rest by our database and storage providers;
- sign-in cookies that page scripts cannot read and that are sent only over secure connections, plus protection against cross-site request forgery;
- PKCE, a safeguard that protects the Google sign-in flow from interception;
- role-based access within each workspace;
- private files served through short-lived signed links;
- refresh tokens for AI tools stored only in hashed form;
- rate limits that slow down abuse.
Members of our team who run BOS can access personal information and workspace content, and use that access to operate, support, troubleshoot and secure BOS. Our team may also review session recordings, which can show workspace content, to improve BOS.
No system is perfectly secure, and we cannot guarantee the security of your information. If a security incident affects your personal information, we will notify you as the law requires.
To report a security vulnerability, email hello@opensession.co.
12. International transfers
Open Session is based in the United States, and the main database and file storage for BOS accounts and workspaces are in the United States. Our service providers, including the hosting, AI, monitoring and consent services described in sections 7 to 9, may process personal information, including workspace content, in other countries where they or their own providers operate, including countries in Europe.
If you use bos.live or BOS from outside the United States, your information will be transferred to the United States and to other countries whose data protection laws may differ from those where you live. You can contact us for more information about these transfers and how we protect the information.
13. Your rights and choices
Your rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- give you the personal information you provided to us in a machine-readable format;
- correct inaccurate information (you can edit most profile details yourself in BOS);
- delete your personal information;
- limit how we use it;
- object to our using it for marketing, or for analytics and session recording.
Where we rely on your consent, you can withdraw it at any time. We will not treat you differently for using these rights. We may decline a request where the law allows, for example if we cannot verify your identity or must keep the information for legal reasons. If we do, we will tell you why.
California
If you live in California, the rights above include the rights California law describes: to know what personal information we collect, use and disclose, and to access, correct and delete it.
We collect these categories of personal information, from the sources in section 4, for the purposes in section 5, and we disclose them to the recipients in section 8:
- Identifiers, such as your name, email address, account IDs, cookie identifiers and IP address.
- Customer records information, such as your name, phone number and job title, if you add them.
- Professional information, such as your organization, role and job title.
- Internet or network activity, such as pages visited, clicks, session recordings, errors and logs.
- Approximate location, derived from your IP address.
- Audio, electronic or visual information, such as images and videos you upload, which may show people, and session recordings.
- Sensitive personal information, limited to your account login: your email address and password.
We keep each category for the periods in section 10.
We do not sell personal information for money. In the BOS app, we do not sell or share personal information, as California law defines those terms. On bos.live, where analytics cookies are on by default, the Google settings described in section 9 may allow Google to use information for advertising-related purposes under its own terms. You can turn off Google Analytics cookies and these settings at any time through Cookie settings, and we treat a GPC signal as a choice to turn them off, as section 9 describes. We use sensitive personal information only to provide BOS and keep it secure. We do not ask for your precise location. Photos you upload may contain location metadata, as section 4 explains.
The EEA, the UK and Switzerland
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases:
- Contract: to provide BOS to account holders who accept our Terms of Service, and to take steps you ask for, such as adding you to the waitlist.
- Legitimate interests: to provide BOS to members a customer invites; to keep bos.live and BOS secure and find and fix errors; to understand and improve BOS through analytics and session recording in the app; to run analytics on bos.live where we do not ask first, and to let Google's tag send the limited measurement requests without cookies described in section 9; and to tell business contacts about BOS.
- Consent: for Google Analytics cookies on bos.live where we ask first, and for marketing email where the law requires consent. You can withdraw consent at any time, for example through Cookie settings on bos.live.
- Legal obligation: to keep records and respond to lawful requests.
You can object at any time to processing based on our legitimate interests. We will stop unless we have compelling legitimate grounds or need the information to establish, exercise or defend legal claims. For analytics and session recording in the BOS app, we cannot yet stop collection for one person while they keep using the app. If you object to them, we will delete the analytics information and recordings linked to your account and tell you how we handled your objection. You can always object to marketing email, and we will stop sending it.
You can also complain to your data protection authority. In the UK, that is the Information Commissioner's Office. In Switzerland, it is the Federal Data Protection and Information Commissioner. We would welcome the chance to address your concern first. If you complain to us about how we handle your personal information, we will acknowledge your complaint within 30 days and tell you the outcome.
How to make a request
- Email us at hello@opensession.co. If you have a BOS account, write from the address on your account, and tell us what you would like us to do.
- Verification. We verify requests by confirming that you control the email address involved, and we may ask for more information if a request is sensitive. We use information you give us for verification only for that purpose.
- Authorized agents. Someone else can make a request for you with your signed permission. We may ask you to confirm your identity with us directly.
- Timing. We aim to respond within 30 days. If we need more time, we will tell you why. Either way, we will respond within the time the law that applies to you allows.
- Workspace content. If your request concerns content your organization controls, we may refer it to your workspace's admins or act on their instructions, because we hold that content for them.
- If we say no. If we decline your request, we will explain why. You can ask us to reconsider by replying to our decision.
14. Children
bos.live and BOS are intended for people aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us personal information, contact us at hello@opensession.co and we will delete it. We have no actual knowledge of selling or sharing the personal information of anyone under 16.
15. Changes to this policy
We may update this policy as bos.live and BOS change. The date at the top shows when it last changed.
- Material changes. If we make a material change, we will tell BOS account holders by email at least 30 days before it takes effect. Where practicable, we will also post a notice on bos.live during that time. We will post the updated policy on this page. A material change is one that uses personal information for a new purpose, shares it with a new kind of recipient, or reduces your rights or choices. Describing a new feature in this policy before you can use it is not a material change. Where the law requires it, we will ask for your consent before applying a material change to personal information we collected before the change.
- Changes required by law or for security may take effect sooner. We will tell you as soon as we reasonably can.
- AI training. We will not start using workspace content to train AI models through a change to this policy alone. We would ask for the customer's prior, express consent first, as our Terms of Service provide.
- Information from Google. Before we use information we receive from Google in a new way, we will ask for your consent.
Other changes take effect when we post them.
We publish this policy in English. If we provide a translation, the English version controls.
16. Contact us
For questions, requests or complaints about this policy or your personal information, email hello@opensession.co.
Open Session Inc., San Diego, California, United States.