Bouleia← Back

Legal

Privacy Policy

Pending legal review. Source of truth: spec/features/privacy.md.

Bouleia is a deliberation tool for hard questions. You convene a panel of three to seven frontier language models, assign each one a role, and ask a question. The council deliberates in parallel and returns a structured verdict. This policy describes what data we hold, where it lives, and how you can get it back or remove it.

What we collect

  • Account— your email address (used by Supabase Auth for magic-link sign-in) and a display name.
  • Council sessions— the question text you ask, the seat configuration (which models, which roles), and the per-session timing and cost metadata.
  • Seat responses and verdicts— the text each seat returns and the synthesised verdict, kept so you can re-read the deliberation later.
  • Custom role library— any custom roles you author for your own use (name, mandate, description), scoped to your account.
  • Custom council templates— any custom panel configurations you save (name, seat list), scoped to your account.
  • Waitlist contacts— for pre-launch signups via the marketing page, your email is added to a Resend audience and mirrored to our local table for suppression-list compliance.

Where it lives

All user data is stored in Supabase (Postgres) hosted in a single region. Every row is protected by row-level security policies so a session, response, or verdict is only ever readable by its owner. The council UI uses Supabase Realtime to stream updates to your browser; the same RLS policies gate what your browser sees.

Third-party sub-processors

  • Supabase— Auth, Postgres, Realtime. Receives all user data.
  • Anthropic / OpenAI / Google / Moonshot / Zhipu / DeepSeek / Alibaba— the LLM providers that power the council. Each seat’s assigned provider receives the question text and the seat’s role mandate for the duration of one deliberation. We do not opt in to any provider’s training-data sharing.
  • Resend— transactional email (magic-link delivery and waitlist).
  • Railway— the hosting platform.

Retention

  • Account data, sessions, seat responses, verdicts, custom roles, and custom templates persist while your account is active and are removed on account deletion.
  • Waitlist contacts are never hard-deleted; opt-out moves the row to unsubscribed and removes it from the active Resend audience.
  • Server logs are scrubbed of PII and rotate at 30 days.

Your rights

You can request a copy of your data or full account deletion by emailing support@bouleia.ai. Deletion cascades through every user-scoped table. Any matching waitlist record is preserved as unsubscribed for suppression-list compliance.

What we will not do

We do not sell, rent, or share your questions, seat responses, verdicts, custom roles, or custom templates beyond the sub-processors strictly required to deliver the service. We do not use your inputs to train models. We do not log question or verdict content in plaintext.

Contact

Questions about this policy: support@bouleia.ai.


Full legal review pending. Cross-border data residency controls, formal procedure for exercising Australian Privacy Principles 12 and 13, and the cookie policy will follow in the reviewed version.