We're committed to protecting your privacy and being transparent about how we collect, use, and safeguard your data.
Last Updated: August 27, 2026
This Privacy Policy describes how Bob ("we," "us," or "our") collects, uses, stores, and protects information when you visit our marketing website or use Bob services. Non-essential marketing analytics require an affirmative choice; using the website does not itself constitute analytics consent. Your use of Bob is also subject to our Terms of Service.
We collect information you choose to provide when you contact us, request services, or book a meeting, such as your name, email address, company information, and the contents of your message. Services we provide under a customer engagement may process the information described in the applicable engagement documents. Applications that include bank-to-general-ledger reconciliation features also process financial account data connected through Plaid, as described in the section titled "Financial Account Data (Plaid)" below.
We may process technical and usage information needed to operate, secure, and improve our website and services. On this marketing website, non-essential analytics and campaign attribution remain disabled unless you explicitly allow analytics.
Essential browser storage remembers your privacy preference. If you allow analytics, we may also use analytics storage to understand website usage and campaign performance. The Privacy choices control on every page lets you allow or decline non-essential analytics at any time.
If you allow analytics, the website preserves an opaque session identifier, original capture time, sanitized landing pathname, and the exact referring origin for a cross-site referral. External referrer paths, queries, and fragments are discarded. It may also preserve Google click identifiers (gclid, gbraid, or wbraid) and the five standard UTM fields (source, medium, campaign, term, and content). It records the first and latest explicit inbound campaign touch for no more than 30 days from the original landing, even when consent is granted later. Values are normalized and decoded in bounded layers; literal, recursively encoded, Unicode-confusable, control, email, and phone patterns, including decimal digits from any script, are rejected. Before consented analytics scripts load, the website removes the query and fragment from browser history. If the original browser document still exposes an unsafe native referrer, trackers remain off while the site performs at most one sanitized same-origin reload after consent. If the new document cannot prove that referrer is safe, analytics remains visibly disabled. The site does not retain arbitrary query parameters, URL queries or fragments, URL credentials, or an email address in this attribution record.
Booking links may carry the preserved five UTM fields to Calendly after analytics consent. We do not add Google click identifiers, the opaque website session identifier, or a static Bob campaign that could overwrite paid-ad attribution. If you have allowed analytics, the booking link's utm_content field carries an opaque, randomly generated correlation token, alongside the original utm_content value in encoded form, so that a completed booking can be associated server-side with the website visit that produced it. The token contains no personal information and is not derived from any identifier; without analytics consent no token is created. A booking-link click is an intent signal only; it is not labeled as a lead, completed booking, or conversion. Calendly processes the booking information you submit under Calendly's own privacy terms.
When the separately approved measurement endpoint is enabled, the website can send versioned consent choices, the bounded attribution record, and booking-button placement to Bob's first-party PPC system using a server-side request signed by an AWS-managed P-256 key. The private key is not available to the browser or the PPC receiver. This handoff does not include the booking form details you enter in Calendly and is disabled when the endpoint is not configured. A Calendly booking completion is not inferred from this browser handoff.
When the separately approved first-party measurement endpoint is enabled and you have allowed analytics, we may record a sanitized page pathname, actively visible and focused time in bounded summaries, a maximum scroll bucket, and a small allowlist of meaningful sections after at least half of a section has been visible for one second. We do not collect cursor movement, keystrokes, form contents, arbitrary page text, full URLs, queries, fragments, screenshots, session replay, browser fingerprints, or chat prompts and responses. For the custom chat demo, we record only that a first message was sent and, once returned authoritatively by the chat service, an opaque conversation reference. The browser does not emit chat-response, sales-handoff, ClickUp-lifecycle, or chat-specific booking-button states.
Linkable consented journey and conversation-reference data is retained for no more than 30 days unless a separately reviewed policy changes that period. De-identified daily aggregates may be retained for up to 13 months for reporting. Access to the operator reporting surface is limited to authorized Bob personnel. If you withdraw analytics consent or a Global Privacy Control signal requires denial, the browser stops collecting this behavioral telemetry, clears unsent journey events, and prevents future correlation; the essential, versioned consent record remains only to honor and document that choice.
We use information to respond to inquiries, arrange meetings, provide agreed services, maintain business records, and operate and secure our website and systems.
We may use aggregated or de-identified information to improve service performance, develop capabilities, and identify and fix technical issues. Financial account data received through Plaid is excluded from these aggregated and de-identified uses. We do not use personal information or customer content to train generalized AI or machine learning models.
We may contact you to send service updates and important notifications, respond to your support requests, share relevant product announcements, and notify you of security or privacy updates.
We process your data as necessary to comply with legal obligations, protect against fraud and abuse, enforce our terms of service, and respond to valid legal requests.
We use reasonable technical and organizational measures designed to protect information, including encryption in transit, access controls, and logging appropriate to the systems and information involved. For applications that process financial account data, we require multi-factor authentication and limit access to those with a business need, and Bob will encrypt that data at rest and maintain an information security program aligned with the FTC Safeguards Rule, including a designated security lead and periodic risk assessments. No method of transmission or storage is completely secure.
We use cloud infrastructure and service providers appropriate to the services we provide. Access to business systems is limited to authorized personnel and providers that need it to perform their work.
We retain personal information for as long as reasonably necessary for the purposes described in this policy, to provide agreed services, and to meet legal, accounting, or reporting obligations. The marketing website's linkable consented attribution and journey records are retained for no more than 30 days from original capture; de-identified daily reporting aggregates may be retained for up to 13 months.
Where an agreed service uses AI models, we may use third-party AI service providers to process the information necessary to provide that service. The applicable service scope and customer agreement govern the information involved. We do not use customer content to train generalized AI or machine learning models.
We use service providers for cloud hosting, infrastructure, and website analytics. On the marketing website, Google Tag Manager and Apollo analytics load only after you explicitly allow analytics. You can later withdraw that choice through the Privacy choices control.
Some applications we build and operate for business clients include bank-to-general-ledger reconciliation features. To power those features, authorized users can connect financial accounts through Plaid Inc. ("Plaid"), a third-party financial data network. When you connect an account, Plaid's Link interface identifies Plaid, shows you the specific data being requested and the purpose it will be used for, and captures your authorization before any data is shared with us. We do not receive or store your online banking credentials; you provide them directly to Plaid or to your financial institution.
Through Plaid we receive read-only financial account data for the accounts you choose to connect: transactions, account balances, and investment holdings. Our Plaid integration cannot initiate payments, transfers, or any other movement of money, and we do not request write access of any kind.
We use financial account data solely to provide the reconciliation functionality the client organization has engaged us to deliver: matching bank activity against general-ledger records, surfacing discrepancies, and producing reconciliation reports. We do not sell, rent, license, or share this data with third parties except the service providers necessary to operate the application, we do not use it for advertising, and we do not use it to train, fine-tune, or improve AI or machine learning models. If we ever need this data for a new purpose, or need a new type of data, we will present a fresh consent flow before collecting or using it.
Plaid collects and processes your financial data under its own End User Privacy Policy, available at https://plaid.com/legal/, and we encourage you to review it. You can view and manage the connections you have made through Plaid, including revoking access, at https://my.plaid.com.
Financial account data received through Plaid is stored in the client-scoped application database of the organization whose application you are using, hosted on Amazon Web Services. It is not joined with other clients' data or with Bob's own marketing or advertising data. It is encrypted in transit, and Bob will encrypt it at rest. Access is limited to the authorized users of that client organization and to Bob personnel who need it to operate the application, and multi-factor authentication is required for the financial applications we build.
We retain financial account data only as long as needed to provide the reconciliation service to the client organization. When a user or administrator disconnects a financial account, or when a client engagement ends, Bob will remove the connection at Plaid and delete the stored financial account data from the application database within 30 days, except where retention is required by law. Because these applications are operated for business clients, we may fulfill individual requests in coordination with the client organization that controls your deployment; you can also contact us directly using the details at the end of this policy.
Bob AI Co, Inc. advertises its own consulting services. To plan, govern, and report on that advertising, our use of the Google Ads API is limited to the single Google Ads account that Bob AI Co, Inc. owns and uses to advertise Bob.pro. No other Google Ads account, including any account belonging to a client, prospect, or other third party, is reached through the Google Ads API or through our internal tooling: the boundary is enforced by a single-account allowlist in the application's own code, not by policy alone. Bob AI Co, Inc. does separately manage Google Ads for a small number of clients — as of the date of this policy, one — in each client's own account and under that client's written authorization. That work sits outside the API access and the internal tooling described in this section, is kept separate from Bob AI Co, Inc.'s own advertising data, and is described further in our Terms of Service.
Explorer-level Google Ads API access is live for Bob AI Co, Inc.'s own account, and Bob AI Co, Inc. is running and paying for its own advertising. We use reads for reporting on that account. The internal tooling can also apply a deliberately narrow set of changes to that same account, and it does so only through a guarded process: a person reviews and explicitly approves each change, an independent automated verifier checks it, and a one-time authorization is required before it is applied. Nothing is applied to the account autonomously. We have applied to Google for Basic Access; the human-approval requirement applies regardless of access level. The current status is also published on our About page.
Our Google Ads API access is scoped to the single Google Ads account Bob AI Co, Inc. owns. We use reads for reporting on that account, and changes to the account are made only through a guarded process that requires explicit human approval before anything is applied. The pinned queries in our application retrieve account structure and configuration, including campaign, ad group, keyword, ad, asset, conversion-action, and change-history records, as well as the performance data needed to interpret our advertising, including impressions, clicks, cost, conversions, and search-term reports. We do not retrieve personal information about end users through the Google Ads API, and we deliberately exclude fields that would return personal data, including change-history user email addresses.
Google Ads API data is stored in infrastructure Bob AI Co, Inc. controls, hosted on Amazon Web Services in the us-east-1 region, encrypted in transit and at rest. Access is restricted to authorized Bob AI Co, Inc. personnel behind single sign-on, and access is logged. There is no client portal, no external reporting surface, and no signup.
We use this data solely to plan, measure, report on, and prepare human-reviewed recommendations for Bob AI Co, Inc.'s own advertising, and to apply the account changes a person has approved. We do not sell, rent, license, or share it with third parties, and we do not use it to train, fine-tune, or improve AI or machine learning models. It is held separately from data we process for clients and is not joined with customer data.
We retain our own Google Ads performance data for as long as it is useful for budget, trend, and year-over-year analysis of our advertising, and we review it periodically and delete records that are no longer needed for that purpose. If our Google Ads API access is terminated or we stop advertising, we cease retrieving new data and delete or archive what we hold in accordance with the Google Ads API Terms of Service.
This access concerns Bob AI Co, Inc.'s own advertising account. We use the data only for our own advertising operations and do not use it to target, profile, or advertise to visitors or customers.
You may request access to personal information we hold about you. Contact us to make a request.
You may request correction or deletion of your personal information, subject to legal and other legitimate retention requirements.
You may object to certain data processing activities. You can opt out of non-essential analytics and marketing communications. Contact our privacy team to exercise these rights.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, use, and share; the right to request deletion of your personal information; the right to opt-out of the sale of personal information (note: we do not sell personal information); and the right to non-discrimination for exercising your privacy rights.
To exercise these rights, contact us at the information provided at the end of this policy. We will verify your identity before processing your request. We aim to respond to all verified requests within 45 days.
Our service providers may process information in the United States and other countries. Where applicable, we use safeguards required by law for international transfers.
Individuals in the EEA, UK, or Switzerland may have privacy rights under applicable law. Contact us to exercise rights or ask questions about processing.
Bob is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover we have collected information from a child under 13, we will delete it immediately. Parents or guardians who believe we have collected information from a child under 13 should contact us immediately.
We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. We will post the updated policy here and revise the date above.
We maintain a version history of our Privacy Policy. You can request previous versions by contacting our privacy team.
Essential storage supports authentication where applicable, remembers privacy preferences, and may hold a one-attempt referrer-cleanup reload marker that contains no campaign or personal data. Analytics storage, including Google Tag Manager or Apollo-related storage, is optional and loads only after affirmative consent on the marketing website and a successful browser referrer safety check.
Use the Privacy choices control displayed on every marketing page to allow or decline analytics. Before a choice, all four Google Consent Mode storage and advertising dimensions are denied and analytics vendors do not load. Allowing analytics grants analytics storage only; advertising storage, ad user data, and ad personalization remain denied. Opting out immediately returns those dimensions to denied, removes Bob attribution storage, known first-party analytics storage and cookies accessible to the page, loaded tracker elements, and queued analytics events, then reloads to stop tag code. A minimal opaque, versioned revocation may remain temporarily so the first-party system can retry recording the withdrawal; the essential preference remains so the choice is honored. Browser JavaScript cannot delete HttpOnly cookies, partitioned storage, or storage owned by third-party domains, so browser or vendor controls may still be required. Declining analytics does not prevent you from viewing the website, using the custom chat demo, or opening a Calendly booking link.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us.
Bob AI Co, Inc. Privacy Team
Email: william@bob.pro
707 West Jones Street, Raleigh, NC 27603
Essential storage remembers this choice. With your permission, analytics also preserves bounded campaign attribution and loads Google Tag Manager and Apollo. Booking links still work if you decline. Read the privacy policy.