Privacy
Embed-only chat. You assert identity. You own moderation.

Identity
We do not authenticate end users. Pass a user object with an opaque stable id from your session. Optional name, email, and avatarUrl are display metadata only. Anonymous chat is not supported. Details: identity docs.
BYO vs Hosted content
- BYO: message bodies and file bytes never leave your systems via the Bootstrapware data path. We host app configuration only.
- Hosted: messages and attachment objects are stored on Bootstrapware. Plain text and files. You moderate; you are responsible for content. 1 GB included. Optional $9.99 add-on raises the cap to 10 GB. Uploads freeze at the cap; text still works.
- Local demo: adapters keep messages in the browser (for example localStorage).
What MCP never receives
MCP configures apps only. Do not send message body or file bytes through MCP tools. See AGENTS.md.
Cancel Hosted
If you cancel Hosted: writes freeze (including uploads), you can export for 30 days, then Hosted messages and objects are deleted. The storage add-on cancels with Hosted. The same timeline is stated on billing and Terms. Guide: moderate Hosted chat.
What you still own
Authentication, authorization, rate limits on your app, and (for BYO) retention of messages and files. For Hosted, moderation and lawful content remain your responsibility. We do not virus-scan attachments.
See also security, attachments, and the company privacy policy.