Bootstrapwarebootstrapware

Privacy

Your server names the person. Storage depends on the plan.

Comments does not run end-user login and does not collect email addresses. Opaque ids can still identify a person inside your app, so they are not anonymous data.
Open discussion where Kai mentions You about the blank rollback owner on the launch checklist.

Identity

Your server derives the user from its own session, checks resource access, and mints an author token. The widget displays an optional name. That name is cosmetic. The opaque id is the actor. Details: identity docs.

Where discussion text lives

  • Local: discussion JSON stays in that browser's storage. Bootstrapware does not receive it.
  • BYO ($9.99): we store published app configuration. Threads, comments, mention ids, and read markers stay on your backend.
  • Hosted ($19.99): we store comment bodies, mention ids, optional display names, read markers, and operational timestamps. You moderate that content. You are responsible for it.

What MCP and webhooks carry

MCP configures apps. It does not accept a comment body, a mention directory, a resource title, or file bytes. Hosted webhooks and mention callbacks carry ids, the actor, and a time. They do not carry the body, a display name, or an email address, and they are not automatic email. See webhooks and AGENTS.md.

Cancel Hosted

If you cancel Hosted, writes freeze immediately. Export remains for 30 days, then Hosted rows are deleted. Moving Hosted to active BYO keeps the stored rows and does not start that clock. The same timeline is on Terms and the company privacy policy. Mechanism: export and purge.

What you still own

Authentication, authorization, and, for BYO, retention of the discussion. For Hosted, moderation and lawful content remain your responsibility. We do not staff a moderation queue.

See also security, privacy by mode, and the company privacy policy.