Privacy
Embed-only checklist. You assert identity. Host context stays yours.
Bootstrapware Onboard is not a CDP. The widget lives inside your product. Your app asserts who is completing setup. Storage depends on BYO vs Hosted.

Identity
We do not authenticate end users. Pass a user object with an opaque stable id from your session plus workspaceKey for shared steps. Live Hosted requires authorToken minted from your BFF. Details: identity docs.
What we never store
- Host context objects (role, plan, flags) sent to MCP or webhooks
- Fact payloads beyond what progress reconciliation requires on your backend
- End-user passwords or session cookies
BYO vs Hosted content
- BYO: progress never leaves your systems via the Bootstrapware data path. We host flow configuration only. Side effects use
onEventon your backend. - Hosted: progress records (opaque ids, step keys, revisions, timestamps) and integration-reported summaries live on Bootstrapware as a paid convenience. You are responsible for summary content your integrations report.
Cancel Hosted
If you cancel Hosted (or lose Hosted entitlement), writes freeze immediately. You may export Hosted progress and summaries from the dashboard for 30 days; after that window we delete Hosted progress data. Downgrading Hosted to active BYO keeps stored data and does not start the 30-day clock. Company-wide policy: privacy policy, terms.