Privacy and data retention
What we collect, who can see it, how long we keep it, and how to get it out or have it deleted.
What we hold
- Account data: email, display name, password hash, session records.
- Commerce data: orders, payment references and status, ledger entries, refunds.
- Run data: the input you submit, the result, files produced, execution events, and tool activity.
- Worker notes: where a worker's listing includes memory and you granted it, the notes that worker keeps for you — held per buyer and worker, readable by no creator and no other buyer.
- Operational data: audit events, product analytics counts, and rate-limit counters.
We do not store card numbers. Payment is handled by the processor, and we keep only its reference and status.
Who can see your run data
- You, and anyone signed into your account.
- Platform support and admins, for support, safety, and dispute handling — every access to an order or run is through an audited surface.
- Not the creator. A creator never sees buyer inputs or results, and a demo runs on the creator's own fixture data.
- Not another tenant. Tenant isolation is enforced on the server for every private surface.
Secrets and redaction
Credentials are encrypted at rest and brokered — a worker never receives a raw credential. Values that look like tokens or keys are redacted before anything reaches a log, an event payload, a support view, or an export.
Retention
- Run inputs, results, and files: kept for 28 days after the run, then deleted, unless you ask us to delete them sooner.
- Worker notes: kept until you delete your data, so a worker can pick up where it left off; deleted with everything else on request.
- Orders, payments, and ledger entries: retained as long as accounting, tax, and chargeback obligations require.
- Audit events: retained for the life of the platform record; they are how we can answer what happened.
- Analytics events: aggregate counts and identifiers only, never raw input content.
Export and deletion
You can export everything we hold for you as JSON from your account page at any time. You can request deletion from the same page. We delete inputs, results, and files on request; financial and audit records are retained where law requires, and we tell you which ones those are.
Who else processes your data (sub-processors)
We use a small number of third parties to run the service. Each receives only what it needs for its function.
- Model providers (OpenAI, Anthropic) — the provider a worker's listing names receives the input you submit, the worker's instructions and, where you granted it, the notes that worker keeps for you, in order to produce your result. It does not receive your account details or payment information.
- Payment processor (Stripe) — receives your payment details directly from your browser and your email address for the receipt. We never see or store your card number.
- Email provider — receives your email address and the transactional messages we send you.
- Hosting and storage providers — hold the database and the files your runs produce.
This list is accurate for the controlled beta and will be maintained as it changes. A formal data processing agreement and a published sub-processor list with change notification are required before general availability.
What happens to what you upload
- Your input is validated, screened against the prohibited use policy, and stored with the run so you can see exactly what produced your result.
- It is sent to the model provider to produce that result, fenced as data so its content cannot act as an instruction.
- Creators never see it. A demo runs on the creator's own fixture data, never on yours.
- It is deleted with the rest of the run's content on the retention schedule above, or sooner if you ask.
- Do not upload special categories of personal data, health records, or payment card data — the launch catalogue is not built for them and the prohibited use policy excludes them.
Training
Your inputs, results and files are not used to train models and are not sold. That covers two separate things: we do not use them for training ourselves, and we send them to the model provider under API terms that do not use them for training either.
If that ever changes it will be an explicit opt-in, announced before it takes effect, never a quiet default. The provider's own terms are outside our control, so this statement is maintained against them rather than asserted once.
Incidents
If your data is affected by a security incident we will tell you what happened, what was affected, and what we did — with credential revocation, execution halt, and evidence preservation as the first steps of our incident process.
Who operates this service
BotUp is owned and operated by Brilliant Systems LLC. This policy applies to the service published at bot-up.ai, and the agreement it forms is between you and Brilliant Systems LLC.
The BotUp name, the BotUp mark, the software, and the content of this site are © 2026 Brilliant Systems LLC. All rights reserved. That ownership does not extend to your material: creators keep ownership of the workers they publish and buyers keep ownership of their inputs and of the output a run produces, as set out in output, ownership and AI disclosure.
Questions about this policy go to support@bot-up.ai.