The short version: your workspace data is yours, we don't sell it, and we don't ship it to third-party analytics vendors. The long version is below.
This policy covers visitors to bo.ge (and its subdomains) and customers
using BackOffice ("we", "us", "our") on the hosted offering. If you self-host, your
privacy stance is governed by your own deployment; this document doesn't apply there.
A single first-party authentication cookie plus a few localStorage entries
for session state. No third-party trackers, no advertising cookies, no remarketing pixels.
Each is contractually bound to the same standards we hold ourselves to.
Access, export, deletion, and correction. Email privacy@bo.ge and we'll respond within 30 days. EU and UK GDPR plus CCPA rights are honoured for all customers regardless of residence.
Production data sits in the EU by default (Frankfurt). R2 blobs are replicated to regional edges. We don't transfer customer-row data outside the region without a written addendum.
Found a vulnerability? Email security@bo.ge. We run a no-litigation policy for good-faith research and will publicly credit fixes (with permission). Encrypt sensitive details with our PGP key, available on request.
We update this policy when material changes happen. The "Last updated" date at the top is the source of truth; significant changes also trigger an email to account owners.
Privacy questions: privacy@bo.ge. General contact: our contact page.