Bess Privacy Policy
Effective date: [EFFECTIVE DATE]
Bess is a personal AI assistant operated by [OPERATOR] ("we", "us"). This policy explains what data Bess handles, why, who else receives it, how long we keep it, and how you can delete it.
Summary
- Each Bess user has their own isolated space. Your conversations, memories, reminders, images and Google credentials are stored inside it, encrypted with a key unique to your space.
- Bess reads your Google data only to do what you ask, or for reminders you set up. It sends email and changes your calendar only after you confirm.
- To write replies, Bess sends the relevant parts of your conversation to an AI model provider. They do not use it to train their models.
- We do not sell your data, use it for advertising, or use it to train AI models.
- You can delete a single chat or your whole space at any time.
What we collect
Account information. When you register at mybess.ai, we store your email address, a hash of your password, and the invite code you used. The account email is not passed into your space.
What you give Bess. This includes:
- the messages you send and the replies Bess writes;
- facts Bess remembers about you at your request or with your consent;
- reminders and scheduled tasks;
- images you create or send;
- items you save to your vault.
Google data (only if you connect your Google account). With your permission, Bess can access:
- Gmail: search and read messages; send email you have confirmed; archive, mark read or unread, and star or unstar messages you ask about;
- Google Calendar: read your events, check when you are free, and create, change or delete events you have confirmed;
- Google Contacts: read only;
- your Google account's name, email address and profile picture, to show which account is connected.
Bess fetches Google data when you ask, or when a reminder you set up needs it. It does not copy your whole mailbox, calendar or contacts into Bess. Your Google access token is stored encrypted inside your space.
Technical data. Our servers record limited operational data: error codes, timings, and random identifiers. Message content is filtered out of these records. We do not use analytics or advertising trackers.
How we use data
We use your data only to provide and improve the features you use. That means answering your requests, carrying out actions you confirm, running reminders you set, keeping the service secure, and fixing problems.
Google user data. Bess's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google data is used only to provide the Bess features you see and use.
- It is not used for advertising.
- It is not sold.
- It is not used to train or improve AI or machine-learning models, other than a model personalized only for you.
- It is transferred to others only as described under "Who receives data", to provide those features.
- People do not read it, except:
- with your explicit permission for specific data, for example when you ask us to look into a problem;
- when necessary for security, such as investigating abuse;
- to comply with the law;
- for our internal operations, using data that has been aggregated and anonymized.
Who receives data
We share data only with the providers needed to run Bess:
| Provider | What they receive | Why |
|---|---|---|
| Vercel AI Gateway, and the AI model provider it routes to | The parts of your conversation needed for a reply, which can include Google data you asked about. When you generate or edit an image, they also receive the prompt and reference images. | To generate Bess's replies and images. Our current model configuration does not allow training on this data. |
| [WEB SEARCH PROVIDER — see open item] | Search terms, when Bess searches the web for you | To answer questions that need current information |
| Websites Bess opens for you | A normal web request from our server | To read a page you asked about |
| Requests made with your permission | To read and act on your Google data | |
| Amazon Web Services (United States, Ohio region) | Encrypted storage, encryption keys and servers | To host Bess. Backups contain only encrypted data. |
| Cloudflare | DNS lookups for mybess.ai | To route visitors to our servers. Cloudflare does not see your traffic. |
| Open-Meteo | Approximate (rounded) location, only if you use weather reminders | To provide weather information |
We may disclose data if the law requires it. If Bess is ever transferred to another operator, we will ask for your consent before your Google data is transferred.
Storage and security
- Your space runs in its own sandbox on a confidential-computing server in the AWS us-east-2 (Ohio) region.
- Its storage is encrypted with a key unique to your space, held in AWS Key Management Service. Every use of that key is logged.
- Google credentials are encrypted again inside your space.
- Data is encrypted in transit.
- Backups are encrypted copies of your space.
No system is perfectly secure. Our administrators can technically operate the servers that run your space. Our policy is to never look at user content except as described under "How we use data". [Remove or update this paragraph when sealed servers (H1) ship.]
Retention and deletion
- Delete a chat. In Bess, you can delete a single chat. It is removed from Bess within about a minute. Encrypted backups of your space made before the deletion may still contain it until those backups are deleted. [Fill in the backup retention period once it is decided — see open items.]
- Delete your space. This deletes your account. The encryption key is disabled immediately and destroyed after 7 days, and all backups are deleted right away. Without the key, any remaining encrypted copies cannot be read. We keep a minimal record that a deletion happened: random identifiers and timestamps, with no content.
- Disconnect Google. In Bess, you can disconnect Google at any time. We revoke Bess's access with Google and delete the stored credentials. If you delete your space without disconnecting first, also remove Bess at Google Account permissions. [Update when automatic revocation (BES-195) ships.]
- Providers. Copies already processed by the providers listed above are governed by their retention policies.
Your choices and rights
- You can see and manage what Bess remembers, your reminders and your saved images in your space.
- You can disconnect Google or delete your data at any time.
- To make other requests, such as access, correction or a copy of your data, contact us at [CONTACT EMAIL].
- Depending on where you live, you may have additional rights under local law.
Children
Bess is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy, we will post the new version here and update the effective date. If the change is significant, we will also tell you in Bess.
Contact
[OPERATOR], [CONTACT EMAIL]
