Privacy Policy
Last updated: September 8, 2026
BGP AI is your business's COO brain, so it works with information that matters to you. This policy explains, in plain language, what we collect, why, which of your connected tools we touch, who helps us run the service, how long we keep it, and the rights you have over your data.
1. Who we are
BGP AI (“BGP AI,” “we,” “us,” or “our”) is operated by Friends Realty Investments Ltd.. We are the data controller responsible for the personal information described in this policy. If you have any questions or wish to exercise your rights, contact us at privacy@bgp.ai.
2. Scope of this policy
This policy applies to personal information we process when you visit our website, create an account, and use the BGP AI service (the “Service”). It does not apply to third-party services you connect to BGP AI, which are governed by their own privacy policies. Where you use BGP AI to process information about your own customers or contacts, you are the controller of that information and we act as your processor, handling it on your behalf and under your instructions.
3. Your data in one paragraph
Your data stays yours. Everything we hold for you is isolated to your workspace and encrypted at rest — your conversations, anything the assistant pulls from your connected tools, the documents you upload, and the notes it keeps about your business. The credentials for your connected accounts are separately encrypted and are never shown to the AI model; the assistant asks our server to act, and it never handles your passwords or tokens. The assistant can read from the tools you connect, because that is what makes it useful — but it only reads while it is answering you, it cannot reach anything you have not connected, and anything it writes or sends waits to be approved before it happens, by a person on your team or, if you choose, by your Board AI reviewing it against your standing rules. You can disconnect any tool at any time from your Integrations page. To generate replies, the relevant content is sent to third-party AI providers — OpenAI, Anthropic, Google and others named in Section 10 — under commercial agreements that prohibit them from training on it. We do not train models on your data. Each of those providers, and each tool you connect, handles what it receives under its own privacy policy and terms; Sections 10 to 12 say who they are, what reaches them, and what that means for you.
4. Information we collect
To run your assistant and provide the Service, we collect:
- Account information — your name, email address, password credentials, and team or organization details.
- Business profile — the details about your business that you share so your assistant understands it.
- Documents you upload — files you give your assistant to learn from or work with, and their contents.
- Conversations with your assistant — your chats and the assistant's responses, so it remembers context and you can look back at what was said.
- Connected-service data — when you choose to connect an integration, the data needed to answer your questions and carry out the actions you approve. Section 5 sets out exactly what this means for each service.
- Usage and technical data — how the Service is used, such as credits consumed, features accessed, log data, device and browser information, and IP address, so we can secure the Service, bill fairly, and improve the product.
- Payment information — billing details needed to manage your subscription. Card numbers are collected and stored by Stripe, our payment processor, and never touch our servers.
5. Connected services: what we access and why
BGP AI only reaches a third-party service after you connect it, and only with the permissions you granted at that moment. Nothing below happens for a service you have not connected. You can see every connected account, and disconnect any of them, on your Integrations page.
Google — Gmail
- Permissions we request — gmail.modify, userinfo.email and openid, requested at the moment you connect a mailbox.
- What we read — Message headers, bodies, attachments, threads, labels, and the mailbox address and message counts shown on your Integrations page.
- What we can write — Sends emails, replies inside existing threads, creates and sends drafts, applies and removes labels, archives messages, and marks them read or unread. We never request permanent deletion, and no tool in the assistant can permanently delete a message.
- What we store — The OAuth access and refresh tokens, encrypted. Message content is fetched live when the assistant is answering you; the portion the assistant acts on is stored on the resulting task record, encrypted, so you have an audit trail of what was sent and why.
- How to revoke — Disconnect the mailbox on your Integrations page. We revoke the token with Google and delete it immediately. You can also review or remove access at myaccount.google.com/permissions.
Meta — Facebook Pages and Instagram
- Permissions we request — pages_show_list, pages_read_engagement, pages_manage_posts, read_insights, instagram_basic, instagram_content_publish, instagram_manage_insights, and business_management.
- What we read — The Pages and Instagram professional accounts you administer, their posts and comments, and the engagement and reach metrics behind your reporting.
- What we can write — Publishes posts to the Pages and Instagram accounts you connect.
- What we store — Page and Instagram access tokens, encrypted, along with the account names and IDs needed to show you which accounts are connected. Post and metric data is fetched when needed for the answer or report you asked for.
- How to revoke — Disconnect on your Integrations page, which deletes the stored tokens. To withdraw the grant at Meta as well, remove BGP AI under Facebook Settings → Business Integrations. Removing it there notifies us and we delete the connection on our side automatically.
TikTok
- Permissions we request — user.info.basic, user.info.profile, video.publish, and video.list.
- What we read — The display name, username and avatar of the TikTok account you connect, and the view, like, comment and share counts of the posts published through BGP AI.
- What we can write — Publishes posts to the TikTok account you connect, using the privacy and disclosure settings a person confirms before each post goes out.
- What we store — TikTok access and refresh tokens, encrypted, along with the account name and open ID needed to show you which accounts are connected. Post metrics are fetched when needed for the report you asked for.
- How to revoke — Disconnect on your Integrations page, which revokes the token with TikTok and deletes our copy. You can also remove BGP AI under TikTok Settings → Security and permissions → Manage app permissions. Removing it there notifies us and we delete the connection on our side automatically.
Intuit — QuickBooks Online
- Permissions we request — com.intuit.quickbooks.accounting.
- What we read — Customers, vendors, invoices, estimates, payments, items, accounts, and the company profile of the QuickBooks company you connect.
- What we can write — Creates and updates records such as invoices, estimates, customers, and payments — each one only after it has been approved.
- What we store — OAuth tokens and the QuickBooks company (realm) ID, encrypted. Accounting records are read live; what an approved action created or changed is stored on the task record, encrypted.
- How to revoke — Disconnect on your Integrations page. We revoke the token with Intuit and delete it immediately. You can also remove the connection from within QuickBooks under Apps.
GoHighLevel
- Permissions we request — Read scopes for contacts, conversations, calendars, opportunities, invoices, users, products, forms, locations, workflows, socialplanner, emails, voice-ai-agents, and voice-ai-dashboard — plus write scopes for contacts, conversations/message, calendars/events, opportunities, invoices, socialplanner/post, emails/templates, emails/campaigns, and voice-ai-agents.
- What we read — Contacts and their custom fields, conversation history, calendars and events, opportunities and pipelines, invoices, products, forms, workflows, the users and location settings on your account, scheduled social planner posts, email templates and campaigns with their delivery statistics, and your voice AI agents and their dashboard.
- What we can write — Creates and updates contacts, sends messages that are logged on the contact timeline, books and updates calendar events, moves opportunities, creates invoices, schedules social planner posts, creates and updates email templates and campaigns, and configures voice AI agents.
- What we store — OAuth tokens and your location ID, encrypted. CRM records are read live; the records an approved action created or changed are stored on the task record, encrypted.
- How to revoke — Disconnect on your Integrations page, which deletes the stored tokens. To withdraw the grant at GoHighLevel as well, uninstall BGP AI from your location's app settings.
monday.com
- Permissions we request — account:read, me:read, boards:read, boards:write, users:read, workspaces:read, updates:read, updates:write, webhooks:read, and webhooks:write.
- What we read — The boards, groups, columns and items in the monday.com account you connect, the values on those items including owners and dates, the updates and comments posted on them, your workspaces, and the names and email addresses of the users on the account so the assistant can name an owner.
- What we can write — Creates items, sets column values such as status, date and owner, moves items between groups, and posts updates on items — each one only after it has been approved. It never deletes or archives items, and never creates or alters boards, groups or columns.
- What we store — The OAuth token and the monday.com account ID, encrypted, plus the board and event of any webhook you ask the assistant to watch. Board and item data is read live; what an approved action created or changed is stored on the task record, encrypted. Column and group names are cached briefly so an approval can name the exact change being made.
- How to revoke — Disconnect on your Integrations page, which deletes the stored token and removes any webhooks we created. monday.com publishes no revocation endpoint, so to withdraw the grant there as well, uninstall BGP AI under Administration → Apps in your monday.com account.
GitHub
- Permissions we request — contents:read, metadata:read, issues:read, and pull_requests:read — read-only, on only the repositories you select.
- What we read — The repositories you explicitly allow when you connect: their names, descriptions, languages and branches, the files they contain, their commit history, and their issues, pull requests and releases. Repositories you do not select are never read, and the installation itself can be limited to a subset on GitHub before it ever reaches us.
- What we can write — Nothing. The GitHub app holds read-only permissions, so your assistant cannot push commits, open or merge pull requests, approve reviews, change settings, or alter anything in your repositories — not by policy, but because the access token carries no such right.
- What we store — The GitHub installation ID and the ID and name of each repository you selected, encrypted. Access tokens are short-lived and minted on demand rather than stored. Repository contents are read live.
- How to revoke — Disconnect a repository on your Integrations page, which removes it immediately. To withdraw access at GitHub as well, uninstall BGP AI under Settings → Applications → Installed GitHub Apps in your account or organisation.
Slack
- Permissions we request — channels:read, groups:read, im:read, mpim:read, channels:history, groups:history, im:history, mpim:history, chat:write, chat:write.public, im:write, users:read, users:read.email, channels:manage, groups:write, channels:join, lists:read, and lists:write.
- What we read — The channels in the workspace you connect and which of them the assistant has been added to, the messages and threaded replies in those channels only, and the names, display names and email addresses of the people in the workspace so the assistant can name a sender. It cannot read a private channel unless someone invites it, and it cannot read a public channel it has not joined. It never reads your direct messages with other people. It also reads the Slack lists you point it at — their columns and the items on them — and only those, because Slack publishes no way to search for a list.
- What we can write — Posts messages to a channel, replies in a thread, sends a direct message, creates a channel, invites people to one, joins a public channel, and archives a channel — each one only after it has been approved. It also schedules a message for later, edits or deletes a message it posted itself, and creates Slack lists and adds, updates or removes items on them. Posting, scheduling, replying, direct messages, edits and deletions always require a person to approve them, because they are visible to your colleagues and cannot be unsent by us.
- What we store — The bot token and the Slack workspace ID, encrypted, plus the workspace name, URL and the assistant's own bot user ID. Messages and channels are read live and are not retained; what an approved action posted is stored on the task record, encrypted. The channel list and a list's column names are cached briefly so an approval can name the exact channel or column being changed.
- How to revoke — Disconnect on your Integrations page, which revokes the token at Slack. To remove the app from the workspace entirely, go to Your workspace → Settings & administration → Manage apps.
Custom apps
- Permissions we request — Whatever your administrator configures when they add the app, shown to you before you connect.
- What we read — Only what the configured endpoints and scopes allow.
- What we can write — Only the operations the connected app exposes, and only after approval.
- What we store — Client credentials and webhook secrets, encrypted.
- How to revoke — Disconnect on your Integrations page.
6. Google user data and the Limited Use requirements
BGP AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice, and stated plainly:
- We use Gmail data only to provide and improve the user-facing features described in this policy — reading the mail you ask about, drafting replies, and sending what you approve.
- We do not transfer Gmail data to others except as necessary to provide those features (see the AI providers in Section 10 and the subprocessors in Section 11), to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit consent.
- We do not use Gmail data for advertising of any kind, including personalized, re-targeted, or interest-based advertising.
- We do not use Google user data to develop, train, or improve generalized artificial intelligence or machine learning models. Gmail content is sent to our AI providers only to generate the specific reply or action you asked for, and those providers are contractually prohibited from training on it.
- Our staff do not read your Gmail data, except with your explicit consent for a specific message, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
7. How we use your information
We use the information above to:
- Provide, operate, and maintain the Service;
- Power your assistant so it can understand your business and prepare the actions you request;
- Process payments and manage your subscription;
- Secure the Service, prevent fraud and abuse, and keep an auditable record of actions taken;
- Provide customer support and respond to your requests;
- Improve and develop the Service, using metadata and aggregated usage — never your conversations, documents, or connected-service data to train AI for other clients;
- Send you service, security, and transactional communications, and — where permitted — occasional product updates you can opt out of;
- Comply with our legal obligations and enforce our Terms of Service.
8. Legal bases for processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data under one or more of the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure, maintain, and improve the Service, provided these interests are not overridden by your rights.
- Legal obligation — to comply with laws that apply to us, such as tax and accounting rules.
- Consent — where required, such as for certain marketing communications; you may withdraw consent at any time.
9. How your data is protected
- Encrypted at rest. Your conversations, the contents of documents you upload, the notes the assistant keeps about your business, and the inputs and results of every action it takes are encrypted in our database. Someone reading the raw database rows cannot read them.
- Credentials are held separately. The access tokens for your connected accounts are encrypted under their own record and are never placed in the AI model's context. The assistant asks our server to perform an action; the server holds the token. The model never sees a password or a token.
- Isolated to your workspace. Every record we store carries the workspace it belongs to, and queries are scoped to that workspace. One client's assistant cannot see another client's data.
- Nothing goes out unapproved. The assistant can read from your connected tools while it is answering you. Anything it writes or sends — an email, an invoice, a post, a booking — is prepared as a task and waits for approval. Human approval is the default and which team members may approve what is yours to configure. An administrator can instead hand approval to Board AI, which reviews each action against your business and your standing rules and approves or rejects it with a written reason; anything it cannot decide still comes to a person.
- Encrypted in transit. All traffic to and from the Service, and between the Service and the tools you connect, travels over TLS.
- Least-privilege staff access. Our staff see only metadata in the ordinary course of business. They do not access your conversations or documents, and they cannot impersonate you. Access for support or security is limited, logged, and only with a legitimate need.
- Everything is on the record. Every action the assistant takes is logged with who approved it and when, so there is always an auditable record of what happened.
No system is perfectly secure, but we work to protect your information and will notify you and the relevant authorities of a personal data breach where the law requires it.
10. AI providers, models, and your content
BGP AI is not one model. To answer a question, draft an action, review an action, make an image or a video, read something aloud, or index your documents so they can be searched, we send the content relevant to that request to one or more third-party AI providers. This is not optional or incidental — without it the assistant cannot work at all. This section explains exactly what leaves our systems, who receives it, and on what terms.
What we send, and what we never send
We send only what that request needs: the relevant part of the conversation, the document or connected-service record the request is about, your business profile and the standing rules your assistant works under, and the instructions the assistant runs on.
We never send the credentials for your connected accounts. Access tokens and passwords are encrypted under their own records and are never placed in a model's context — the model asks our server to act, and our server holds the token. No AI provider receives your Gmail, QuickBooks, Slack, Meta, TikTok, GitHub, monday.com or GoHighLevel credentials.
Which providers receive your content
On our own accounts, the providers below may process your content. Each is an independent company that decides its own practices, and each has its own privacy policy — linked here so you can read it before you rely on this Service:
- OpenAI — Text and reasoning, image generation, read-aloud voices, transcription, and the embeddings that make your documents searchable. Privacy policy.
- Anthropic (Claude) — Text and reasoning, including drafting and the Board AI review of proposed actions. Privacy policy.
- Google (Gemini and Veo) — Text and reasoning, reading images and screenshots, image generation, short-form video generation, read-aloud voices, and embeddings. Privacy policy.
- xAI (Grok) — Text and reasoning, where your plan offers it and an administrator selects it. Privacy policy.
- Moonshot AI (Kimi) — Text and reasoning over long documents, where your plan offers it and an administrator selects it. Privacy policy.
- Cohere — Reranking — ordering search results from your own documents by relevance. Privacy policy.
- HeyGen — Presenter (avatar) video: rendering a person on camera reading a script you approved. Privacy policy.
The terms those providers work under
- We contract with each on business terms, not consumer terms. Under those agreements your content is used to return the response to that request, and is not used to train their general models. We do not train models on your data, and nothing your business teaches your assistant informs another client's assistant.
- Each provider remains responsible for its own processing. Once content has been transmitted to a provider, that provider handles it under its own privacy policy and terms, in its own systems. Our agreement with them binds what they may do with it, but we do not operate their systems and cannot control or audit them beyond what that agreement gives us.
- They may keep a copy for a limited time even though they may not train on it. AI providers generally retain requests for a short period to detect abuse, investigate security incidents, and meet their own legal obligations. Those retention periods are set by the provider, not by us, and are described in the policies linked above.
- Where a model is served through a cloud host — Azure OpenAI or Amazon Bedrock — that host processes the request too, under the same restrictions.
- Provider safety systems may refuse or filter a request. That decision is the provider's and is applied by their systems before we see a result.
Which model runs, and changes to this list
Which models are available depends on your plan, and an administrator of your workspace may choose between the models the plan offers. We may add, replace, or stop using a provider or a model — because of availability, quality, cost, or because a provider changes its own terms. We keep this section current, and where a change materially affects how your personal data is processed we will tell you before it takes effect, so you can object or stop using the Service. Where a provider is unavailable, a request may be routed to another provider on this list.
If you bring your own API key
Some plans let you supply your own API key so that AI usage runs on your own account with a provider. You may do this for OpenAI, Anthropic (Claude), Google Gemini, xAI (Grok), Moonshot AI (Kimi), Groq, DeepSeek, Mistral, Cohere, Voyage AI, Jina, and OpenRouter. Where you do, the position changes in a way you should understand:
- The processing happens under your contract with that provider, not ours. Their terms, their retention, their pricing, and their training policy apply as you agreed them.
- Whether that provider may train on the content you send is determined by the settings and plan on your account with them. We cannot change it, and the no-training commitments we hold on our own accounts do not extend to yours.
- We transmit the content and your key to that provider to carry out the requests your workspace makes. Your key is encrypted at rest, is never placed in a model's context, and is deleted when you remove it.
- We are not responsible for how a provider you chose handles your content. That relationship is yours.
Presenters, likeness, and voice
If you use presenter video, the script and the presenter you selected — including any photograph or video you upload for that presenter — are sent to HeyGen to render the clip, and are processed under HeyGen's own terms and privacy policy. A person's face and voice are personal data, and in some places are treated as sensitive. Where you upload the likeness or voice of a real person, you are responsible for having their informed consent for this use, as set out in our Terms of Service; tell us if that consent is withdrawn and we will delete the presenter and ask HeyGen to do the same.
What we do not do
- We do not train models — ours or anyone else's — on your conversations, documents, or connected-service data.
- We do not send Google user data to any provider permitted to train on it (see Section 6).
- We do not sell your content, and we do not use it for advertising.
11. Who helps us run the Service (subprocessors)
Beyond the AI providers in Section 10, a small number of providers help us deliver BGP AI. Each is bound by contract to protect your data and to use it only to provide services to us, and each is governed by its own privacy policy:
- Amazon Web Services (AWS) — Hosting, database, and file storage. Where an AI model is served to us through Amazon Bedrock, AWS also processes that request. Privacy policy.
- Microsoft Azure — Where an OpenAI model is served to us through Azure OpenAI rather than OpenAI directly. Privacy policy.
- Stripe — Payment processing and subscription billing. Stripe stores your card details so we never do. Privacy policy.
- Resend — Delivery of our transactional and notification email to you. Privacy policy.
We may add or replace a subprocessor as the Service changes. When we do, we update this page, and where the change materially affects the processing of your personal data we notify you before it takes effect. If you object to a new subprocessor, tell us at privacy@bgp.ai; if we cannot offer you a reasonable alternative, you may stop using the affected feature or terminate.
The services you connect yourself — Google, Meta (Facebook and Instagram), TikTok, Intuit QuickBooks, GoHighLevel, monday.com, GitHub, Slack, and any custom app your administrator configures — are not our subprocessors. They are your own accounts. We reach them on your instruction and under the permissions you granted, and your relationship with each is governed by that provider's own terms and privacy policy, directly with them.
We do not sell your personal information, and we do not share it with third parties for their own marketing. We may disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you.
12. Data that leaves through your connected accounts
Reading is one thing; sending is another. When an action is approved and executes — an email sent, a post published, an invoice created, a message posted in Slack, an item written to a board — that content leaves BGP AI and enters the receiving platform, and from that moment it is held by that platform under your agreement with it, and by whoever receives or can see it.
Please understand what that means before you approve something:
- We cannot recall a sent email, unpublish a post a platform has already distributed, or remove a message someone has already read.
- Deleting the record in BGP AI does not delete what the other platform holds. Ask that platform, using its own controls.
- What we keep afterwards is the audit record — what was sent, by whom, when, and who or what approved it — encrypted, so you can always see what happened.
- Where what you send contains other people's personal data, you are the controller of that processing and are responsible for having a lawful basis for it, including under marketing and anti-spam rules.
13. International data transfers
We and our subprocessors may process your information in countries other than the one you live in, including the United States. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) to ensure your data receives an equivalent level of protection.
14. How long we keep your data
We keep your data for as long as your account is active so your business's knowledge stays safe and available to you. If you downgrade or pause your subscription, your data is preserved rather than deleted. Where your plan or your administrator sets a retention window for conversations, tasks, or assistant memories, we delete anything past that window on a nightly schedule; tasks still awaiting approval are never deleted by that process, however old they are.
When you delete your account, or on your request, we delete or anonymize your personal data within a reasonable period, except where we must retain it to comply with legal, tax, or accounting obligations, resolve disputes, or enforce our agreements. Backups are purged on a rolling schedule.
15. Disconnecting a tool and deleting your data
You are in control of both, and neither requires you to contact us:
- Disconnect a tool from your Integrations page. We delete the stored credentials for that account immediately, and the assistant loses all access to it. Where the provider offers a revocation endpoint — Google and Intuit do — we also revoke the grant with them in the same step. For the others, the per-service instructions in Section 5 show how to withdraw the grant on their side as well.
- Delete data already stored by deleting the conversations or tasks it belongs to inside the app.
- Request deletion of everything we hold for you — a connected service's data, your whole workspace, or your account — using the contact form at businessgrowthpartners.ai, or by emailing privacy@bgp.ai. Tell us which of the three you want. We confirm in writing when it is done, and you do not need an active subscription to ask.
Use the same route if you are a customer of one of our clients rather than a client yourself — for example, if your details reached us through a business that connected its CRM or its mailbox. Tell us which business you dealt with. They are the controller of that data, so we will pass the request to them and act on it ourselves as their processor.
16. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with your data protection authority. To exercise any of these rights, email privacy@bgp.ai or use the contact form at businessgrowthpartners.ai. We will respond within the timeframe required by law and will not discriminate against you for exercising your rights.
17. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to or deletion of that information, and to correct inaccurate information. In the past twelve months we have collected the categories of information described in Section 4 (identifiers, account and business records, commercial and usage information, and content you provide).
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive personal information for purposes other than providing the Service. To exercise your California rights, email privacy@bgp.ai. You may use an authorized agent to submit a request on your behalf.
18. Cookies and similar technologies
We use strictly necessary cookies to keep you logged in and keep the Service secure, and limited analytics to understand how the Service is used. We do not use advertising cookies or sell data to advertisers. You can control cookies through your browser settings, though disabling necessary cookies may break parts of the Service.
19. Children's privacy
BGP AI is a business tool intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
20. Changes to this policy
We may update this policy as the Service evolves. When we make material changes, we will update the “Last updated” date above and notify you by email or in the product before the changes take effect. Your continued use of the Service after an update means you accept the revised policy.
21. Contact us
For privacy questions, to exercise your rights, or to request deletion, email privacy@bgp.ai or use the contact form at businessgrowthpartners.ai. For anything else, reach us at hello@bgp.ai. A real person will reply.
