Legal
Privacy Policy
On this page
1. Scope#
This Privacy Policy explains how BridgeMind LLC (“BridgeMind,” “we”), a limited liability company based in the United States, handles personal information when you use the BridgeMind desktop app (the “App”), bridgemind.ai, account and billing services, and the BridgeMind backend APIs that operate those products. Legacy desktop apps we still make available, including BridgeSpace and BridgeVoice, are covered until we retire them.
Some data is processed on our servers. Some data is stored or processed only on your device. Coding-agent CLIs and plugins you connect send data to those vendors under their terms, not as BridgeMind subprocessors.
For residents of the European Economic Area (EEA), the United Kingdom, and Switzerland, this policy also describes our roles and your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, and the Swiss Federal Act on Data Protection (“FADP”). For interactions with our AI features, it describes the Article 50(1) transparency notice of the EU AI Act (Regulation (EU) 2024/1689).
2. Information We Collect#
- Account and identity data, such as email address, password or social-login flow details, user ID, roles, email-verification status, and subscription tier.
- Billing and subscription data, such as Stripe customer IDs, subscription IDs, plan, status, renewal dates, credit balances, and limited transaction metadata. We do not store full payment card numbers.
- Hosted product content you create or store with us, such as API-key metadata, vocabulary entries synced to our API, and prompts you send to hosted features (Create with AI, Auto supervisor, cloud transcription).
- Communications, such as support email, newsletter signups, and historical waitlist, job-application, event, or bug-bounty records if we still hold them from earlier programs. Those public programs are not current offerings on bridgemind.ai.
- Usage, device, and security data, such as IP address, browser and device information, session and CSRF cookies, auth refresh activity, rate-limit and audit logs, product analytics events, and error telemetry on the API.
- Desktop-app local data that stays on your device unless a feature sends it: encrypted sign-in credentials, device fingerprints, local settings, selected microphones, chats, agent memory, plugin connection files, and local databases. BridgeVoice may also store custom dictionaries and downloaded Whisper model files.
- AI and audio data when you use those features. App dictation uploads audio to the BridgeMind API for cloud transcription (Together Whisper). BridgeVoice can transcribe on-device with local models or in the cloud via our API. Hosted drafting and Auto send the prompts or terminal context you submit to our API and then to the model providers we use for that feature. Code and Agent turns that launch a CLI on your machine send context to that vendor under your account, not through BridgeMind.
3. How We Collect Information#
We collect information directly from you when you create an account, buy a subscription, submit a form, use a hosted feature, or contact us.
We also collect information automatically from browsers, desktop apps, and APIs, including analytics events, security logs, cookie data, and device or app configuration data needed to run the service.
We may receive information from third parties you choose to use with BridgeMind, including authentication providers (Amazon Cognito, and Google or Apple if you use those sign-in buttons), payment processors, analytics providers, and AI service providers for hosted features.
4. How We Use Information#
- Provide, secure, and maintain the App, bridgemind.ai, and related services.
- Authenticate builders, manage accounts, issue and refresh sessions, and enforce subscription, credit, or feature-access controls.
- Process purchases, renewals, cancellations, invoices, refunds, and support requests.
- Provide hosted AI features you request, such as cloud transcription, Create with AI, and Auto supervisor turns.
- Detect abuse, spam, fraud, policy violations, and security incidents, including by using CAPTCHA, audit logging, rate limits, and monitoring.
- Measure product usage and reliability through PostHog. Website and App analytics are on by default (see Section 8).
- Send product and marketing emails when you opt in. You can unsubscribe at any time.
- Comply with legal obligations and enforce our agreements.
5. Legal Basis for Processing (EEA, UK, Switzerland)#
If you are located in the EEA, the UK, or Switzerland, we process your personal data only where we have a lawful basis to do so under Article 6(1) of the GDPR (and corresponding provisions of the UK GDPR and the Swiss FADP). We rely on the following bases, mapped to the purposes described in Section 4:
- Performance of a contract (Article 6(1)(b)): creating and operating your account, authenticating you, providing the services you sign up for, processing payments and renewals, delivering hosted AI features you request, and responding to product-support requests arising from your use of the services.
- Legitimate interests (Article 6(1)(f)): protecting the security and integrity of our services, preventing fraud and abuse, maintaining audit logs and rate-limit records, operating CAPTCHA and anti-automation controls, measuring product performance and reliability (including PostHog analytics as described in Section 8), communicating essential service updates, and defending legal claims. We balance these interests against your rights and freedoms before relying on this basis. You may object (see Section 12).
- Consent (Article 6(1)(a)): product and marketing emails where required by law, and any other processing for which we ask you to opt in. You can withdraw consent at any time through the unsubscribe link or by contacting us — withdrawal does not affect the lawfulness of processing before withdrawal. Analytics cookies are not consent-gated; see Section 8.
- Legal obligation (Article 6(1)(c)): keeping tax, accounting, and billing records, responding to lawful requests from public authorities, and complying with applicable data-protection, consumer-protection, and anti-fraud laws.
6. AI, Audio, and Desktop-App Disclosures#
Interaction with an AI system (EU AI Act Article 50(1)). When you chat with an agent, use voice commands, run a routine, or otherwise interact with an AI feature in the App, on the BridgeMind website, or in a legacy app, you are interacting with an artificial intelligence system and not with a human. Output may be inaccurate, incomplete, or unsuitable for your intended use.
App dictation is cloud-only: audio is sent to the BridgeMind API and transcribed by Together AI (Whisper). Other transcription providers (Groq, Fireworks, or a model routed through OpenRouter) may be used depending on configuration. BridgeVoice (legacy) can transcribe on-device with local Whisper models you download, or in the cloud via the same API.
For hosted BridgeMind features (cloud transcription, Create with AI, Auto supervisor, titles, and similar API calls), we do not use your prompts, transcriptions, or code to train foundation models. Providers we pay for those hosted calls are engaged to return a result to us.
That commitment does not bind coding-agent CLIs you launch (Claude Code, Codex, and others) or plugins you connect. Those products send data using your credentials under their privacy terms. We cannot promise they will not train or retain.
The App may access local folders you grant, terminal sessions, clipboard, microphone, accessibility (to paste dictation into the frontmost app), notifications, and an isolated in-app browser when you use those features. Auto may send terminal scrollback to our API to propose the next prompt. Optional Discord Rich Presence, if you turn it on, publishes activity strings to the local Discord app and never includes chat titles.
7. How We Share Information#
We share information with service providers that help us operate BridgeMind. Depending on the feature, those providers may include Amazon Web Services (including Cognito for authentication), Cloudflare (CDN, WAF, and Turnstile), Stripe, SendGrid, PostHog, Sentry (API error monitoring only), OpenRouter and the model providers it routes to for hosted AI (which may include OpenAI, Anthropic, Google, or Microsoft), OpenAI and xAI for hosted voice features, and Together AI, Groq, or Fireworks for cloud transcription.
If you choose Sign in with Google or Sign in with Apple, that provider processes the sign-in under its terms and we receive the identifiers needed to create or open your BridgeMind account. If you link Discord, we store Discord identifiers needed to grant the Pro role. YouTube embeds on the website are loaded from Google.
We may also share information when required by law, to protect rights or security, in connection with a merger or asset sale, or with your direction — including when you connect a plugin or launch a third-party engine.
We do not currently sell personal information for money, and we do not engage in “sharing” of personal information for cross-context behavioural advertising as defined under U.S. state privacy laws.
8. Cookies, Local Storage, and Analytics#
Strictly necessary cookies and similar storage keep you signed in and protect the session (authentication, CSRF, session). Those cookies are required for the site to work.
We also use PostHog on bridgemind.ai and in the App (macOS) to measure usage. There is no cookie banner. Analytics capture is on by default. The website SDK stores an anonymous id in cookies and localStorage, records pageviews and the events listed in our tracking plan, and, once you sign in, identifies that device to your BridgeMind account id with subscription tier — not your email address. Session replay is off on the marketing site. The App uses a separate PostHog project and does not attach email to the person profile.
You may object to this analytics processing by emailing [email protected]. We will stop analytics collection associated with your account. Ad blockers may still drop the pixel; that is your choice, not a substitute for an account-level request.
Desktop apps also store settings locally outside of browser cookies. Auto-update checks contact our downloads CDN and send standard client information such as app version and operating system.
9. Retention#
We retain personal information for as long as needed to provide the services, maintain legitimate business records, resolve disputes, comply with law, and enforce agreements.
Local desktop-app data remains on your device until you delete it or remove the app. On the server side, deactivated accounts and related data may be purged after our retention window if they are no longer needed. Billing records are retained for the period required by applicable tax and accounting law. Audio uploaded for transcription is processed to return text and is not kept as a conversation archive.
10. Security#
We use administrative, technical, and organizational safeguards intended to protect personal information. These include encrypted local credential storage in our desktop apps, authentication and session controls, rate limiting, audit logging, access controls, and third-party infrastructure and monitoring tools.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. International Transfers#
BridgeMind LLC is based in the United States, and our service providers may process information in the United States and other countries. When we transfer personal data from the EEA, the UK, or Switzerland to a country that has not been recognised as providing an adequate level of data protection, we rely on appropriate safeguards under Article 46 of the GDPR. These typically include the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the Swiss addendum where applicable, and, where a provider is certified, the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks.
You may request a copy of the safeguards we rely on for a given transfer by contacting [email protected].
12. Your Rights and Choices#
Depending on where you live, you may have rights under applicable privacy law. For residents of the EEA, the UK, and Switzerland, these rights include, subject to the conditions and exceptions set out in the GDPR, UK GDPR, and FADP:
- Access (Article 15): to obtain confirmation of whether we process your personal data and to receive a copy.
- Rectification (Article 16): to correct inaccurate or incomplete personal data.
- Erasure / “right to be forgotten” (Article 17): to request deletion of your personal data.
- Restriction (Article 18): to request that we limit processing in certain circumstances.
- Portability (Article 20): to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Objection (Article 21): to object to processing based on legitimate interests (including analytics) or to direct marketing.
- Withdraw consent (Article 7(3)): where processing is based on consent, at any time, without affecting the lawfulness of processing before withdrawal.
- Automated decisions (Article 22): we do not currently make decisions producing legal or similarly significant effects about you based solely on automated processing.
To exercise any of these rights, contact [email protected]. We will respond within one month, extendable by up to two further months where necessary given the complexity and number of requests, consistent with Article 12(3) GDPR. We may need to verify your identity before acting on your request.
You also have the right to lodge a complaint with a supervisory authority in the EEA member state or the UK where you live, where you work, or where the alleged infringement took place. A list of EU supervisory authorities is available from the European Data Protection Board at edpb.europa.eu, and the UK supervisory authority is the Information Commissioner’s Office (ICO) at ico.org.uk.
You can manage billing through the Stripe portal (Manage plan on bridgemind.ai) or account billing at app.bridgemind.ai, and you can control local app data and operating system permissions on your device.
13. Children#
Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. For builders in the EEA, we do not knowingly offer information-society services directly to children under 16 without parental consent where required by local law. If you believe a child has provided personal information to us, contact us so we can review and address it.
14. Changes to This Policy#
We may update this Privacy Policy from time to time. If we make a material change, we will update the date above and, when appropriate, provide additional notice.
15. Contact#
BridgeMind LLC is based in the United States. Privacy questions or requests may be sent to [email protected].
