BCD Privacy
Effective September 26, 2026
BCD stores account and device metadata needed to operate the service, plus metadata-only product telemetry such as install/device identifier, version, platform, tool name, success/error status, duration, and error type.
Telemetry does not store file contents, file paths, command text or arguments, process output, clipboard contents, or screenshots.
Remote tool payloads pass through the relay in memory to complete requested actions and are not intentionally persisted. Account credentials and OAuth/device tokens are hashed where applicable. BCD does not sell user data.
If you choose Google sign-in, we receive your Google account identifier and verified email address to create or connect your BCD account. We do not request Gmail, Drive, contacts, or calendar access. We retain the identifier and email while your BCD account remains active, and do not retain Google access or refresh tokens. Temporary sign-in verification records expire after 10 minutes. Google handles authentication under its own privacy policy.
If you choose a paid subscription, Stripe processes your payment details. Stripe collects your billing address and any business tax details you provide to calculate taxes and issue invoices. BCD stores the Stripe customer, subscription, invoice, and payment identifiers, plan, payment status, amounts, and dates needed to provide access and handle billing. BCD does not receive or store your full card number or security code. Stripe handles payment information under its own privacy policy. Billing records may be retained as required for accounting and dispute handling.
Our public website pages (home, prompts, iOS, pricing, signup, sign-in, support, and policy pages) use a first-party cookie to count visits. We record the page, the site or campaign that referred you, and, if you create an account, which of those visits led to it and the resulting subscription revenue. We do not record IP addresses or browser details for this, do not use third-party analytics or advertising scripts, and do not track account, computer, or AI tool activity this way. Browsers sending Global Privacy Control or Do Not Track are not counted. Visit records are kept for up to 13 months, or while a linked account remains active.
When a tool call fails, we keep the tool name, the kind of failure, its error code and the account it happened on for 30 days, so we can fix problems you run into. We never keep the request's contents, file paths, commands or output.
Product telemetry defaults to 30-day retention. Local audit logs remain on the user’s computer, are not uploaded as audit content, and default to 90-day retention.
Support requests store the email and message you submit for up to 180 days so the request can be handled. Avoid including credentials or secrets.
Video tools run on your computer. If you ask BCD to transcribe a video, Apple speech recognition on that computer turns the speech into text; for languages without on-device support, Apple processes the audio under its own privacy policy. BCD does not receive the audio or the video.
If you ask to hear about the Windows version, we store that email address, your language, and the visit record it came from, and use it only to tell you when BCD runs on Windows. Ask through the support page to be removed.
Referral codes link a new signup to the referring account. We retain referral attribution and reward records while the related accounts remain active. Referrers see aggregate counts, not the invited account’s email or payment details.
For privacy or support questions, use the BCD support page.