Last updated: September 3, 2026
BOB AI Holdings Corp (“we”, “us”, or “our”) operates BOB, an AI-powered financial operations platform for small businesses — an assistant that helps you track spending, manage invoices, and move money with your approval. BOB is a financial technology company and is not a bank. Bank deposit services provided by Erebor Bank NA, Member FDIC. This Privacy Policy describes how we collect, use, and protect your information when you use our Service. The Service is available on the web and as an iOS app. This policy covers both.
Production session replay is limited to the public joinbob.ai landing page under the masking and collection limits described above; authenticated product pages are not recorded in production. Except for the first name, email address, and bounded business category, employee range, and revenue range on a successful public waitlist submission described above, we do not send PostHog names, email addresses, detailed business or financial records, conversation or other form contents, raw authenticated URLs, or other free-form customer content through these analytics paths.
Where applicable, we rely on our legitimate interests to operate, secure, measure, and improve the Service for the limited analytics described in this policy. For PostHog analytics, safeguards include data minimization, discarded client IP data, memory-only public analytics, supported browser Do Not Track signals, and masked replay limited to the public landing page. Separately, Meta advertising attribution is limited to public marketing pages and waitlist conversions and uses the data described above.
We do not collect or store:
We do not sell personal information for money. We disclose data only as described in this policy. Some privacy laws may define the Meta advertising attribution described below as “sharing” or “targeted advertising.” Where applicable, you may opt out of that use by contacting contact@joinbob.ai.
We may disclose data to:
We retain account data for as long as your account remains active and as needed to provide the Service, enforce our terms, and comply with legal obligations. We may retain limited records (including security and fraud-prevention logs) after deletion requests where required by law or legitimate security interests.
Unless deleted earlier, the current PostHog project configuration permits analytics and reliability data to be retained for up to 84 months. We periodically review that period and delete or aggregate data earlier when it is no longer needed to measure product performance, investigate reliability, or meet legal obligations.
You may request deletion of your account and associated data by contacting us at contact@joinbob.ai.
We use commercially reasonable administrative, technical, and organizational safeguards to protect data, including encryption in transit (TLS) and at rest, API key authentication with per-key rate limiting, and HMAC-verified webhook signatures.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected users as required by applicable law.
Depending on your location, you may have rights to access, correct, delete, restrict, or export your personal data, and to opt out of sale, sharing, or targeted advertising.
To submit a request, contact contact@joinbob.ai. We will verify your request and respond within the timeframe required by applicable law.
We use essential session cookies for authentication. We use PostHog as our analytics and reliability service provider. On public marketing and sign-in pages, PostHog runs without analytics cookies or local/session storage, does not create person profiles, and honors supported browser Do Not Track signals. PostHog does not track visitors across unrelated websites on our behalf. The internal authenticated pilot uses session-scoped browser storage and is limited to BOB staff accounts. Production session replay is used only on the public joinbob.ai landing page and applies the masking and collection limits described in Section 2.2; authenticated product pages remain excluded.
Public marketing pages use Meta Pixel and Meta Conversions API for advertising attribution. Meta Pixel may set or read the _fbp browser identifier and the _fbc ad-click identifier, and the waitlist form passes those identifiers to our server so the corresponding browser and server conversion events can be deduplicated. Meta may process this information under its own privacy policy.
BOB offers an opt-in Model Context Protocol (MCP) connector that lets third-party AI assistants (such as Claude.ai or ChatGPT) read and act on your BOB data on your behalf. You install the connector by signing in with OAuth from inside the assistant — the assistant receives a scoped access token from us, and uses it to call a defined set of tools (for example, listing invoices, drafting an invoice, or sending one).
What the AI assistant’s provider receives:
What we receive: the tool name, the tool arguments, the response we returned, and the access token’s scoped identity. We do not receive the raw prompts you write inside the AI assistant — only the structured tool calls the assistant makes on your behalf.
What we store as audit records: the tool name, the access token’s scoped identity, the status of the call (ok / error / denied), an error message when relevant, the latency in milliseconds, a request identifier, and a SHA-256 hash of the tool arguments. We retain a hash rather than the raw arguments so that repeat calls with the same inputs can be grouped during security review without us persisting customer-identifying fields like email addresses or invoice amounts. Tool responses we returned to the assistant are not stored. Audit data is retained per Section 6.
Provider privacy policies apply. Each AI assistant provider has its own privacy policy governing what they collect, how they use your prompts (including potentially for model training), and how long they retain conversation history. Review your assistant’s privacy policy before connecting — for example, Anthropic’s Privacy Policy covers Claude.ai usage.
Scope and revocation. Each connector token is scoped to a specific set of capabilities (for example, invoices:read or invoices:write), shown on the consent screen at install time. To revoke a connector, disconnect it from inside the AI assistant’s connector settings; most AI assistant clients will, in addition, call our standard RFC 7009 revocation endpoint to invalidate the token on our side, but we cannot guarantee third-party client behavior. For a guaranteed server-side revocation — for example, if you have lost access to the AI assistant account or want to be certain the token cannot be used — email contact@joinbob.ai and we will revoke it directly. Access tokens also expire automatically after one hour; if the assistant did not refresh the token via offline_access, it will lose access at that point regardless.
Money-moving actions. Tools that send invoices, void invoices, or mark invoices paid are flagged to the assistant as destructive operations; the assistant is expected to (and Claude.ai does) present a confirmation prompt before executing them.
Push notifications. If you enable notifications, we store a device push token so we can alert you to approval requests, held payments, and other account activity. Notifications are delivered through Apple and Expo. You can turn them off in iOS Settings.
Face ID and passkeys. You can sign in with a passkey protected by Face ID or Touch ID. Your biometric data stays on your device. We only receive confirmation that your device approved the sign-in.
Camera. The camera is used only to scan the pairing code when you link your phone. Nothing is recorded or stored.
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.
We may update this Privacy Policy from time to time. We will update the “Last updated” date and, where required by law, provide additional notice. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
For privacy-related questions or requests, contact us at contact@joinbob.ai.