Privacy Policy
Effective September 19, 2026
Who this covers
Build Bots Now is operated by Nebulon Labs LLC. This policy covers two different groups of people: our customers, who sign in and build assistants, and our customers' visitors, who chat with an assistant on someone else's website. Where the two differ, it says so.
1. Information we collect from customers
- Account information: your email address, display name and profile photo, provided by Google Sign-In or by you at sign-up. Authentication is handled by Firebase Authentication; we never see or store your password.
- Content you upload: the documents, Q&A pairs, text and URLs you give an assistant, plus the settings and appearance you choose.
- Billing information: your subscription status and invoice history. Card details go directly to Stripe and are never sent to or stored on our servers.
- Operational logs: errors and request records we need to keep the service running.
2. Information collected from visitors who chat
When someone uses an assistant on a customer's site, we store the questions asked, the answers given, the page's origin, the browser type, a truncated IP address prefix, and counters used to enforce question limits. We do this so the customer can review conversations and so limits cannot be bypassed.
On a free assistant, visitors also get a daily question limit. To count it without cookies, we combine the visitor's IP address and browser type into a one-way code that cannot be turned back into either. We keep that code and the day's count for two days.
If a visitor asks for a person or books an appointment, the name, contact details and message they give are sent to the customer by email, Slack, Discord, webhook or the customer's booking tool, whichever the customer has connected, and a copy is kept so the customer can see it in the dashboard.
Someone at the customer's business can take over a conversation and reply to the visitor in person. While they do, the visitor's messages go to that person rather than the assistant, and both sides are stored with the rest of the transcript, under the name the person uses in the dashboard. To show whether the visitor is still there, the chat window checks in every few seconds while it is open, and we note when it last did.
If the customer connects their own API, the assistant may send it values a visitor gave in the chat, such as an order number, to look something up, and may repeat what the API answers. We send only the lookups the customer has turned on, and we keep a record of each call (what was asked, whether it worked, and when) so the customer can check it.
The chat widget sets no cookies, and stores nothing in the visitor's browser until they open the chat. Once they do, it keeps one entry in local storage on that site: a code identifying the conversation, when it started, and whether the chat window was open, so a refresh or another page carries on the same conversation. It holds no personal information, is removed when the conversation expires (after 12 hours at most), and is not shared with other sites. The widget does not track visitors across sites, and it does not build a profile of anyone.
Visitors may type personal information into a chat box. We ask customers not to solicit it, but where it happens the customer is the controller of that data and we process it on their behalf. Visitor requests about that data should go to the site that hosts the assistant.
3. How we use information
- To create, host and run your assistants.
- To answer questions using the content you supplied.
- To bill you, and to send receipts and service notices.
- To provide support and investigate abuse.
- To keep the service secure and working.
We do not sell personal information, we do not share it with advertisers, and we do not use your content to train models offered to anyone else.
4. Third-party processors
- Google Cloud Platform and Firebase: hosting, authentication, databases, file storage, and the Conversational Agents and Vertex AI Search services that index your content and generate answers.
- Stripe: payment processing, subscriptions and invoices.
- Brevo: sending email, including handoff emails that carry a visitor's details to the customer.
Each processes data under its own terms and under agreements that limit what it may do with it.
5. Where data is processed
Data is processed in the United States on Google Cloud infrastructure. If you are outside the US, using the service means your information is transferred there.
6. Data sharing
We share information only with the processors above, when you ask us to, or when we are legally required to. If the business is ever sold or merged, customer data may transfer as part of it, and we will say so before it happens.
7. Security
All traffic is encrypted in transit. The dashboard has no direct access to our databases. Every read and write goes through an authenticated API that checks your membership of the account first. Secrets and API keys are held server-side only. No system is perfectly secure, but this is the standard we hold ourselves to.
8. Cookies and tracking
The dashboard uses Firebase Authentication, which stores a sign-in token in your browser so you stay signed in. It also keeps a few settings in your browser's storage: whether you picked light or dark mode, which account you last used, and an unfinished assistant from the start page until you sign in or close the tab. We run no advertising trackers and no third-party analytics. The embeddable widget, as above, sets no cookies and stores only the conversation a visitor has opened.
9. Data retention
We keep your account and content while your account is open. Deleting your account removes account data and uploaded content within 30 days, except for records we are required to keep for tax and accounting.
Conversation transcripts are deleted automatically about 30 days after the conversation, whether the assistant is running or archived. Handoff and booking records are kept while the assistant exists and are deleted with it. Records of calls to a customer's connected API are deleted automatically after 30 days. Counters used for question limits and abuse prevention are deleted within a few days.
10. Your rights
You may request access to, correction of, a copy of, or deletion of your personal information at any time by emailing privacy@nebulonlabs.com. Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or the CCPA/CPRA, including the right not to have personal information sold or shared, which we do not do in any case. We will not discriminate against you for exercising any of them.
11. Children's privacy
Build Bots Now is a business product and is not directed at children under 13. We do not knowingly collect their information; if we learn we have, we delete it.
12. Changes to this policy
We will post any changes here and update the effective date. Material changes will be announced by email or in the dashboard before they take effect.
13. Contact
Nebulon Labs LLC
14707 S Dixie Hwy, Suite 402C #182, Palmetto Bay, FL 33176
Privacy: privacy@nebulonlabs.com
Support: hello@nebulonlabs.com