What we hold, and who can see it
BOB holds your goals, your calendar, your health data and, if you connect it, your money. This policy sets out what we hold, where it is stored, who can access it, and the limits of what we can promise. It is written to be understood rather than to be survived.
Who we are
BOB is operated by JC1 LTD, a company registered in Northern Ireland under company number NI711308, trading as jc1.tech. Our registered office address is held on the public register at Companies House.
For the purposes of UK data protection law, JC1 LTD is the data controller for the personal data described here. That means we decide what is collected and why, and we are accountable for it.
The short version
- We hold what you put into BOB, plus what you explicitly connect to it.
- Your data is stored in the United Kingdom.
- We do not sell it, we do not advertise against it, and we share it only with the providers needed to operate the service.
- There is no end-to-end encryption, and an administrator can technically read your data. That is a real trade-off and it is explained in full below.
- You can export or delete everything you hold in BOB, on request and at no cost.
What we hold
Nearly all of it is data you typed in or asked us to fetch. Nothing here is bought from a data broker, and none of it is inferred about you from third-party tracking.
| Category | What that means in practice | How we get it |
|---|---|---|
| Account | Email address, display name, and a profile photo if your sign-in provider supplies one. | You, at sign-up, or Google if you sign in that way. |
| Planning | Themes, goals, stories, tasks, sprints, habits, routines, notes and acceptance criteria. | You. |
| Journals | Free-text journal entries and daily check-ins. Often the most personal thing in the app. | You. |
| Calendar | Event titles, times and attendee counts from calendars you connect, plus the blocks BOB schedules. | Google Calendar, with your authorisation. |
| Health and fitness | Workouts, heart-rate variability, sleep and recovery, nutrition, weight and body composition. | You, or Strava and Apple Health if you connect them. See below. |
| Finance | Transactions, balances, pots, budgets and net-worth history for accounts you connect or enter by hand. | You, or your bank via an authorised connection. |
| Reading, media and travel | Books, watch history, game activity and trip plans, where you connect those services. | You, or the service you connect. |
| Integration credentials | OAuth access and refresh tokens for the services you connect. Never your passwords, which we never see. | The service, when you authorise it. |
| Technical and diagnostic | Error logs, sync status, AI usage counts and quotas, and records of automated jobs that ran on your account. | Generated as you use BOB. |
| Support messages | Anything you send us through the chat on this site or by email. | You. |
You can use BOB without connecting anything. Every integration in that list is optional, off until you turn it on, and disconnectable at any time.
Health and sensitive data
Health data gets special protection under UK GDPR, and rightly so. If you use BOB's fitness, recovery or nutrition features, we are processing special category data about you.
We rely on your explicit consent to do that, which is the condition set out in Article 9(2)(a). In practice that means the health side of BOB does nothing until you switch it on or connect a provider, and turning it off or disconnecting withdraws that consent. Withdrawing does not affect anything we lawfully did beforehand, and it does not affect the rest of your account.
We do not use health data for advertising, and we do not share it with insurers, employers or any other third party beyond the providers listed below. We do not sell it. Should this ever change, we would seek your consent first rather than amend this page quietly.
Why we are allowed to hold it
| What we do | Lawful basis |
|---|---|
| Run your account and give you the app you asked for | Performance of a contract |
| Health, fitness and recovery features | Explicit consent (Art. 9(2)(a)) |
| Optional AI features and optional integrations | Consent |
| Keeping BOB secure, debugging it, preventing abuse | Legitimate interests |
| Emails you need in order to use the service | Performance of a contract |
| Keeping business and tax records | Legal obligation |
Where we rely on consent, you can withdraw it without giving a reason and without losing access to the rest of BOB. Where we rely on legitimate interests, you can object, and we will either stop or explain why we believe we may continue.
Encryption, and who can actually see your data
Many privacy policies leave this question vague. We would rather set it out directly, because the answer should inform what you choose to put into the service.
BOB is not end-to-end encrypted, and an administrator can technically read your data.
No one at JC1 LTD reads your goals, journals or health data in the ordinary course of operating the service, and we have no commercial reason to do so. We will not, however, claim to be technically incapable of it, because that would not be accurate.
What is encrypted
- In transit. Everything between your device and our servers travels over TLS.
- At rest. All stored data is encrypted on disk by our infrastructure provider using AES-256. This protects against someone physically removing a disk from a data centre.
- Integration credentials. Tokens for connected financial accounts are additionally encrypted at the application layer with a key held separately from the database, so a database export alone does not yield working credentials. We are extending this to all integration tokens.
What is not
Your goals, tasks, journals, calendar, health and finance records are stored so that our servers can read them. They have to be: the parts of BOB that provide its value - scoring your Top 3 overnight, scheduling into your calendar, breaking a goal into stories, the coaching features - run on our servers, and a server cannot process data it cannot read.
True end-to-end encryption, where only your device holds the key, would make all of those features impossible. That is the trade-off. We have chosen a functional planner over an encrypted notebook, and you are entitled to know that this choice was made on your behalf.
So what actually protects you
- Enforced separation between users. Every record is stamped with its owner, and the database refuses any read or write where the owner does not match the signed-in account. This is enforced by the database itself, not by application code that could forget. No BOB user can reach another user's data.
- Very few people with access. Administrative access is limited to what is needed to operate and support the service, and the number of people holding it is currently in the low single figures.
- Access is logged. Administrative access to the database is recorded by our infrastructure provider, so it can be reviewed after the fact.
- Notification. Where we access the contents of an individual account for support or debugging, it is either at your request or we will inform you that we have done so.
Our guidance is straightforward. BOB is a suitable place for your goals, your training and your week. If information is sensitive enough that its disclosure through legal compulsion or a security incident would cause you real harm, it should not be placed in BOB, nor in any product offering a comparable architecture.
Where your data lives
Your data is stored and processed in the United Kingdom. Our databases, server functions and hosting all run in Google Cloud's London region.
Some of the third parties listed below operate outside the UK. Where data reaches them, transfers are covered by UK adequacy regulations or by the International Data Transfer Addendum to the EU Standard Contractual Clauses.
Who else touches your data
We use other companies to run BOB. They act on our instructions, they may not use your data for their own purposes, and none of them pay us for access. This list is complete as at the date at the bottom of this page.
| Who | What for | Where |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, sign-in, server functions | UK (London region) |
| Brevo | Transactional email - sign-in links, digests, notifications | EU |
| Google AI, Anthropic, OpenRouter | The optional AI features, where you enable them | EU / US |
| Apple | Distribution of the iOS app through TestFlight | EU / US |
Services you connect yourself - Google Calendar, Strava, your bank, and similar - are not our sub-processors. You have your own relationship with them, governed by their terms, and you can revoke our access from their side at any time as well as from within BOB.
AI features
Every AI feature in BOB is a switch you turn on. With them all off, BOB is a planner that does what you tell it and nothing else, and no content of yours is sent to any AI provider.
When you do turn one on, the relevant content - a goal you asked to break down, the items being scored, the journal entry being summarised - is sent to the model provider to generate the response. We ask providers not to train their models on it, and we choose providers who offer that commitment. We cannot audit their infrastructure, so we are telling you what we have contracted for rather than what we have personally verified.
If you supply your own API key, your content goes to that provider under your own account and your own agreement with them, not ours.
No AI feature in BOB makes a decision with a legal or similarly significant effect on you. It suggests an order for your week; it does not decide anything about you.
What we store on your device
This website sets no advertising or analytics cookies. We do not run Google Analytics, a tag manager, or any third-party tracker on it. This is verifiable in your browser's developer tools.
The site stores two strictly-necessary items locally: a short-lived chat session identifier, held only until you close the tab, and, if you start a beta sign-up, the details you entered so the form survives a reload. Neither follows you across sites, and neither needs consent under the Privacy and Electronic Communications Regulations.
The app itself stores your sign-in session and a local cache of your own data, so it opens instantly and keeps working when your connection drops. Signing out clears it.
How long we keep it
- While your account is open - your content stays until you delete it, because deleting your own history is your call and not ours.
- When you delete your account - your content is deleted within 30 days, including from routine backups within a further 30 days.
- Diagnostic and error logs - kept up to 90 days, then discarded.
- Support conversations - kept up to 12 months.
- Billing and tax records - kept 6 years, because HMRC requires it. This is the one category we cannot delete on request.
Your rights
Under UK data protection law you can ask us to:
- give you a copy of what we hold about you, in a portable format;
- correct anything inaccurate;
- delete your data, subject only to the billing records above;
- restrict or object to particular processing;
- withdraw consent for anything relying on it, such as AI features or health data.
Email privacy@jc1.tech. We will respond within one month, at no charge, and you do not need to give a reason.
If we get it wrong, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or by telephone on 0303 123 1113. You are not required to raise the matter with us first, though we would welcome the opportunity to resolve it.
Because this is a beta
BOB is in private beta. Beta software can and occasionally does lose data. We take backups and we test, but BOB should not be treated as the sole copy of anything you cannot afford to lose. Export is available, and we will assist you with it on request.
If we ever suffer a personal data breach that is likely to result in a risk to you, we will report it to the ICO within 72 hours and notify you directly where the risk is high. Our notification will describe what actually occurred and what we are doing about it.
Contact
Privacy questions, requests and complaints: privacy@jc1.tech.
We handle privacy correspondence by email so that requests are logged and answered promptly. If you require a postal address for the service of formal documents, our registered office is recorded at Companies House against company number NI711308.
If we change this policy in a way that materially affects you, we will notify you by email before the change takes effect rather than silently republishing this page.