Privacy Policy
Last updated: 8 September 2026
This policy explains what Better Run, Inc. ("Bubbling", "we", "us") does with personal data. It covers our websites at bubbling.ai and alerts.bubbling.ai, the Bubbling dashboards, the Bubbling Alerts product, our ingestion API and embed SDK, and our email to you.
1. We wear two hats, and the difference matters
Read this section first. Everything else follows from it.
We are a controller of data about our own visitors and customers. When you visit our site, create an account, pay us, or write to support, we decide why and how that data is used. Sections 3 to 9 apply.
We are a processor of the conversations our customers send us. A business connects its chat assistant to Bubbling, and we read those conversations to produce alerts and analytics for that business. That business decides what to send and why. We act on its instructions. Section 10 applies.
If you talked to a chat assistant and reached this page, we are almost certainly wearing the second hat. We do not have a relationship with you, and we cannot identify which business holds your conversation without more information. Contact the business you were chatting with. Section 10 says what we can still do to help.
2. Who to contact
Better Run, Inc., 651 N Broad St, Suite 201, Middletown, DE 19709.
Privacy questions and requests: privacy@bubbling.ai.
3. The personal data we hold as a controller
Website visitors. Pages requested, referring page, approximate location derived from IP address, browser and device type, and the date and time. See the Cookie Notice for what is set in your browser.
Account holders. Name, work email address, password credentials, company name, job role if you give it, profile picture if you give one, language, and time zone.
Configuration you write. The projects you create, the sources you connect, the monitors you write in plain English, and the notification settings you choose. A monitor is a sentence you wrote, so treat it as yours.
Usage and diagnostics. Which features you use, API calls, ingestion volumes, errors and stack traces, and audit records of security-relevant actions such as sign-in and key rotation.
Billing. Company billing details, plan, invoices, and the last four digits and expiry of a payment card. Our payment processor holds the full card number. We never receive it.
Communications. Email, support tickets, and anything you tell us in them. Sales enquiries and the business contact details in them.
Applicants and partners. If you apply for a job or work with us commercially, the data you send us for that purpose.
We collect this from you directly, from your use of the Service, from the systems you connect, and from our payment and email providers.
4. Why we use it, and on what legal basis
The legal bases below are the ones the GDPR and the UK GDPR name. Where those laws do not apply, read the "why" and ignore the basis.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, deliver the Service | To perform our agreement with you | Contract |
| Take payment, send invoices, chase non-payment | To perform our agreement, and to protect our business | Contract, legitimate interests |
| Answer support and email | To perform our agreement, and to serve you well | Contract, legitimate interests |
| Keep the Service secure, detect abuse, keep audit logs | To protect the Service, our customers, and their End Users | Legitimate interests, legal obligation |
| Measure and improve the Service | To build a product people can use | Legitimate interests |
| Send product and service email you cannot opt out of, such as a security notice | To perform our agreement, and to meet legal duties | Contract, legal obligation |
| Send marketing email | To grow the business | Consent where required, otherwise legitimate interests |
| Meet accounting, tax, and other legal duties | Because the law requires it | Legal obligation |
| Establish, exercise, or defend a legal claim | To protect our rights | Legitimate interests |
Where we rely on legitimate interests, we weigh them against your rights first, and you can object at privacy@bubbling.ai under Section 9.
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined in California law. We have not done so in the last 12 months.
5. Who we share it with
Sub-processors. Vendors who process personal data to help us run the Service. The current list, with what each one does and where it is, is at Sub-processors. Each one is bound by a written contract, processes only on our instructions, and meets the standards our Data Processing Addendum requires.
Professional advisers. Lawyers, accountants, and auditors, under a duty of confidence.
Authorities. Where the law compels it, or to establish or defend a legal claim. We assess every request, we resist one that is overbroad or unlawful, and we tell the affected customer unless the law forbids it.
A successor. In a merger, acquisition, financing, or sale of assets, subject to this policy. We will tell you if a new entity takes over as controller.
We do not share personal data with anyone else, and we do not disclose Customer Data to advertisers or data brokers under any circumstances.
6. Where the data goes
We run the Service on Google Cloud infrastructure in us-central1, Iowa, United States, and our sub-processors are all in the United States.
If personal data moves from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum for UK transfers and the Swiss adaptations for Swiss transfers. We assess each transfer, and we apply encryption in transit and at rest, access control, and a policy of challenging unlawful government requests. Ask at privacy@bubbling.ai for a copy of the clauses.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and configuration | While the account is open, then 90 days after it closes |
| Billing records and invoices | 7 years, because tax and accounting law requires it |
| Support email and tickets | 3 years after the last message |
| Security and audit logs | 12 months |
| Website server logs | 90 days |
| Marketing contacts | Until you unsubscribe, then a suppression record so we do not contact you again |
| Customer Data we process for a customer | As the customer instructs. Section 10 |
Backups follow their own cycle and are overwritten within 7 days. We keep data longer where a legal claim or a legal duty requires it, and we delete or anonymize it when the reason for holding it ends.
8. How we protect it
We encrypt data in transit with TLS and at rest. We restrict access to the people who need it for their job, over multi-factor authentication and least privilege. We keep audit logs, we patch our systems, we separate our production environment from our development environment, we require every employee and contractor to sign a confidentiality agreement, and we review our vendors before we use them. Annex II of the Data Processing Addendum describes these measures in full.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant regulator as the law requires. Report a vulnerability to privacy@bubbling.ai.
9. Your rights
If you are in the EEA, the UK, or Switzerland, you can ask us to give you a copy of your personal data, correct it, delete it, restrict how we use it, or send it to another provider in a portable form. You can object to processing we base on legitimate interests, and you can object to direct marketing at any time and without a reason. Where we rely on consent, you can withdraw it, and the withdrawal does not affect what we did before it.
If you are in California, you can ask what personal data we collected about you and where it came from, ask for a copy, ask us to correct it or delete it, and limit our use of sensitive personal information. We do not sell or share personal information, so there is nothing to opt out of. You can use an authorized agent. We will not discriminate against you for exercising a right.
Other US states with a comprehensive privacy law grant broadly the same rights, and we honour them on the same terms.
Write to privacy@bubbling.ai. We answer within one month, and we can extend that by two months for a complex request, in which case we will tell you why. We will verify who you are before we act, and we will ask for no more information than the verification needs.
If you are unhappy with our answer, you can complain to your supervisory authority: the ICO in the United Kingdom, your national data protection authority in the EEA, the FDPIC in Switzerland, or the California Privacy Protection Agency. We would rather you told us first.
10. Conversations we process for a customer
This section covers the transcripts a business sends us about its own End Users.
The business is the controller. We are the processor. The business decides what to send, why, and for how long we keep it. It must tell its End Users what it does and obtain any consent required. Our Data Processing Addendum is the contract that governs this.
What is in the data. Message text written by the End User and by the assistant, timestamps, the identifier the business uses for that End User, and technical metadata about the session. Whatever personal data the End User typed into the chat comes with it, because that text is the point of the Service.
What we do with it. We store it, and we analyse it with a large language model to produce a summary, an outcome, a sentiment, an intent, a product area, and a match against the monitors the business wrote. We deliver the results to the business by email, in Slack, and in its dashboard.
What we do not do with it. We do not use it to train generative models, ours or anyone else's. Our AI sub-processor is contractually bound to the same restriction and does not train on it. We do not sell it, we do not use it for advertising, we do not use it for our own purposes, and we do not combine one customer's data with another's.
How long we keep it. For as long as the business instructs. When the business deletes a conversation or closes its account, we delete it under Section 13 of the Terms of Service: within 90 days, with backups following their own cycle.
If you are an End User. Contact the business you chatted with. It holds the relationship, it knows which conversation is yours, and it can reach us. If you write to privacy@bubbling.ai we will pass your request to the right customer where we can identify it, and we will tell you that we have done so, but we cannot act on the data ourselves without that customer's instruction.
11. Children
The Service is a business tool and it is not directed at children. We do not knowingly collect personal data from a child under 16 as a controller. If a business sends us a conversation held with a child, that business is responsible for the lawful basis for it. Tell us at privacy@bubbling.ai if you believe we hold a child's data as a controller, and we will delete it.
12. Changes
We can update this policy. The date at the top always says when. If a change is material, we will tell account holders by email or in the dashboard at least 30 days before it takes effect. Previous versions are available at privacy@bubbling.ai.