Privacy Policy

Benenota Pty Ltd (ABN 60 691 836 085) ("Bower", "we", "us", or "our") operates the Bower platform at app.bowerlabs.ai. This policy explains what personal information we collect, how we use and protect it, and what you can do about it.

It sits alongside our Terms of Service. Where the Terms and this policy describe the same thing, particularly de-identified data, they say the same thing. Section 6 below is the counterpart to section 8 of the Terms.

We are bound by the Australian Privacy Act 1988 and the Australian Privacy Principles. Where the GDPR or UK GDPR applies to you, we act as processor for your workspace content and as controller for your account and billing data.

1. Who this applies to

  • Visitors to the Bower website
  • Users of the Bower platform, on any plan
  • Anyone who contacts us by email, support, or research interview

It does not apply to third-party sites we link to.

2. Who to contact

Benenota Pty Ltd, 16 Bluejay Street, QLD 4220, Australia
Data Protection Officer: David Lyon, privacy@bowerlabs.ai

3. What we collect

3.1 What you give us. Name, email, affiliation, account credentials and profile, your communications with us, and billing details, which are processed by Stripe and never stored on our servers.

3.2 What you capture. Notes, protocols, images, audio and video recordings, transcripts, documents, experimental observations, and your conversations with Bird, plus capture metadata such as timestamps and device type. This content may contain personal information depending on how you use the platform. You own it, and that includes what the Service generates from it: transcripts, extracted values, summaries, and Bird's responses are treated as your content too. See section 7 of the Terms.

3.3 What we collect automatically. Device and browser type, IP address, and usage data such as feature usage and session duration. On our marketing website we also collect, with your consent, the advertising measurement data described in section 12. Product analytics and session replay require your cookie consent. In Restricted-mode workspaces, session replay, autocapture, and every other content-bearing capture are disabled outright, and the analytics events that remain carry only event names and metadata, never content.

4. Why we use it

PurposeLawful basis (GDPR Art. 6)Data used
Provide and operate BowerContract 6(1)(b)Account data, workspace data
AI processing: transcription, extraction, chat, searchContract 6(1)(b)Content you submit for processing
Authenticate users and manage accountsContract 6(1)(b)Email, credentials
AI quality monitoring and evaluation (section 5.3)Legitimate interests 6(1)(f)AI request and response text, token counts
Security, abuse prevention, audit loggingLegitimate interests 6(1)(f)IP address, user agent, actions
De-identifying data, and using the result (section 6)Legitimate interests 6(1)(f)See section 6
Product analytics and session replayConsent 6(1)(a)Usage data, with cookie consent only
Measuring our advertising, and showing Bower ads to people who visited our marketing websiteConsent 6(1)(a)Marketing-website visit data, with cookie consent only. Never research content
Product and service updatesLegitimate interests 6(1)(f)Email
SupportContract 6(1)(b)Email, account data
Legal and regulatory obligationsLegal obligation 6(1)(c)As required

We do not sell personal information.

5. AI processing

5.1 When AI runs. AI features operate on content you choose to capture or upload, as part of features you can see. Some steps are automatic, such as generating a title for a new note, extracting text from a file you upload, and indexing content for search. We do not run AI over your content for purposes unrelated to the features in front of you.

5.2 Training. We do not use your identifiable content to train, fine-tune, or benchmark any AI model. Separately, we require our AI providers to be contractually barred from training on your content and from retaining or logging it for human review beyond what is needed to return a result. Those are two different commitments, one ours and one theirs, and we keep them distinct because they protect different things.

5.3 Quality monitoring, and what it retains. To keep AI features reliable we retain records of AI requests and responses in a third-party observability service, named on our sub-processor page with its processing location and current agreement status. We notify workspace owners of material changes to that list. Those records contain the request and response text itself, and it is not de-identified.

This is service operation, not model improvement: what these records improve is Bower's own prompts, product code, and configuration, and nothing is learned into any model's weights. This material is not treated as de-identified data under section 6, is not used under section 6.2, and is not used to train any model. It is used only by Bower: the service processes it solely on our behalf under its data processing terms, and access is limited to people working on service quality and incident response. The service we use today limits our access to the most recent 90 days of these records. We do not yet enforce a fixed deletion schedule for these records; if we adopt one, we will state the period here.

Workspaces in Restricted mode send nothing to this service, enforced server-side. For other workspaces, capture of request and response text is controlled by a platform-level setting that Bower operates; there is no per-workspace toggle today, and Restricted mode is the way to turn this capture off for a workspace. Details are on our AI and your data page.

We have removed an earlier sentence in this policy that said all providers were configured for zero retention or inference only. Read narrowly it referred to AI providers, but sitting in this section it implied more than was true, and section 5.3 is the accurate account.

6. De-identified data

This section is the privacy counterpart to section 8 of the Terms of Service. It says the same thing. If you find a difference between the two, tell us and we will fix it.

6.1 Two tests, and both must pass. Before we use anything you captured for the purposes in 6.2, it must be de-identified and stripped of your substantive research content.

  • Test 1, personal identifiability. All direct and indirect identifiers removed or irreversibly transformed, so there is no reasonable likelihood of identifying an individual, or you, or your organization or lab, from the data alone or combined with other data we hold. For audio and visual material that includes faces, hands, voices, screen contents, identifying text, and file metadata. An aggregate small enough to re-expose one customer is not de-identified.
  • Test 2, substantive research content. Stripped of your results, findings, novel methods, discoveries, inventions, patentable subject matter, and trade secrets. These are yours absolutely, whether or not anyone is identifiable, and they are never used for the purposes in 6.2 and never surfaced to another customer.

De-identifying a person does not make your science ours. Passing one test is not enough. Where the GDPR or UK GDPR applies to you, we apply Test 1 at the standard those laws set for anonymization; until data meets it, we continue to treat it as personal information under this policy.

6.2 What we may do with the result. Where both tests are passed, we may use the data to develop and improve the platform, to improve our models and their outputs, and to develop new products and services. Data that has passed both tests is ours rather than yours, and it is not returned or deleted when your subscription ends, because by then it cannot be linked back to you. We do not sell it, and we do not publish it beyond aggregate statistics about use of the Service that identify no customer, no individual, and no research content. We take reasonable steps to ensure it cannot be reverse-engineered or re-identified.

6.3 What this covers today. We only do this with data we have actually de-identified to the standard above. Today that is operational telemetry once aggregated: usage counts, feature adoption, timing, and error rates, combined so that neither you nor any individual is identifiable. The raw rows behind those figures carry workspace and user identifiers so we can run the Service and support you; only the aggregates are used under 6.2. It does not include your free text, audio, images, or video, because we do not yet operate a pipeline capable of de-identifying that material to this standard. Until we do, none of it is used under 6.2. If that changes we will say so before relying on it, and give notice under section 14.

6.4 If you joined before 15 October 2026. Content captured under our earlier policy stays governed by the commitment we gave then. Section 6.2 applies only to content captured on or after the effective date of this version.

7. Sharing and disclosure

7.1 Sub-processors. We share data with providers who help us operate Bower. Our sub-processor page lists each one, what it processes, where, and its current DPA or BAA status. Where an agreement is not in place we say so on the entry rather than leaving you to assume.

7.2 Team workspaces. In a shared workspace, content and metadata may be visible to other authorized members according to their role and the item's privacy setting.

7.3 Legal. Where required by law, regulation, or court order, or to protect the rights, safety, or security of Bower, our users, or others. Where we are permitted to tell you first, we will.

7.4 Advertising. If you consent to advertising cookies on our marketing website, LinkedIn receives the fact that you visited it, so we can measure our advertising there and show Bower ads to people who have already visited. This applies to the marketing website only. Nothing you capture in Bower, and no research content, is ever used for advertising or shared with an advertising provider.

We do not sell personal information.

8. Where your data goes

Your data is stored on Google Cloud infrastructure in the United States (us-central1, Iowa), and most processing happens there. Inference for some newer Google AI models runs on Google's global endpoint, which can serve a request from a region outside the US while your stored data stays in us-central1. Other sub-processors' locations are on the sub-processor page.

For transfers from Australia, we take reasonable steps under Australian Privacy Principle 8 to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles, principally through the data protection terms in each provider's agreement.

For transfers subject to the GDPR, the safeguard depends on the provider: Standard Contractual Clauses where they are incorporated into an applicable DPA, or the EU-US Data Privacy Framework where the recipient participates. We do not claim that Standard Contractual Clauses are in place for a provider whose sub-processor entry says no DPA is currently signed.

9. How long we keep things

WhatHow long
Notes, protocols, files, and the audio and images you captureUntil you delete them, or you delete your account
Items you move to trash30 days, then permanently deleted from the database and file storage
Version history7 days on Free, 1 year on Pro, 7 years on Team
Audit logs30 days on Free, 1 year on Pro, 7 years on Team
AI quality-monitoring records (section 5.3)Accessible to us for the most recent 90 days; no fixed deletion schedule yet
Session replay, where you consented and the workspace is not Restricted30 days
Expired share linksDeleted promptly after expiry
Revoked share links30 days
Used or expired invitations90 days
Database backupsLimited periods appropriate to their purpose, then automatically deleted

One thing worth being explicit about: raw audio and images are not deleted after they are transcribed or read. They stay attached to your note as the source record, which is usually what you want in a lab notebook, and they are removed when you delete the note or the attachment.

10. Security

  • Encryption in transit (TLS) and at rest (AES-256)
  • Workspace-level isolation enforced at the data layer, not just in the interface
  • Role-based access control, with per-item privacy settings
  • Audit logging of every create, update, and delete in your workspace
  • Session timeout after 30 minutes of inactivity
  • Secrets held in Google Secret Manager, private networking between services

No system is completely secure. Our Data privacy page has the technical detail.

11. Health information and Restricted mode

Bower acts as a Business Associate under HIPAA, not a Covered Entity. If you will place protected health information in Bower, you need a signed Business Associate Agreement with us, and you should enable Restricted mode on that workspace: it is how the protections below are enforced.

Restricted mode confines the workspace to providers covered by our BAA and blocks the rest server-side. AI inference already runs entirely inside that boundary for every workspace; what Restricted mode adds is that nothing is sent to the AI quality-monitoring service (section 5.3), session replay and every other content-bearing analytics capture are disabled (the analytics events that remain carry only names and metadata), share links cannot be created, and connectors, external AI app access, and literature lookups are unavailable. See Restricted mode.

Health information is sensitive information under the Privacy Act. We collect it only where you provide it through your use of the Service and where the Act permits.

Data breaches. If a breach is likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we will notify affected Covered Entities as required by HIPAA and by any applicable Business Associate Agreement.

12. Cookies

We use cookies and browser storage to keep you signed in, remember your preferences, and, with your consent, understand how the product is used and measure our advertising.

On our marketing website, analytics and advertising cookies load only after you accept them. Until you do, none are set. The analytics providers are Google Analytics and PostHog; the advertising provider is LinkedIn. To change a choice you have already made, clear this site's stored data in your browser and the banner will ask again.

In the Bower app, analytics and session replay require your consent and are disabled entirely for workspaces in Restricted mode. See our Cookie policy.

13. Your rights

RightHow to use it
Access your personal informationSettings > Security > Export my data
Correct itSettings > Profile
Delete itSettings > Security > Delete account
Export it (portability)Download as JSON from Settings > Security
Object or restrict processingprivacy@bowerlabs.ai
Withdraw consentSettings > Security, analytics cookies

Deletion covers your personal information and your content. It does not reach data that has already passed both tests in section 6 and been incorporated into a model or aggregate, because that data can no longer be connected to you. Section 6.2 says the same thing and section 8.7 of the Terms says it again.

You can complain to us at privacy@bowerlabs.ai. We aim to respond within 30 days. If you are not satisfied you can complain to the Office of the Australian Information Commissioner, or to your local supervisory authority.

14. Changes to this policy

We may update this policy. We will notify you of material changes by email or in-app notification at least 30 days before they take effect. The current version always lives at this address.

15. Contact

privacy@bowerlabs.ai
Data Protection Officer: David Lyon
Benenota Pty Ltd, 16 Bluejay Street, QLD 4220, Australia