Terms of Service

These Terms of Service ("Terms") govern your access to and use of the Bower website, applications, and related services (together, the "Service").

The Service is operated by Benenota Pty Ltd (ABN 60 691 836 085) ("Bower", "we", "us", or "our").

By accessing or using the Service, you agree to these Terms and to our Privacy Policy, which forms part of them. If you do not agree, you must not use the Service.

Section 8 is the part most people want to read first. It sets out what you own, what we may do with data once it has been de-identified, and what we will never do with your results.

1. Definitions

  • Customer Data means everything you upload, capture, or create using the Service: notes, protocols, images, audio and video recordings, transcripts, documents, and your conversations with Bird.
  • Discovery Content has the meaning given in clause 8.5.
  • De-identified Data means Customer Data that has passed both tests in clause 8.2.
  • Institutional Agreement means a signed enterprise agreement, Business Associate Agreement, data processing agreement, or institutional data agreement between you (or your organization) and Bower.
  • Output means content the Service generates from your Customer Data, including transcripts, extracted values, summaries, and Bird's responses.
  • Restricted mode means the workspace setting described in clause 10.

2. Order of precedence

If you have an Institutional Agreement with us, that agreement wins. Where it conflicts with these Terms, the following order applies, highest first:

  • a Business Associate Agreement, for anything it covers
  • any other Institutional Agreement
  • these Terms
  • our Privacy Policy and the pages it references

Nothing in these Terms reduces a protection you have been given in an Institutional Agreement. If your institution's research ethics approval, data governance policy, or funding conditions restrict how your data may be handled, tell us before you upload it, so we can confirm whether the Service is suitable.

3. The Service

Bower is an AI-native research platform that helps researchers and research teams capture, organize, and reason over their lab work. It includes note capture, protocols, file management, voice transcription, photo and document text extraction, semantic search, live voice and video mode, and an AI research assistant (Bird).

The Service is offered in beta. That means:

  • Features may change, evolve, or be removed
  • The Service may contain bugs or errors
  • Performance and availability are not guaranteed
  • Outputs, including AI-generated Outputs, may be incomplete or inaccurate

You accept the risks inherent in using beta software.

4. Eligibility and authority

  • You must be at least 18 years old, or the age of legal majority where you live, to use the Service.
  • If you use the Service on behalf of an organization or institution, you represent that you have authority to bind that entity to these Terms.
  • If you upload data about other people, you represent that you have the consents, approvals, and ethics clearances needed to do so.

5. Accounts and access

Some features require an account. You agree to:

  • Provide accurate and current information
  • Keep your credentials secure and not share them
  • Accept responsibility for activity under your account
  • Tell us immediately if you suspect unauthorized access

We are not responsible for unauthorized access resulting from your failure to protect your credentials.

6. Acceptable use

You agree to use the Service only for lawful purposes. You must not:

  • Violate applicable laws or regulations
  • Upload or process content you do not have the right to use
  • Interfere with or compromise the Service
  • Access data belonging to other users without permission
  • Use the Service to generate or distribute harmful, misleading, or unlawful material
  • Reverse-engineer, decompile, or disassemble the Service
  • Use the Service for automated data collection or scraping

We may suspend or terminate access if these Terms are breached.

7. Your data and the license you grant us

7.1 You own your data

We do not own any of your Customer Data. You retain all right, title, and interest, including all intellectual property rights, in and to your Customer Data. Nothing in these Terms transfers ownership of your research, your data, or your intellectual property to us.

7.2 The license you grant us, and its limits

To run the Service for you, we need permission to handle your Customer Data. You grant us a non-exclusive, worldwide, royalty-free license to host, store, copy, transmit, process, display, and back up your Customer Data, and to make it available to the sub-processors listed on our sub-processor page, for these purposes only:

  • providing, operating, and maintaining the Service, including its AI features
  • personalizing the Service for you, where you use features that adapt to your work
  • securing the Service and investigating abuse or security incidents
  • providing support when you ask for it
  • monitoring and evaluating the quality and reliability of the Service, as described in clause 9.3
  • meeting our legal and regulatory obligations

This license lasts for as long as you use the Service, and afterwards only for as long as it takes to complete deletion under clause 17 and the Privacy Policy, including deletion from backups, and to meet our legal obligations. It does not include a right to improve our products from your identifiable Customer Data. Every improvement right we hold lives in section 8 and is limited by it.

7.3 Outputs

As between you and us, you own the Outputs the Service generates from your Customer Data, and Outputs are treated as Customer Data under these Terms.

Because of how generative AI works, Outputs are not guaranteed to be unique. Another customer may receive a similar or identical Output from a similar request. This does not affect your ownership of your own Outputs, and it does not permit us to give any other customer your Discovery Content, which clause 8.5 prohibits absolutely.

7.4 What you are responsible for

  • The legality and integrity of your Customer Data
  • Compliance with your institutional, ethical, and regulatory obligations, including human research ethics approvals
  • Reviewing AI Outputs before you rely on or publish them
  • Deciding whether the Service is appropriate for your use case, and whether a workspace should be in Restricted mode

8. De-identified data

The principle behind this section is simple: you own the data, we own the learnings. What follows is where that line sits and how it is enforced.

8.1 We do not train on your identifiable data

We will not use identifiable Customer Data to train, fine-tune, benchmark, or otherwise develop any artificial intelligence or machine learning model. This applies to your notes, protocols, transcripts, images, video, and your conversations with Bird. It applies to our own models and to anyone else's. Clause 9.3 describes the one nearby activity this does not prohibit: using retained requests as test inputs to measure the quality of the Service.

8.2 Two tests, and both must pass

De-identification is not one gate. Before we use any Customer Data under clause 8.3, it must pass both of the tests below. Passing one is not enough. De-identifying a person does not make your science ours.

Test 1, personal identifiability. All direct and indirect identifiers have been removed or irreversibly transformed, so that there is no reasonable likelihood of identifying an individual, or you, or your organization or lab, from the data alone or combined with other data we hold. For audio and visual material this includes faces, hands, voices, screen contents, identifying text, and the metadata attached to the file. An aggregate is not de-identified if the sample is small enough to re-expose a single customer.

Test 2, substantive research content. The data has been stripped of Discovery Content, as defined in clause 8.5.

We take reasonable steps to ensure that data de-identified under this clause cannot be reverse-engineered, re-identified, or linked back to you, your organization, or any individual, whether by us or by a third party. Where the GDPR or UK GDPR applies to you, we apply Test 1 at the standard those laws set for anonymization; until data meets it, it remains Customer Data.

8.3 What we may do with De-identified Data

Where Customer Data has passed both tests in clause 8.2, we may use and disclose it to develop and improve the Service, to improve our models and their Outputs, and to develop new products and services.

De-identified Data is our data, not yours. Clause 8.7 explains what that means when your subscription ends.

We do not sell De-identified Data, and we do not publish it, with one narrow exception: aggregate statistics about use of the Service, such as the number of active labs, that identify no customer, no individual, and no research content.

8.4 What this right covers today

We exercise clause 8.3 only over data we have actually de-identified to the standard in clause 8.2. We would rather tell you what that means in practice than let you assume it is broader than it is.

Today it covers operational telemetry once aggregated: usage counts, feature adoption, timing and performance measurements, and error rates, combined so that neither you nor any individual is identifiable. The raw telemetry rows behind those figures carry workspace and user identifiers so we can run the Service and support you; the rows themselves are not used under clause 8.3, only the aggregates.

It does not currently cover free text, audio, images, or video. We do not yet operate a pipeline capable of de-identifying that material to the standard in clause 8.2, and until we do, none of it is used under clause 8.3. If that changes, we will describe what changed on our AI and your data page before we rely on it, and we will give notice under clause 22.

8.5 Your discoveries stay yours

Discovery Content means the substance of your science: your results, findings, observations, novel methods, discoveries, inventions, patentable subject matter, and trade secrets, together with any data from which they can be derived.

Discovery Content is yours absolutely. It is excluded from clause 8.3 entirely, whether or not any individual is identifiable and whether or not it has been de-identified. We do not use it to train, fine-tune, or benchmark any model. We do not surface it to any other customer. We do not disclose it to any third party except as clause 9 requires to run the Service for you, or as clause 12.3 requires by law.

Patent novelty. Nothing we do under clause 8.3 is intended to be, or will be, a public disclosure of your Discovery Content, and we will not use De-identified Data in a way that would prejudice your ability to obtain patent protection or to maintain your trade secrets.

What clause 8.3 actually targets is the process layer: how research is carried out rather than what is discovered. The sequence and timing of steps, the technique of executing a protocol, the shape of a workflow, and generic patterns of lab work. We can learn how a centrifugation step is typically run without taking what you found in the pellet.

8.6 No leakage between customers

We treat keeping your content out of other customers' results as an obligation in its own right, not as something de-identification alone delivers. A model trained on de-identified material can still reproduce a distinctive input, so the tests in clause 8.2 are a precondition and not the whole control.

We will not surface your Customer Data or Discovery Content to any other customer, whether directly, through search, or through a model Output. The one exception is sharing you initiate yourself: a share link you create, a workspace member you invite, or an integration you connect.

8.7 De-identified Data and the end of your subscription

When your subscription ends, or when you delete your account, we delete your Customer Data as described in clause 17 and in the Privacy Policy.

De-identified Data is different. Once Customer Data has passed both tests in clause 8.2 and has been incorporated into a model, dataset, or aggregate, it is no longer your Customer Data. It is not returned to you and it is not deleted on termination, because by then it can no longer be linked back to you. This is the one part of section 8 that customers most often want to talk through, and we would rather it be on the page than in a footnote. Section 8 survives termination or expiry of these Terms: the rights in it, and equally the protections in clauses 8.5 and 8.6.

8.8 Visual and protocol data

The Service can capture images and video tied to a protocol, including live voice and video mode. Visual material carries identifiers that text does not: faces, hands, voices, whiteboards, and screens showing unpublished work.

Both tests in clause 8.2 apply to visual material in full. As stated in clause 8.4, we cannot yet de-identify visual material to that standard, so visual and video Customer Data is not currently used under clause 8.3 at all. If we build that capability we will say so before we use it, and clause 8.5 will still exclude anything that shows your Discovery Content.

9. AI features and the providers behind them

9.1 What you should expect from AI Outputs

  • AI Outputs may be inaccurate, incomplete, or misleading
  • You must review and validate them before relying on or publishing them
  • The Service does not replace academic, professional, clinical, or regulatory judgment

AI features run on the content you capture, as part of features you can see. Some steps are automatic: generating a title for a new note, extracting text from a file you upload, indexing content for search. We do not run AI over your content for purposes unrelated to the features in front of you.

9.2 Our providers are bound by the same restriction

Your Customer Data is sent to AI providers so they can return a result. We require our AI providers to be contractually barred from training on your Customer Data, and from retaining or logging it for human review beyond what is needed to return that result and to meet their legal obligations. Every AI provider that receives your Customer Data is covered by our Business Associate Agreement, for all workspaces, not only those in Restricted mode. Which providers those are, and what each one receives, is listed on our AI and your data page.

Two claims are often run together and should not be. "No provider trains on your data" is a statement about our vendors. "Bower does not train on your identifiable data" is clause 8.1, and it is our own commitment. Both are true. Neither implies the other.

Every provider that processes data on our behalf is named on our sub-processor page, with the data it handles and its current agreement status.

9.3 Quality monitoring, and what it retains

This clause discloses something most terms leave out, because you should not have to discover it.

To keep AI features reliable, we retain records of AI requests and the responses to them, in a third-party observability service. The service we use is named on our sub-processor page, with its processing location and current agreement status, and we notify workspace owners of material changes to that list. Those records contain the request and response text itself, and it is not de-identified. We use them to find and fix quality failures, to evaluate changes before we ship them, and to investigate incidents you report. What improves from these records is Bower itself: our prompts, our product code, and our configuration. Nothing is learned into any model's weights.

This is service operation under clause 7.2, not model improvement. That distinction is doing real work here, so to be explicit: this material is not De-identified Data, it is not used under clause 8.3, and it is never a training signal for any model. When we evaluate whether a change to the Service, including a change of model, maintains quality, retained requests may be used as test inputs. That measurement is quality monitoring under this clause: it measures the Service, and nothing from it enters a model.

These records are used only by Bower: the service processes them solely on our behalf under its data processing terms, and access is limited to people working on service quality and incident response. The service we use today limits our access to the most recent 90 days of these records. We do not yet enforce a fixed deletion schedule for them; if we adopt one, we will state the period here.

Workspaces in Restricted mode send nothing to this service. That block is enforced server-side and cannot be turned off from the app. For other workspaces, capture of request and response text is controlled by a platform-level setting that Bower operates; there is no per-workspace toggle today, and Restricted mode is the way to turn this capture off for a workspace. Details are on our AI and your data page.

10. Restricted mode and protected health information

Bower acts as a Business Associate under HIPAA. We are not a Covered Entity. Where you are a Covered Entity or another Business Associate and you will place protected health information ("PHI") in the Service, you must have a signed Business Associate Agreement with us before you do so, and you should enable Restricted mode on the workspace that will hold it. Restricted mode is how the controls described below are enforced; without it, they are not.

Restricted mode confines a workspace to providers covered by our signed BAA and blocks the rest server-side. In a Restricted-mode workspace:

  • AI processing is confined to providers covered by our BAA. This is now true of every workspace, so in Restricted mode it is a guarantee that cannot be relaxed rather than a change in routing
  • No content is sent to the AI quality-monitoring service (clause 9.3) or to product analytics
  • Share links cannot be created
  • Connectors, external AI app access, and literature lookups are unavailable
  • Word (.docx) conversion happens inside Bower rather than at the usual third-party converter; legacy .doc conversion uses Google Workspace, covered by a separate signed BAA

Where a BAA is in place, it takes precedence over these Terms for everything it covers, as set out in clause 2. Restricted mode is a set of technical controls. It does not by itself make your organization HIPAA compliant, and you remain responsible for your own safeguards, training, and risk assessments.

The current controls are described in full on our Restricted mode page.

11. Confidentiality

We treat your Customer Data, and your Discovery Content in particular, as your confidential information. We will not disclose it except as these Terms permit, and we limit internal access to people who need it to operate or support the Service.

12. Privacy, sharing, and disclosure

12.1 Privacy. Our handling of personal information is governed by our Privacy Policy, which forms part of these Terms.

12.2 Shared workspaces. In a team or shared workspace, content and metadata may be visible to other authorized members according to their role and the entity's privacy setting. If you delete your account, content you created in a shared workspace is preserved for the team, and a workspace admin takes over administering it. That is a change of custody and access control, not of ownership: the content stays owned by whoever owns it under clause 7.1 and your own agreements, whether that is you, your employer, your institution, or another rights-holder.

12.3 Legal disclosure. We may disclose Customer Data where required by law, regulation, or court order, or to protect the rights, safety, or security of Bower, our users, or others. Where we are legally permitted to tell you first, we will.

13. Plans, billing, and trials

  • Pricing and plan details are described on the website
  • Paid plans are billed in advance
  • Fees are non-refundable unless required by law
  • We may modify pricing or plan features with reasonable notice

14. Service availability

We aim for high availability but do not guarantee uninterrupted service. We may:

  • Modify, suspend, or discontinue parts of the Service
  • Introduce new features or usage limits
  • Perform maintenance that affects availability

The Service is provided on an "as is" and "as available" basis.

15. Our intellectual property

All intellectual property rights in the Service itself, including software, design, branding, models we develop, and underlying technology, are owned by Benenota Pty Ltd or its licensors. These Terms grant you no rights to our intellectual property except as needed to use the Service. Open-source components are governed by their own licenses.

16. Feedback

If you send us feedback or suggestions about the Service, we may use them without restriction or payment. This clause covers your suggestions about the product. It does not reach your Customer Data or your Discovery Content, which stay governed by sections 7 and 8.

17. Deletion and termination

  • You can delete your account at any time from Settings > Security.
  • Deleted items go to trash and are permanently removed after 30 days.
  • We may suspend or terminate accounts that breach these Terms or where required by law.
  • On termination your right to use the Service ends. What happens to your data is governed by the Privacy Policy and by clause 8.7.

Export your data before you delete your account. You can do that from the same settings page.

18. Disclaimers

To the maximum extent permitted by law:

  • We make no warranties regarding accuracy, reliability, or fitness for purpose
  • Use of the Service is at your own risk
  • Beta features are provided without guarantees

19. Limitation of liability

To the maximum extent permitted by applicable law, including the Australian Consumer Law, Benenota Pty Ltd will not be liable for:

  • Indirect, incidental, special, consequential, or punitive damages
  • Loss of data, research outcomes, or profits
  • Interruption of research
  • Reliance on AI-generated Outputs

Where our liability cannot be excluded by law, our total aggregate liability for any claim related to the Service will not exceed the greater of the total fees you paid us in the 12 months before the claim and AUD 1,000.

Nothing in these Terms excludes or limits any right you have under the Australian Consumer Law that cannot be excluded or limited by agreement.

20. Indemnity

You agree to indemnify us against third-party claims arising from your Customer Data, your unlawful use of the Service, or your breach of these Terms, except to the extent a claim results from our own breach of these Terms or our negligence.

21. Governing law

These Terms are governed by the laws of the State of Queensland, Australia. Disputes under these Terms are subject to the exclusive jurisdiction of the courts of Queensland, Australia.

22. Changes to these Terms

22.1 Notice. We may update these Terms. We will communicate material changes by email or in-app notification at least 30 days before they take effect. Continued use after that date constitutes acceptance.

22.2 How section 8 applies to existing customers. Section 8 is new in version 2.0. The rights in clause 8.3 apply only to Customer Data collected on or after the effective date above. Customer Data collected under the Terms dated 8 February 2026 stays governed by the commitment given then, and is not brought within clause 8.3 by this update. Clause 8.1, which is the promise not to train on identifiable data, is unchanged in substance and applies to everything.

23. General

  • Entire agreement. These Terms, the Privacy Policy, and any Institutional Agreement are the entire agreement between us about the Service, applied in the order set out in clause 2.
  • Severability. If part of these Terms is found unenforceable, the rest continues in force.
  • Waiver. Not enforcing a clause is not a waiver of it.
  • Assignment. You may not assign these Terms without our consent. We may assign them as part of a merger, acquisition, or sale of assets; whoever takes them on remains bound by them, including section 8 and clause 2.
  • Force majeure. Neither of us is liable for delay or failure caused by events beyond reasonable control, other than your payment obligations.
  • Notices. Legal notices to us go to legal@bowerlabs.ai. Notices to you go to your account email or by in-app notification.

24. Contact

Questions about these Terms: legal@bowerlabs.ai

Benenota Pty Ltd, 16 Bluejay Street, QLD 4220, Australia