Bourdon

Privacy Policy

Last updated: September 1, 2026

The short version: your memory lives on your own instance, and we don't read it.

Bourdon Hosted is operated by RADLAB LLC, a Wyoming limited liability company ("RADLAB", "we"). This policy covers the hosted service at bourdon.ai and your instance at <your-slug>.bourdon.app. If you self-host the Bourdon engine, none of this applies - we hold nothing at all.

What we collect

Your email address (collected at checkout; it is where your claim link, receipts and service notices go), your console sign-in (email and a password we store only as a hash), and the operational record of your instance: its generated name, its state, and which machine and volume it runs on. On a Team plan we also hold each member's email address and role, any outstanding invitations, and - for agent credentials minted through the console - which member minted them, their trust tier, granted namespaces, and whether revocation is pending: that record is what lets an owner revoke a departing member's agents in one step. Agent tokens are shown once and are never stored by the hosted control plane. Billing details - name, address, tax ID, card - are collected and held by Stripe; we store only the identifiers that link your subscription to your instance.

What we do not read

Your memory library - the content your agents store - lives on your instance's own encrypted volume. The control plane that runs this service records where your memory lives and who pays for it, never the memory itself. Our account database cannot answer what your agents remember, and that is by design, not by policy.

Honesty about access

We operate the machines your instance runs on, which means we hold root on them. Rather than pretend otherwise, we give you the check on that power: every privileged action taken on your instance is written to an audit log you can read in your console.

Sub-processors

Fly.io (runs your instance's machine and holds its encrypted volume) · Neon (our account database - account records only, never library content) · Stripe (payments and billing identity) · Resend (transactional email).

Retention and deletion

Your volume is encrypted at rest. When you delete your instance we destroy the machine and volume, verify with the host that they are gone, and email you a receipt. One honest caveat: the host keeps automatic volume snapshots for up to 5 days and offers no way to purge them early - your receipt names the exact date after which no copy of your memory exists on our infrastructure. After composing that receipt, we remove the instance's member, invitation, agent-control and audit records and redact its email and Stripe links from our database. We keep a non-personal tombstone (generated instance name, lifecycle dates and technical configuration) so a deleted instance cannot be mistaken for a live one. Your separate console login remains so you can receive the result and is deletable from the console after the instance is gone. Stripe keeps transaction records under its legal and financial obligations.

Trial instances

A trial runs on its own isolated virtual machine, exactly like a paid instance. Anything your agents store in a trial is yours, and we treat it exactly like paid memory: we don't read it. Trials expire on the schedule shown when you start one; at expiry the trial machine and everything on it are deleted, permanently. If you upgrade before expiry, nothing moves and nothing is copied: the same instance simply becomes your paid instance, with your memory already in place. If you gave us an email address when starting a trial, we use it only to reach you about that trial.

What we don't do

We don't sell your data. We don't run ads or ad tracking. There are no analytics scripts on your console. We don't train anything on your memory - we can't, we can't read it.

What we do count, on our own server and in aggregate: that a page was viewed, that a trial was requested and how it came out, that a checkout started or completed. Those counts carry no cookie, no IP address, no user agent and no account. The only things kept alongside them are the referring site's hostname and a utm_source tag when a link carries one.

Your rights

You can access your account details and change your password in the console. Email corrections go through support so we can update access and billing ownership together. You can delete your instance at any time, erase the remaining console login after deletion completes, and take your memory to a self-hosted Bourdon - the engine is free software. Depending on where you live you may have statutory rights (access, portability, erasure); write to us and we will honor them.

Children

Bourdon Hosted is a paid service for people old enough to enter a contract; it is not directed to children under 16.

International transfers

Our infrastructure runs in the United States. If you use the service from elsewhere, your account data is processed in the US.

Changes

We'll update the date above when this policy changes, and notify you by email of any material change before it takes effect.

Contact

support@bourdon.ai · RADLAB LLC, a Wyoming limited liability company, is the data controller.