Privacy Policy
Last updated: 2026-07-20
This Privacy Policy explains how Fjord LLC (“we,” “us,” “our,” or “Company”) collects, uses, stores, and protects information when you use Bommel Bot(the “Service”).
By using the Service, you acknowledge that you have read, understood, and agree to this Privacy Policy. This Privacy Policy is incorporated into and forms part of our Terms of Service. If you do not agree with this Privacy Policy, you must immediately discontinue use of the Service.
Modifications: We reserve the right to modify this Privacy Policy at any time, at our sole discretion. Material changes will be effective immediately upon posting. Your continued use of the Service after such modifications constitutes acceptance of the updated Privacy Policy.
1. Information We Collect
Authentication Data
The Service offers multiple authentication methods. Depending on your chosen method, we may collect:
Google OAuth Authentication
If you choose to authenticate using Google OAuth, we collect information provided by Google’s OAuth service, which may include:
- Your primary email address
- Your full name
- Your profile picture URL
- Other information made available by Google’s OAuth service
Important:We do not store, access, or have the ability to access your Google account password. Authentication is handled entirely through Google’s OAuth service, and we receive only the information Google provides through its API.
Email/Password Authentication
If you choose to register using email and password, we collect:
- Your email address
- A hashed version of your password (we do not store plain-text passwords)
User-Provided Account and Profile Data
We collect data you voluntarily provide when creating or updating your account, including but not limited to:
- Name or chosen username
- Age and date of birth
- Gender
- Location information (city, geographic coordinates)
- Phone number
- Email address
- Bio and personal description
- Interests and preferences
- Account photos and images
- Preferred contact method
- Tier-Specific Uploads (Pro Tier): Images and documents uploaded utilizing the expanded storage features available to Pro tier subscribers.
- Any other information you choose to provide
Voluntary Provision: You acknowledge that all account information is provided voluntarily and at your own discretion. Fjord LLC does not require you to provide any specific information beyond what is necessary for account creation.
Payment Information
If you subscribe to the paid Pro tier, your payment and billing information is collected and processed directly by our third-party payment processor, Stripe. We do not collect, process, or store your financial account information, full credit card numbers, or bank details on our servers. The data you provide to Stripe is governed by Stripe’s Privacy Policy.
Automatically Collected Information
When you use the Service, we may automatically collect certain information, including:
- IP address and approximate location
- Device information (type, operating system, browser)
- Usage data (pages visited, features used, time spent)
- Log data (access times, error logs)
- Cookies and similar tracking technologies
Important: We do not store, access, or have the ability to access passwords for third-party accounts (including Google accounts). All authentication is handled through secure third-party services (Google OAuth) or our own secure password hashing system.
2. How We Use Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Service across the Free and Pro tiers
- To create and manage your account
- To authenticate your identity
- To process, host, and serve documents and images uploaded by Pro tier users
- To communicate with you regarding your account, the Service, or updates
- To monitor and analyze usage patterns and trends
- To detect, prevent, and address fraud, abuse, security issues, or technical problems
- To enforce our Terms of Service
- To comply with legal obligations
- To protect our rights, property, or safety, or that of our users or others
3. Information Sharing and Disclosure
No Sharing with Other Users
The Service is configured as a private, non-social utility environment. Your account data, uploaded files, images, documents, and personal details are strictly private and are not shared, broadcast, or made visible to any other users of the Service.
Third-Party Service Providers
We share information exclusively with reliable third-party service providers who provide the core backend, hosting, and infrastructure necessary to run the platform:
- Firebase Product Family (Google): Core backend infrastructure, database hosting, authentication, and cloud-based file storage for images and documents uploaded by users.
- Google:OAuth authentication and, in Free-tier bookmark card views, Google AdSense advertising. AdSense may process device, browser, IP address, cookie, consent, and ad-interaction data under Google’s own privacy terms.
- Stripe: Payment processing, subscription management, and fraud prevention. When you make a purchase, personal data necessary to facilitate the transaction and prevent fraud is shared with Stripe.
- Cloud hosting providers: Server infrastructure and data storage.
Third-Party Liability: Fjord LLC is not responsible for the privacy practices, data breaches, security incidents, or actions of third-party service providers. Your use of third-party services (including Google, Firebase, and Stripe) is subject to their respective privacy policies and terms of service.
Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, government investigations). We may also disclose information to protect our rights, property, or safety, or that of our users or others.
Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to a successor entity. You acknowledge that such transfers may occur and that the successor entity may continue to use your information in accordance with this Privacy Policy.
No Sale for Money: Fjord LLCdoes not sell your personal information for monetary payment. Google AdSense’s collection and use of advertising data may be treated as “sharing,” targeted advertising, or a “sale” under some privacy laws. Where required, the Service presents Google’s certified consent and privacy controls before eligible advertising is served. We may also share aggregated, anonymized, or de-identified data that cannot reasonably identify you.
4. Data Storage, Security, and Retention
Storage Location
Your information is stored on servers operated by third-party service providers (including the Firebase Product Family and cloud hosting providers) which may be located in the United States or other jurisdictions. By using the Service, you consent to the transfer, storage, and processing of your information in such locations.
Security Measures
Bommel Bot is engineered to protect your data with controls modeled on financial-industry standards. We implement reasonable technical and organizational security measures designed to protect your information, including:
- Encryption in transit: all network traffic is encrypted with TLS 1.2+.
- Encryption at rest: managed cloud storage (Google Firestore) is encrypted at rest with AES-256.
- Client-side, zero-knowledge backups:you can export an encrypted backup protected with AES-256-GCM using a key derived from your passphrase via PBKDF2-HMAC-SHA-256 (310,000 iterations, unique per-file salt and IV). The passphrase never leaves your device and is never stored — if lost, the backup cannot be recovered.
- Authentication & access control: authentication via Google (Firebase Authentication), with password hashing for email/password accounts and per-user data isolation enforced by Firestore Security Rules scoped to the authenticated account.
- Least-privilege credentials: service credentials follow least-privilege practices; secrets are stored in a secured secret manager or environment and never in source control.
- Application security: strict schema validation (Zod) on all writes, SSRF protections on server-side fetches (allow-listed hosts, blocked private ranges, protocol/port restrictions), output encoding and framework auto-escaping to mitigate XSS, security headers on responses, and parameterized/typed data access.
- Operational practices: minimal logging that excludes content, credentials, and secrets; generic client-facing error messages with detailed diagnostics kept server-side; dependency and vulnerability monitoring; and regular encrypted backups with tested restoration.
- Abuse prevention: rate limiting and other controls to detect and prevent abuse.
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. You acknowledge that:
- Security measures may not prevent all unauthorized access
- Data breaches may occur despite security measures
- Third-party service providers may experience security incidents
- You use the Service at your own risk
Your Security Responsibilities
Security is a shared responsibility. To help keep your account and data safe, you should:
- Use a strong, unique password on your Google account and enable 2-step verification
- Keep your device and browser up to date
- Store backup passphrases safely — we cannot recover them
Reporting a Vulnerability
We welcome responsible disclosure. Email support@bommel.bot with details and steps to reproduce. Please do not publicly disclose issues before we have had a reasonable chance to remediate.
Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. After account deletion, we will make reasonable efforts to delete your information from our active systems; however:
- Some information may remain in backups, logs, or archived systems for a reasonable period
- We may retain information as required by law or to comply with legal obligations
- We may retain information to resolve disputes, enforce agreements, or protect our rights
- Aggregated or anonymized data may be retained indefinitely
We are not obligated to retain your information for any specific period after account deletion.
Data Breach and Security Incident Disclaimer
To the fullest extent permitted by law, Fjord LLC shall not be liable for any loss, damage, or harm resulting from:
- Unauthorized access to your account or information
- Data breaches, security incidents, or cyberattacks
- Loss, corruption, or deletion of your data (including documents and images stored via Firebase)
- Security failures of third-party service providers
- Any other security-related incidents
You acknowledge that you use the Service at your own risk and that Fjord LLC makes no warranties regarding the security of your information. In the event of a data breach, Fjord LLC’s liability, if any, shall be limited as set forth in our Terms of Service.
5. Your Rights and Choices
Account Controls
You have the following rights regarding your information, subject to applicable law and the limitations set forth in this Privacy Policy and our Terms of Service:
- Access: You may access your data through your account settings
- Update: You may update or correct your account information at any time
- Delete: You may delete your account and request deletion of your data (including uploaded documents and images)
Account Deletion
You may delete your account at any time through the Service’s account deletion feature or by contacting us. Upon account deletion:
- We will make reasonable efforts to permanently delete your information from our active systems
- Some information may remain in backups, logs, or as required by law
- We are not obligated to retain or provide your information after account deletion
Limitations on Rights
Your rights are subject to the following limitations:
- We may retain information as required by law or legal obligations
- We may retain information to resolve disputes or enforce agreements
- Deletion requests may take reasonable time to process
- Some information cannot be deleted if it is necessary for the Service to function
- Your rights may be limited by applicable law or court orders
Cookies and Tracking
You may control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Service. We use cookies and similar technologies for authentication, security, and functionality. On eligible Free-tier card views, Google AdSense may also use cookies or similar storage to deliver, measure, limit, and personalize advertising, subject to your region and consent choices. Pro users do not receive AdSense units.
For visitors in the EEA, United Kingdom, and Switzerland, we use a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework. Applicable U.S. state privacy choices are also presented through Google’s Privacy & Messaging controls. You can revisit those controls when available or use your browser and Google advertising settings to manage your choices. Advertising is not enabled until the production consent messages have been configured and reviewed.
6. International Data Transfers
The Service is operated from the United States. If you are accessing the Service from outside the United States, you acknowledge that:
- Your information will be transferred to, stored in, and processed in the United States
- Data protection laws in the United States may differ from those in your jurisdiction
- By using the Service, you consent to such transfer, storage, and processing
- Fjord LLC is not responsible for compliance with data protection laws outside the United States
If you are subject to the General Data Protection Regulation (GDPR) or other international data protection laws, you acknowledge that Fjord LLC may not provide the same level of protection as required by such laws, and you use the Service at your own risk.
7. Children’s Privacy
The Service is NOT intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are under 18, you must not use the Service.
If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information. However, we are not obligated to verify the age of users, and you represent and warrant that you are at least 18 years old.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. However, Fjord LLC assumes no responsibility for verifying user ages or preventing underage use of the Service.
8. Third-Party Links and Services
The Service may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices, content, or security of such third-party services. Your use of third-party services (including Google OAuth, the Firebase Product Family, and Stripe) is subject to their respective privacy policies and terms of service.
Third-Party Liability: Fjord LLC expressly disclaims all liability for:
- Privacy practices of third-party services
- Data breaches or security incidents of third-party services
- How third-party services use or share your information
- Any harm resulting from your use of third-party services
9. California Privacy Rights (CCPA)
If you are a California resident, you may have certain rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information we collect
- The right to delete your personal information
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us at privacy@bommel.bot. However, your rights are subject to the limitations set forth in this Privacy Policy and our Terms of Service, including our right to retain information as required by law or for business purposes.
10. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time, at our sole discretion. Material changes will be effective immediately upon posting to the Service. Your continued use of the Service after such modifications constitutes acceptance of the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically. The “Last updated” date at the top indicates when this Privacy Policy was last revised.
If you do not agree to any modifications to this Privacy Policy, you must immediately discontinue use of the Service and delete your account.
11. Limitation of Liability and Disclaimers
To the fullest extent permitted by applicable law, Fjord LLC shall not be liable for any loss, damage, or harm resulting from:
- Unauthorized access to or use of your account or information
- Data breaches, security incidents, or cyberattacks
- Loss, corruption, deletion, or alteration of your data (including tier-specific uploads)
- Security failures of third-party service providers
- Any failure to protect or secure your information
- Any violation of this Privacy Policy by third parties
Fjord LLCmakes no warranties, express or implied, regarding the security, accuracy, or reliability of the Service or the protection of your information. The Service is provided “as is” and “as available” without warranties of any kind.
For additional limitations of liability, please refer to our Terms of Service. In no event shall Fjord LLC’s total liability exceed the amount you paid to Fjord LLC in the twelve (12) months prior to the action giving rise to liability, or one hundred dollars ($100), whichever is greater.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Fjord LLC
530-B Harkle Road, STE 100, Santa Fe, NM 87505
United States
Email: privacy@bommel.bot
Response Time: We will make reasonable efforts to respond to your inquiries, but we are not obligated to respond within any specific timeframe. Some requests may require verification of your identity.
This Privacy Policy is incorporated into and forms part of our Terms of Service. By using the Service, you acknowledge that you have read, understood, and agree to both this Privacy Policy and our Terms of Service.