Privacy Policy

Effective December 7, 2025

This Privacy Policy describes how Botterfly AI ("we," "us," or "our") collects, uses, and protects your information when you use our AI-powered project management platform.

1. Information We Collect

We may collect the following types of information:

  • Account information: Name, email address, contact information, and business details you provide during registration.
  • Workspace data: Projects, tasks, standup responses, retrospective entries, CRM records, and other content you create within the platform.
  • Integration data: Data from connected third-party services (e.g., Slack, calendar providers, meeting tools) that you authorize.
  • Communication data: Meeting transcripts, notes, and messages processed through our AI features.
  • Automatically collected information: IP addresses, browser type, device information, website usage patterns, and system logs.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process and respond to your requests, including AI-powered task generation, standup summaries, and retrospective insights
  • Improve our AI models and platform capabilities (using aggregated, anonymized data only)
  • Send service updates, security alerts, and support messages
  • Comply with legal obligations
  • Detect, prevent, and address fraud or technical issues

3. Third-Party Integrations

When you connect third-party services (such as Slack, Google Calendar, or meeting platforms), we access only the data necessary to provide the requested functionality. Integration data is encrypted using AES-256-GCM encryption. Upon disconnecting an integration, associated data is permanently deleted within 48 hours.

4. Data Security

We implement industry-standard security measures to protect your information, including:

  • End-to-end encryption for data in transit and at rest
  • Multi-factor authentication
  • Regular security assessments and audits
  • HMAC signature validation for all webhooks
  • Role-based access controls

5. Data Retention

  • Account information: Retained for 30 days following account termination.
  • Workspace data: Retained in accordance with your organization's retention policies and applicable regulations.
  • System logs: Retained for up to 12 months.
  • Integration data: Deleted within 48 hours of disconnecting the integration.

6. Your Rights

You have the right to access, correct, delete, and export your personal data. We honor rights under applicable data protection regulations, including GDPR and CCPA. To exercise any of these rights, please contact us using the information below.

7. Cookies and Tracking

We use essential cookies to maintain session state and preferences. We do not use third-party advertising trackers. Analytics data is collected in aggregate to improve the platform and is never sold to third parties.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through an in-app notification. Your continued use of the service after such changes constitutes acceptance of the updated policy.

9. Contact Us

If you have any questions about this Privacy Policy, please contact us at: