Legal
Privacy Policy
Last updated: 29 July 2026 · Applies during Bolo’s private beta.
Bolo is currently in private beta. This policy is intentionally short and will be expanded, with notice to all customers, before general availability. Questions: founders@boloinbox.com.
Who we are
Bolo (“we”) is a unified client-communication platform operated by Bolo Communications. It brings a firm’s WhatsApp Business, SMS, Instagram, email, web and in-app conversations into one team inbox.
What we collect
- Account data — names, work email addresses and roles of the teammates a firm invites.
- Conversation data — messages, attachments and metadata that flow through the channels a firm connects. This data belongs to the firm; we process it to provide the service.
- Usage data — basic product analytics and logs used to keep the service reliable and secure.
How we use it
To operate the inbox, route messages, generate team-side AI summaries and reminders, provide support, and meet legal obligations. We do not sell personal data, and we do not use a firm’s client conversations to advertise to anyone.
No one can access your data (PII)
Personally identifiable information (PII) in your conversations — client names, phone numbers, account numbers, balances, case details — is locked down by default:
- Encrypted at rest and in transit. PII is encrypted at the field level, not just at the disk level, and every decryption event is recorded in the audit log.
- No standing employee access. No one at Bolo — engineers, support, founders — can read your conversation data or PII as part of their normal work. There is no admin backdoor.
- Support access is exceptional and logged. In the rare case a firm explicitly asks us to help with an issue that requires touching their data, access is time-bound, limited to the minimum needed, approved by the firm, and fully logged for the firm to review.
- Your team is gated by you. Inside your firm, access is role-scoped and controlled entirely by your admins. Field-level redaction masks PII from teammates who don’t need it.
Never sold, never shared, never used for anything else
- We never sell, rent or trade your data or your clients’ PII to anyone, for any reason.
- We never share your data with third parties for their own purposes — no advertisers, no data brokers, no analytics resellers.
- We never use your conversations to train AI models — not ours, not anyone else’s. Bolo AI features process your data only to serve your team, inside your workspace.
- We never advertise to your clients or mine their data for marketing profiles.
- Data moves only where it must to deliver the service: the channels you connect (for example, Meta’s WhatsApp Business Platform, as an official Meta Business Provider) and the India-hosted cloud infrastructure it runs on, each bound by contract to the same protections.
Where it lives
Customer data is hosted on cloud infrastructure in India, encrypted at rest, with an audit log on by default and configurable retention windows per client type.
Who can see it
Access inside a firm is role-scoped and controlled by the firm’s admins. Inside Bolo, no one has standing access to customer data or PII; any exceptional, firm-approved access is time-bound and logged, as described above.
Your choices
Firms can export their data and can request deletion of their workspace by writing to founders@boloinbox.com. Individuals whose data appears in a firm’s conversations should contact that firm, which controls the data; we assist firms in meeting such requests.
Contact
For any privacy question or request: founders@boloinbox.com.