privacy · effective July 6, 2026
Privacy, written to be read.
Bubblio puts an AI support character — video and text — on businesses' websites. That means two kinds of people trust us with data: the businesses that sign up, and the visitors who talk to the bubble on their sites. This page covers both, in plain language. The plain language is the policy.
The two hats we wear
For our customers (businesses with a Bubblio account) and for visitors to bubblio.dev itself, we decide how data is handled — we are the controller.
For visitors who chat with the bubble on a customer's site, the business you talked to decides why the conversation exists and what happens to it — they are the controller, and we process it on their behalf. If you spoke to a bubble on someone's site and want your conversation handled, start with that business; we help them honor your request.
What we collect from customers
Your account: email, name, company, and a password we store only as a secure hash — we cannot read it. Billing runs through Stripe; we never see or store full card numbers. We keep usage records (session minutes, tool calls, message counts) because that is literally what the meter bills on, and you can see the same numbers we do in your dashboard.
Your API keys and webhook secrets exist to be secret: webhook secrets are stored encrypted, per customer, and every webhook we send your server is signed.
What the widget processes about visitors
Conversation transcripts (text), the results your business's own tools return, and — only if a visitor types it to request follow-up — an email address. Video and audio are processed in real time by our avatar infrastructure partners to render the call; we do not store recordings of video calls — what persists is the text transcript.
For same-device conversation history, the widget keeps a random anonymous identifier in the visitor's browser (localStorage). It is continuity, not identity: it is never linked to a name or email, unlocks only that browser's own past conversations, and its access key expires after 30 days.
Knowledge content is opt-in
We index a business's website only after they explicitly add it in their dashboard — public pages only, honoring robots.txt, with an honest user-agent (BubblioBot) that site owners can block. Customers can also upload PDFs. Deleting a source deletes its indexed content immediately — and for PDFs, the stored file itself.
Analytics on bubblio.dev
This site uses Vercel Analytics: anonymous and cookieless. No advertising trackers, no fingerprinting, no data sales. Interaction events (like moving the sliders on our cost calculator) carry numbers, not identities.
Who processes data for us
These providers run parts of the service, each only for the purpose listed:
We do not use your data or your visitors' conversations to train AI models, and we do not sell data to anyone.
Retention and deletion
Account data lives while your account does. Transcripts, tool-call records, and resolution receipts persist so your inbox, analytics, and visitors' conversation history keep working. Email bubblio@andresio.com to delete sessions or your whole account, and we will. Removing a knowledge source removes its content immediately.
Your rights
Access, correction, export, deletion — email bubblio@andresio.com and a human reads it. If you are in the EU/EEA or a jurisdiction with similar rights (GDPR and kin), those rights apply as written there. For conversations you had with a bubble on a business's site, the fastest path is that business — we assist them with every request.
Security, children, changes
Traffic is encrypted in transit; passwords are hashed; tenant data is isolated per customer; webhook secrets are encrypted and requests signed. Bubblio is not directed at children under 16. When this policy changes, the date above changes with it, and material changes are emailed to customers.