Privacy · effective July 6, 2026

Privacy, written to be read.

Bubblio puts an agent door on businesses' products — a structured entrance AI agents can knock on. That means two kinds of people trust us with data: the businesses that sign up, and the AI agents (and the humans behind them) that visit a door. This page covers both, in plain language. The plain language is the policy.

The two hats we wear

For our customers (businesses with a Bubblio account) and for visitors to bubblio.dev itself, we decide how data is handled — we are the controller.

For AI agents that knock on a customer's door, the business whose door it is decides why the conversation exists and what happens to it — they are the controller, and we process it on their behalf. If an agent acting on your behalf visited someone's door and you want that handled, start with that business; we help them honor your request.

What we collect from customers

Your account: email, name, company, and a password we store only as a secure hash — we cannot read it. We keep usage records (agent visits, tool calls, quotes and confirms) so you can see the same numbers we do in your dashboard. If you declare a priced action, the charge runs on your own Stripe account — we never see or store card numbers, and never hold the funds ourselves.

Your API keys and webhook secrets exist to be secret: webhook secrets are stored encrypted, per customer, and every webhook we send your server is signed.

What the agent door processes about visiting agents

A visiting AI agent's conversation with your door — its questions, the results your own tools return, and for actions it runs, the quote and receipt — persists as a transcript in your dashboard. What persists is the transcript, marked as agent traffic. The questions tier is anonymous; agent keys (bak_…) are held in custody by Bubblio and never shared with the platform's own code.

Knowledge content is opt-in

We index a business's website only after they explicitly add it in their dashboard — public pages only, honoring robots.txt, with an honest user-agent (BubblioBot) that site owners can block. Customers can also upload PDFs. Deleting a source deletes its indexed content immediately — and for PDFs, the stored file itself.

Analytics on bubblio.dev

This site uses Vercel Analytics: anonymous and cookieless. No advertising trackers, no fingerprinting, no data sales. Interaction events carry numbers, not identities.

Who processes data for us

These providers run parts of the service, each only for the purpose listed:

Supabasedatabase and file storage
ModalAPI hosting
Vercelweb hosting and anonymous analytics
Stripepayments
Anthropicthe language model behind ask answers
Voyage AIsearch embeddings for knowledge
Resendtransactional email

We do not use your data or your visitors' conversations to train AI models, and we do not sell data to anyone.

Retention and deletion

Account data lives while your account does. Transcripts, tool-call records, and quote receipts persist so your dashboard's activity and receipts keep working. Email bubblio@andresio.com to delete sessions or your whole account, and we will. Removing a knowledge source removes its content immediately.

Your rights

Access, correction, export, deletion — email bubblio@andresio.com and a human reads it. If you are in the EU/EEA or a jurisdiction with similar rights (GDPR and kin), those rights apply as written there. For a conversation an agent had with a business's door on your behalf, the fastest path is that business — we assist them with every request.

Security, children, changes

Traffic is encrypted in transit; passwords are hashed; tenant data is isolated per customer; webhook secrets are encrypted and requests signed. Bubblio is not directed at children under 16. When this policy changes, the date above changes with it, and material changes are emailed to customers.