Privacy

Privacy Policy

Last updated: June 28, 2026

Bullseye is an organizational intent layer: it captures the "why" behind what your team builds from the sources you connect, reconciles it into current, provenance-backed facts, and serves that context to your AI coding agents. This policy explains what we collect to do that, the controls you have, and how we protect it.

What we collect

We collect only what's needed to capture intent from the sources you choose to connect, reconcile it, and serve it back:

What we don't do

Your controls — capture is consent-gated and reversible

You decide what Bullseye reads, and you can withdraw that at any time:

How we use your data

Your data is used to provide the service and nothing else: to capture intent from your connected sources, reconcile it into current facts, and serve that context to the AI agents you use — plus to operate your account, bill your subscription, and provide support.

Subprocessors

Data retention

Captured evidence is retained while the relevant source is connected, within a rolling recency window — current intent is the point, so stale intent is actively de-prioritized and aged out. When you disconnect a source, disable a meeting or channel, or delete your organization, the associated evidence and the candidate facts derived from it are purged.

Security

All integration credentials are encrypted with AWS KMS envelope encryption; data is encrypted at rest and in transit. Tenants are isolated at the database layer with row-level security. Bullseye is cloud-hosted on AWS; code diffs are processed in-flight and never persisted.

Your rights

You can access, export, or delete your organization's data at any time. Deleting your organization removes its evidence, derived facts, and credentials. For data requests under GDPR, CCPA, or similar regimes, contact us and we will respond within the applicable statutory window.

Contact

Questions about this policy or your data? Email privacy@bullseye-code.com.