Privacy Policy
Last updated: June 28, 2026
Bullseye is an organizational intent layer: it captures the "why" behind what your team builds from the sources you connect, reconciles it into current, provenance-backed facts, and serves that context to your AI coding agents. This policy explains what we collect to do that, the controls you have, and how we protect it.
What we collect
We collect only what's needed to capture intent from the sources you choose to connect, reconcile it, and serve it back:
- Account information — email, name, and organization details from signup.
- Integration credentials — OAuth and API tokens for the sources you connect, stored encrypted with AWS KMS envelope encryption.
- Evidence from connected sources you authorize — this can include git activity (commits, pull requests, code context), tickets (Jira, Linear), documents (Notion, Google Drive, Confluence, SharePoint), conversations (Slack, Teams, Discord), meeting transcripts (Gong, Fireflies, Otter, Granola, Zoom), CRM records (Salesforce, HubSpot), and incidents (PagerDuty, incident.io). Each source is opt-in and individually governed (see Your controls).
- Derived intent facts — the decisions, constraints, and goals we reconcile from that evidence, with provenance linking each fact back to its source.
- Git-organization member roster — member logins read from your connected git provider, used to determine your per-seat billing count. Automated and bot accounts are excluded.
- Billing information — handled by Stripe; we do not store full card numbers.
What we don't do
- We do not persist raw code diffs — they are processed in-flight and discarded.
- We do not sell or share your personal data with third parties.
- We do not use your code, conversations, documents, or intent to train AI models — neither ours nor our subprocessors'.
- We are not a surveillance product. Bullseye exists to feed agents better context, never to score or monitor individual people.
Your controls — capture is consent-gated and reversible
You decide what Bullseye reads, and you can withdraw that at any time:
- Per-source opt-in — no source is read until you connect it. Conversation channels are opt-in: a channel is only read once you enable it.
- Meeting kill switch — meeting transcripts are opt-out per meeting; disabling one immediately stops capture. Title-exclusion rules let you exclude whole classes of meetings (for example 1:1s) before they are ever ingested.
- Redaction — likely secrets are stripped from conversational and transcript content before extraction.
- Purge on disable — disabling a meeting or disconnecting a source purges the captured evidence and reconciles away the candidate facts derived from it. Confirmed intent you've explicitly kept is preserved unless you delete it.
How we use your data
Your data is used to provide the service and nothing else: to capture intent from your connected sources, reconcile it into current facts, and serve that context to the AI agents you use — plus to operate your account, bill your subscription, and provide support.
Subprocessors
- Anthropic — powers the AI that classifies and reconciles intent. Your content is not used to train Anthropic's models.
- Amazon Web Services — hosting, storage, and key management (KMS), in the United States.
- Stripe — subscription billing and payment processing.
Data retention
Captured evidence is retained while the relevant source is connected, within a rolling recency window — current intent is the point, so stale intent is actively de-prioritized and aged out. When you disconnect a source, disable a meeting or channel, or delete your organization, the associated evidence and the candidate facts derived from it are purged.
Security
All integration credentials are encrypted with AWS KMS envelope encryption; data is encrypted at rest and in transit. Tenants are isolated at the database layer with row-level security. Bullseye is cloud-hosted on AWS; code diffs are processed in-flight and never persisted.
Your rights
You can access, export, or delete your organization's data at any time. Deleting your organization removes its evidence, derived facts, and credentials. For data requests under GDPR, CCPA, or similar regimes, contact us and we will respond within the applicable statutory window.
Contact
Questions about this policy or your data? Email privacy@bullseye-code.com.