Privacy Policy
BitsWeave · Last updated August 29, 2026
This policy explains what data BitsWeave handles across the platform at bitsweave.com, the Model Context Protocol (MCP) connector used by AI tools such as ChatGPT, Claude, Codex, and Cursor, and the BitsWeave browser extension.
Data we collect
- Account data — your name, email address, sign-in credentials, and the organizations you belong to, with your role in each.
- Workspace content — documents, records (notes, tasks, decisions, projects, and custom record types), the context graph that links them, and work-session activity events streamed from development tools you connect.
- Connected-service data — when you install a broker for a third-party service (for example GitHub, Grafana, email, or WhatsApp), we store the connection credentials and ingest messages and events from that service into your organization’s workspace.
- Billing data — subscription status, credit balance, and usage metering. Payments are processed by Stripe; we never receive your full card number.
- Usage and diagnostics — server logs, performance telemetry, and per-feature AI token usage, kept to operate and secure the service.
How we use data
We use the data above only to:
- provide the service — store, search, and display your work context
- power the AI features you invoke (see “AI processing”)
- sync with the third-party services you connect
- bill for usage and prevent abuse
- monitor reliability, debug problems, and secure the service
We do not sell your data or run third-party ad campaigns on this site. Measurement cookies are covered in Cookies and measurement.
Cookies and measurement
This site uses Google Tag Manager and Google Analytics (GA4) under Consent Mode. We store your choice in a first-party cookie named bw_consent for 180 days. Accept all turns on analytics and ads-measurement cookies. Essential only keeps those cookies off. We do not sell your data.
AI processing
Features such as context summaries, search embeddings, suggested actions, and the assistant send the relevant workspace content to large-language-model providers through our model gateway. Providers may include Anthropic, Groq, Fireworks AI, and OpenAI, and models reached through OpenRouter.
OpenRouter is a routing service that forwards a request to an upstream model provider. We configure OpenRouter to route only to providers that do not train on submitted content, and we do not enable training-permitted providers. Content is sent only when a feature needs it, and only the content the feature operates on. We do not use your workspace content to train models.
ChatGPT plugin and MCP access
You can connect AI hosts — ChatGPT, Claude, Codex, Cursor, and others — to BitsWeave through the Model Context Protocol (MCP) connector. A connection is authorized by you through OAuth and acts as you within your active organization.
- What a connected session can read — the advertised tools cover your organization’s documents, records, context search and summaries, sessions, and notifications.
- What it can write — creating and updating documents and records, and other operations it discovers through the tool catalog and invokes as explicit tool calls.
- What it cannot do — billing, onboarding, and platform-administration operations are blocked from the connector surface.
Data a tool returns is received by the AI host you connected (for example OpenAI for ChatGPT) and is then governed by that host’s own privacy policy. We do not scrape or store chat memory from those products. You can revoke a connection at any time from the host or by contacting us.
Who receives data
- AI model providers — receive workspace content for the AI features described above.
- Stripe — receives billing details to process payments.
- Infrastructure providers — host and transport the service.
- Connected services and AI hosts — when you (or a tool acting for you) invoke an operation against a connected service, that request goes to the service; results returned to a connected AI host go to that host.
We do not sell or rent personal data, and we share it with no one else except as required by law.
Browser extension
The BitsWeave browser extension is a companion for the platform. It handles:
- Account identity — when you sign in, the extension reads your BitsWeave account name and email to display who is signed in.
- Authentication tokens — OAuth access and refresh tokens issued by BitsWeave, used to make authenticated requests on your behalf.
- Your work sessions — the extension fetches your own BitsWeave work sessions in order to display them.
- Active tab info — only when you use the “Save page” action, the extension reads the current tab’s title and URL. It does not read page content.
Tokens and your basic profile are stored locally on your device via the browser’s extension storage; they are not synced or shared. The extension talks only to the first-party BitsWeave API (bitsweave.com). It does not collect or transmit web browsing history, page content, location, health, financial information, or personal communications. Sign out (or remove the extension) to clear all locally stored tokens and profile data.
Data retention
- Account data and workspace content — retained for as long as your account and organization are active, and deleted when your account is deleted.
- Connected-service credentials — retained until you uninstall the broker or delete your account.
- Billing records — retained as long as required for tax and accounting obligations.
- Logs and diagnostics — retained for a limited operational window, then deleted.
Your controls
- Organization management — organization admins can invite and remove members and manage roles.
- Workspace content — you can edit and delete documents and records from the app or through connected tools.
- Connected services — uninstall a broker at any time; ingestion from that service stops and its tools are disabled.
- Connected AI tools — revoke a connected host from that host, or ask us to revoke it.
- Account deletion — email us to request deletion; we perform a hard delete of your account and associated personal data.
Contact
Questions about this policy, or a data request: [email protected]. See also Support and the Terms of Use.