Bopier turns prompts into lead-magnet apps. That means we sit between two groups of
people: creators (you, building apps) and visitors (people filling out those apps). This policy explains what each side gives us,
what we do with it, and how to get it back or delete it.
01 Who we are
Bopier is operated by KRKA. Questions, access requests, and deletion requests
go to support@bopier.com. We're the data controller
for creator accounts and a data processor on behalf of creators for the leads
captured through their apps.
02 What we collect from creators
- Account basics from Google sign-in. Name, email address,
profile image, and Google account ID. We use Google OAuth via BetterAuth —
we never see your Google password.
- Profile you set. Username, website URL, any bio fields you
fill in.
- Content you create. Prompts, app titles, form schemas,
system instructions, app icons.
- Usage telemetry. Which apps you ran, timestamps, token
counts, errors, rate-limit counters. Used to bill overages, debug, and
catch abuse.
- Billing metadata. Stripe customer and subscription IDs,
plan status, trial end date, invoice history. We never store card
numbers — Stripe does.
03 What we collect from visitors
When a visitor runs one of your apps, we collect the form fields they submit
(including their email address), the AI-generated result, and a run timestamp.
We store this as a lead in your dashboard. Visitors see a notice that
their email goes to the creator of the app before they submit.
We also log a coarse IP address and user-agent for rate limiting (30 runs per
app per hour). These are discarded after 30 days.
04 Sub-processors we share data with
To keep the product running we send data to a small, named list of vendors.
Each has its own privacy terms that you should read if you want the full
story.
| Vendor | What it does | What it sees |
|---|
| Vercel | Application hosting | All requests, IP, user-agent |
| Turso (libSQL) | Primary database | Accounts, apps, leads, transactions |
| BetterAuth + Google | Authentication | Email, name, Google account ID |
| OpenRouter, OpenAI, Anthropic | AI generation / execution | Prompts + visitor form inputs at run time |
| Resend | Transactional email delivery | Visitor email + generated result body |
| Stripe | Subscription billing | Email, card (held by Stripe), invoice data |
We do not sell personal data. We do not share it with advertising networks.
We don't use third-party analytics that fingerprint visitors.
05 How long we keep things
- Creator accounts: for the lifetime of the account. Delete
your account and we erase profile data, apps, and transaction history
within 30 days.
- Leads: as long as your subscription is active. If you
cancel, leads remain exportable for 30 days, then are deleted.
- Held leads (trial / unpaid): retained for 30 days so you
can unlock them by subscribing. After that they're purged.
- Rate-limit and error logs: 30 days rolling.
- Invoices and Stripe records: 7 years (tax-law requirement).
06 AI and generated content
When a visitor submits a form, the combined prompt (your app's system prompt
+ the visitor's inputs) is sent to our model providers through OpenRouter.
Providers process the request to generate a result, and — per our agreements
with them — don't train on the data.
Results are generated on the fly. We store the visitor's inputs and the final
text in your dashboard. We do not retain intermediate model activations,
reasoning traces, or tool-call outputs beyond what appears in the final
result.
07 Cookies and similar tech
- Session cookie — set after Google sign-in. HttpOnly,
Secure, SameSite=Lax. Used only to keep you logged in.
- CSRF token — short-lived, per-request.
- No marketing, analytics, or tracking cookies.
08 Your rights
If you're in the EU/UK, California, or a similar privacy regime: you have
the right to access, correct, port, or delete your personal data. Most of
this is one click in /account and /dashboard. For anything that isn't, email support@bopier.com and we'll respond within 30 days.
Visitors: if an app collected your email and you want it removed, email us
with the app's URL and the email address you used. We'll forward the request
to the creator and delete our copy.
09 Security
Data is encrypted in transit (TLS) and at rest (Turso, Stripe, Resend all
encrypt by default). Payment card data never touches our servers. We limit
employee access to production systems to the people who need it for support
and on-call duties.
10 Changes to this policy
If we change anything material we'll email the address on your account at
least 14 days before it takes effect. Non-material changes (typos, new
sub-processor of the same kind) we'll just publish here with an updated
date.
11 Affiliate links
If you interact with a bop through an affiliate link (a URL containing ?ref=<username>), the user identified by that username may be
able to see your email and submitted responses in their affiliate dashboard,
in addition to the bop's creator. Affiliate visibility depends on which party
had active quota at the time of submission — in some cases the lead may be
retained by the bop creator alone, or by the platform. You can tell you are
using an affiliate link by inspecting the URL before submitting. Deletion
requests (Section 08) propagate to all parties that retained a copy.