Legal

Privacy Policy

We treat privacy as a technical requirement, not a compliance checkbox. This policy explains what we collect, how it's handled, and the rights you have over it.

Last updated February 19, 2026

The data we hold

To operate the runtime and HiveLang, we categorize data as follows:

  • Credential data — OAuth tokens, API keys, and secrets. Stored encrypted and never written to standard application logs.
  • Interaction data — chat sessions, system prompts, and agent execution logs, used for state management and context persistence.
  • Environment data — workspace configuration, team members, and integration status.

Controller and processor roles

For account registration, billing, security, fraud prevention, platform analytics, and support, Bothive generally acts as a data controller because we decide why and how that information is used to operate the Service.

For prompts, uploaded files, workflow payloads, end-user conversations, integration data, bot memory, and agent actions that you configure, Bothive generally acts as a processor or service provider on your behalf. You are responsible for making sure you have a lawful basis, required notices, permissions, and consents before sending personal data into bots, integrations, or third-party models.

LLM processing

Bothive acts as an orchestration layer between your agents and large language models (Groq, Gemini, OpenAI, Anthropic).

  • No training — we never use your private prompts or HiveLang scripts to train generalized models. Your code is your IP.
  • Provider retention — underlying LLM providers may have their own retention policies; Bothive isn't responsible for their practices.
  • Abuse logs — we log failed or malicious prompt attempts to protect platform integrity.

You should not send sensitive personal data, regulated records, children's data, payment-card data, health information, biometric identifiers, or government-issued identifiers into an agent unless you have a lawful reason, clear user notice, and the right safeguards for that use case.

Encryption & data sovereignty

Technical assurance

In transit: TLS 1.3 · At rest: AES-256-GCM
Database: Supabase / PostgreSQL with Row-Level Security
Isolation: per-tenant access policies

Third-party data flow

We share data only with a verified set of essential processors:

PartnerPurpose
SupabaseInfrastructure, identity, and core storage.
OpenAI / AnthropicLLM inference and agent reasoning.
Groq / GeminiFast inference and fallback routing.
PaystackMarketplace transactions and billing.

Some providers may process data outside Nigeria or outside your country. Where applicable law requires transfer safeguards, we rely on contractual, security, and operational safeguards appropriate to the type of data and the provider involved.

Cookies & tracking

Bothive uses technical-only tracking — no third-party advertising trackers or pixels. See our Cookie Policy for detail.

Nigeria data protection notice

Where the Nigeria Data Protection Act, 2023 or related Nigeria Data Protection Commission requirements apply, we process personal data only where we have an appropriate lawful basis, such as consent, contract performance, legal obligation, legitimate interests, or another basis recognized by applicable law.

We design our handling of personal data around purpose limitation, data minimization, access control, security safeguards, retention limits, and accountability. If we identify a privacy or security incident that legally requires notification, we will assess it and make required notices to affected users, customers, regulators, or other parties as applicable.

Your rights & data deletion

Under GDPR (Article 17) and CCPA you have the right to be forgotten. On request, we purge all interaction history and credentials from our active databases within thirty (30) days. Encrypted backups may persist for up to ninety (90) days in an offline state.

If Nigerian data-protection law applies to you, you may also have rights to:

  • request access to personal data we hold about you
  • ask us to correct inaccurate or incomplete personal data
  • request deletion where retention is no longer lawful or necessary
  • object to or restrict certain processing activities where the law allows
  • withdraw consent where we rely on consent as the lawful basis
  • raise a complaint with the Nigeria Data Protection Commission where applicable

These rights are not absolute; for example, we may retain limited records where needed for security, fraud prevention, tax, accounting, dispute handling, or other legal obligations.

Legal disclosure

We disclose user data to law enforcement only when required by a valid, binding subpoena or court order, and we'll notify you unless legally prohibited from doing so.

Contact

For questions about your data or to exercise your rights, email privacy@bothive.cloud.