Privacy Policy
Privacy for a custom-service business that should not need your private data to start.
Last updated: July 10, 2026. Boring AI is operated by Tilton Group LLC and builds AI-powered growth systems, previews, pages, follow-up assets, and related implementation support. This policy explains what we collect, why we use it, and the data we do not want you to send through normal support or preview channels.
01Information you provide
We may collect contact details, business name, website URL, preview requests, scope notes, support messages, uploaded or linked public assets, checkout email, and implementation notes you provide. We prefer public business information and narrow project context over private customer data.
02Website and analytics data
The site may collect basic technical data such as pages viewed, referrer, approximate region, device/browser type, timestamps, and security logs. We use this to understand whether pages work, improve conversion paths, prevent abuse, and debug broken experiences.
03Payment data
Payments are processed by Stripe. Boring AI receives limited payment metadata needed for receipts, support, fulfillment, taxes, disputes, and fraud prevention. We do not store full card numbers or card security codes.
04AI-assisted production
Boring AI may use internal tools, automation, and AI-assisted workflows to draft, analyze, build, QA, and improve deliverables. Customer-provided materials should be limited to what is necessary for the project. Do not provide sensitive or regulated data unless a separate safe handling path has been approved.
05How we use information
We use information to respond to support, prepare previews, deliver paid services, process billing, maintain project records, improve site performance, detect abuse, and document customer-approved scope decisions.
06Processors and sharing
We may use infrastructure and business processors such as Cloudflare, Stripe, email providers, analytics providers including GA4, Microsoft Clarity, and PostHog, storage, security tools, and internal operations tools. We do not sell customer personal information. We share data only when needed to operate the service, comply with law, protect the business, or complete approved work.
07Retention
We keep support, billing, project, and security records for as long as needed to operate the service, resolve disputes, meet tax or legal obligations, and preserve project history. Records that are no longer useful may be deleted or archived.
08Your choices
You can request access, correction, deletion, or a privacy review by emailing [email protected]. Some records may be retained where required for billing, tax, fraud prevention, dispute handling, legal compliance, or security.
09Sensitive data boundary
Do not send passwords, payment credentials, private customer records, medical details, legal files, financial account data, identity documents, or regulated data through normal forms or support email. If sensitive access is needed, we will define the narrow handoff separately.
10Contact
Boring AI is operated by Tilton Group LLC. Privacy requests go to [email protected]. Plain review-safe address: privacy@tryboringai.com. Support page: https://tryboringai.com/support/. Principal and mailing address: 2108 N St, Ste N, Sacramento, CA 95816.
11Project-access rule
Boring AI is built to start from public business facts, owner-approved copy, and narrow implementation access. We do not need private customer databases, bank credentials, medical records, government IDs, or platform passwords in normal support. If access is required, we prefer scoped user invitations, temporary roles, or customer-owned handoff steps so the owner can revoke access when the work is complete.
Privacy requests are reviewed against operational obligations. If deletion would erase required billing, tax, fraud-prevention, dispute, or security records, we may keep the narrow record required for that purpose while deleting unnecessary project notes or support content.
12Cookies, retention, rights, security, and processors
The site may use cookies or similar tools for security, page performance, analytics, and attribution. Typical processors may include Cloudflare for hosting/security, Stripe for payments, GA4, Microsoft Clarity, and PostHog for measurement/session analytics when configured, email providers for support, and internal storage/operations tools. Billing/tax records may be retained up to seven years; support/project records are generally reviewed after 24 months unless needed for disputes, fraud prevention, legal compliance, or active service history.
Depending on where you live, you may have rights to access, correct, delete, export, object to, or restrict certain personal information. Send requests to [email protected]. Data may be processed in the United States or other countries where processors operate. We use reasonable administrative and technical safeguards, but no internet service is risk-free. Boring AI is not directed to children under 16.
13Detailed deletion and opt-out workflow
Privacy requests should include the email address used for checkout or support and the specific request: access, correction, deletion, export, analytics opt-out, or support-history review. We target an acknowledgement within 10 business days and completion within 30 days where practical, unless a legal, tax, dispute, fraud-prevention, security, or active-service reason requires more time or partial retention.
Boring AI does not sell customer personal information. If a future advertising system creates a “sale” or “share” classification under applicable privacy law, users may request opt-out through [email protected]. Marketing and analytics cookies can also be limited through browser settings or privacy tools.