Privacy Policy
Effective September 30, 2026
BotForeman LLC sets up, personalizes, and supports AI assistants for individuals, families, and small businesses. This page explains what information we and your assistant handle, why, who else sees it, and the choices you have. We wrote it in plain language on purpose. If anything here is unclear, write to [email protected].
The short version
- Your assistant works for you. It only reads your email, calendar, or other accounts if you connect them.
- We do not sell your information, and we do not use it to advertise to you.
- We do not use your conversations or your data to train AI models.
- Each customer's assistant runs in its own separate account on a computer we manage.
- You can ask for a copy of your information, or ask us to delete it, at any time.
1. Who we are
"BotForeman," "we," and "us" mean BotForeman LLC, a Utah limited liability company. "You" means the person or business using our services. "Your assistant" means the AI assistant we set up for you, which runs on Hermes Agent software.
BotForeman LLC1290 South Carriage Lane
Antimony, UT 84712
General questions: [email protected]
Legal notices: [email protected]
2. What information we handle
When you sign up
Our welcome assistant, Iris, asks a few questions so we can build your assistant. That includes your name and the names of the people the assistant will work for, what you would like help with, how you like to be spoken to, anything the assistant should never do, which AI provider you want to use, and your Telegram name. If you tell us about a family member or friend who helps you with sign-in codes, we record that person's name and how to reach them. If you contact us by email or phone, we keep what you send us.
When you pay
Payments are handled by Stripe. We receive your name, email address, billing details, and whether your subscription is active. We do not receive or store your full card number.
When you use your assistant
Your assistant handles what you send it: text messages, voice notes, files, and photos. It keeps notes, which we call its memory, about your preferences and ongoing tasks so it can help you better over time. When BotForeman provides voice transcription for your assistant, it runs on our own computers. If you connect your assistant to another voice service, that service's own terms apply.
When you connect other accounts
Only if you choose to connect them, your assistant can use your email (for example Microsoft Outlook or Gmail), your calendar, and WhatsApp. Once connected, it can read what is in those accounts and act on them when you ask, for example drafting or sending an email, or adding a calendar appointment. Section 6 explains these connections in detail.
Technical information
The computers that run assistants keep logs: times, errors, and which features were used. We use them to keep your assistant running and to fix problems. Our website, botforeman.com, does not use advertising or analytics cookies. Our website host, Cloudflare, processes standard technical information such as IP addresses to deliver the site and protect it from attacks.
3. How we use it
We use your information to:
- set up and personalize your assistant;
- run your assistant so it can answer you and do what you ask;
- support, troubleshoot, update, and repair it;
- bill you and manage your subscription;
- tell you about your service, for example if your assistant stops responding (we may also tell the helper you named);
- keep our systems and our customers secure, and meet legal requirements.
We do not sell your information. We do not use it for advertising. We do not share it with data brokers. We do not use it to train AI models.
4. AI providers and your conversations
The thinking part of your assistant is an AI model from a provider you choose, such as OpenAI (ChatGPT) or xAI (Grok). To answer you, your assistant sends the relevant parts of your conversation to that provider, along with any file, photo, email, or calendar item it is working on for you.
Your assistant normally signs in to that provider with your own account. That means the provider's own privacy policy and the settings on your account there also apply, including whether the provider may use your chats to improve its models. You can review and change those settings with the provider.
Backup models. The only time your assistant uses an AI account that is not yours is when we choose, at our sole discretion, to give it a backup model to use if your own provider is down or has reached its limit. A backup model is a courtesy we pay for. We are not obliged to provide one, we may change or stop it at any time, and we do not provide one at all if you have not paid your own AI provider (such as OpenAI, xAI, or Anthropic). Backup models come from providers such as OpenRouter, DeepInfra, or others. We choose backup providers based in North America. When a backup model is used, the part of your conversation it needs, including any file or photo it is working on, is processed by that provider under its own policies, which may include keeping or training on data. We do not control those policies, and they can change without notice.
5. Who else sees your information
- The messaging service you use carries the messages between you and your assistant, and its own privacy policy applies. Most customers use Telegram. Hermes Agent, the software your assistant runs on, can also connect to WhatsApp (including the WhatsApp Cloud API), Signal, iMessage (through BlueBubbles or Photon), SMS (Twilio), email, Discord, Slack, Microsoft Teams, Google Chat, Mattermost, Matrix, IRC, LINE, SimpleX Chat, Weixin (WeChat), WeCom (Enterprise WeChat), Feishu / Lark, DingTalk, QQ, Yuanbao, Home Assistant, ntfy, Buzz, Raft, A2A (agent-to-agent), Microsoft Graph, webhooks, a relay, and an API server, and others we may add.
- Your AI provider processes your conversations, and so does any backup model service we use, as described in section 4.
- Microsoft, Google, and other services you connect hold your email and calendar in the first place; your assistant reads and writes them through the sign-in you approve.
- Stripe (through its affiliate Link) processes payments.
- Cloudflare hosts our website, and our email hosting provider handles mail sent to our botforeman.com addresses.
- The BotForeman team. The family members who run BotForeman, and the automated tools we use to operate the service, may look at your assistant's files, logs, and conversations only when needed to set it up, support it, fix it, or keep it secure.
- When the law requires it. We may disclose information if a valid legal process requires it, or to protect someone's safety.
- If the business changes hands. If BotForeman is sold or merged, your information may move to the new owner, who must keep honoring this policy.
6. Microsoft and Google account connections
Microsoft Outlook and calendar
To connect a Microsoft account, you sign in with Microsoft and approve our app, named "BotForeman Assistants." The app asks for these Microsoft Graph permissions, all of them delegated:
- Read and write your mail (Mail.ReadWrite), so your assistant can read, sort, and draft email;
- Send mail as you (Mail.Send), so it can send an email when you ask it to;
- Read and write your calendar (Calendars.ReadWrite), so it can check and add appointments;
- Maintain access (offline_access), so it can keep working without asking you to sign in again every hour;
- Sign you in and read your basic profile (User.Read, plus the standard openid and profile sign-in permissions).
"Delegated" means the app acts only on behalf of the one person who signed in and approved it, and only on that person's own mailbox and calendar. It does not ask for organization-wide permissions, and it cannot read anyone else's mailbox in your organization.
The sign-in tokens Microsoft issues are stored with your assistant, inside its own separate account on the computer that runs it, and in our backup copies of your assistant (section 7), so we can restore it without asking you to sign in again. They are not shared with anyone outside BotForeman.
Your assistant uses your Microsoft data only to do what you ask. It does not use it for advertising, does not sell it, and does not use it to train AI models. When it works on an email or appointment, that item is sent to your chosen AI provider as part of the task, as described in section 4.
You can remove the connection at any time. Tell your assistant or email us, and we will disconnect it, delete the stored tokens, and remove them from our backup copies within 90 days. You can also remove the app yourself: for a personal Microsoft account, visit account.live.com/consent/Manage; for a work or school account, your organization's IT administrator can remove it.
Google (Gmail and Google Calendar)
Google connections work the same way: you sign in with Google and approve our app. It asks for access to Gmail (read, organize, draft, and send), Google Calendar, Google Drive, Google Docs, Google Sheets, and read-only access to your contacts. The tokens are stored with your assistant and in our backup copies, and your assistant uses your Google data only to do what you ask. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can remove access at any time at myaccount.google.com/permissions, or ask us to disconnect it.
7. Where it is stored and how we protect it
Your assistant and its memory live on computers that BotForeman manages, located in the United States. Each customer's assistant runs in its own separate Windows user account, apart from every other customer's. Access to those computers is limited to the BotForeman team.
We keep backup copies of each assistant, including its settings, memory, conversation history, and the sign-in tokens for any accounts you connect, so we can restore it if a computer fails without making you sign in to everything again. The backups are stored on BotForeman-managed computers in the United States, and only the BotForeman team and our own automated tools can open them.
No system is perfectly secure. If we learn of a security problem that affects your information, we will tell you promptly.
8. How long we keep it
We keep your information while you are a customer. If you cancel, we delete your assistant, its memory, its conversation history, and any connected-account tokens within 30 days, and remove it from our backups within 90 days. If you would like a copy first, ask before you cancel. We keep billing records as long as tax and accounting law require. Stripe keeps its own payment records under its own policy.
9. Your choices and rights
- Get a copy. Ask us for a copy of the information we and your assistant hold about you.
- Correct it. Tell your assistant, or tell us, if something it knows about you is wrong.
- Delete it. Ask us to delete your information, or any part of it.
- Disconnect accounts. You can disconnect email, calendar, or WhatsApp at any time, as described in section 6.
- Cancel. You can cancel your subscription at any time.
To make a request, email [email protected]. We may need to confirm it is really you before we act. We will answer within 30 days.
If you live outside the United States, or in a state with its own privacy law, you may have additional rights under the laws where you live. We will honor those rights as the law requires.
10. Children
A family plan can include an assistant for a child. A parent or guardian sets it up and is responsible for how the child uses it. We do not knowingly collect personal information from a child under 13 without a parent's or guardian's permission. If you believe we have, write to us and we will delete it.
11. Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change is significant, we will tell current customers by message or email before it takes effect.
12. How to reach us
Questions or requests: [email protected]. Legal notices: [email protected]. By mail: BotForeman LLC, 1290 South Carriage Lane, Antimony, UT 84712.
See also our Terms of Service.