Bobook AppCareinfo@bobook.club

Privacy Notice: Bobook AppCare

Last updated: 6 October 2026

This notice explains how Bobook Limited handles personal data for Bobook AppCare (the free Vibe Health Check and the Health Check & Launch audit) and on this website (appcare.bobook.club).

1. Who is responsible

  • Your data as our client or contact: the controller is Bobook Limited, a company registered in Ireland (CRO 785764), Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland. Contact for any privacy question or request: info@bobook.club.
  • Your app's end users' data: if any becomes visible to us during the audit, you (the app owner) are the controller and we act as your processor. See section 4, and section 7 of our Terms.

2. What data we collect

  • Contact details: your name, email address, business name and the messages you send us (for example when you ask for a free Vibe Health Check, book the audit or join the EU waitlist).
  • App details: your app's URL, the builder you used, the country where your business is established (we need this to check eligibility), and your public repo link if you send it.
  • Billing details: name, billing address, optional tax ID, business name, app URL and payment status. Payments are processed by Stripe. We don't see or store your full card number.
  • Audit records: a log of the access you grant us, our working notes (which may include short excerpts of your code, configuration or logs), the audit report and our emails with you.
  • Website technical data: when you visit this site, our hosting provider processes technical data such as your IP address and browser details to deliver the page and keep it secure.

3. Why we use it and our lawful bases

  • To answer your enquiry and run the free Vibe Health Check: steps you ask us to take before entering a contract (GDPR Art. 6(1)(b)).
  • To deliver the audit (access, review, report, walk-through call and any refund): performance of our contract with you (Art. 6(1)(b)).
  • To bill you (invoices and payments): performance of our contract with you (Art. 6(1)(b)).
  • To keep billing, invoice and accounting records: compliance with a legal obligation (GDPR Article 6(1)(c)) under Irish company, tax and VAT law.
  • To keep you on the EU waitlist and write when we open to EU businesses: your consent (Art. 6(1)(a)), which you can withdraw at any time.
  • To keep our website and service secure and to deal with legal claims: our legitimate interests (Art. 6(1)(f)).

We don't sell your data, we don't use it for advertising, and we don't make decisions about you by automated means that have legal or similarly significant effects.

4. Your end users' data (we act as your processor)

We don't need your end users' personal data to do the audit, and the free check only looks at public information. We ask you to give us staging access, or redacted or sample logs, wherever possible. Read-only access may still make some of it visible to us, for example in a database, logs or an admin console. If it does, we act as your processor under the processor terms in section 7 of our Terms (GDPR Art. 28). In short:

  • we look at no more than the audit needs, and use it only to carry out the audit on your documented instructions;
  • we don't export or download it from your systems. A short excerpt we analyse (for example a log line) may still contain some, and may be processed by OpenAI as our sub-processor (see section 5);
  • at the end of the audit we delete any of it that ended up in our notes, and we remove our access when we deliver the report.

If you are an end user of an app we audited, please contact the app's owner, who is responsible for your data.

5. Who we share it with

We use these service providers (processors), who handle data on our behalf under contract. For any of your end users' data, they are our sub-processors (see section 7 of our Terms):

  • Stripe: checkout, payments and invoices. Stripe also acts as an independent controller for some purposes, such as fraud prevention and legal compliance (see Stripe's privacy policy at stripe.com/privacy).
  • Google Workspace: our email.
  • OpenAI (the OpenAI API): our AI provider. We use the OpenAI API, through our own API account, to help analyse issues in your app and draft our reports. To do that, we may send it excerpts of your code, configuration or logs. We don't put passwords, API keys, tokens or other credentials or secrets into it: we remove them from excerpts before sending. We don't put payment data into it. An excerpt may still contain some of your end users' personal data (for example in a log line); for that data, OpenAI is our sub-processor (see section 4). If we add or change an AI provider, we update this list first.

What OpenAI's API data policy says (checked 6 October 2026, at openai.com/enterprise-privacy and platform.openai.com/docs/guides/your-data): data sent to the OpenAI API is not used to train OpenAI's models unless the customer opts in to share it, and we don't opt in. Except for certain endpoints and features listed in OpenAI's documentation, OpenAI may keep API inputs and outputs for up to 30 days to provide the service and identify abuse, and then removes them, unless longer retention is required by law or is reasonably necessary to protect OpenAI's services or others from harm.

Your app's data stays in your own systems; we work in them through the read-only access you grant, apart from the excerpts described above. We may also share data with our professional advisers (for example our accountant) or with authorities where the law requires it.

6. International transfers

Some of our providers, including Stripe and Google, may process data outside the European Economic Area, for example in the United States. Where they do, the transfer is protected by the EU–US Data Privacy Framework (where the provider is certified) or by the European Commission's Standard Contractual Clauses.

For the OpenAI API, OpenAI's Data Processing Addendum (openai.com/policies/data-processing-addendum) says that, for customers based in the EEA such as us, OpenAI Ireland Limited processes the data, and that any transfer of it outside the EEA is made under the European Commission's Standard Contractual Clauses or an EU adequacy decision.

7. How long we keep it

  • Billing, invoice and payment records: We keep billing, invoice and payment records (including those processed through Stripe) for six years after the end of the financial year to which they relate, as required by Irish company, tax and VAT law. We may keep them for longer where this is needed for an ongoing tax enquiry or audit, or to establish, exercise or defend a legal claim.
  • Audit records: deleted within 90 days after we deliver the report, except what we must keep for billing or legal claims. If you start a monthly plan, we keep them while you're a customer.
  • Your end users' data: not kept by us. Anything incidental in our notes is deleted at the end of the audit, and our access is removed when we deliver the report. Excerpts sent to the OpenAI API are kept by OpenAI only as described in section 5.
  • Free Vibe Health Check enquiries that don't lead to an audit: up to 12 months.
  • EU waitlist: until we open to EU businesses and contact you, or until you ask us to remove you.

8. Your rights

You have the right to access your data, correct it, have it deleted, restrict or object to its use, receive it in a portable format, and withdraw consent at any time (without affecting earlier use). To use any of these rights, email info@bobook.club. We reply within one month.

You can also complain to the Irish Data Protection Commission (www.dataprotection.ie), or to the data protection authority where you live. We'd appreciate the chance to sort it out first.

9. Cookies and analytics

This website does not set cookies and does not use analytics, advertising or tracking tools, external fonts or third-party scripts. Stripe's checkout page is run by Stripe and is covered by Stripe's own privacy and cookie policies.

10. Changes

We may update this notice. The "Last updated" date above shows the current version.

11. Contact

Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland · CRO 785764 · info@bobook.club