Bare

Privacy Policy

Intel CFO LLC, d/b/a Bare AI Labs · Effective September 8, 2026 · Published August 10, 2026 · Contact: support@gobare.ai

This policy governs your use of the Service from the date it is published above.

This policy describes how Intel CFO LLC, d/b/a Bare AI Labs (“Bare,” “we,” “us”) handles data when you use the Bare AI assistant at https://www.gobare.ai (the “Service”).

Your conversations live in your browser, not on our servers. When you send a message, we process it to answer you and do not store it. What we do keep is metadata — thread titles, timestamps, counters — and it’s all listed in one table below, with retention times. One temporary beta exception exists (feedback you choose to send us), and it’s disclosed plainly in Section 5. That’s the policy; the rest is detail.

1. What we collect

DataWhat it isWhy
Anonymous session IDOne opaque identifier in a signed cookie (bare_sid)To enforce daily usage limits without requiring an account
Thread metadataThread titles (short, derived from your first message, capped at 120 characters), timestamps, message counts, routing laneSo your thread list works across reloads
Usage countersTurns per day, token countsUsage limits and abuse prevention
Account identifierYour sign-in identifier (for example, the email tied to your Google sign-in or email link) — only if you choose to sign inOptional features and, later, paid plans
Waitlist and sign-in emailEmail address, consent timestamp, waitlist position, and referral codes you generate or use (Section 6)To reserve access, send sign-in links, and deliver referral access codes
Analytics dataPage views, approximate location, device/browser info via Google Analytics (Section 8)To understand how the product is used
IP-derived abuse signalsIP addresses appear in firewall/load-balancer logs (kept a limited period); our rate-limit table stores a salted hash that auto-expires in 48 hoursAbuse and attack prevention only
Operational logsContent-free logs: request IDs, lanes, lengths, token counts, error namesKeeping the Service running
Beta feedback (temporary)Only what you explicitly choose to send — see Section 5Fixing beta issues

Thread titles are the one conversation-derived string we store, and they are capped and short. That’s it.

2. What we don’t collect (the longer list)

We never store on our servers:

This isn’t just a promise — it’s how the system is built. Our database schema has no place to put message content, and automated checks on every deployment verify that no content-bearing fields are added and that logs stay content-free.

3. How your messages are processed

When you send a message, it travels over an encrypted connection to our servers and then to the AI infrastructure that hosts the models we use. Your message is processed in memory to generate the response, which streams back to your browser. We process your messages to answer you; we do not store or log them. Our AI infrastructure provider commits that customer inputs are not retained or used to train models — a commitment we rely on.

Your conversation history — the thing that gives an AI assistant context — is assembled on your device from your local storage and sent with each request, transiently, within size caps. That is how Bare remembers your conversation without our servers keeping it.

4. Deleting your data — Burn Receipt

5. Beta feedback — the one exception (temporary)

During the private beta, you can flag a response or send feedback. This is the only way conversation content ever reaches our storage, and it happens only when you explicitly send it.

6. Waitlist and sign-in email

Before public launch, access is gated. Two flows involve your email address:

These emails are transactional only, sent through Amazon SES from addresses on gobare.ai. Bounces and spam complaints are processed automatically so suppressed addresses stop receiving mail. We do not buy or rent email lists, and we do not use waitlist or sign-in addresses for marketing newsletters unless you separately opt in. To have your waitlist entry removed, email support@gobare.ai.

7. Optional Google connection

If you connect your Google account (Gmail, Calendar, Drive, Contacts), you grant OAuth-scoped access that Bare uses only to fulfill the requests you make. Your Google tokens are stored in your browser — not on our servers — and travel with each request transiently. Content retrieved from Google is processed in memory to answer you and is not retained. Disconnect anytime in the product or via your Google account’s security settings. Bare’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Analytics (Google Analytics 4)

The Service uses Google Analytics 4 (measurement ID G-S8EQP52FET). The Google tag sends page views, approximate location, and device/browser information to Google and sets Google cookies (_ga, _ga_*). We use this to understand how the product is used.

What GA4 never sees: your conversations. Message content stays in your browser, and our analytics events carry metadata only — never message content, prompts, thread titles, or anything conversation-derived. This is enforced by automated checks on every release.

The Service is operated for users in the United States. Before we accept EU/UK launch traffic, GA4 cookies on our public surfaces will be gated behind a consent flow with matching GA4 admin settings.

9. Cookies

CookieWho sets itPurposeNecessary?
bare_sidBareSigned, HttpOnly, Secure session identifier — one opaque ID; how usage limits work without an accountStrictly necessary
bare_betaBareSigned cookie recording that you redeemed a beta access code, so the waitlist gate lets you throughStrictly necessary
_ga, _ga_*Google AnalyticsUsage measurement (Section 8)Not strictly necessary

We set no advertising or cross-site tracking cookies.

10. Who processes data besides us (sub-processors)

A full named sub-processor list is maintained internally and is available to regulators on request. No data brokers. No ad-tech beyond the analytics above. We do not sell your personal information, and we do not use your conversations to train models — we don’t have them.

11. Your privacy rights (including California)

We aim to honor the rights below for everyone, not just where a statute requires it. If you are a California resident, the CCPA/CPRA specifically gives you:

To exercise any right: support@gobare.ai. We will verify requests using the minimal information we hold (which is the point — for anonymous users there is usually nothing to return, and nothing linking data to you). We will respond within the timelines the law requires (generally 45 days under CCPA/CPRA).

We do not use or disclose sensitive personal information for purposes requiring a “Limit the Use” option, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.

12. Children

The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). You must be 13 or older to use the Service. Honesty note: we do not verify age — we barely verify anything about you, which is the point — so this is an eligibility rule, not a technical control. If you believe a child under 13 has provided personal information to us, contact support@gobare.ai and we will delete it.

13. Security

No system is perfectly secure, and we don’t claim to be the exception. What we can say honestly: the most sensitive data — your conversations — isn’t on our servers to be breached.

14. Data retention

DataWhereHow long
Conversation transcriptsYour device (browser local storage)Under your control — delete anytime (Burn)
Thread metadata (titles, timestamps, counters)Our databaseUntil you delete the thread or your account
Account record (sign-in identifier)Our databaseUntil you delete your account
Usage countersOur databaseAuto-expire on a rolling basis
Waitlist entry (email, position, referral codes)Our databaseUntil the waitlist program ends or you ask us to remove it
Beta feedback (excerpt, comment, screenshot)Our cloud (beta only)30 days, automatic deletion
Operational logs (content-free)Our cloudLimited period (30-day target) — never contain message content
IP addresses in security logsEdge/firewall logs; salted hash in rate-limit tableLimited period in logs; 48-hour auto-expiry on the hash
Temporary generated mediaCloud scratch storageMinutes to hours; hard-deleted within 1 day

15. Where data is processed

The Service is operated from the United States, and processing happens on US infrastructure. If you use the Service from outside the US, your requests are processed in the US.

16. Changes to this policy

Material changes will be posted at https://www.gobare.ai with a dated changelog. If a change would meaningfully reduce your privacy protections, we will notify you prominently in the product before it takes effect. We won’t quietly walk back the commitments in Section 2.

17. Contact

Privacy questions, rights requests, anything else: support@gobare.ai