Privacy Policy

Last updated: April 2026

This policy applies to bowr.ai and all Bowr products and services.

1. Introduction

Bowr Pty Ltd (ABN ‭85 190 343 165‬) ("Bowr", "we", "us", or "our") is committed to protecting the privacy of all individuals whose personal information we handle. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information in connection with our products and services.

We are bound by the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained in that Act. We take our obligations under this legislation seriously. For users located in the United Kingdom or European Economic Area, we also comply with the requirements of the UK GDPR and EU General Data Protection Regulation (GDPR) as applicable.

By using our website, products, or services, you agree to the collection and use of your information in accordance with this Privacy Policy.

2. Who This Policy Applies To

This Privacy Policy applies to:

  • Visitors to bowr.ai and any related Bowr websites

  • Businesses and individuals who sign up for and use Bowr products and services ("Customers")

  • Individuals who interact with an AI intake agent powered by Bowr on a Customer's website ("End Users")

  • Bowr operates as both a data controller (in respect of Customer account information) and a data processor (in respect of End User information collected through our intake conversations on behalf of Customers).

3. What Personal Information We Collect

3.1 Information we collect from Customers

When you sign up for or use Bowr, we may collect:

  • Full name and contact details including email address and phone number

  • Business name, ABN, and industry type

  • Billing and payment information (processed securely by our payment provider Stripe — we do not store card details)

  • Login credentials and account preferences

  • Usage data including how you interact with the Bowr dashboard and features

  • Widget configuration settings including brand colours, service areas, and intake preferences

  • Communications you send to us including support requests and feedback

3.2 Information collected through Bowr intake conversations (End User data)

When End Users interact with an AI intake agent powered by Bowr on a Customer's website, we may collect on behalf of that Customer:

  • Name and contact details including phone number and email address

  • Details of the enquiry including matter type, service interest, and situation description

  • Urgency and timing information

  • Financial, health, legal, or other sensitive context provided voluntarily by the End User

  • Full conversation transcripts

This End User data is collected on behalf of and for the benefit of the relevant Customer. Customers are responsible for ensuring they have appropriate consent and authority to collect this information from their website visitors.

3.3 Technical and usage data

We automatically collect certain technical information when you visit our website or use our services, including:

  • IP address and approximate geographic location

  • Browser type and version, operating system, and device type

  • Pages visited, time spent, and navigation patterns

  • Referring URLs and search terms

  • This information is collected using cookies and similar tracking technologies. See Section 10 for more detail on our use of cookies.

4. How We Use Personal Information

4.1 Customer account information

We use Customer information to:

  • Provide, operate, and improve the Bowr platform and services

  • Process payments and manage billing

  • Send transactional communications including account notifications, receipts, and service updates

  • Provide customer support and respond to enquiries

  • Send marketing communications where you have consented or where permitted by law (you may opt out at any time)

  • Comply with our legal obligations

  • Protect against fraud and misuse of our services

4.2 End User intake data

When End Users interact with an AI intake agent powered by Bowr on a Customer's website, we collect on behalf of that Customer: name, contact details, enquiry details, conversation transcripts, and any other information the End User voluntarily provides. This data is processed by Anthropic's API to generate AI responses. Anthropic does not retain or train on this data per their API data processing agreement. End User data is not used by Bowr for our own marketing purposes and is not sold to third parties.

5. Disclosure of Personal Information

We may disclose personal information to:

  • Service providers who assist us in operating our business, including cloud hosting providers, payment processors (Stripe), email delivery services, analytics providers, and customer support tools — all of whom are bound by confidentiality obligations

    Our current sub-processors include: Supabase Inc (database storage, hosted on AWS ap-southeast-2, Sydney, Australia), Anthropic PBC (AI response generation, USA), Stripe Inc (payment processing, USA), Resend Inc (transactional email delivery, USA), ClickSend Pty Ltd (SMS delivery, Australia), and Railway Corp (application hosting, USA). We maintain data processing agreements with each sub-processor and will update this list as sub-processors change.

  • Customers, in respect of End User intake data collected through their Bowr-powered widget

  • Law enforcement or regulatory authorities where required by law or to protect our legal rights

  • Successor entities in the event of a merger, acquisition, or sale of all or part of our business

We do not sell, rent, or trade personal information to third parties for their own marketing purposes.

Some of our service providers may be located outside Australia. Where we disclose personal information to overseas recipients, we take reasonable steps to ensure those recipients handle the information in accordance with the Australian Privacy Principles.

6. Sensitive Information

Some End Users may voluntarily disclose sensitive information during intake conversations — including health information, financial circumstances, legal matters, or other personal circumstances. This information is:

  • Collected only as part of the intake conversation on behalf of the relevant Customer

  • Stored securely and accessible only to the relevant Customer through their Bowr dashboard

  • Never used by Bowr for any purpose other than delivering the intake brief to the Customer

  • Never shared with third parties except as required by law

Bowr's AI intake agent is designed to collect only the information necessary to qualify an enquiry. It is not designed or intended to collect sensitive information beyond what is voluntarily and relevantly provided by the End User.

6A. Health and Mental Health Services

Where Bowr is used by health practitioners, psychologists, psychiatrists, counsellors, or other registered health professionals, the following applies:

Bowr intake conversations are administrative pre-screening tools. They are not clinical consultations, therapeutic sessions, or medical assessments. Nothing shared in a Bowr intake conversation is protected by therapeutic privilege or professional confidentiality obligations applicable to clinical interactions.

Customers who are registered health professionals are solely responsible for ensuring their use of Bowr complies with their obligations under the Health Practitioner Regulation National Law, AHPRA guidelines, Australian Psychological Society (APS) ethics guidelines, and any other applicable professional standards.

Bowr does not store health information separately from other conversation data. All conversation data is accessible by the practice through their dashboard and is subject to the retention periods described in Section 8.

7. Data Security

We take data security seriously and implement appropriate technical and organisational measures to protect personal information from unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS/SSL

  • Encryption of data at rest

  • Access controls limiting who within our organisation can access personal information

  • Regular security reviews and updates

  • Secure third-party infrastructure (our services are hosted on enterprise-grade cloud infrastructure)

  • No method of transmission over the internet or electronic storage is 100% secure. While we take all reasonable precautions, we cannot guarantee the absolute security of information transmitted to or from our services.

In the event of a data breach that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with our obligations under the Notifiable Data Breaches scheme.

8. Data Retention

We retain personal information for as long as necessary to provide our services and comply with our legal obligations:

  • Customer account information is retained for the duration of the account and for a period of 7 years following account closure, in accordance with our tax and record-keeping obligations

  • End User intake data is retained for the duration of the Customer's active account. Customers can configure automatic deletion of conversation data after 30, 60, or 90 days from their dashboard. On account cancellation, End User data is retained for 30 days to allow data export, then permanently deleted.

  • Marketing communications preferences are retained until you opt out or withdraw consent

  • Technical and usage data is typically retained for 12 months

You may request deletion of your personal information at any time, subject to our legal retention obligations. See Section 11 for how to make such a request.

9. Your Rights Under the Australian Privacy Act

Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you

  • Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading

  • Make a complaint about how we have handled your personal information

To exercise any of these rights, please contact us using the details in Section 12. We will respond to access and correction requests within a reasonable timeframe and at no charge in most circumstances.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.

9A. Additional Rights for UK and European Economic Area (EEA) Users

If you are located in the United Kingdom or European Economic Area, the following additional provisions apply to you under the UK GDPR and EU General Data Protection Regulation (GDPR) respectively.

Legal basis for processing

We process your personal information on the following legal bases:

  • Contract performance — processing necessary to provide the Bowr service you have signed up for, including account management, billing, and service delivery

  • Legitimate interests — processing necessary for our legitimate business interests, including fraud prevention, security, improving our services, and direct marketing to existing customers, where those interests are not overridden by your rights

  • Consent — where you have given explicit consent, including for marketing communications and, at signup, for data processing under GDPR

  • Legal obligation — where processing is necessary to comply with applicable law

Your additional rights

In addition to the rights described in Section 9, if you are in the UK or EEA you also have the right to:

  • Erasure ("right to be forgotten") — request that we delete your personal information where there is no compelling reason for its continued processing

  • Restriction of processing — request that we restrict processing of your personal information in certain circumstances

  • Data portability — receive a copy of your personal information in a structured, commonly used, machine-readable format, and have it transferred to another controller where technically feasible

  • Object to processing — object to processing based on legitimate interests or for direct marketing purposes

  • Withdraw consent — where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal

To exercise any of these rights, contact us at hello@bowr.ai with subject line "Privacy Request — GDPR". We will respond within 30 days.

Data transfers outside the UK/EEA

Bowr is operated from Australia. When you use our services, your personal information is transferred to and processed in Australia and potentially other countries where our service providers operate (including the United States). We ensure such transfers are protected by appropriate safeguards including standard contractual clauses and data processing agreements with our service providers.

Right to lodge a complaint

If you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

If you are in the EEA, you have the right to lodge a complaint with your local data protection authority.

Data controller

For the purposes of UK/EU GDPR, the data controller is: Bowr, Melbourne, Victoria, Australia hello@bowr.ai

10. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to improve your experience and analyse how our services are used. Cookies are small text files stored on your device.

We use the following types of cookies:

  • Essential cookies — required for the website to function correctly, including maintaining your login session

  • Analytics cookies — used to understand how visitors interact with our website (we use tools such as Google Analytics)

  • Marketing cookies — used to deliver relevant content and measure the effectiveness of our communications

You can control or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our website and services.

11. Access, Correction, and Deletion Requests

To request access to, correction of, or deletion of your personal information, please contact us at:

Email: hello@bowr.ai

Subject line: Privacy Request

Please include your full name, the email address associated with your account (if applicable), and a clear description of your request. We will acknowledge your request within 5 business days and respond substantively within 30 days.

For End Users seeking access to data collected through a Bowr-powered widget on a third-party website, please contact the relevant business (our Customer) directly, as they are the data controller in respect of that information.

12. Contact Us

For any privacy-related questions, concerns, or requests, please contact:

Email: hello@bowr.ai
Website: bowr.ai
ABN: ‭85 190 343 165‬
Melbourne, Victoria, Australia

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. We will notify Customers of material changes by email or by displaying a prominent notice on our website. The date of the most recent update is shown at the top of this document.

Your continued use of our services after any changes to this Privacy Policy constitutes your acceptance of the updated policy.