Privacy Policy
Last updated: April 2026
This policy applies to bowr.ai and all Bowr products and services.
1. Introduction
Bowr Pty Ltd (ABN 85 190 343 165) ("Bowr", "we", "us", or "our") is committed to protecting the privacy of all individuals whose personal information we handle. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information in connection with our products and services.
We are bound by the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained in that Act. We take our obligations under this legislation seriously. For users located in the United Kingdom or European Economic Area, we also comply with the requirements of the UK GDPR and EU General Data Protection Regulation (GDPR) as applicable.
By using our website, products, or services, you agree to the collection and use of your information in accordance with this Privacy Policy.
2. Who This Policy Applies To
This Privacy Policy applies to:
Visitors to bowr.ai and any related Bowr websites
Businesses and individuals who sign up for and use Bowr products and services ("Customers")
Individuals who interact with an AI intake agent powered by Bowr on a Customer's website ("End Users")
Bowr operates as both a data controller (in respect of Customer account information) and a data processor (in respect of End User information collected through our intake conversations on behalf of Customers).
3. What Personal Information We Collect
3.1 Information we collect from Customers
When you sign up for or use Bowr, we may collect:
Full name and contact details including email address and phone number
Business name, ABN, and industry type
Billing and payment information (processed securely by our payment provider Stripe — we do not store card details)
Login credentials and account preferences
Usage data including how you interact with the Bowr dashboard and features
Widget configuration settings including brand colours, service areas, and intake preferences
Communications you send to us including support requests and feedback
3.2 Information collected through Bowr intake conversations (End User data)
When End Users interact with an AI intake agent powered by Bowr on a Customer's website, we may collect on behalf of that Customer:
Name and contact details including phone number and email address
Details of the enquiry including matter type, service interest, and situation description
Urgency and timing information
Financial, health, legal, or other sensitive context provided voluntarily by the End User
Full conversation transcripts
This End User data is collected on behalf of and for the benefit of the relevant Customer. Customers are responsible for ensuring they have appropriate consent and authority to collect this information from their website visitors.
3.3 Technical and usage data
We automatically collect certain technical information when you visit our website or use our services, including:
IP address and approximate geographic location
Browser type and version, operating system, and device type
Pages visited, time spent, and navigation patterns
Referring URLs and search terms
This information is collected using cookies and similar tracking technologies. See Section 10 for more detail on our use of cookies.
4. How We Use Personal Information
4.1 Customer account information
We use Customer information to:
Provide, operate, and improve the Bowr platform and services
Process payments and manage billing
Send transactional communications including account notifications, receipts, and service updates
Provide customer support and respond to enquiries
Send marketing communications where you have consented or where permitted by law (you may opt out at any time)
Comply with our legal obligations
Protect against fraud and misuse of our services
4.2 End User intake data
When End Users interact with an AI intake agent powered by Bowr on a Customer's website, we collect on behalf of that Customer: name, contact details, enquiry details, conversation transcripts, and any other information the End User voluntarily provides. This data is processed by Anthropic's API to generate AI responses. Anthropic does not retain or train on this data per their API data processing agreement. End User data is not used by Bowr for our own marketing purposes and is not sold to third parties.
5. Disclosure of Personal Information
We may disclose personal information to:
Service providers who assist us in operating our business, including cloud hosting providers, payment processors (Stripe), email delivery services, analytics providers, and customer support tools — all of whom are bound by confidentiality obligations
Our current sub-processors include: Supabase Inc (database storage, hosted on AWS ap-southeast-2, Sydney, Australia), Anthropic PBC (AI response generation, USA), Stripe Inc (payment processing, USA), Resend Inc (transactional email delivery, USA), ClickSend Pty Ltd (SMS delivery, Australia), and Railway Corp (application hosting, USA). We maintain data processing agreements with each sub-processor and will update this list as sub-processors change.
Customers, in respect of End User intake data collected through their Bowr-powered widget
Law enforcement or regulatory authorities where required by law or to protect our legal rights
Successor entities in the event of a merger, acquisition, or sale of all or part of our business
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
Some of our service providers may be located outside Australia. Where we disclose personal information to overseas recipients, we take reasonable steps to ensure those recipients handle the information in accordance with the Australian Privacy Principles.
6. Sensitive Information
Some End Users may voluntarily disclose sensitive information during intake conversations — including health information, financial circumstances, legal matters, or other personal circumstances. This information is:
Collected only as part of the intake conversation on behalf of the relevant Customer
Stored securely and accessible only to the relevant Customer through their Bowr dashboard
Never used by Bowr for any purpose other than delivering the intake brief to the Customer
Never shared with third parties except as required by law
Bowr's AI intake agent is designed to collect only the information necessary to qualify an enquiry. It is not designed or intended to collect sensitive information beyond what is voluntarily and relevantly provided by the End User.
6A. Health and Mental Health Services
Where Bowr is used by health practitioners, psychologists, psychiatrists, counsellors, or other registered health professionals, the following applies:
Bowr intake conversations are administrative pre-screening tools. They are not clinical consultations, therapeutic sessions, or medical assessments. Nothing shared in a Bowr intake conversation is protected by therapeutic privilege or professional confidentiality obligations applicable to clinical interactions.
Customers who are registered health professionals are solely responsible for ensuring their use of Bowr complies with their obligations under the Health Practitioner Regulation National Law, AHPRA guidelines, Australian Psychological Society (APS) ethics guidelines, and any other applicable professional standards.
Bowr does not store health information separately from other conversation data. All conversation data is accessible by the practice through their dashboard and is subject to the retention periods described in Section 8.
7. Data Security
We take data security seriously and implement appropriate technical and organisational measures to protect personal information from unauthorised access, disclosure, alteration, or destruction. These measures include:
Encryption of data in transit using TLS/SSL
Encryption of data at rest
Access controls limiting who within our organisation can access personal information
Regular security reviews and updates
Secure third-party infrastructure (our services are hosted on enterprise-grade cloud infrastructure)
No method of transmission over the internet or electronic storage is 100% secure. While we take all reasonable precautions, we cannot guarantee the absolute security of information transmitted to or from our services.
In the event of a data breach that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with our obligations under the Notifiable Data Breaches scheme.
8. Data Retention
We retain personal information for as long as necessary to provide our services and comply with our legal obligations:
Customer account information is retained for the duration of the account and for a period of 7 years following account closure, in accordance with our tax and record-keeping obligations
End User intake data is retained for the duration of the Customer's active account. Customers can configure automatic deletion of conversation data after 30, 60, or 90 days from their dashboard. On account cancellation, End User data is retained for 30 days to allow data export, then permanently deleted.
Marketing communications preferences are retained until you opt out or withdraw consent
Technical and usage data is typically retained for 12 months
You may request deletion of your personal information at any time, subject to our legal retention obligations. See Section 11 for how to make such a request.
9. Your Rights Under the Australian Privacy Act
Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
Access the personal information we hold about you
Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading
Make a complaint about how we have handled your personal information
To exercise any of these rights, please contact us using the details in Section 12. We will respond to access and correction requests within a reasonable timeframe and at no charge in most circumstances.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
9A. Additional Rights for UK and European Economic Area (EEA) Users
If you are located in the United Kingdom or European Economic Area, the following additional provisions apply to you under the UK GDPR and EU General Data Protection Regulation (GDPR) respectively.
Legal basis for processing
We process your personal information on the following legal bases:
Contract performance — processing necessary to provide the Bowr service you have signed up for, including account management, billing, and service delivery
Legitimate interests — processing necessary for our legitimate business interests, including fraud prevention, security, improving our services, and direct marketing to existing customers, where those interests are not overridden by your rights
Consent — where you have given explicit consent, including for marketing communications and, at signup, for data processing under GDPR
Legal obligation — where processing is necessary to comply with applicable law
Your additional rights
In addition to the rights described in Section 9, if you are in the UK or EEA you also have the right to:
Erasure ("right to be forgotten") — request that we delete your personal information where there is no compelling reason for its continued processing
Restriction of processing — request that we restrict processing of your personal information in certain circumstances
Data portability — receive a copy of your personal information in a structured, commonly used, machine-readable format, and have it transferred to another controller where technically feasible
Object to processing — object to processing based on legitimate interests or for direct marketing purposes
Withdraw consent — where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, contact us at hello@bowr.ai with subject line "Privacy Request — GDPR". We will respond within 30 days.
Data transfers outside the UK/EEA
Bowr is operated from Australia. When you use our services, your personal information is transferred to and processed in Australia and potentially other countries where our service providers operate (including the United States). We ensure such transfers are protected by appropriate safeguards including standard contractual clauses and data processing agreements with our service providers.
Right to lodge a complaint
If you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
If you are in the EEA, you have the right to lodge a complaint with your local data protection authority.
Data controller
For the purposes of UK/EU GDPR, the data controller is: Bowr, Melbourne, Victoria, Australia hello@bowr.ai
10. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to improve your experience and analyse how our services are used. Cookies are small text files stored on your device.
We use the following types of cookies:
Essential cookies — required for the website to function correctly, including maintaining your login session
Analytics cookies — used to understand how visitors interact with our website (we use tools such as Google Analytics)
Marketing cookies — used to deliver relevant content and measure the effectiveness of our communications
You can control or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our website and services.
11. Access, Correction, and Deletion Requests
To request access to, correction of, or deletion of your personal information, please contact us at:
Email: hello@bowr.ai
Subject line: Privacy Request
Please include your full name, the email address associated with your account (if applicable), and a clear description of your request. We will acknowledge your request within 5 business days and respond substantively within 30 days.
For End Users seeking access to data collected through a Bowr-powered widget on a third-party website, please contact the relevant business (our Customer) directly, as they are the data controller in respect of that information.
12. Contact Us
For any privacy-related questions, concerns, or requests, please contact:
Email: hello@bowr.ai
Website: bowr.ai
ABN: 85 190 343 165
Melbourne, Victoria, Australia
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. We will notify Customers of material changes by email or by displaying a prominent notice on our website. The date of the most recent update is shown at the top of this document.
Your continued use of our services after any changes to this Privacy Policy constitutes your acceptance of the updated policy.