Privacy policy
Last updated:
This privacy policy describes how b0gy LLC (“b0gy,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our website (b0gy.com), the Zero platform (portal.b0gy.com), and our advisory services.
b0gy is based in Las Vegas, Nevada. If you have questions about this policy, contact us at privacy@b0gy.com.
1. Overview — data roles and categories
We handle three distinct categories of data. Understanding the distinction matters because different rules and rights apply to each.
Service Data — personal information you provide to create and manage your account (name, email, billing info).
Customer Data — data that Zero discovers from your connected cloud accounts, repositories, and integrations (resource metadata, cost data, deployment records, security findings). You own this data; we process it on your behalf to deliver the service. Customer Data is governed by our Terms of Service.
Usage Data — data collected automatically about how you interact with our website and platform (pages visited, features used, timestamps, IP addresses).
2. Information we collect
2.1 Service Data (you provide this)
| Data | Source | Purpose |
|---|---|---|
| Name, email address, profile photo | OAuth via GitHub or Google | Account creation and authentication |
| Organization name | You, during setup | Multi-tenant workspace |
| Billing name, address | You, via Stripe checkout | Payment processing |
| Payment method (card details) | Stripe (we never see full card numbers) | Subscription billing |
| Email address for newsletters | You, via subscribe form | Newsletter delivery |
| Contact form submissions | You, via website form | Responding to inquiries |
| Notification preferences | You, via platform settings | Delivering notifications per your choices |
2.2 Customer Data (discovered from your environments)
When you connect cloud accounts and integrations, Zero discovers and processes:
- Cloud resource metadata — resource types, names, configurations, tags, regions, relationships, and status from GCP, AWS, and GitHub
- Cost and billing data — spend amounts, usage metrics, and pricing data from GCP BigQuery exports and AWS CUR/Athena
- Repository metadata — repository names, deployment records, PR metadata, CODEOWNERS contents, and dependency manifests via GitHub App
- Security findings — CVEs from public databases (NVD, OSV), configuration drift, stale resources, and missing ownership
- Integration metadata — Jira issue identifiers and Slack channel/workspace identifiers for notification delivery
We access this data via read-only federated identity (GCP Workload Identity Federation, AWS OIDC). No long-lived credentials or API keys are stored. You control access by managing IAM trust policies in your own cloud accounts and can revoke access at any time.
2.3 Usage Data (collected automatically)
- Log data — IP address, browser type, operating system, referring URL, pages viewed, timestamps
- Platform usage — features accessed, actions taken, session duration
- Analytics — aggregated usage patterns via Google Analytics (in production only)
- Bot protection signals — Cloudflare Turnstile collects browser fingerprint signals and interaction patterns to distinguish humans from bots on our contact form
3. How we use information
| Purpose | Data used |
|---|---|
| Provide and operate Zero | Service Data, Customer Data |
| Process payments and billing | Billing data |
| Send transactional emails (account, billing, security alerts) | Email address |
| Send newsletters | Email address (you opt in) |
| Respond to contact form submissions | Contact info, message content |
| Deliver advisory services | Service Data, engagement communications |
| Detect and prevent abuse, fraud, and security threats | Usage Data, log data |
| Improve the platform and fix bugs | Usage Data, aggregated Customer Data |
| Comply with legal obligations | As required |
We do not use your Customer Data for advertising, marketing, or training machine learning models. We do not sell or share your personal information with third parties for their own marketing purposes.
4. How we share information
We share information only in these circumstances:
Service providers (sub-processors). We use third-party services to operate Zero. Each processes data only as needed to provide their service to us. Below we separate the providers that are always in use to run the platform from the integrations and clouds that engage only when you connect them.
Always active — core platform and billing. These operate for every account.
| Provider | Purpose | Data shared |
|---|---|---|
| Google Cloud Platform | Infrastructure hosting (Cloud Run, Cloud SQL, GCS) — this is where Zero runs | All platform data |
| Cloudflare | DNS, bot protection (Turnstile) | IP addresses, browser signals |
| Stripe | Payment processing and billing | Billing and payment data |
| SendGrid (Twilio) | Transactional email — account, billing, and security messages (newsletters only if you opt in) | Email addresses, message content |
| Google Analytics | Marketing-site analytics | Pseudonymous usage data |
| GitHub or Google (OAuth) | Sign-in — you authenticate with one of them | User identity |
Only when you connect them. These engage solely when you turn on a feature or link an account — connect nothing and none apply. Note the difference in the data shared column: integrations receive your data to do their job, while connected clouds are your own accounts that Zero reads from (least-privilege, short-lived tokens) and shares nothing back to.
| Provider | Purpose | Data shared | Enabled when |
|---|---|---|---|
| GitHub (Microsoft) App | Repository and supply-chain integration | Repository and organization metadata | You connect the GitHub integration |
| Atlassian (Jira, Confluence) | Issue-tracking integration | User identity, issue metadata | You link Atlassian |
| Slack (Salesforce) | Notification delivery | User identity, notification content | You link Slack |
| Amazon Web Services (AWS) | Cloud inventory, cost, and posture | None — your own account, read by Zero | You connect AWS |
| Microsoft Azure | Cloud inventory, cost, and posture | None — your own account, read by Zero | You connect Azure |
| Google Cloud Platform (your account) | Cloud inventory, cost, and posture | None — your own account, read by Zero | You connect GCP |
Legal requirements. We may disclose information if required by law, subpoena, court order, or government request, or if we reasonably believe disclosure is necessary to protect our rights, your safety, or the public.
Business transfers. If b0gy is acquired, merged, or sells substantially all its assets, your information may be transferred to the successor entity. We will notify you before your information becomes subject to a different privacy policy.
We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising.
5. Data retention
| Data category | Retention period |
|---|---|
| Active account data | Duration of your account |
| Customer Data | Duration of your subscription + 30-day export window, then deleted within 30 days |
| Payment and invoice records | 7 years (tax and legal compliance) |
| Usage logs | 12 months |
| Newsletter subscriber data | Until you unsubscribe, then deleted within 30 days |
| Contact form submissions | 12 months |
| Backups containing personal data | Purged within 90 days of primary data deletion |
You can request deletion of your account and associated data at any time by contacting privacy@b0gy.com.
6. Data security
We implement technical and organizational measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest
- Keyless connector model — no stored cloud credentials
- Role-based access controls and audit logging
- Infrastructure hosted on Google Cloud Platform with their physical and environmental security controls
- Regular security reviews of our codebase and infrastructure
No system is 100% secure. If we discover a breach affecting your personal data, we will notify you promptly and in accordance with applicable law.
7. Cookies and tracking technologies
We use minimal tracking. Here is what is set and why:
| Technology | Type | Purpose |
|---|---|---|
| Cloudflare Turnstile | Strictly necessary | Bot protection on contact form. No consent required. |
| Google Analytics | Analytics | Aggregated website usage metrics. Only active on the production site. Uses IP anonymization. |
| Session cookies | Strictly necessary | Maintaining your authenticated session in Zero. |
We do not use advertising cookies, retargeting pixels, or social media trackers. We do not participate in real-time bidding or ad exchanges.
If your browser sends a Global Privacy Control (GPC) signal, we honor it as an opt-out of any non-essential tracking.
8. Your privacy rights
You may have the following rights regarding your personal information under applicable law:
- Access — request a copy of the personal information we hold about you
- Correction — request that we correct inaccurate information
- Deletion — request that we delete your personal information
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent — where processing is based on consent (e.g., newsletters), you can withdraw at any time
To exercise any of these rights, contact us at privacy@b0gy.com. We will respond within 30 days (or sooner if required by applicable law). We will not discriminate against you for exercising your rights.
For Customer Data, please direct your request to the organization that subscribed to Zero. We will assist them in responding.
9. California privacy rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
Categories of personal information collected in the preceding 12 months:
| CCPA category | Examples | Source |
|---|---|---|
| Identifiers | Name, email, IP address, account ID | You, OAuth providers |
| Financial information | Billing address, payment info (via Stripe) | You |
| Internet activity | Pages visited, features used, login times | Automatic collection |
| Professional information | Job title, company name (if provided) | You |
| Geolocation | Approximate location derived from IP address | Automatic collection |
We do not sell or share (as defined by CCPA) your personal information.
Your California rights:
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (we do not sell or share, but you can contact us to confirm)
- Right to non-discrimination for exercising your rights
How to submit a request: Email privacy@b0gy.com or use the contact form on our website. We will verify your identity before processing the request. You may designate an authorized agent to submit a request on your behalf.
10. Nevada privacy rights
If you are a Nevada resident, you have the right to opt out of the sale of your covered information. We do not sell your personal information as defined by Nevada SB 220. To submit an opt-out request or for questions, contact privacy@b0gy.com. We will respond within 60 days.
11. Other US state privacy rights
Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) have rights similar to those described in Sections 8 and 9. To exercise your rights, contact privacy@b0gy.com.
For states that require an appeal process: if we deny your request, you may appeal by emailing privacy@b0gy.com with “Appeal” in the subject line. We will respond within 60 days.
12. Children’s privacy
Zero is designed for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, contact us at privacy@b0gy.com.
13. Changes to this policy
We may update this policy from time to time. When we do, we will update the “last updated” date at the top. For material changes, we will notify account holders by email at least 30 days before the change takes effect.
We encourage you to review this policy periodically.
14. Contact
b0gy LLC Las Vegas, NV
Privacy inquiries: privacy@b0gy.com Legal inquiries: legal@b0gy.com Security issues: security@b0gy.com General: hello@b0gy.com