Privacy Policy
Effective date: 26 June 2026 · Last updated: 26 June 2026
1. Who We Are
Bilot ("we", "our", "us") is an AI LinkedIn content management service operated as Business Pilot. We provide the Bilot platform accessible at bilot.ai ("the Service"). When you use the Service, you entrust us with your data. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have over it.
Questions? Reach us at legal@bilot.ai.
2. Data We Collect
Account data
When you register, we collect your full name, email address, and a hashed password (we never store plain-text passwords). If you sign up via LinkedIn, we collect your LinkedIn member ID, display name, and profile photo URL from the OAuth response.
Workspace and business profile data
To personalise your AI manager, you provide information about your business: what you do, your target audience, tone of voice preferences, content goals, and LinkedIn objectives. This data is stored in your workspace and used exclusively to generate content on your behalf.
Knowledge items
You can add Knowledge items (customer stories, insights, product updates, etc.) to train your AI voice. Each item has a privacy classification label that you control: Public Safe (may appear in published posts) or Internal Only (used as context but not published verbatim). These classification labels are organisational tools to help you manage your own content — they are not technical isolation guarantees. Any Knowledge item content that is used as context for content generation will be transmitted to third-party AI providers (see Section 4 below). You are solely responsible for ensuring that the content you enter into the Knowledge Base does not contain confidential, personally identifiable, or legally protected third-party information. See Section 6 (Your Responsibility for Knowledge Base Content) for full details.
LinkedIn OAuth tokens
To publish content to LinkedIn on your behalf, we store your LinkedIn OAuth access and refresh tokens. These are encrypted at rest using AES-256-GCM. We use them solely for the purpose of posting approved content and reading basic profile data needed for publishing. We do not access your LinkedIn connections, messages, or any data beyond what is strictly required to operate the publishing feature.
Generated content
All AI-generated LinkedIn posts, image descriptions, and regeneration variants are stored in your account so you can review, edit, approve, and publish them. You retain full ownership of this content.
Billing data
Payment information (card details, billing address) is collected and processed exclusively by Stripe, Inc. We do not store or access your payment card details. We store only your Stripe Customer ID, Subscription ID, plan details, subscription status, and billing period dates, which Stripe provides to us to synchronise your account status.
Usage and operational data
We collect usage logs (e.g. number of posts prepared, features used, errors encountered) for billing accuracy (enforcing plan quotas), product improvement, and security monitoring. These logs do not contain your post content, business profile text, OAuth tokens, or payment data.
3. How We Use Your Data
- To create and manage your account.
- To provide the AI LinkedIn content management service, including generating posts, images, and scheduling.
- To publish approved content to LinkedIn on your behalf using your stored OAuth token.
- To process subscription payments and enforce plan usage limits.
- To send transactional emails (email confirmation, password reset, billing receipts). We do not send marketing emails without your explicit consent.
- To detect and prevent fraud, abuse, and security incidents.
- To improve the product. We may analyse aggregated, anonymised usage patterns. We do not use your personal content to train shared AI models.
4. AI Providers and Subprocessors
Bilot uses third-party AI providers (currently OpenAI) to generate content. Any Knowledge item content that you have added to your Knowledge Base may be transmitted to these providers as context for content generation requests. We do not send your LinkedIn OAuth tokens or stored passwords to any AI provider. We do not make any other guarantees about which Knowledge Base content will or will not be included in AI provider requests — this depends on the content generation operation being performed.
It is your responsibility to ensure that the content you enter into your Knowledge Base does not contain confidential, personally identifiable, or legally protected third-party information before it is processed. See Section 5A below and Section 5A of our Terms of Service for your obligations.
Our current key subprocessors include: Stripe (billing), LinkedIn (OAuth and publishing), and OpenAI (content generation). We enter into data processing agreements (DPAs) with each subprocessor. AI providers we use do not use your data to train their shared models under our API DPAs. Your content remains yours.
5A. Your Responsibility for Knowledge Base Content
Bilot is a tool for processing information you choose to provide. We are not responsible for the content you enter into your Knowledge Base. The following applies whenever you add Knowledge items:
You are the data controller. If you enter personal data relating to third parties (clients, contacts, colleagues), you — not Bilot — are the data controller under GDPR. You must have a lawful basis for sharing that data with an AI processing service. Bilot acts as your data processor.
Anonymise before you enter. Do not enter real client names, commercially sensitive details, contract specifics, or information covered by any duty of confidentiality. Describe outcomes and experience in general, anonymised terms. For voice and tone learning, publicly available information is sufficient.
No confidentiality guarantee. Any content you submit may be sent to third-party AI providers as part of content generation. Bilot does not guarantee that content entered into the Knowledge Base will remain confidential or will not be processed by those providers under their own terms.
By using the Knowledge Base, you confirm that you have read and agree to Section 5A of the Terms of Service which sets out your full obligations, including your indemnification commitment.
5. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), our legal bases for processing your data are:
- Contract: Processing necessary to deliver the service you subscribed to (generating content, publishing, billing).
- Legitimate interests: Security monitoring, fraud prevention, product analytics using anonymised data.
- Legal obligation: Complying with applicable law and regulatory requirements.
- Consent: Marketing communications and optional analytics features (where required by law).
6. Data Retention
- Account and workspace data: retained while your account is active plus 30 days after deletion.
- Generated content and Knowledge items: deleted within 30 days of account deletion.
- Billing records: retained for 7 years as required by tax and accounting law.
- OAuth tokens: deleted immediately when you disconnect LinkedIn publishing consent or delete your account.
- Usage logs: retained for 12 months, then aggregated and anonymised.
7. Your Rights
Under GDPR and applicable data protection law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and all associated data ("right to be forgotten") — available in Settings → Data & Privacy. Deletion is scheduled with a 30-day grace window during which you can cancel; after that it is executed automatically and is irreversible. You can also email legal@bilot.ai; we action verified requests within 30 days.
- Export your data in a portable format — available in Settings → Data & Privacy. The export is a ZIP containing your profile, workspaces, posts, Knowledge items (including each item's privacy setting), feedback, and notification preferences, delivered via a single-use download link valid for 48 hours.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where processing is consent-based.
- Lodge a complaint with a supervisory authority (e.g. your national data protection authority).
To exercise any of these rights, email legal@bilot.ai. We respond to all requests within 30 days.
8. Cookies
We use essential browser storage required for authentication (session token storage in localStorage) and security, which involves no third parties. With your consent — and only with your consent — we additionally use Google Analytics 4 cookies to understand product usage: the analytics script is not loaded and no data is sent to Google unless you accept the cookie banner, and you can withdraw consent at any time. Analytics events never include your name, email address, post content, or Knowledge content. We do not use advertising cookies or cross-site tracking cookies. Full details, including cookie names and retention periods, are in our Cookie Policy. You can delete stored local data by clearing your browser storage.
9. Security
We protect your data using TLS in transit, AES-256-GCM encryption for sensitive tokens at rest, bcrypt password hashing, and regular security reviews. We restrict access to user data on a strict need-to-know basis. In the event of a data breach affecting your rights, we will notify you and the relevant authorities within 72 hours as required by GDPR.
10. Changes to This Policy
We may update this Privacy Policy as the product evolves. We will notify you of material changes by email and/or an in-app notice at least 14 days before changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or data requests:
Email: legal@bilot.ai