Bot Commander is local-first: your private desktop workspace stays on your computer unless you choose a connected provider, team service, publishing destination, or remote-control feature. The Bot Commander website separately collects limited information when you subscribe, submit a form, download the app, or arrive through a measured campaign. We do not sell that information.
Bot Commander ("we", "us", the "Software") is designed to keep its core workspace data on your device. The desktop app does not send your conversations, files, contacts, financial records, or credentials to Bot Commander merely because you use the app. Data leaves your device only when you choose a feature that requires an external service, such as an AI provider, team synchronization, website publishing, social posting, email delivery, banking connection, or remote control.
By default, core data generated or stored by the Software is kept on your local computer in ~/.botcom/:
| Data | Location | Who Can Access It |
|---|---|---|
| Conversations & chat history | ~/.botcom/memory.db |
You only |
| CRM contacts & deals | ~/.botcom/crm.db |
You only |
| Financial records & invoices | ~/.botcom/crm.db |
You only |
| Reminders & scheduled tasks | ~/.botcom/schedule.db |
You only |
| Configuration & preferences | ~/.botcom/config.json |
You only |
| API keys & credentials | Platform secure credential store (Windows Credential Manager, macOS Keychain, or Linux system keyring) | You only |
If you enable team synchronization, mobile/remote access, cloud-backed connectors, or another optional integration, the records needed for that feature may also be transmitted to and stored by the service you selected. The app identifies these features during setup or configuration.
The only data that leaves your device is what you explicitly send:
When you send a message, it is transmitted to the AI provider you configured (e.g., Anthropic, OpenAI, Google). This is governed entirely by that provider's privacy policy — not ours. We recommend reviewing:
When you activate a Skill that connects to an external service (Gmail, Google Calendar, GitHub, Telegram, Coinbase, etc.), data may be transmitted to that service as part of the operation (e.g., sending an email, posting a tweet, executing a trade). This is:
The public website at botcom.ai is separate from the local desktop workspace. When you subscribe to the newsletter or submit another website form, we may collect the information you provide, such as your email address, along with campaign information associated with your visit.
Campaign measurement may use URL parameters and first-party browser storage to remember information such as UTM values, a campaign or tracking identifier, landing page, referrer, platform, content variant, and a random session identifier. When you follow a tracked link, submit a form, or begin a download, the website may record that event so we can compare campaign performance and improve future marketing.
The Bot Commander website relay is designed to hash IP-address and user-agent values for tracked clicks rather than store those raw identifiers. Raw visitor IP addresses and user agents for form submissions are disabled by default. Processed relay events are configured for limited retention. We do not sell campaign-attribution or newsletter information.
We use Google Analytics 4 on botcom.ai to understand aggregate website traffic and campaign performance. Google Analytics may use cookies or similar technologies and may process information such as pages viewed, approximate location, device and browser information, referral source, and interactions with the website. We do not intentionally send form contents, email addresses, or other directly identifying information to Google Analytics.
Google processes this information under its own terms. Learn more at How Google uses information from sites or apps that use its services. You can also use browser controls or Google's Analytics opt-out tools to limit this collection.
Your API keys (AI providers, Coinbase, etc.) and skill credentials (Gmail, GitHub, etc.) are stored using your operating system's secure credential storage: Windows Credential Manager on Windows, Keychain on macOS, and the supported system keyring or secure credential store on Linux. They are:
Bot Commander can connect to third-party services through integrations and Skills. The public website also uses service providers for hosting, newsletter storage, downloads, and other functions. Each provider processes information under its own terms and privacy policy. Use optional integrations at your discretion.
The Software is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction) and we do not knowingly engage with such users.
You control the data stored by the desktop Software. To remove local Bot Commander data, uninstall the Software and delete the ~/.botcom/ folder.
To ask about, correct, or request deletion of information submitted through the Bot Commander website, contact legal@botcom.ai. We may need enough information to locate the relevant record and verify the request.
If we make material changes to this Privacy Policy, we will note them in the Software's release notes. Continued use of the Software after changes constitutes your acceptance.
For privacy-related questions: legal@botcom.ai
Local-first by design. Transparent when a connected feature needs data. Your workspace remains yours.