Bot Commander Bot Commander
Features AI Agents Security FAQ Redeem Pricing Roadmap Blog Get the Com

Privacy Policy

Last Updated: August 3, 2026
Version: 1.2

The Short Version

Bot Commander is local-first: your private desktop workspace stays on your computer unless you choose a connected provider, team service, publishing destination, or remote-control feature. The Bot Commander website separately collects limited information when you subscribe, submit a form, download the app, or arrive through a measured campaign. We do not sell that information.


1. Local-First Desktop Software

Bot Commander ("we", "us", the "Software") is designed to keep its core workspace data on your device. The desktop app does not send your conversations, files, contacts, financial records, or credentials to Bot Commander merely because you use the app. Data leaves your device only when you choose a feature that requires an external service, such as an AI provider, team synchronization, website publishing, social posting, email delivery, banking connection, or remote control.


2. What Stays On Your Machine

By default, core data generated or stored by the Software is kept on your local computer in ~/.botcom/:

Data Location Who Can Access It
Conversations & chat history ~/.botcom/memory.db You only
CRM contacts & deals ~/.botcom/crm.db You only
Financial records & invoices ~/.botcom/crm.db You only
Reminders & scheduled tasks ~/.botcom/schedule.db You only
Configuration & preferences ~/.botcom/config.json You only
API keys & credentials Platform secure credential store (Windows Credential Manager, macOS Keychain, or Linux system keyring) You only

If you enable team synchronization, mobile/remote access, cloud-backed connectors, or another optional integration, the records needed for that feature may also be transmitted to and stored by the service you selected. The app identifies these features during setup or configuration.


3. What Leaves Your Machine

The only data that leaves your device is what you explicitly send:

3.1 Messages to AI Providers

When you send a message, it is transmitted to the AI provider you configured (e.g., Anthropic, OpenAI, Google). This is governed entirely by that provider's privacy policy — not ours. We recommend reviewing:

  • Anthropic Privacy Policy
  • OpenAI Privacy Policy
  • Google Privacy Policy

3.2 Skill Operations

When you activate a Skill that connects to an external service (Gmail, Google Calendar, GitHub, Telegram, Coinbase, etc.), data may be transmitted to that service as part of the operation (e.g., sending an email, posting a tweet, executing a trade). This is:

  • Always initiated by your explicit instruction
  • Governed by the respective third-party service's privacy policy
  • Never routed through Bot Commander

3.3 Website Forms and Campaign Measurement

The public website at botcom.ai is separate from the local desktop workspace. When you subscribe to the newsletter or submit another website form, we may collect the information you provide, such as your email address, along with campaign information associated with your visit.

Campaign measurement may use URL parameters and first-party browser storage to remember information such as UTM values, a campaign or tracking identifier, landing page, referrer, platform, content variant, and a random session identifier. When you follow a tracked link, submit a form, or begin a download, the website may record that event so we can compare campaign performance and improve future marketing.

The Bot Commander website relay is designed to hash IP-address and user-agent values for tracked clicks rather than store those raw identifiers. Raw visitor IP addresses and user agents for form submissions are disabled by default. Processed relay events are configured for limited retention. We do not sell campaign-attribution or newsletter information.

3.4 Website Analytics

We use Google Analytics 4 on botcom.ai to understand aggregate website traffic and campaign performance. Google Analytics may use cookies or similar technologies and may process information such as pages viewed, approximate location, device and browser information, referral source, and interactions with the website. We do not intentionally send form contents, email addresses, or other directly identifying information to Google Analytics.

Google processes this information under its own terms. Learn more at How Google uses information from sites or apps that use its services. You can also use browser controls or Google's Analytics opt-out tools to limit this collection.


4. API Keys and Credentials

Your API keys (AI providers, Coinbase, etc.) and skill credentials (Gmail, GitHub, etc.) are stored using your operating system's secure credential storage: Windows Credential Manager on Windows, Keychain on macOS, and the supported system keyring or secure credential store on Linux. They are:

  • Encrypted by the operating system
  • Never transmitted to Bot Commander
  • Never included in any logs or error reports

5. Third-Party Services

Bot Commander can connect to third-party services through integrations and Skills. The public website also uses service providers for hosting, newsletter storage, downloads, and other functions. Each provider processes information under its own terms and privacy policy. Use optional integrations at your discretion.


6. Children's Privacy

The Software is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction) and we do not knowingly engage with such users.


7. Your Rights

You control the data stored by the desktop Software. To remove local Bot Commander data, uninstall the Software and delete the ~/.botcom/ folder.

To ask about, correct, or request deletion of information submitted through the Bot Commander website, contact legal@botcom.ai. We may need enough information to locate the relevant record and verify the request.


8. Changes to This Policy

If we make material changes to this Privacy Policy, we will note them in the Software's release notes. Continued use of the Software after changes constitutes your acceptance.


9. Contact

For privacy-related questions: legal@botcom.ai


Local-first by design. Transparent when a connected feature needs data. Your workspace remains yours.