Privacy Policy - Bull AI
1. Overview
This Privacy Policy explains how Bull AI (operated by VJR Prism Analytics Private Limited) collects, uses, shares, and protects information when you access or use our website, applications, WhatsApp experiences, APIs, and related services (collectively, the "Platform").
This policy is intended to be clear and generally applicable. Your use of the Platform is also governed by our Terms and Conditions.
2. Information We Collect
Depending on how you use the Platform, we may collect information you provide and information generated through your use of the Platform.
- Account and contact details you choose to share (such as name, email address, and phone number).
- Inputs, content, and preferences you submit (such as messages, queries, settings, and feedback).
- Technical and usage information needed to operate and secure the Platform (such as device and browser details, log data, and diagnostics).
- Cookies and similar technologies used to remember preferences and support platform functionality.
- With your consent, usage analytics (for example, pages visited and features used) collected via PostHog and Google Analytics (GA4) through Google Tag Manager. This data does not include your portfolio, payment details, or AI conversation content.
- MCP connector account and OAuth details. If you connect an MCP client, we process the Bull AI account and contact details associated with that connection, together with public client registration metadata (such as client name, client URI, application type, and redirect URI), requested and approved scopes, the canonical MCP resource, consent and grant status or version, and lifecycle timestamps such as creation, last use, expiry, and revocation. We store one-way hashes of authorization code and refresh-token values for validation and lifecycle management; we do not intentionally log raw authorization codes, access tokens, refresh tokens, PKCE verifiers, client secrets, or bearer values.
- MCP tool requests and results. We process the request identifier, authorized tool and scope, bounded inputs (for example, a company identifier or document query), bounded tool results, source or citation fields when supplied, and the metering outcome needed to provide the MCP service. Do not submit broker passwords, one-time passcodes, payment-card details, or unrelated secrets to MCP tools.
- MCP usage, quota, and security diagnostics. We may process timestamps, rate-limit, quota, and credit reservation or outcome data, status and error codes, client, account, and connection identifiers, and security or performance diagnostics used to operate the service, prevent abuse, and investigate incidents.
3. How We Use Information
We use information to:
- Provide, maintain, and improve the Platform and customer support.
- Deliver AI-assisted features and generate outputs in response to your requests.
- Personalize your experience (for example, saving settings and preferences).
- Send service-related communications (including WhatsApp updates if you register a phone number and opt in).
- Monitor performance, prevent abuse, and protect the security and integrity of the Platform.
- Comply with legal obligations and enforce our terms.
- Authenticate MCP clients, obtain and record consent, enforce approved scopes, and maintain or revoke MCP connections.
- Run bounded MCP research tools and return company or document information that you request.
- Apply account entitlements, metering, quotas, credits, rate limits, and related billing controls where applicable.
- Use usage and security diagnostics to troubleshoot failures, detect abuse, and protect users and service providers.
6. Security & Retention
We use reputable cloud and infrastructure providers and implement reasonable administrative, technical, and organizational safeguards designed to protect information. This may include encryption in transit (such as TLS), encryption at rest for sensitive data, access controls (including role-based access where appropriate), and monitoring. While we take security seriously, no method of transmission or storage is 100% secure.
We retain information for as long as reasonably necessary to provide the Platform, comply with legal obligations, resolve disputes, and enforce our agreements, as permitted by law.
For MCP OAuth, authorization codes are one-use and short-lived, and access and refresh token lifetimes are configuration-controlled. Refresh tokens are bound to a resource and may be rotated; disconnecting an MCP connection at /mcp/connections revokes the consent and refresh-token family, and outstanding access tokens fail on their next use. We retain token hashes and lifecycle records rather than raw token values.
Our current operational defaults treat never-used OAuth client registrations as stale after 30 days and previously used clients as stale after 180 days since last use. A stale client is disabled first; a never-used disabled row may be deleted only after a further seven-day review window and only when it has no active consent, unexpired authorization code, refresh token, or other child record. Previously used disabled rows remain audit records until an approved security or privacy retention policy permits deletion. Expired credential records and MCP tool, metering, and diagnostic records follow separate retention criteria and may be retained longer when needed for legal, security, accounting, or dispute purposes.
7. Your Rights & Requests
Depending on your jurisdiction and applicable law, you may have certain rights relating to your personal information. We will respond to verified requests as required by applicable law. To make a request, contact us using the details below.
- You can disconnect or revoke an MCP client from the authenticated MCP Connections account surface; reconnecting requires a new authorization and consent.
- You can request account deletion through the account controls or by contacting us. The deletion workflow removes or de-identifies user-owned MCP OAuth, usage, and billing records where applicable, subject to legally required or security-retained records.
- For privacy questions, data-access or deletion requests, or concerns about MCP data handling, contact info@bull-ai.in.
8. Children’s Privacy
The Platform is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can take appropriate steps.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here.
10. Contact Us
For privacy questions or requests, contact us at info@bull-ai.in.
Related: Terms and Conditions · Disclaimer