Skip to main content
Bull AI LogoBull AI

Privacy Policy - Bull AI

1. Overview

This Privacy Policy explains how Bull AI (operated by VJR Prism Analytics Private Limited) collects, uses, shares, and protects information when you access or use our website, applications, WhatsApp experiences, APIs, and related services (collectively, the "Platform").

This policy is intended to be clear and generally applicable. Your use of the Platform is also governed by our Terms and Conditions.

2. Information We Collect

Depending on how you use the Platform, we may collect information you provide and information generated through your use of the Platform.

  • Account and contact details you choose to share (such as name, email address, and phone number).
  • Inputs, content, and preferences you submit (such as messages, queries, settings, and feedback).
  • Technical and usage information needed to operate and secure the Platform (such as device and browser details, log data, and diagnostics).
  • Cookies and similar technologies used to remember preferences and support platform functionality.
  • With your consent, usage analytics (for example, pages visited and features used) collected via PostHog and Google Analytics (GA4) through Google Tag Manager. This data does not include your portfolio, payment details, or AI conversation content.
  • MCP connector account and OAuth details. If you connect an MCP client, we process the Bull AI account and contact details associated with that connection, together with public client registration metadata (such as client name, client URI, application type, and redirect URI), requested and approved scopes, the canonical MCP resource, consent and grant status or version, and lifecycle timestamps such as creation, last use, expiry, and revocation. We store one-way hashes of authorization code and refresh-token values for validation and lifecycle management; we do not intentionally log raw authorization codes, access tokens, refresh tokens, PKCE verifiers, client secrets, or bearer values.
  • MCP tool requests and results. We process the request identifier, authorized tool and scope, bounded inputs (for example, a company identifier or document query), bounded tool results, source or citation fields when supplied, and the metering outcome needed to provide the MCP service. Do not submit broker passwords, one-time passcodes, payment-card details, or unrelated secrets to MCP tools.
  • MCP usage, quota, and security diagnostics. We may process timestamps, rate-limit, quota, and credit reservation or outcome data, status and error codes, client, account, and connection identifiers, and security or performance diagnostics used to operate the service, prevent abuse, and investigate incidents.

3. How We Use Information

We use information to:

  • Provide, maintain, and improve the Platform and customer support.
  • Deliver AI-assisted features and generate outputs in response to your requests.
  • Personalize your experience (for example, saving settings and preferences).
  • Send service-related communications (including WhatsApp updates if you register a phone number and opt in).
  • Monitor performance, prevent abuse, and protect the security and integrity of the Platform.
  • Comply with legal obligations and enforce our terms.
  • Authenticate MCP clients, obtain and record consent, enforce approved scopes, and maintain or revoke MCP connections.
  • Run bounded MCP research tools and return company or document information that you request.
  • Apply account entitlements, metering, quotas, credits, rate limits, and related billing controls where applicable.
  • Use usage and security diagnostics to troubleshoot failures, detect abuse, and protect users and service providers.

4. How We Share Information

We may share information in the following circumstances:

  • With trusted service providers that help us operate, secure, and support the Platform.
  • With partners you choose to connect with or where you provide consent.
  • To comply with law, respond to lawful requests, or protect rights, safety, and security.
  • In connection with a corporate transaction (such as a merger, acquisition, or asset sale).
  • With an MCP client or connected application that you authorize, limited by the approved OAuth scopes and the data returned for its requests.
  • With processors and infrastructure providers for identity and authentication, databases and cloud hosting, security and monitoring, customer support, analytics where you consent, and payment processing (including Razorpay where applicable).

We require service providers to handle information in a manner consistent with this policy and applicable contractual and legal obligations. We may also share aggregated or de-identified information that cannot reasonably be used to identify you.

5. Cookies & Choices

We use cookies and similar technologies on the Platform. Some are necessary for the Platform to function; others are optional and only enabled with your consent.

  • Necessary cookies. Authentication and session cookies (provided by Supabase) that keep you signed in and protect your account. These are always active.
  • Analytics (opt-in). Product analytics powered by PostHog and Google Analytics (GA4) through Google Tag Manager help us understand how the Platform is used — for example, which pages are visited and which features are popular. Analytics data does not include your AI prompts, portfolio holdings, or payment details.
  • Marketing & advertising (separate opt-in). With your additional consent, we use Google Tag Manager to support marketing measurement (such as conversion tracking). This may involve processing by Google LLC, including in the United States.
  • Session replay (separate opt-in). With your additional consent, PostHog may record screen interactions to help us identify usability issues. All text and form inputs are masked by default.

You can manage your analytics, marketing, and replay preferences from the consent banner or your Account settings. Withdrawing consent is as simple as granting it.

When you use AI features, your prompts are sent to third-party AI providers to generate responses. These providers do not receive your analytics data. Billing is processed by Razorpay.

6. Security & Retention

We use reputable cloud and infrastructure providers and implement reasonable administrative, technical, and organizational safeguards designed to protect information. This may include encryption in transit (such as TLS), encryption at rest for sensitive data, access controls (including role-based access where appropriate), and monitoring. While we take security seriously, no method of transmission or storage is 100% secure.

We retain information for as long as reasonably necessary to provide the Platform, comply with legal obligations, resolve disputes, and enforce our agreements, as permitted by law.

For MCP OAuth, authorization codes are one-use and short-lived, and access and refresh token lifetimes are configuration-controlled. Refresh tokens are bound to a resource and may be rotated; disconnecting an MCP connection at /mcp/connections revokes the consent and refresh-token family, and outstanding access tokens fail on their next use. We retain token hashes and lifecycle records rather than raw token values.

Our current operational defaults treat never-used OAuth client registrations as stale after 30 days and previously used clients as stale after 180 days since last use. A stale client is disabled first; a never-used disabled row may be deleted only after a further seven-day review window and only when it has no active consent, unexpired authorization code, refresh token, or other child record. Previously used disabled rows remain audit records until an approved security or privacy retention policy permits deletion. Expired credential records and MCP tool, metering, and diagnostic records follow separate retention criteria and may be retained longer when needed for legal, security, accounting, or dispute purposes.

7. Your Rights & Requests

Depending on your jurisdiction and applicable law, you may have certain rights relating to your personal information. We will respond to verified requests as required by applicable law. To make a request, contact us using the details below.

  • You can disconnect or revoke an MCP client from the authenticated MCP Connections account surface; reconnecting requires a new authorization and consent.
  • You can request account deletion through the account controls or by contacting us. The deletion workflow removes or de-identifies user-owned MCP OAuth, usage, and billing records where applicable, subject to legally required or security-retained records.
  • For privacy questions, data-access or deletion requests, or concerns about MCP data handling, contact info@bull-ai.in.

8. Children’s Privacy

The Platform is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can take appropriate steps.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here.

10. Contact Us

For privacy questions or requests, contact us at info@bull-ai.in.