Good Bones Web Privacy Policy
Good Bones Web (“Good Bones,” “we,” “us,” or “our”) provides small-business websites, business-specific AI assistants, and related technology services.
Information we may collect
Depending on the service, we may collect business/contact information, onboarding responses, project or prospect information, assistant chat history, explicit saved memory, uploaded photos/files, support communications, security/service metadata, and billing/transaction records when paid service is enabled.
The current public website contact form opens the visitor’s own email application. It does not silently submit the typed inquiry to a Good Bones database before the visitor sends the email.
Why we use information
We use information to provide and customize the requested service, preserve authorized business/project continuity, operate onboarding and support, secure/troubleshoot the service, maintain business/legal/accounting records, and comply with law or our agreements.
AI processing
The standard Good Bones Business Assistant is designed to perform core AI inference on Good Bones-controlled infrastructure using locally operated models and software. Standard V1 assistant prompts, saved memory, and uploaded job photos are not intentionally sent to a third-party hosted model API for inference.
Good Bones does not use customer content to train or fine-tune a general-purpose model for other customers unless the customer separately gives written authorization.
If a future architecture change materially changes where customer content is processed, we will update the applicable notices and contract records before using that arrangement where required.
Service providers
Operational providers can include Cloudflare for website/onboarding infrastructure, Google/Gmail for email delivery, and private-networking providers. Current model/software notices appear in our Third-Party Technology & Model Notices.
A payment processor has not yet been selected for this policy version. Before live payment processing is enabled, the processor must be added to the provider/subprocessor register and relevant notices. Good Bones does not intend to store full payment-card numbers or card security codes itself.
Sale and advertising
Good Bones does not sell customer personal information and does not use customer-assistant content for third-party behavioral advertising.
The current public website does not intentionally deploy third-party behavioral-advertising trackers. Hosting/security providers can process ordinary connection metadata needed to deliver and protect the site.
Retention
We retain information only for legitimate service, security, accounting, legal, or customer-requested purposes.
- Ordinary uploaded assistant media that is not explicitly remembered is normally eligible for automated pruning after approximately 30 days.
- Photos or references explicitly saved to a project/memory can be retained longer.
- Explicit saved memory can remain for business continuity until deleted/forgotten, no longer needed, or account closure cleanup.
- Conversation history can remain while an account is active and reasonably needed for continuity, support, security, or dispute resolution.
- Legal, billing, tax, security, and contract records can be kept for lawful business/recordkeeping periods.
Verified deletion requests are handled subject to legal, security, backup, accounting, and dispute-preservation needs.
Security
We use safeguards appropriate to the service, including customer/tenant separation, access controls, restricted administrative access, backups/checkpoints, and incident-response procedures. No system can be guaranteed perfectly secure.
Customers are responsible for protecting access credentials and avoiding unnecessary submission of highly sensitive data.
Sensitive and regulated data
Unless a separate written agreement specifically authorizes it, do not submit:
- HIPAA-regulated protected health information;
- Social Security numbers or government-identification credentials;
- full payment-card/bank credentials;
- passwords, private keys, authentication secrets, or access tokens;
- biometric identifiers used for identification;
- information obtained without required rights, notice, or consent; or
- data for prohibited automated high-impact decision-making.
The standard V1 service is not represented as HIPAA-ready.
Customer responsibilities
Customers are responsible for ensuring they have the legal right and any required notice/consent to provide customer/prospect records, business information, images, and files to Good Bones.
Privacy requests
You may request reasonable access, correction, export, or deletion, subject to identity/authority verification and lawful retention requirements.
Email: goodbonesweb@gmail.com
Suggested subject: Privacy Request — Good Bones Web
Children
Good Bones services are intended for business users age 18 or older and are not directed to children under 13. Do not create child accounts or knowingly submit under-13 personal information.
Contact
Good Bones Web
goodbonesweb@gmail.com
The exact legal contracting person/entity is identified in the applicable customer Order Form and Master Service Agreement.