Boop — Privacy Policy
Last updated: 20 August 2026
Core Software Solutions Group Limited (“we,” “our,” and/or “us”) values the privacy of the people who use Boop, our mobile application, together with our website and related services (collectively, our “Services“). “Boop“ means the automated companion made available through the Services. This Privacy Policy explains how we collect, use, and disclose personal information from users of our Services (“you” or “your”). As used here, “personal information” means any information relating to an identified or identifiable individual. Where applicable, we indicate whether you must provide us with particular personal information and the consequences of not doing so; where information is optional, declining to provide it means the features that depend on it will not be available to you.
By using our Services, you agree to the collection, use, disclosure, and procedures described in this Privacy Policy. Your use of our Services is also subject to our Terms of Service.
Personal Information We Collect
A. Personal information you provide to us
Account creation. When you create an account we collect your email address and, if you set one, a password. If you sign in with Apple or Google, we receive the identifier and email address they release to us.
Setup and profile. When you set up your account and complete your profile, we collect the information you choose to provide about yourself, your circumstances and your objectives. Depending on what you choose to provide, this may include information concerning your health or wellbeing, which is addressed in Section C below.
Your interactions with the Services. When you interact with Boop we may receive text, image and audio information from that interaction, together with your telephone number if you choose to provide one. The Services allow you to submit this text, image and audio information and other materials to the Services (“Prompts“), which generate responses based on your Prompts (“Outputs“). If you include personal information in your Prompts, we will collect that information, and it may be reproduced in the Outputs. In respect of voice and video interactions, we retain a text record of the interaction. We do not retain recordings of your audio or video.
Content you create within the Services. Written entries, records, lists and other material you choose to create or store using the Services, including any health or fitness information you record.
Communications. If you contact us for support or to report a problem, we may receive your email address, the contents of your message, and anything you attach.
Payment information. Subscriptions are purchased through the Apple App Store or Google Play, and those stores collect payment information under their own policies. We do not receive your card details. We receive only whether your subscription is active and when it expires.
B. Personal information we collect when you use our Services
Information from your device, with your permission. With your permission, the Services may access health and fitness data held on your device, your calendar, your microphone and camera, images you choose to provide, and your location at the time you choose to record it. Each of these permissions is optional and may be withdrawn at any time in your device settings. We do not track your location in the background. Where the Services use biometric authentication to lock content on your device, we receive only confirmation of the result and never receive biometric data.
Device information. We receive information about the device and software you use to access our Services, including IP address, operating system version, device identifiers, application version, and push notification tokens.
Usage information. To help us understand how you use our Services and to improve them, we automatically receive information about your interactions with the Services and the dates and times of your use. Our analytics record actions taken within the Services and do not include the content of your messages or of any other material you have created.
C. Sensitive information
Some of the information above concerns your physical or mental health and is treated as sensitive information under applicable law. We process such information on the basis of your explicit consent, which you provide by electing to connect a health application, to answer questions concerning your wellbeing, or to disclose such information to the Services. You may withdraw that consent at any time by disconnecting the relevant integration, deleting the content, or deleting your account, following which features dependent upon that information will cease to operate. If it appears that you or another person may be in immediate danger, we may process what is necessary to respond.
Health and fitness data obtained from your device is used only to provide the features you have enabled. It is never used for advertising, marketing or data mining, and is never sold or shared for those purposes.
How We Use the Personal Information We Collect
We use the personal information we collect:
To provide, maintain, improve, secure and enhance our Services;
To generate Boop’s responses, and to personalise your experience of the Services, including by remembering information about you and tailoring what Boop says and shows you;
To send you push notifications, messages and calls you have enabled;
To understand and analyse how you use our Services and to develop new features;
To communicate with you, respond to your requests, and provide support;
To facilitate transactions and manage subscriptions;
To detect indications that you or another person may be at risk of harm, and to respond;
To generate de-identified or aggregated data, which we may use for any lawful purpose;
To find and prevent fraud and abuse, and to respond to trust and safety issues;
For compliance purposes, including enforcing our Terms of Service or other legal rights, or as required by applicable law or requested by any judicial process or governmental agency; and
For other purposes for which we provide specific notice at the time of collection.
A limited number of authorised staff may access the content of interactions with Boop where needed for safety, to answer a support request, or to diagnose a fault.
We do not sell your personal information, we do not share it with advertisers or data brokers, we do not use it for targeted advertising, and we do not use your content to train artificial intelligence models. The providers who process content on our behalf are contractually prohibited from using it to train their models.
Legal Bases for Processing European and UK Personal Information
If you are located in the European Economic Area, Switzerland, or the United Kingdom, we process your personal information only where we have a valid legal basis:
Consent. Where you have consented to the processing — including your explicit consent for information concerning your health, and your consent to receive text messages or scheduled calls. You may withdraw consent at any time, free of charge, without affecting the lawfulness of processing before withdrawal.
Contractual necessity. Where processing is required to enter into or perform our contract with you — for example, to provide the Services and respond to your requests.
Compliance with a legal obligation. Where we are required to process your personal information by law.
Legitimate interests. Where we or a third party have a legitimate interest — specifically in product development, internal analytics, safety, and improving the security and performance of the Services. We rely on this only where those interests are not overridden by your rights.
Vital interests. Where processing is necessary to protect someone’s life.
How We Disclose the Personal Information We Collect
Vendors and service providers. We may disclose information we receive to vendors and service providers retained in connection with the provision of our Services, such as IT, security, hosting, communications, and payment service providers.
AI service providers. We may disclose information we receive to vendors that provide artificial intelligence services that provide backend support for our Services.
Analytics providers. We use analytics and diagnostics services to collect and process usage and error data.
Partners and affiliates. We may disclose information we receive to our corporate affiliates, parents, or subsidiaries for any purpose described in this Privacy Policy.
As required by law and similar disclosures. We may access, preserve, and disclose your personal information if we believe doing so is required or appropriate to: (a) comply with law enforcement requests and legal process, such as a court order or subpoena; (b) respond to your requests; or (c) protect your, our, or others’ rights, property, or safety.
Merger, sale, or other asset transfers. We may transfer or disclose your personal information to service providers, advisers, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company, or in which we sell, liquidate, or transfer all or a portion of our assets. Use of your information following any such event will be governed by the provisions of this Privacy Policy in effect at the time the information was collected.
Consent. We may also disclose your information with your permission.
Our service providers act on our instructions under written contracts and are required to protect your personal information to the standard set out in this Privacy Policy.
Your Choices
Your European and UK privacy rights. If you are located in the European Economic Area, Switzerland, or the United Kingdom, you may request access to the personal information we maintain about you, update and correct inaccuracies, restrict or object to our processing, have your personal information deleted, or exercise your right to data portability. You may withdraw any consent you previously provided at any time and free of charge. You also have the right to lodge a complaint with a supervisory authority, including in your country of residence or place of work — in the United Kingdom, the Information Commissioner’s Office (ico.org.uk).
Your United States privacy rights. Depending on your state, you may have the right to know, access, correct, delete and port your personal information, to opt out of the sale or sharing of personal information and of certain profiling, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We use sensitive personal information only to provide the Services you requested, to keep them secure, and to comply with law. Where state consumer health data laws apply, including in Washington, Nevada and Connecticut, we process consumer health data only with your consent and do not sell it. Boop is not a HIPAA covered entity, and this Privacy Policy — not HIPAA — governs the health information you give us.
Device settings. You may withdraw any device permission, and disable notifications, at any time through your device settings. Text messages and scheduled calls may be disabled within the application.
Exercising your rights. You may exercise these rights using the controls in the app, or by contacting us using the details at the end of this Privacy Policy. Before fulfilling a request we may ask you to provide reasonable information to verify your identity. Please note that there are exceptions and limitations to each of these rights, and that we may retain personal information for backups, prevention of fraud and abuse, satisfaction of legal obligations, or where we otherwise reasonably believe we have a legitimate reason to do so.
Retention and Deleting Your Information
We retain personal information for as long as your account exists and for as long as necessary for the purposes described in this Privacy Policy, and we keep records for as long as the law requires.
You may delete your account, and the information associated with it, from within the application. Deletion is permanent. Following deletion of your account, we will erase your personal information from our live systems within 30 days; backups are overwritten in accordance with their own cycle. We may retain information that can no longer identify you.
Children
Our Services are not directed to children under the age of 13, and we do not knowingly collect personal information from them. If we learn that we have collected personal information from a child under 13 without the consent required by law, we will delete it.
If you are under 18, you may use our Services only if a parent or legal guardian has agreed to our Terms of Service on your behalf and supervises your use of them. Boop is an AI companion and may not be suitable for some minors. We recommend parental involvement for users under 18.
Third Parties
Our Services may contain links to other websites, products, or services that we do not own or operate. We are not responsible for the privacy practices of these third parties. This Privacy Policy does not apply to your activities on those services or to any information you disclose to them.
Security
We make reasonable efforts to protect your personal information using technical, organisational and physical safeguards designed to improve the security of the personal information we maintain, including encryption and restricting internal access. However, as no electronic transmission or storage of information can be entirely secure, we can make no guarantees as to the security or privacy of your personal information.
International Transfers
We are based in the United Kingdom. We and our service providers may process personal information in the United Kingdom, the European Economic Area, the United States and other countries, and where we host data may change over time. Where personal information is transferred out of the United Kingdom or the European Economic Area to a country without an adequacy decision, we rely on the UK International Data Transfer Agreement or Addendum, or European Commission-approved Standard Contractual Clauses, or otherwise transfer in accordance with applicable data protection law. To obtain a copy of the safeguards we use, you can contact us as described below.
Changes to This Privacy Policy
We will post any adjustments to this Privacy Policy on this page, and the revised version will be effective when it is posted. If we materially change the ways in which we use or disclose personal information previously collected from you, we will notify you through our Services, by email, or by other communication.
Contact Information
Core Software Solutions Group Limited, a company registered in England and Wales, is responsible and is the data controller for the processing of your personal information. If you have any questions, comments, or concerns about our processing activities, please email us at admin@heyboop.ai. Our registered office address is available on our website and on the Companies House register.