Privacy Policy

Last updated: 9 October 2026

Effective date: 9 October 2026

1. Who we are

This Privacy Policy explains how Bedrock Flow, Inc., a Delaware corporation doing business as TypeOrb ("Bedrock Flow", "we", "us"), with its address at 9450 Southwest Gemini Drive, PMB 54889, Beaverton, OR 97008, USA, collects and uses personal data when you visit typeorb.com, sign up for or use the TypeOrb service at app.typeorb.com (the "Service"), or communicate with us.

For privacy questions or requests, contact contact@typeorb.com or write to the address above.

Bedrock Flow, Inc. is the controller of the personal data described in Section 3 below.

1.1 EU representative (Article 27 GDPR)

Bedrock Flow, Inc. is established in the United States. Because we offer the Service to businesses in the European Union, we have appointed the following company as our representative in the EU under Article 27 GDPR:

FOCUS ON TARGET sp. z o.o.

ul. Gospodarcza 26, 20-213 Lublin, Poland

KRS 0001169404, NIP 9462753052, REGON 541544296

Email: eu-rep@typeorb.com

You may contact our EU representative, instead of or in addition to us, about any matter relating to our processing of your personal data. Supervisory authorities may also contact the representative. The representative forwards requests to us and does not decide how your data is processed.

1.2 United Kingdom

The Service is offered only to businesses in the United States and in the European Union and the wider European Economic Area. It is not offered to customers in, and our website and Service are not directed at, the United Kingdom.

1.3 Data protection officer

We have not appointed a data protection officer because we are not required to do so under Article 37 GDPR. Privacy questions can be sent to contact@typeorb.com.

2. Our role: controller and processor

Controller. We are the controller of personal data we collect for our own purposes: data about website visitors, people who sign up or contact us, account holders and their users (account, billing, and usage data), and sales contacts.

Processor. When our business customers upload or connect material to the Service, such as documents, call recordings and transcripts, writing samples, employee profiles, and the content generated from them ("Customer Content"), we process any personal data in it on behalf of that customer, under our Data Processing Addendum. The customer is the controller. If your personal data is in Customer Content (for example, you are an employee whose voice profile was set up by your employer, or you took part in a recorded customer call), please contact that organization to exercise your rights. We will help them respond.

3. Personal data we collect, purposes, and legal bases

DataPurposeLegal basis (GDPR)
Account data: name, work email, company, role, password hash or sign-in identifiers from Google, Microsoft, or LinkedInCreate and manage your account, authenticate you, provide the ServiceContract (Art. 6(1)(b)); for users added by their employer, our and the customer's legitimate interest in providing the Service (Art. 6(1)(f))
Billing data: billing contact, company billing address and country, VAT/tax ID, plan (monthly or annual) and Seat count, payment status. Card details are collected by our payment processor, Stripe, not by usCharge fees, calculate and collect taxes, issue invoices, process refunds, check that we offer the Service in your country, prevent fraud, meet tax and accounting rulesContract; legal obligation (Art. 6(1)(c)) for tax and accounting records
Profile data you choose to add, including public professional profile information (for example a LinkedIn profile summary used to set up a voice profile)Personalize the Service and set up voice profilesContract; legitimate interests
Usage and device data: pages and features used, clicks, session identifiers, IP address, approximate location derived from IP, browser and device type, referrer, error logs and server logsOperate, secure, debug, and improve the Service and website; measure product useLegitimate interests; consent for non-essential cookies and similar technologies (see Section 6)
Communications: emails, support requests, refund requests, call notes, survey responses, and support chat messages (with your user ID, email address, and name, and any attachments you send)Answer questions, provide support, handle refunds, improve the ServiceContract; legitimate interests
Sales data: business contact details of people at US companies, company information, interactions with our emails and website, information from public sources and business data providersContact prospects at US businesses, manage our CRMLegitimate interests (B2B outreach to US businesses). You can opt out at any time
Legal and security records: Terms acceptance logs (user, timestamp, IP address, document version), cookie consent records, records of requests and complaints, abuse reportsProve acceptance and consent, enforce our Terms, defend legal claimsLegitimate interests; legal obligation

Where we rely on legitimate interests, our interests are running a secure and useful B2B service, understanding how it is used, and growing our business. You can ask us for more information about the balancing test. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

Marketing. Our sales outreach is limited to business contacts at companies in the United States. Every marketing email identifies us, includes our postal address, and has a working unsubscribe link, as required by the US CAN-SPAM Act, and we honor opt-outs promptly. We do not send unsolicited marketing emails to contacts in the European Union or EEA; we will only send them marketing where they have consented or another lawful basis under applicable e-marketing law applies. Account holders receive service and transactional emails needed to run the Service.

4. AI processing

The Service uses large language models and other AI models from third-party providers to research, plan, draft, and evaluate content. The Service writes the prompts sent to these models: each prompt combines our own instructions with relevant Customer Content, including some of the inputs you and your users provide. The prompt is sent to the model provider to generate a response. We:

  • choose the model we consider best for each task; customers do not choose models. We access models through OpenRouter, an AI routing service based in the United States;
  • use models developed by OpenAI, Google, Anthropic, xAI, and Mistral, and models developed by China-based companies (DeepSeek, Moonshot AI, MiniMax, and Z.ai). Models developed by China-based companies are run for us only by inference providers located in the United States, under those providers' own terms. Customer Content is processed only in the United States;
  • do not use Customer Content to train or fine-tune AI models, ours or anyone else's, and have opted out of model training with OpenRouter and the model providers, so that requests are routed only to providers that do not train on the data we send;
  • note that model providers may retain prompts and outputs for a limited period for abuse and safety monitoring under their own terms, after which they delete them; we do not promise that providers keep no copy;
  • do not send AI prompts or outputs to our product analytics tool (PostHog). Our observability system (SigNoz, which we run on Railway's cloud platform) receives technical logs and traces that can contain prompts, including some user inputs, which we use to monitor and debug the Service and keep for 30 days; and
  • do not use AI to make decisions about individuals that have legal or similarly significant effects.

Some features search the public web and may retrieve publicly available information, which can include information about people (for example, authors of articles). We use it only to support content you request. The providers that may process your data are listed on our subprocessor page at typeorb.com/subprocessors, and the list is also available on request at contact@typeorb.com.

5. Who we share personal data with

We do not sell personal data. We share it only with:

  • Service providers (processors/subprocessors) that host, store, analyze, monitor, email, bill, and power AI features for us, under contracts that limit their use of the data: hosting (Fly.io, United States); vector database (Turso, United States); job queues (Upstash Redis, United States); file storage (Backblaze B2, United States); AI routing and models (OpenRouter and the model providers in Section 4, United States); image and media models (Replicate, United States); web research (Apify, Czech Republic; does not process Customer Content); profile enrichment at onboarding (Clay, United States); product analytics (PostHog, United States; no AI prompts); error monitoring (Sentry, United States); logs and traces (SigNoz, self-hosted on Railway, United States); transactional email (Resend, United States); CRM for sales prospects (HubSpot, EU data centre); email and documents (Google Workspace, United States); and customer support chat for signed-in users (Chatwoot, our support chat software, which we host ourselves on Railway in the United States; loaded only after you open the chat widget; it receives your user ID, email address, name, and the messages and attachments you send).
  • Stripe, our payment processor, which processes payment and billing data for us. Stripe acts as an independent controller for some processing, such as fraud prevention and meeting its own legal obligations, under its own privacy policy.
  • Integrations you connect, such as LinkedIn, when you ask us to publish or retrieve content.
  • Professional advisers such as lawyers, accountants, and auditors.
  • Authorities where the law requires it, or to protect rights, safety, and security.
  • Our EU representative, to the extent needed to handle requests sent to it.
  • A buyer or successor in a merger, acquisition, or sale of assets, subject to this Policy.

Our current list of subprocessors, with their location, purpose, and whether they may process Customer Content, is at typeorb.com/subprocessors.

6. Cookies and analytics

Our website and app use cookies and similar technologies such as browser local storage. Strictly necessary ones (for example, to keep you signed in, secure your session, and remember your cookie choice), and functional ones that remember settings you choose (such as theme, language, and your last sign-in method), are set without consent. The support chat in the app is loaded only after you open it. Checkout and the billing portal are hosted by Stripe on its own pages, and Stripe sets no cookies on our domains. When you first visit, a cookie banner lets you Accept or Reject non-essential cookies with equally prominent buttons, or choose by category. Non-essential technologies, including PostHog product analytics, are used only after you click Accept. Before you make a choice, and if you reject, PostHog is not loaded at all: it sets no cookies, stores nothing in local or session storage, sends no events, and creates no session ID. In the app, Sentry session replay, which records how a page was used with text and inputs masked, runs only after you accept. Sentry error reporting, without session replay and without personal data, runs on the basis of our legitimate interest in keeping the Service working. We treat a Global Privacy Control signal from your browser as a rejection of non-essential cookies. We remember your choice for about 6 months and keep an anonymous record of it (time, choice, and banner version). You can change or withdraw your choice at any time through in the website footer or in the app. Details are in our Cookie Notice at typeorb.com/cookies.

We host our website fonts ourselves, so loading them does not send your IP address to Google.

We do not use advertising cookies or cross-site tracking pixels.

7. International transfers

Bedrock Flow, Inc. is based in the United States, so personal data we collect from people in the European Economic Area (EEA) is transferred to us in the US. Our hosting is in the United States (Fly.io regions iad, Virginia, and lax, Los Angeles), and some service providers process data in other countries, as shown on our subprocessor page. AI processing for the Service, including the processing of prompts that contain Customer Content, takes place in the United States: we use OpenRouter's US endpoint, and requests are routed only to model providers in the United States. This means that Customer Content of customers in the European Union leaves the EU and is processed in the United States.

Bedrock Flow, Inc. is not certified under the EU-U.S. Data Privacy Framework. For personal data in Customer Content, including Customer Content of EU customers that is processed by us and our AI providers in the United States, transfers are made under the European Commission's Standard Contractual Clauses incorporated into our Data Processing Addendum at typeorb.com/dpa. For onward transfers to our service providers outside the EEA, we use Standard Contractual Clauses or other transfer mechanisms recognized under Chapter V GDPR, such as an adequacy decision that covers the recipient, together with additional safeguards where needed. When we collect personal data directly from you, for example when you visit our website or use your account, we do so as a controller that is itself subject to the GDPR under Article 3(2) GDPR. This direct collection is not a transfer by an exporter in the EU, so Standard Contractual Clauses do not apply to it; instead, we protect that data under the GDPR and apply the safeguards described in this Policy wherever we process it. The Standard Contractual Clauses in our Data Processing Addendum govern the Customer Content we process on behalf of customers in the EU. Customer Content is processed only in the United States. You can request a copy of the relevant safeguards at contact@typeorb.com.

8. How long we keep data

  • Account data and Customer Content: for as long as the account is active, then deleted from active systems within 30 days after the subscription is cancelled or terminated or after we issue a refund (or earlier at the customer's request, under our DPA).
  • Backups: purged within 90 days after deletion from active systems.
  • Product analytics data (PostHog): 12 months, then deleted or aggregated.
  • Server logs, observability logs and traces (SigNoz), and error monitoring data (Sentry): 30 days.
  • Billing, invoice, and tax records: as long as the law requires (for example, 7 years in the United States, and the period set by local rules for EU tax records).
  • CRM data about sales prospects: while it remains relevant to our business, and deleted earlier if you ask us.
  • Support communications: 3 years after the request is closed.
  • Terms acceptance records, consent records, and other legal records: for the duration of the contract plus the applicable limitation period.

9. Your rights under GDPR

If the GDPR applies to you, you have the right to: access your personal data; correct it; delete it; restrict its processing; receive it in a portable format; object to processing based on legitimate interests, including profiling; object at any time to direct marketing; and withdraw consent at any time, without affecting earlier processing. To exercise your rights, email contact@typeorb.com. We will respond within one month, which may be extended by two months for complex requests. We may need to verify your identity.

You have the right to lodge a complaint with your local data protection supervisory authority, in particular in the EU or EEA country where you live or work or where the alleged infringement took place. A list of EU authorities is available at edpb.europa.eu. You can also contact our EU representative (Section 1.1). We would appreciate the chance to address your concern first.

10. US state privacy rights (including California)

This section applies to residents of California and other US states with comprehensive privacy laws, to the extent those laws apply to us.

Categories collected in the last 12 months (CCPA categories): identifiers (name, email, IP address, account IDs); customer records (billing contact and address); commercial information (subscription and purchase history); internet or other electronic network activity (usage and device data); geolocation (approximate, from IP); professional or employment information (company, job title, public professional profile); audio or electronic information (call recordings and transcripts uploaded as Customer Content, processed as a service provider); and inferences (product usage patterns). We do not collect sensitive personal information for the purpose of inferring characteristics, other than account login credentials used to access your account.

Sources: you, your employer or organization, your devices, integrations you connect, public sources, and business data providers.

Purposes: the business and commercial purposes described in Section 3.

Disclosure: we disclose each category to the service providers and contractors described in Section 5 for business purposes. We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the last 12 months. We do not knowingly sell or share personal information of consumers under 16.

Retention: see Section 8.

Your rights: to know what personal information we collect, use, and disclose; to access and receive a copy; to delete; to correct; to opt out of sale or sharing (not applicable, as we do neither); to limit use of sensitive personal information (not applicable, as we do not use it for those purposes); and not to be discriminated against for exercising these rights. You can make a request by emailing contact@typeorb.com. We will verify your identity by matching information you provide with our records. You may use an authorized agent, who must show your written permission. We honor Global Privacy Control signals as an opt-out of sale and sharing for the browser that sends them, and as a rejection of non-essential cookies.

If your personal information is in Customer Content, we act as a service provider to our customer and will refer your request to them.

11. Security

We use technical and organizational measures to protect personal data, including encryption in transit (HTTPS), access controls, separation of development and production environments, and data processing agreements with our service providers. No system is completely secure. If you believe your account has been compromised, contact contact@typeorb.com.

12. Children

The Service is for businesses and is not directed to children. Users must be at least 18. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this Policy

We may update this Policy. We will post the new version with a new "Last updated" date and, for material changes, notify account holders by email or in the Service before the change takes effect.

14. Contact

Bedrock Flow, Inc. (d/b/a TypeOrb), 9450 Southwest Gemini Drive, PMB 54889, Beaverton, OR 97008, USA. Email (privacy, security, and all other questions): contact@typeorb.com. EU representative: FOCUS ON TARGET sp. z o.o., ul. Gospodarcza 26, 20-213 Lublin, Poland, eu-rep@typeorb.com.