Privacy
What passes through BNH.
Updated 2026-09-23
BNH Labs operates BNH. This notice covers the public website, account service, and remote-computer integration. Your AI platform and sign-in providers also process information under their own policies.
Account and sign-in information
When you sign in with Google through Auth0, we receive a verified sign-in identifier and, when supplied, your email address, email-verification status, and display name. We use them to authenticate you, display your account, and maintain its identity. We store an internal account identifier, the external identity binding, account membership, and invitation-use records.
The current sign-in requests basic OpenID, profile, and email access. It does not request Gmail or Google Drive access. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements where applicable. Google sign-in data is used for the account functions described here, not advertising.
Cookies and authorization
The public site has no analytics or tracking cookies. The account service uses a necessary secure, HTTP-only session cookie and request-forgery protection. Browser sessions are temporary and held in service memory; short-lived sign-in transactions are stored on the server. Signing out ends the BNH browser session, not your Google or Auth0 session.
The browser sign-in adapter uses provider tokens to verify identity and does not retain those tokens after that exchange. Separately, the integration handles OAuth access tokens when authorizing requests; AI and identity providers may manage their own access and refresh tokens. BNH stores verifiers for its device and legacy caller credentials and session records needed to validate access.
Paired computers and work you request
We store device identifiers, public keys, names, platform and client versions, pairing and revocation records, and connection metadata. Device private identity keys stay with the device's signing backend; they are not uploaded as pairing data.
Commands, arguments, paths, operation status, results, and transferred files can pass through and be stored by the Hosted service. The paired computer also keeps local operation records and retained output. These records make routing, recovery, file transfer, and troubleshooting possible. Files or command output may contain personal information or secrets: choose what you expose to the integration.
What your AI platform receives
When you invoke the integration, ChatGPT or another configured caller receives the requested tool results, such as device information, operation status, command output, and file content. Account-linked mode can also provide an internal account identifier. The platform processes your conversation and these results under its own terms, privacy policy, and your account settings. This notice does not promise a particular retention or training policy for an independent provider.
Service providers and operational records
Google and Auth0 process sign-in information. Hosting and network providers process traffic and stored service data as needed to operate the service; the current infrastructure uses DigitalOcean and Cloudflare. The configured AI and tunnel providers participate in integration traffic. Authorized operators may access service records to support users, investigate problems, and protect the service.
Request and security records include timestamps, routes, status codes, request and operation identifiers, account/device references, and approval or revocation events. Network infrastructure can also record IP addresses and request metadata. Information may be disclosed where legally required or necessary to address abuse or protect rights. Providers may process data in countries other than your own.
Retention and deletion
Retention differs between account records, operation content, security history, local device state, logs, and backups. Cleanup of eligible Hosted operation content does not erase every related identifier, local copy, backup, or provider copy. Revoking a device or signing out is not account deletion.
The current service makes completed-operation payloads and reports eligible for cleanup after seven days and unreferenced file resources after 24 hours. These are cleanup thresholds, not a guarantee that every copy is deleted at that time. Operation identifiers and security history can remain after content cleanup. Account records, security records, and backups currently have no automatic service-wide expiry and can remain until manually removed. To request account closure or deletion of personal information, email bnhdevs@gmail.com. Requests are handled manually after identity verification; records needed to prevent abuse, preserve revocations, resolve disputes, or meet legal obligations may be retained. Deletion does not recall data already sent to your AI platform or remove copies on your own computers. Independent providers apply their own retention policies.
Security and your choices
BNH uses authenticated connections, access checks, and local authorization. No service can guarantee complete security. Account authentication does not grant arbitrary authority on your computer; the local Supervisor and chosen platform configuration still govern execution.
You can sign out, revoke paired devices, and manage the integration through your AI platform. Account deletion is not yet self-service. For support, privacy, or deletion requests, contact bnhdevs@gmail.com. We may need to verify your identity before handling a request. Do not send passwords, invitation codes, access tokens, or private keys.
Changes to this notice
We will update this page as the beta changes and identify the revision date above. Material new uses of Google data require updated disclosure and any necessary consent.