Your information
Privacy policy
Last updated September 23, 2026
AATMA NEW YORK LLC, based in New York, United States, operates Bodhi. This policy explains how we handle information across the Bodhi website, desktop app, accounts and optional cloud service. Contact support@usebodhi.app with privacy questions.
Research on your device
Bodhi Desktop can store your sources, notes, highlights, canvases and drafts locally without an account or subscription. Creating an account alone does not upload that research. When an eligible account has cloud sync enabled, its Library transfers automatically between its connected devices.
Your local files and browser storage remain under your device’s security controls. Signing out hides the account’s Library in Bodhi; it does not erase downloaded files, exports or backups from your computer.
Information used by the service
- Accounts: your email, profile information, authentication records and sessions, used to sign you in, secure your account and recover access.
- Synced research: files, text, citations, annotations, project organization and related metadata, used to store and synchronize your Library and provide recovery.
- Billing: subscription status, customer and invoice references, discounts and storage usage, used to provide your plan and resolve billing issues. Polar handles payment details; Bodhi does not collect full card numbers.
- Support: information you send us, used to respond to your request.
- Operations: connection information, security logs and error diagnostics, used to deliver, protect and troubleshoot the service. Providers may receive your IP address and device/browser information when you connect.
Google sign-in
If you choose Google sign-in, we request basic identity information, including your name, email and profile picture, to authenticate and identify your account. This sign-in does not request access to your Gmail messages or Google Drive documents.
AI and other connected features
If you use an AI provider, prompts and the research context needed for your request are sent to the provider you select. That provider’s terms, retention and privacy policies apply. Bodhi Sync does not include AI-provider fees.
Optional local search models download from Hugging Face and then run on your device. The model download itself does not upload your research. Provider API keys are device settings and are not part of Library sync; whether they remain saved between sessions depends on your settings.
Features such as maps, online source lookup, remote previews, web search and opening external links contact the relevant services and can disclose the query, location or resource being requested. The app’s Privacy settings limit supported background lookups. They do not disable account sync or requests you make to your selected AI provider.
Service providers and disclosure
We use Convex for cloud application data and authentication infrastructure, Cloudflare for website delivery and file storage, Resend for account emails, Zoho for support email, Sentry for backend error reporting, and Polar for payments. Google participates when you choose Google sign-in. These providers process information needed for their respective services and may process it in the United States or other countries.
We configure error reporting to minimize research content and credentials. We do not sell your research or use it for targeted advertising. We may disclose information when necessary to comply with legal obligations, prevent fraud or abuse, or protect the service and its users.
Security and local storage
Cloud research uses encrypted connections and service-managed encryption at rest. It is not end-to-end encrypted: the service must be able to process data to provide sync and recovery. Access is controlled by your account and session permissions.
The account and research sites use session cookies and local browser storage for sign-in and app functionality. This product website does not set advertising cookies or load analytics scripts. Hosting providers may still record requests for delivery and security.
Retention and your choices
We retain account and research information to provide the service, recovery and support. After paid access ends, retained cloud research has a 90-day read-only recovery period. Research moved to Trash is recoverable for 30 days. Eligible cloud data may be removed after its applicable retention period; local originals and exports are not deleted by cloud retention.
Deletion from active storage may not immediately remove copies in backups. We may retain records needed for billing, fraud prevention, legal obligations and resolving disputes. Canceling a subscription and deleting an account are separate actions.
You can export research from Bodhi. To request access, correction or deletion of account information, or ask about applicable privacy rights, email support@usebodhi.app. We may need to verify that you own the account before acting. Requests concerning payment records may also involve Polar.
Changes to this policy
We will update this page when our practices change and revise the date above. Where required, we will provide additional notice of material changes.