Security

Always on. Always secure.

Your data is in safe hands.

From encryption to access control, Bolb applies rigorous standards so customer feedback stays secure, private, and compliant — whether it comes from in-store channels, staff reports, or voice uploads.

Last updated: July 2026

Built for trust

Privacy and security are part of the product — not an afterthought.

GDPR

Bolb is built for European retail. We process data under GDPR and design every feature with privacy by default.

EU infrastructure

Customer data is stored in EU-hosted cloud infrastructure through Supabase, with encryption at rest and in transit.

No model training

Your store's feedback is never used to train public AI models. Processing is limited to delivering insights back to you.

Store isolation

Each store's data is separated through database-level access controls. Users only see what their role allows.

Trusted data storage

Sensitive feedback deserves layered protection.

Customer voices often contain personal details. Bolb separates raw sensitive data from the redacted insights your team actually works with.

Encryption everywhere

All traffic uses HTTPS (TLS 1.2+). Data at rest is encrypted by our cloud provider. Sensitive fields — such as raw voice transcripts and OAuth tokens — are additionally encrypted with AES-256-GCM using dedicated secrets.

Private storage

Voice recordings are stored in private buckets with no public access. Files are retrieved only through short-lived signed URLs after authentication.

PII redaction

Before transcripts are displayed, embedded, or clustered, personal details like names, phone numbers, and email addresses are automatically masked.

Automatic deletion

Audio files are automatically deleted after 30 days. Stores can also delete recordings and associated analysis on request.

Platform security

Access is verified, limited, and logged.

Every user session is authenticated. Database policies ensure stores only access their own data.

Role-based access

Store owners, managers, and staff see different views. Access is enforced through authenticated sessions and row-level security policies in the database.

Encrypted credentials

Third-party integration tokens (such as Gmail OAuth refresh tokens) are encrypted with AES-256-GCM before being stored — never in plain text.

Support access on request

Bolb engineers do not browse customer data by default. Access for troubleshooting requires explicit customer approval.

Minimal data collection

We collect only what is needed to deliver insights: feedback content, store structure, team accounts, and operational logs.

Your data, your decisions

You maintain control over your data at all times.

Data retention

Data is kept for as long as your store uses Bolb. Retention periods can be aligned with your internal policies as we move beyond pilot.

Right to deletion

Stores can delete recordings and associated feedback. When you stop using Bolb, data is deleted or returned according to your agreement.

You stay in control

The store is the data controller for customer-facing feedback. Bolb acts as a processor, handling data only on the store's instructions.

Sub-processors

We use Supabase (hosting, database, auth, storage) and OpenAI (transcription and analysis). OpenAI API data is not used to train their models.

FAQ

Common questions about security and data handling

Questions about security?

We're happy to walk through our data handling in detail — especially during pilot onboarding.

Contact us