Privacy Policy
Last updated: August 2, 2026
This policy describes how BouttheB Technologies (“Praxia,” “we,” “us”) handles your information when you use trypraxia.com, the hosted Praxia Cloud service at app.trypraxia.com, and the Praxia mobile app. The short version: we collect what the product needs to run your operations, we don’t sell it, and you can ask us to delete it.
What we collect
- Account information. Your email address, display name, and organization details when you create an account.
- Operational data. The projects, commands, schedules, and results you create in Praxia — this is the substance of the service, and it belongs to you.
- Connected Google data. If you connect a Google account, Praxia receives only the data covered by the permissions you approve: Gmail messages and thread metadata; calendars, events, and attendees; and Google Drive file metadata and supported content from Docs, Sheets, and text files. Each connection stays tied to the exact Google identity that authorized it.
- Device data for notifications. If you enable push notifications, we store a device token so we can deliver them. You can revoke it any time from settings.
- Payment information. Handled entirely by Stripe; we never see or store card numbers.
- Basic usage data. Session cookies to keep you signed in and server logs for reliability and abuse prevention. We do not run advertising trackers.
Google Workspace connections
Connecting Gmail, Google Calendar, or Google Drive is optional and initiated by you. Praxia uses the resulting Google API data only to provide the connected features you see and control in the product:
- Gmail. Read access lets Praxia index, search, summarize, and reconstruct email threads across the mailboxes you connect. Send access is used only for a reply you review and explicitly approve, from the Google account shown before sending.
- Google Calendar. Praxia reads calendars and events to show your schedule and identify conflicts. It creates, updates, or deletes an event only in the account and calendar named in the action; consequential changes require confirmation.
- Google Drive, Docs, and Sheets. Read-only access lets Praxia find and index supported files so you can search and use them as context. Praxia does not modify or delete Drive files through this connection.
OAuth access and refresh tokens are encrypted at rest. Indexed message bodies, supported file text, and Praxia email drafts are also encrypted at rest and isolated by organization. Dashboard access to connected Google data is limited to workspace owners and administrators. Praxia does not use Google user data for advertising, sell it, use it to build marketing profiles, or use it to train general-purpose or shared AI models. When you explicitly request an AI-assisted summary or draft, only the content needed for that user-facing request is sent to the AI processor that performs it.
Disconnecting a Google account immediately removes Praxia’s stored authorization and stops future access. Previously indexed copies remain available to the workspace so its operational history does not vanish unexpectedly; you can request deletion of that indexed data or your entire organization at any time, and we complete deletion requests within 30 days. You can also revoke access directly from your Google account permissions.
Praxia’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
YouTube connections
Praxia publishes on your behalf to platforms you connect yourself. Those connections are the only way we reach your accounts, and they only ever do what the capability you enabled needs.
Praxia’s YouTube publishing uses YouTube API Services. By connecting a channel you are also agreeing to the YouTube Terms of Service, and Google’s handling of your information is governed by the Google Privacy Policy.
- What we ask for. Permission to upload videos to the channel you choose; to manage that channel’s videos, thumbnails, and playlists; and to read that channel’s own analytics. Nothing else — the requested permissions are fixed in our source code, and we cannot widen them without you approving a new connection.
- What we store. The authorization itself, encrypted, in a credential vault. The systems that do the publishing never receive it outright — they are issued a short-lived lease for a single step. We also store your channel’s name and ID, so we can confirm we are publishing to the right channel before anything goes out, and the resulting video ID and URL as the receipt that the upload actually happened.
- What we never do. We do not sell YouTube data, use it for advertising, use it to train AI models, share it with any other organization on Praxia, or touch any channel other than the one you connected.
- How you revoke it. Disconnect the channel inside Praxia at any time, or revoke Praxia’s access directly from your Google account permissions. Either one takes effect immediately.
- What happens to the data. Revoking deletes the stored authorization and the channel identity we kept alongside it. Videos already published stay on your channel — they are yours, and we do not remove them.
What we don’t do
- We do not sell your data or share it with advertisers.
- We do not use your operational data to train AI models. Work you dispatch runs through your own connected AI agent accounts and machines.
- Biometric data (such as Face ID) never leaves your device — the mobile app uses Apple’s on-device authentication and we never receive it.
Service providers
We rely on a small set of processors to run the service: Vercel (hosting), managed database hosting, Stripe (payments), Resend (transactional email), AI model providers for user-requested drafting and analysis, and Apple/Google push notification services. Each receives only what it needs to perform its function; we do not allow processors to use connected Google data for advertising or general model training.
Retention and deletion
We keep your data while your account is active. You can request an export or deletion of your account and its data at any time via the contact form; we complete deletion requests within 30 days.
Security
Session and device tokens are stored hashed, access is scoped per organization, and privileged actions are audit-logged. The self-hosted open-source core keeps your data on your own infrastructure — see the security policy.
Children
Praxia is a business tool and is not directed at children under 13. We do not knowingly collect personal information from children.
Changes
If we make material changes to this policy, we will update this page and note the new effective date above. Questions? Reach us through the contact form.