Privacy Policy

Effective Date: September 22, 2026 Last Updated: September 22, 2026

Mitari, Inc. ("Bohmian," "we," "us," or "our") operates the Bohmian website, hosted platform, APIs, GitHub App, managed assurance and verification services, and related products and integrations (collectively, the "Services").

This Privacy Policy explains how we collect, use, disclose, and otherwise process information in connection with the Services.

For information that Bohmian processes on behalf of an organization using the Services, that organization may determine how the information is collected and used. In those circumstances, Bohmian generally acts as a service provider or processor on behalf of the organization. For information such as account, billing, website, support, and business-contact information that Bohmian processes for its own business purposes, Bohmian may act as the applicable controller or business under privacy law.

1. Information We Collect

The information we collect depends on how you interact with the Services and which features and integrations your organization enables.

Account and Contact Information

When you create an account, join an organization, request a demonstration, contact us, or otherwise interact with Bohmian, we may collect information such as:

Authentication and Integration Information

When you authenticate through or connect a third-party service, we may receive information necessary to establish and operate the integration.

For example, when you install or use the Bohmian GitHub App, we may receive GitHub usernames, organization information, installation identifiers, repository names, repository permissions, pull-request metadata, branch information, and other information made available within the permissions authorized for the App.

We do not receive your GitHub password.

Other integrations may provide comparable account, organization, configuration, or resource information depending on the integration and permissions you authorize.

Customer Content

The Services may process content that you or your organization provide, upload, connect, or authorize Bohmian to access ("Customer Content").

Depending on the feature being used, Customer Content may include:

Customer Content may contain personal information if you or your organization include personal information in materials submitted to the Services.

Assurance, Intent, and Verification Data

As part of providing the Services, Bohmian may create and store information derived from analysis of Customer Content, such as:

We refer to this information collectively as "Service Output Data."

API and Technical Information

When you use our website, applications, APIs, or integrations, we may automatically collect technical information such as:

Usage and Interaction Information

We may collect information about how the Services are used, including features accessed, verifier usage, analysis modes, Assurance Credit consumption, actions taken, pages viewed, workflow activity, and interactions with Service outputs.

We use this information to operate, secure, support, analyze, and improve the Services.

Communications

If you communicate with us by email, through the Services, or through another support or business channel, we may retain the content of those communications and associated contact information.

Billing Information

If you purchase a subscription, Assurance Credits, or other paid Services, our payment providers process payment information on our behalf.

Bohmian may receive information such as billing name and address, transaction identifiers, payment status, subscription information, and limited payment-method information. Bohmian does not store full payment-card numbers.

Website and Analytics Information

We may use cookies, local storage, and similar technologies to operate the website and Services, remember preferences, maintain sessions, prevent fraud and abuse, and understand use of our website and products.

We may collect information such as pages viewed, referral sources, browser information, device information, and approximate geographic region.

We do not use Customer Content to create advertising profiles.

2. How We Use Information

We may use information described in this Policy to:

We may also use aggregated or de-identified information for analytics, research, capacity planning, product development, benchmarking of system performance, and other lawful business purposes where that information does not identify a person or reveal a customer's proprietary Customer Content.

3. AI and Model Providers

Certain Bohmian features use artificial-intelligence models provided by Bohmian or by third-party model providers.

When an external model provider is used to perform a requested analysis, Bohmian may provide that provider with Customer Content, instructions, or other information reasonably necessary to perform the requested operation.

We use such providers to provide functionality requested through the Services, not to advertise to you.

Bohmian does not use a customer's private Customer Content to train third-party foundation models unless the customer affirmatively authorizes that use or we separately agree with the customer in writing.

Bohmian may process Customer Content, Service Output Data, logs, metadata, and related information as reasonably necessary to operate, secure, troubleshoot, evaluate, support, and improve the Services.

Where an Order Form, data processing agreement, enterprise agreement, or other written agreement establishes additional restrictions regarding Customer Content, model providers, retention, or model training, that agreement will apply.

4. Third-Party Verifiers and Customer-Directed Integrations

The Services may allow customers to connect or use third-party verifiers, models, APIs, repositories, platforms, or other external services.

If you or your organization configure Bohmian to transmit information to a third-party verifier or integration, Bohmian may transmit the Customer Content and other information reasonably necessary to perform the requested operation.

Information received by a third party is subject to that third party's terms and privacy practices.

Bohmian does not control how independently operated third parties process information after it has been transmitted to them at your organization's direction.

5. How We Disclose Information

We do not sell personal information.

We do not disclose personal information for cross-context behavioral advertising.

We may disclose information in the following circumstances.

Service Providers and Subprocessors

We use third parties to help operate our business and Services. These may include providers of:

These providers may process information as necessary to perform services for Bohmian and are subject to applicable contractual or legal restrictions.

Customer Organizations and Administrators

If you use Bohmian through an organization account, authorized administrators of that organization may be able to access information associated with your use of the organization's account, including account information, activity, integrations, Requirements, verification activity, usage, and Service Output Data.

Your organization's use and handling of that information is governed by its own policies and practices.

Customer-Directed Third Parties

We disclose information to integrations, verifiers, platforms, or other third parties when you or your organization instruct us to do so, including by enabling or configuring an integration.

Legal Requirements and Protection

We may disclose information where we reasonably believe disclosure is required by applicable law, regulation, legal process, or governmental request.

We may also disclose information where reasonably necessary to protect the rights, property, safety, security, or integrity of Bohmian, our customers, users, the Services, or others; investigate fraud or abuse; enforce our agreements; or establish, exercise, or defend legal claims.

Business Transactions

Information may be disclosed or transferred in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable law and confidentiality protections.

6. What We Do Not Do

Bohmian does not:

7. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and reliability, fulfilling contractual commitments, resolving disputes, enforcing agreements, and complying with legal obligations.

Retention periods depend on the nature of the information and the context in which it is processed.

In general:

Account and organization information may be retained while the applicable account or customer relationship remains active and for a reasonable period afterward for legal, security, billing, and administrative purposes.

Customer Content and Service Output Data may be retained while necessary to provide features such as run history, Intent, requirements management, evidence, analytics, and assurance history, subject to applicable account settings and customer agreements.

Logs, telemetry, and security records may be retained for periods reasonably necessary for security, debugging, fraud prevention, service reliability, and operational analysis.

Billing and transaction records may be retained as required for accounting, tax, audit, dispute-resolution, and legal purposes.

Communications and support records may be retained as reasonably necessary to maintain business records and provide ongoing support.

When information is no longer required, we may delete or de-identify it, subject to technical limitations, backup cycles, legal requirements, and legitimate security needs.

An applicable Order Form, enterprise agreement, or data processing agreement may establish different retention or deletion requirements for a customer.

8. Customer Content and Account Deletion

Customers may request deletion of accounts or associated information by contacting us at info@bohmian.ai.

Organization administrators may also have controls within the Services for managing or deleting certain information.

Deletion requests are subject to applicable law, the requesting party's authority, technical limitations, backup and security processes, and any contractual retention obligations.

If Bohmian processes personal information contained in Customer Content solely on behalf of one of our customers, individuals should generally direct privacy requests concerning that information to the customer that controls the applicable account. We will assist our customers with such requests as required by applicable law and applicable agreements.

9. Security

We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, use, alteration, disclosure, or destruction.

These measures may include encryption in transit, access controls, authentication controls, logging, infrastructure security practices, and review of our security procedures.

No method of transmission or electronic storage is completely secure, and we cannot guarantee absolute security.

If your organization requires additional security, confidentiality, retention, or data-processing commitments, those commitments may be addressed through an enterprise agreement, data processing agreement, or other written agreement with Bohmian.

10. Your Privacy Rights and Choices

Depending on where you live and applicable law, you may have rights concerning your personal information, which may include rights to:

We do not discriminate against individuals for exercising privacy rights provided by applicable law.

To submit a privacy request, contact:

info@bohmian.ai

We may need to verify your identity or authority before fulfilling a request.

If you submit a request concerning information that Bohmian processes on behalf of your employer or another customer organization, we may refer the request to that organization.

Marketing Communications

You may opt out of marketing communications by using the unsubscribe mechanism included in the communication or by contacting us.

You will continue to receive transactional, security, billing, and other communications necessary to operate your account or provide the Services.

Integrations

You may revoke third-party integrations through the relevant third-party service or through Bohmian where that functionality is available.

For example, you may uninstall the Bohmian GitHub App or change its repository access through GitHub.

11. International Users and Data Transfers

Bohmian is based in the United States, and information processed through the Services may be transferred to and processed in the United States and other jurisdictions in which Bohmian or its service providers operate.

Privacy and data-protection laws in those jurisdictions may differ from the laws where you live.

Where applicable law requires a particular mechanism or safeguard for an international transfer of personal information, Bohmian will use an appropriate legally recognized mechanism.

12. Legal Bases for Processing

Where applicable data-protection law requires a legal basis for processing personal information, Bohmian processes information based on one or more of the following grounds:

Where Bohmian processes Customer Content solely on behalf of a customer acting as a controller, the customer is responsible for establishing the appropriate legal basis for that processing.

13. Sensitive and Regulated Information

The Services are designed primarily for business and professional assurance workflows.

You and your organization are responsible for determining whether Customer Content contains sensitive or regulated information and whether use of the Services for that information is legally and contractually permitted.

Unless Bohmian has expressly agreed otherwise in writing, you should not submit information requiring specialized regulatory handling, such as protected health information subject to HIPAA, full payment-card information, government identification numbers, or similarly sensitive personal information where specialized contractual or regulatory safeguards are required.

14. Third-Party Sites and Services

The Services may contain links to or integrate with third-party websites, applications, platforms, or services.

This Privacy Policy does not govern independently operated third parties. Their collection and use of information are governed by their own privacy policies and terms.

15. Children's Privacy

The Services are not directed to children under the age of 16.

We do not knowingly collect personal information directly from children under 16. If you believe a child has provided personal information to Bohmian inappropriately, please contact us at info@bohmian.ai.

16. Changes to This Privacy Policy

We may update this Privacy Policy as our Services and practices evolve or as required by law.

When we make changes, we will update the Effective Date or Last Updated date above.

If we make a material change to how we collect, use, or disclose personal information, we will provide notice through an appropriate method, such as through the Services, by email, or by another reasonably prominent means where required or appropriate.

Changes to this Privacy Policy apply prospectively from their effective date. We will obtain consent where required by applicable law before using personal information for a materially different purpose that requires such consent.

17. Additional Agreements

Certain customers may enter into a data processing agreement, enterprise agreement, Order Form, business associate agreement, or other written agreement with Bohmian that contains additional privacy, security, retention, or data-processing commitments.

To the extent such an agreement establishes more specific obligations regarding Customer Content, those provisions will govern the applicable processing.

18. Contact Us

If you have questions or concerns about this Privacy Policy or Bohmian's privacy practices, or would like to exercise an applicable privacy right, contact us at:

Mitari, Inc. Bohmian info@bohmian.ai