Privacy Policy
Effective Date: September 22, 2026 Last Updated: September 22, 2026
Mitari, Inc. ("Bohmian," "we," "us," or "our") operates the Bohmian website, hosted platform, APIs, GitHub App, managed assurance and verification services, and related products and integrations (collectively, the "Services").
This Privacy Policy explains how we collect, use, disclose, and otherwise process information in connection with the Services.
For information that Bohmian processes on behalf of an organization using the Services, that organization may determine how the information is collected and used. In those circumstances, Bohmian generally acts as a service provider or processor on behalf of the organization. For information such as account, billing, website, support, and business-contact information that Bohmian processes for its own business purposes, Bohmian may act as the applicable controller or business under privacy law.
1. Information We Collect
The information we collect depends on how you interact with the Services and which features and integrations your organization enables.
Account and Contact Information
When you create an account, join an organization, request a demonstration, contact us, or otherwise interact with Bohmian, we may collect information such as:
- name;
- email address;
- company or organization name;
- job title or role;
- account and organization identifiers; and
- other information you choose to provide.
Authentication and Integration Information
When you authenticate through or connect a third-party service, we may receive information necessary to establish and operate the integration.
For example, when you install or use the Bohmian GitHub App, we may receive GitHub usernames, organization information, installation identifiers, repository names, repository permissions, pull-request metadata, branch information, and other information made available within the permissions authorized for the App.
We do not receive your GitHub password.
Other integrations may provide comparable account, organization, configuration, or resource information depending on the integration and permissions you authorize.
Customer Content
The Services may process content that you or your organization provide, upload, connect, or authorize Bohmian to access ("Customer Content").
Depending on the feature being used, Customer Content may include:
- source code and repository contents;
- pull requests, commits, configurations, and related development artifacts;
- documents and document contents;
- spreadsheets and spreadsheet contents;
- policies, standards, procedures, specifications, and internal documentation;
- requirements, assurance contracts, constraints, and other statements of expected behavior;
- data, prompts, model-related materials, test results, and evaluation artifacts;
- files submitted through the Bohmian website or API; and
- other materials your organization chooses to analyze through the Services.
Customer Content may contain personal information if you or your organization include personal information in materials submitted to the Services.
Assurance, Intent, and Verification Data
As part of providing the Services, Bohmian may create and store information derived from analysis of Customer Content, such as:
- extracted, inferred, drafted, approved, rejected, or edited requirements;
- requirement applicability and verifier bindings;
- findings and classifications;
- evidence and evidence references;
- verification and assurance results;
- analysis explanations;
- scores, statuses, and confidence information;
- run histories and execution records;
- generated recommendations, fixes, or proposed modifications; and
- related metadata and audit information.
We refer to this information collectively as "Service Output Data."
API and Technical Information
When you use our website, applications, APIs, or integrations, we may automatically collect technical information such as:
- IP address;
- browser type and version;
- device and operating-system information;
- request timestamps;
- API usage;
- endpoint and feature usage;
- response status and error information;
- authentication and security events;
- logs and diagnostic information; and
- identifiers associated with your account, organization, integration, or session.
Usage and Interaction Information
We may collect information about how the Services are used, including features accessed, verifier usage, analysis modes, Assurance Credit consumption, actions taken, pages viewed, workflow activity, and interactions with Service outputs.
We use this information to operate, secure, support, analyze, and improve the Services.
Communications
If you communicate with us by email, through the Services, or through another support or business channel, we may retain the content of those communications and associated contact information.
Billing Information
If you purchase a subscription, Assurance Credits, or other paid Services, our payment providers process payment information on our behalf.
Bohmian may receive information such as billing name and address, transaction identifiers, payment status, subscription information, and limited payment-method information. Bohmian does not store full payment-card numbers.
Website and Analytics Information
We may use cookies, local storage, and similar technologies to operate the website and Services, remember preferences, maintain sessions, prevent fraud and abuse, and understand use of our website and products.
We may collect information such as pages viewed, referral sources, browser information, device information, and approximate geographic region.
We do not use Customer Content to create advertising profiles.
2. How We Use Information
We may use information described in this Policy to:
- provide, operate, maintain, and administer the Services;
- authenticate users and manage accounts and organizations;
- connect and operate integrations authorized by customers;
- process Customer Content and perform requested assurance, verification, Intent, and analysis workflows;
- extract, draft, manage, evaluate, and apply Requirements;
- operate specialist verifiers and generate Service Output Data;
- maintain histories, evidence, audit trails, dashboards, and other Service functionality;
- calculate usage, Assurance Credits, subscriptions, and billing;
- respond to support requests and customer communications;
- diagnose failures and troubleshoot technical issues;
- monitor and improve reliability, quality, usability, and performance;
- detect, investigate, and prevent fraud, abuse, unauthorized access, security incidents, and violations of our Terms;
- develop and improve features and functionality;
- send transactional, administrative, security, billing, and service-related communications;
- send product announcements and other marketing communications where permitted by law;
- comply with legal obligations and enforce our agreements; and
- establish, exercise, or defend legal claims.
We may also use aggregated or de-identified information for analytics, research, capacity planning, product development, benchmarking of system performance, and other lawful business purposes where that information does not identify a person or reveal a customer's proprietary Customer Content.
3. AI and Model Providers
Certain Bohmian features use artificial-intelligence models provided by Bohmian or by third-party model providers.
When an external model provider is used to perform a requested analysis, Bohmian may provide that provider with Customer Content, instructions, or other information reasonably necessary to perform the requested operation.
We use such providers to provide functionality requested through the Services, not to advertise to you.
Bohmian does not use a customer's private Customer Content to train third-party foundation models unless the customer affirmatively authorizes that use or we separately agree with the customer in writing.
Bohmian may process Customer Content, Service Output Data, logs, metadata, and related information as reasonably necessary to operate, secure, troubleshoot, evaluate, support, and improve the Services.
Where an Order Form, data processing agreement, enterprise agreement, or other written agreement establishes additional restrictions regarding Customer Content, model providers, retention, or model training, that agreement will apply.
4. Third-Party Verifiers and Customer-Directed Integrations
The Services may allow customers to connect or use third-party verifiers, models, APIs, repositories, platforms, or other external services.
If you or your organization configure Bohmian to transmit information to a third-party verifier or integration, Bohmian may transmit the Customer Content and other information reasonably necessary to perform the requested operation.
Information received by a third party is subject to that third party's terms and privacy practices.
Bohmian does not control how independently operated third parties process information after it has been transmitted to them at your organization's direction.
5. How We Disclose Information
We do not sell personal information.
We do not disclose personal information for cross-context behavioral advertising.
We may disclose information in the following circumstances.
Service Providers and Subprocessors
We use third parties to help operate our business and Services. These may include providers of:
- cloud infrastructure and hosting;
- databases and storage;
- authentication and identity services;
- AI and model services;
- monitoring and application diagnostics;
- analytics;
- email and communications;
- customer support;
- payment processing; and
- security and fraud prevention.
These providers may process information as necessary to perform services for Bohmian and are subject to applicable contractual or legal restrictions.
Customer Organizations and Administrators
If you use Bohmian through an organization account, authorized administrators of that organization may be able to access information associated with your use of the organization's account, including account information, activity, integrations, Requirements, verification activity, usage, and Service Output Data.
Your organization's use and handling of that information is governed by its own policies and practices.
Customer-Directed Third Parties
We disclose information to integrations, verifiers, platforms, or other third parties when you or your organization instruct us to do so, including by enabling or configuring an integration.
Legal Requirements and Protection
We may disclose information where we reasonably believe disclosure is required by applicable law, regulation, legal process, or governmental request.
We may also disclose information where reasonably necessary to protect the rights, property, safety, security, or integrity of Bohmian, our customers, users, the Services, or others; investigate fraud or abuse; enforce our agreements; or establish, exercise, or defend legal claims.
Business Transactions
Information may be disclosed or transferred in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable law and confidentiality protections.
6. What We Do Not Do
Bohmian does not:
- sell personal information;
- use Customer Content to build advertising profiles;
- disclose Customer Content to advertising networks for targeted advertising; or
- use a customer's private Customer Content to train third-party foundation models without the customer's affirmative authorization or a separate agreement permitting that use.
7. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and reliability, fulfilling contractual commitments, resolving disputes, enforcing agreements, and complying with legal obligations.
Retention periods depend on the nature of the information and the context in which it is processed.
In general:
Account and organization information may be retained while the applicable account or customer relationship remains active and for a reasonable period afterward for legal, security, billing, and administrative purposes.
Customer Content and Service Output Data may be retained while necessary to provide features such as run history, Intent, requirements management, evidence, analytics, and assurance history, subject to applicable account settings and customer agreements.
Logs, telemetry, and security records may be retained for periods reasonably necessary for security, debugging, fraud prevention, service reliability, and operational analysis.
Billing and transaction records may be retained as required for accounting, tax, audit, dispute-resolution, and legal purposes.
Communications and support records may be retained as reasonably necessary to maintain business records and provide ongoing support.
When information is no longer required, we may delete or de-identify it, subject to technical limitations, backup cycles, legal requirements, and legitimate security needs.
An applicable Order Form, enterprise agreement, or data processing agreement may establish different retention or deletion requirements for a customer.
8. Customer Content and Account Deletion
Customers may request deletion of accounts or associated information by contacting us at info@bohmian.ai.
Organization administrators may also have controls within the Services for managing or deleting certain information.
Deletion requests are subject to applicable law, the requesting party's authority, technical limitations, backup and security processes, and any contractual retention obligations.
If Bohmian processes personal information contained in Customer Content solely on behalf of one of our customers, individuals should generally direct privacy requests concerning that information to the customer that controls the applicable account. We will assist our customers with such requests as required by applicable law and applicable agreements.
9. Security
We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, use, alteration, disclosure, or destruction.
These measures may include encryption in transit, access controls, authentication controls, logging, infrastructure security practices, and review of our security procedures.
No method of transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
If your organization requires additional security, confidentiality, retention, or data-processing commitments, those commitments may be addressed through an enterprise agreement, data processing agreement, or other written agreement with Bohmian.
10. Your Privacy Rights and Choices
Depending on where you live and applicable law, you may have rights concerning your personal information, which may include rights to:
- request access to personal information we maintain about you;
- obtain information regarding how we collect, use, or disclose personal information;
- request correction of inaccurate personal information;
- request deletion of personal information;
- obtain a portable copy of certain personal information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- appeal certain decisions concerning privacy-rights requests where applicable.
We do not discriminate against individuals for exercising privacy rights provided by applicable law.
To submit a privacy request, contact:
We may need to verify your identity or authority before fulfilling a request.
If you submit a request concerning information that Bohmian processes on behalf of your employer or another customer organization, we may refer the request to that organization.
Marketing Communications
You may opt out of marketing communications by using the unsubscribe mechanism included in the communication or by contacting us.
You will continue to receive transactional, security, billing, and other communications necessary to operate your account or provide the Services.
Integrations
You may revoke third-party integrations through the relevant third-party service or through Bohmian where that functionality is available.
For example, you may uninstall the Bohmian GitHub App or change its repository access through GitHub.
11. International Users and Data Transfers
Bohmian is based in the United States, and information processed through the Services may be transferred to and processed in the United States and other jurisdictions in which Bohmian or its service providers operate.
Privacy and data-protection laws in those jurisdictions may differ from the laws where you live.
Where applicable law requires a particular mechanism or safeguard for an international transfer of personal information, Bohmian will use an appropriate legally recognized mechanism.
12. Legal Bases for Processing
Where applicable data-protection law requires a legal basis for processing personal information, Bohmian processes information based on one or more of the following grounds:
- performance of a contract or taking steps requested before entering into a contract;
- Bohmian's legitimate interests in operating, securing, supporting, and improving its business and Services, where those interests are not overridden by applicable privacy rights;
- compliance with legal obligations; or
- consent, where consent is required or otherwise appropriate.
Where Bohmian processes Customer Content solely on behalf of a customer acting as a controller, the customer is responsible for establishing the appropriate legal basis for that processing.
13. Sensitive and Regulated Information
The Services are designed primarily for business and professional assurance workflows.
You and your organization are responsible for determining whether Customer Content contains sensitive or regulated information and whether use of the Services for that information is legally and contractually permitted.
Unless Bohmian has expressly agreed otherwise in writing, you should not submit information requiring specialized regulatory handling, such as protected health information subject to HIPAA, full payment-card information, government identification numbers, or similarly sensitive personal information where specialized contractual or regulatory safeguards are required.
14. Third-Party Sites and Services
The Services may contain links to or integrate with third-party websites, applications, platforms, or services.
This Privacy Policy does not govern independently operated third parties. Their collection and use of information are governed by their own privacy policies and terms.
15. Children's Privacy
The Services are not directed to children under the age of 16.
We do not knowingly collect personal information directly from children under 16. If you believe a child has provided personal information to Bohmian inappropriately, please contact us at info@bohmian.ai.
16. Changes to This Privacy Policy
We may update this Privacy Policy as our Services and practices evolve or as required by law.
When we make changes, we will update the Effective Date or Last Updated date above.
If we make a material change to how we collect, use, or disclose personal information, we will provide notice through an appropriate method, such as through the Services, by email, or by another reasonably prominent means where required or appropriate.
Changes to this Privacy Policy apply prospectively from their effective date. We will obtain consent where required by applicable law before using personal information for a materially different purpose that requires such consent.
17. Additional Agreements
Certain customers may enter into a data processing agreement, enterprise agreement, Order Form, business associate agreement, or other written agreement with Bohmian that contains additional privacy, security, retention, or data-processing commitments.
To the extent such an agreement establishes more specific obligations regarding Customer Content, those provisions will govern the applicable processing.
18. Contact Us
If you have questions or concerns about this Privacy Policy or Bohmian's privacy practices, or would like to exercise an applicable privacy right, contact us at:
Mitari, Inc. Bohmian info@bohmian.ai