Version 3.1 | Effective August 1, 2026
This Privacy Policy explains how FohBoh.ai, Inc. (“FohBoh,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through fohboh.ai, the Sentry and Cortex pages and applications, standalone or embedded MGE services, related APIs and connectors, events, communications, and other services that link to this Policy (collectively, the “Services”).
This Policy addresses personal information about identifiable people. It does not govern non-personal business data except where that data is linked or reasonably linkable to a person. A customer agreement, DPA, or employee notice may provide additional or different terms.
FohBoh as controller/business.
We determine the purposes and means of processing account, website, sales, event, billing, security, and business-contact information used to operate FohBoh’s business.
FohBoh as processor/service provider.
When we process Customer Data on behalf of an enterprise customer to provide MGE, Sentry, Cortex, CAAR, connector, or API services, the customer generally determines the purposes and means of that processing and FohBoh acts on documented instructions. The customer’s privacy notice and our DPA govern that processing. Individuals should ordinarily direct requests about Customer Data to the relevant customer.
FohBoh for Certification Records and IUM.
We determine the purposes and means of processing FohBoh-owned certification and uncertified logs, security and operational telemetry, usage and IUM measurements, and related integrity records when used to operate, secure, verify, protect, and improve our certification infrastructure. Where those records contain personal information, this Policy, applicable privacy law, confidentiality duties, and the customer agreement continue to apply regardless of ownership.
Customers are responsible for providing required notices and obtaining required rights or permissions for personal information they make available through the Services.
Category
Examples
Typical source
Identifiers and account data
Name, business email, telephone number, login identifier, organization, role, authentication and account settings.
You, your employer/customer, identity provider.
Commercial and relationship data
Subscription, order, billing, pilot, partner, support, meeting, and communication records.
You, customer administrators, sales/support interactions.
Internet and device activity
IP address, browser, device, pages viewed, referring URLs, session events, feature usage, logs, cookie or similar identifiers.
Your device, website and service telemetry.
Professional information
Employer, title, work location, franchise or business affiliation, permissions, and role-based access.
You, your organization, integrations.
Customer operational data
Transaction, order, delivery, processor, vendor, contract, inventory, labor, payroll, royalty, supply-chain, or location records that may contain employee, customer, vendor-contact, or other personal information.
Customer uploads; POS, payroll, DSP, processor, vendor and other authorized systems.
Credentials and integration data
API keys, OAuth tokens, connector identifiers, service-account metadata and system permissions.
You, administrators, enabled integrations.
Certification and evidence metadata
Certified and uncertified logs, rule and KPI versions, mappings, rule execution or failure, Trust Scores, certification status, source references, timestamps, hashes, signatures, exceptions, approvals, override records, CAAR, lineage, provenance and audit metadata.
MGE/Sentry processing and authorized users.
Cortex content
Prompts, queries, voice or text input, responses, feedback, approved context and related telemetry.
Authorized users and configured services.
Inferences and analytics
Product usage trends, fraud/security signals, service health, support needs, and account-level operational patterns.
Derived from the information above.
The Services are not designed to receive full payment-card numbers, CVVs, Social Security numbers, protected health information, biometric identifiers, precise geolocation, or other regulated sensitive personal information unless a written agreement expressly authorizes the data and safeguards. Please do not upload such information without authorization.
MGE and Sentry use deterministic rules for variance calculations; the same governed inputs and rule version are intended to produce the same calculation. Authorized people may enter contract terms, validate mappings, approve exceptions, or invoke governed overrides. We may record those actions as evidence, security, or audit metadata.
FohBoh owns Intelligence Under Management (“IUM”) and the certified and uncertified logs generated by MGE, Sentry, and headless trust-layer processing (“FohBoh Certification Records”), including certification events, rule-execution history, certification status, Trust Score history, exceptions, overrides, hashes, signatures, lineage, provenance, operational telemetry, usage measurements, and the compilation and structure of those records. Customer retains ownership of Customer Data and the readable content of its source records. FohBoh’s ownership does not eliminate privacy rights, confidentiality restrictions, security obligations, or contractual limits applicable to information contained in a log.
In a headless deployment for a data platform, POS provider, or system of record, source data is processed automatically within the authorized technical pathway. FohBoh does not routinely inspect or use readable source data for an independent purpose. Human access, if technically possible, is restricted to authorized support, security or incident response, legal compliance, or another purpose permitted by the applicable agreement. Deployments designated as “no-view” use the technical restrictions defined in their Security Addendum.
Cortex may send authorized prompts and context to approved AI providers to generate responses. MGE certification of a source metric does not make every AI-generated statement certified. We contractually and technically limit provider use where available and as specified in the applicable DPA or enterprise agreement.
We do not use Customer Data to train a general-purpose model for unrelated customers unless the customer expressly authorizes that use in writing. We may use service telemetry and de-identified or aggregated information for security, quality, and improvement as allowed by contract and law.
The Services are not intended to make solely automated decisions that produce legal or similarly significant effects concerning individuals. Customers must provide appropriate human review and comply with laws applicable to their use of outputs.
We collect personal information directly from you; from your organization and its administrators; through your use of the Services; from systems, vendors, and integrations you authorize; from service providers and business partners; and from public or commercially available business sources where lawful.
We may disclose personal information to:
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or process it for targeted advertising as those terms are defined by applicable U.S. state privacy laws. If our practices change, we will update this Policy and provide required choices before the change applies.
We and authorized providers may use essential cookies and similar technologies for authentication, security, preferences, load balancing, and service operation, and analytics technologies to understand website and product use. Where required, non-essential technologies will be controlled through a consent or preference tool. Browser settings may block some technologies, but essential features may not function.
We do not currently respond to browser “Do Not Track” signals as a universal standard has not been adopted. Where legally required and technically supported, we honor recognized opt-out preference signals for covered sale, sharing, or targeted-advertising activity; we do not currently engage in those activities.
Purpose
Typical legal basis
Provide contracted Services and account functionality
Performance of a contract or steps requested before entering a contract.
Secure, administer, support, measure, and improve the Services
Legitimate interests in operating a secure and effective B2B service, balanced against individual rights.
Required records, compliance, and legal process
Compliance with legal obligations and establishment or defense of legal claims.
Optional marketing or non-essential technologies
Consent where required; otherwise legitimate interests subject to applicable choices.
Customer Data processed for an enterprise customer
The customer determines the legal basis; FohBoh processes on documented instructions under a DPA.
We retain personal information only for as long as reasonably necessary for the purposes described, including to provide Services, preserve security and transaction records, meet contractual evidence and audit requirements, comply with law, resolve disputes, and enforce agreements. Actual periods depend on the data class and applicable agreement.
Data class
General retention approach
Account and relationship records
For the active relationship and a reasonable period afterward for administration, tax, dispute, and legal needs.
Customer Data and generated outputs
During the service term and for the return/deletion period stated in the enterprise agreement, DPA, or retention schedule.
FohBoh Certification Records and CAAR evidence
As configured or contractually required—and as reasonably needed to preserve IUM, rule performance, reproducibility, chain of custody, audit readiness, security, and version history. Partner access may end before FohBoh retention; legal holds may extend retention.
Security, access, API, and audit logs
For periods appropriate to security monitoring, investigation, usage verification, and contracted audit requirements.
Billing and IUM metering records
For the contract, billing-dispute, tax, audit, and legal limitation periods.
Website analytics and cookies
According to the applicable cookie or analytics setting and provider configuration.
Deletion may not remove records that must be retained by law or agreement, are subject to legal hold, reside in protected backups until ordinary rotation, or consist of limited integrity, security, billing, or audit metadata. A cryptographic hash may remain personal information if it can reasonably be linked to a person; we do not treat hashing alone as anonymization.
We use administrative, technical, and organizational safeguards designed for the data and risks involved. Depending on the Service and agreement, these may include encryption in transit and at rest, role-based access, multi-tenant isolation, credential and key controls, logging, monitoring, integrity hashes, digital signatures, vulnerability management, backups, incident response, and personnel controls.
No system is completely secure. Detailed and binding security commitments are contained in the applicable Security Addendum, DPA, and enterprise agreement. Public descriptions do not expand or replace those commitments. Customers share responsibility for endpoint security, identity administration, least privilege, connector configuration, and lawful data handling.
FohBoh is based in the United States, and information may be processed in the United States and other countries where we or our authorized providers operate. Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses, and contractual and technical supplementary measures. Details may be provided in the applicable DPA.
Depending on where you reside and applicable exemptions, you may have rights to request access, correction, deletion, portability, or information about processing; to object to or restrict certain processing; to opt out of covered sale, sharing, targeted advertising, or profiling; to withdraw consent where processing is based on consent; and to appeal a denied request.
Submit a request to privacy@fohboh.ai with the subject “Privacy Request.” We may verify identity and authority and may ask you to identify the relevant FohBoh customer. Authorized agents must provide legally sufficient authorization. We will not discriminate against you for exercising applicable rights.
If your information is contained in Customer Data, FohBoh ordinarily acts for the customer. We may refer the request to that customer or assist it under our DPA. You may also contact the customer directly. Rights are subject to legal limitations, exemptions, and retention obligations.
You may opt out of non-transactional marketing emails through the unsubscribe link. Service, security, legal, billing, and account communications are not marketing and may continue while relevant.
The Services are business services not directed to children, and users must be at least 18. We do not knowingly collect personal information from children under 13 through the Services. If you believe a child has provided personal information, contact privacy@fohboh.ai.
The Services may link to or integrate with third-party services. Their privacy practices are governed by their notices, not this Policy. Customer administrators decide which integrations to enable and should evaluate the third party’s terms, permissions, and data practices.
We may update this Policy prospectively. We will post the revised version and effective date and provide additional notice when required by law or contract. We will not quietly or retroactively use previously collected personal information for a materially incompatible purpose without the notice, choice, or authorization required by law and applicable agreements.
FohBoh.ai, Inc. is a Delaware corporation. Privacy questions, rights requests, and complaints may be sent to privacy@fohboh.ai. Enterprise customers should also use the contacts and procedures in their DPA or agreement.
What to know
Summary
Categories collected
Identifiers/account data; commercial and professional information; device and internet activity; Customer operational data; credentials/integration data; certification/evidence metadata; Cortex content; and derived service analytics.
Purposes
Provide, secure, support, certify, document, measure, bill, and improve the Services; operate MGE, Sentry, Cortex, CAAR, APIs, and connectors; communicate; comply with law; and protect rights.
Disclosures
Authorized service providers, AI providers for Cortex, customer-enabled integrations, advisers, authorities, and transaction parties as described in this Policy.
Sale/sharing
We do not sell personal information for money or share it for cross-context behavioral advertising.
Retention
Only as long as reasonably necessary for service, security, evidence, contractual, billing, audit, legal, and dispute purposes, subject to the applicable agreement and retention schedule.
Rights contact
privacy@fohboh.ai
Surface
Additional notice
FohBoh.ai website
Primarily processes visitor, business-contact, cookie, event, and communications data. Authenticated account processing is described below.
Sentry / CAAR
Processes authorized operational and vendor records through deterministic rules; may record human-entered terms, mappings, approvals, exceptions, and overrides; preserves source references, evidence and integrity metadata.
Cortex
Processes prompts and approved context and may disclose them to authorized AI providers. Responses are probabilistic; do not submit unnecessary personal or sensitive information in prompts.
Standalone/headless MGE and APIs
Processes source data automatically within customer-configured scopes; creates FohBoh-owned certified and uncertified logs, calls, certification events, versions, outputs, errors, IUM measures, and security/audit records; provides the authorized partner contract-limited log access while in good standing.