BOL is operated by Sushanta Kumar Sahu under the developer brand SWYAM SAMARTH, Kalahandi, Odisha, India. Contact support@bolona.in for support, privacy, complaints and deletion requests. Hours: 10:00–18:00 India Standard Time.
This policy covers BOL Android, BOL Keyboard, the optional floating microphone, website and support. BOL is intended for adults aged 18 and over.
Data and purposes
- Content: audio/video you deliberately submit, transcripts, edits, requested speaker labels/timing and text you explicitly submit to an AI action. We process these to deliver that feature, not to train BOL-owned models.
- Identity: Google Sign-In provides name, email and account identifier; guests use an opaque Firebase identifier. Identity supports job ownership, account security and usage/entitlements.
- Operations: durations, route/provider/model, error category, request and audio usage, app/device/OS version, crash and ANR diagnostics. Network infrastructure may process IP addresses for delivery/security. We do not request precise location, contacts, browsing history or unrelated editor text.
- Billing: when subscriptions are enabled, Google Play handles payment credentials; BOL processes purchase tokens, plan, verification, expiry and usage, not full card, bank or UPI credentials.
- Support: information you voluntarily email, handled through Zoho Mail. Do not send passwords or API keys.
Microphone and keyboard
Capture begins only after your action and Android permission. Active capture uses Android’s ongoing foreground-service notification. Enabling BOL Keyboard does not authorize continuous listening. Voice/AI text capture is disabled in password fields. Selected text, or the latest verified BOL insertion where permitted, is sent only when you invoke that action. Keyboard background photos stay on your device.
Processing providers
Audio travels securely through BOL’s Google Cloud backend to the provider required for your request. Plain transcription uses Sarvam AI; requested speaker labels/precise word timing use ElevenLabs. Explicit AI text actions use DeepSeek with ZAI/GLM as a configured fallback; some language functions use Sarvam. Gemini is not an active public BOL route. Credentials remain backend-only.
Google Cloud/Firebase provide hosting, authentication, restricted records and Crashlytics. Optional Drive backup uses narrow file access to your visible BOL Data folder. Once authorized, eligible notes sync automatically; audio restoration follows the selected restore mode.
Providers may process outside India and retain or use data under their API terms/account settings. BOL does not promise provider zero retention or no training without a verified account-specific agreement. See Sarvam, ElevenLabs, DeepSeek, ZAI, Google and Zoho. BOL remains responsible for its own data handling.
Storage and retention
- Device and Drive: no automatic age-based deletion. Server-account deletion does not remove these copies. Uninstalling or explicitly choosing “Sign out & clear” can remove device data; read the confirmation.
- Completed server transcripts: a separate restricted BOL application-data store retains them for 30 days from completion, with scheduled expiry deletion and a database TTL backstop. This is not a permanent library backup.
- Temporary processing: objects are removed after processing where possible; a one-day storage lifecycle is the backstop for abandoned long jobs. Short synchronous and live source audio is processed transiently, not kept by BOL as recordings.
- Logs: content-free operational logs use a 30-day window. Crashlytics uses its own platform retention; BOL does not attach audio, transcripts, editor text, emails or keys to reports. We do not equate its platform retention with the transcript period.
- Purchases/support: records are kept only as needed for service, disputes, security and applicable legal obligations. Independent legal record-keeping can survive account deletion. Public subscriptions remain unavailable until verified billing is enabled.
Billing and deletion safeguards
Restricted purchase tokens and verification records expire 90 days after the recorded subscription expiry, unless a legal obligation requires separate retention. Request-result replay records expire after one day. Account deletion removes BOL-controlled account, usage, purchase and content records; a hashed deletion guard lasts at most one day to prevent in-flight requests restoring deleted records. It contains no transcript or audio. Google Play retains its independent transaction records and manages subscription cancellation.
Your controls
Use a guest account, control Android microphone permission, choose Drive authorization, disconnect Drive, delete device/Drive copies, or request BOL server-account deletion in Settings or through the external deletion page. Disconnecting Drive stops future access but does not delete files already there. We verify ownership before acting and explain any legal exception.
Advertising, training and security
BOL does not sell recordings/transcripts, target behavioral advertising using their contents or train BOL-owned AI models on them. No behavioral-advertising SDK is in this launch scope. HTTPS protects transit; cloud stores use platform encryption and restricted access. Absolute security cannot be guaranteed. Review AI output before use.
Changes and questions
Material changes will be communicated through the app or website as appropriate. Contact support for access, correction, deletion, complaints or provider questions.