Privacy Policy
Blackmount.ai Inc
Effective: October 1, 2026
This policy explains how Blackmount.ai Inc, a Delaware corporation ("Blackmount", "we", "us"), handles personal data in connection with the Blackmount Agent Builder: our business website pages, sales and demo pages (including demo.blackmount.ai), hosted AI agents and embeddable chat widgets, customer dashboards and reports, the API, and the desktop agent.
It does not cover the Blackmount consumer browser products on app.blackmount.ai and the related extensions and apps, which have their own privacy policy.
Contact for anything in this policy: info@blackmount.ai.
1. Our role
- Our customers' agents. When a company uses Blackmount to run an AI assistant on its website or on a page we host for it, that company is the controller of its visitors' conversations and leads, and Blackmount processes them on the company's behalf under a Data Processing Agreement. If you chatted with a company's assistant, please direct requests about that data to the company; we will help them respond.
- Our own activities. For our own website and sales pages, the demo agents we build for prospects, our outreach, and our customers' account and billing records, Blackmount is the controller.
- Template improvement. For the limited purpose of improving our shared industry templates (§3), Blackmount is an independent controller of the build observations described there.
2. What we collect
People who chat with an agent or demo
- Messages you type and the assistant's replies, with the sources it cited.
- Contact details you choose to give — name, email, company, phone, and details of your request (for example, quantities or application for a quote). An email address or phone number typed into a chat message may be detected and stored as a lead, and forwarded to the company's sales inbox.
- Technical and attribution data captured when a conversation starts: IP address, browser user-agent, HTTP referrer, any
refor campaign tag in the link you followed (our outreach links can carry a tag identifying the recipient), country (where our hosting adds it) and a timestamp. Page views of demo pages record the referrer, user-agent andreftag. - Approximate location and network. For visits to Blackmount's own demo pages, we may look up the approximate city, region, country and network operator of the IP address recorded at the start of a conversation, using an IP-geolocation service (ip-api.com), and combine it with visit counts and the
reftag, so we can tell which outreach recipient or company visited our demos. - On hosted demo pages only, a browser
sessionStorageflag that remembers whether you minimised the chat. It is cleared when you close the tab. The embeddable widget stores nothing in your browser.
Visitors to our web pages
- Google Analytics. We use Google Analytics 4 on our website and on pages served by the Agent Builder application. It sets cookies and collects data such as pages viewed, referrer, device and browser information and IP address, to help us understand how our pages are used. See §8 for how to opt out.
- Fonts and images. Some of our pages load fonts from Google Fonts, and demo and dashboard pages may display a company logo loaded from that company's own website; your browser contacts those hosts to fetch them.
- Demo requests. If you ask us for a demo, we collect the details you submit and send you a confirmation email.
Customers and desktop-agent users
- Account data — name, email and sign-in identifiers via Firebase Authentication (Google) for desktop-agent and API account users; organisation; the agents you are granted; billing contact details. Customer dashboards and reports are opened with private per-project links.
- Device records — an opaque per-installation ID and first/last-seen times, used to enforce seat limits.
- Usage records — per-request status and estimated cost, used for metering and spend caps.
- Content you provide — documents, uploaded files, website URLs, and the text, chunks and vector embeddings we derive from them; agent configuration, including custom instructions.
- Desktop-agent data — when a tool reads local files, its result (which can include file contents) is sent to our servers and the hosted model to produce an answer. So that sessions can be reopened, continued and audited, we store:
- conversations and the charts and tables ("artifacts") generated in them;
- a session record of the file names, dataset columns and dimensions, computed results and output file names the agent has worked with;
- the state of tool calls (your message, the tool's arguments, earlier tool results and artifacts in the same task), which is kept after the call completes;
- task records and approvals; and
- tool-call logs in which credentials and selected fields are masked and outputs are truncated; other personal information in free text may remain.
People whose public information appears in a demo
We build demonstration agents from publicly available company websites and product documents. These are business documents; they may incidentally contain names or business contact details published by that company.
3. Why we use it
| Purpose | Data | Legal basis (where GDPR or similar law applies) |
|---|---|---|
| Answer questions and run a customer's agent | Messages, Customer Content | Processing on the customer's instructions (we are its processor) |
| Capture leads and send them to the company's sales inbox | Contact details, conversation context | Processing on the customer's instructions |
| Improve a customer's own agent by reviewing unanswered or refused questions | Messages | Processing on the customer's instructions |
| Respond to demo requests made to Blackmount | Contact details you submit | Steps at your request before a contract; our legitimate interest in responding |
| Tell real prospects apart from our own testing, and measure our outreach (Blackmount's own demos) | IP address, approximate location and network, user-agent, referrer, ref tag |
Our legitimate interest in understanding whether our business outreach reaches its intended recipients |
| Security, abuse prevention, rate limiting | IP address, request data | Our legitimate interest in keeping the Services secure |
| Accounts, seats, metering, spend caps, billing | Account, device and usage data | Performance of our contract with the customer |
| Template improvement (see below) | Build observations derived from Customer Content, which may include personal data present in that content | Our legitimate interest in improving the quality of our product for all customers |
| Website analytics | Google Analytics data | Our legitimate interest in understanding and improving our business website |
| Legal compliance and defending claims | Any of the above, as needed | Legal obligation; our legitimate interests |
Template improvement. While building a customer's agent we record build observations — product categories and terminology found in the customer's content, and evaluation questions the agent could not answer, with the reason. These records are linked to the customer's project, may contain text from its content, and are reviewed only by Blackmount staff. We use them to derive de-identified, generalised patterns (such as question types and product categories) that improve the industry templates we use for all customers. We never share Customer Content or these records with other customers. Customers can opt out by emailing info@blackmount.ai; we then stop using their content for this purpose and delete the stored observations linked to their project.
We do not sell personal data. Blackmount does not use customer or visitor data to train AI models.
4. Who we share it with
We share personal data only as described here:
- Service providers that process data for us, listed in the subprocessor list in DPA Annex 3: Supabase (database), Railway (application hosting), OpenRouter (model gateway) and the model hosting providers it routes each request to, OpenAI (embeddings and agent building), Anthropic (agent building), LlamaIndex (document parsing), Resend (email), Google (Firebase Authentication and Google Analytics), and, only if enabled, Firecrawl's cloud service (web collection). For Blackmount's own demo visitor reporting we also use ip-api.com for IP geolocation.
- The company whose agent you used. Lead notifications are emailed to the sales address that company configured, and conversations are available to it in its dashboard.
- Tools a customer connects. If a company connects its own tool servers to its agent, the data needed for those tools is sent to the servers the company chose.
- Legal and corporate. We may disclose data where required by law or legal process, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of assets, with notice to affected customers.
5. Where it is stored
Our database and application hosting are in the United States. Model, email and other service providers may process data in the United States and other countries. Where we transfer personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, we use the safeguards described in DPA §9 (EU Standard Contractual Clauses, the UK Addendum and Swiss amendments).
6. How long we keep it
- Customer data (conversations, leads, attribution data, Customer Content and desktop-agent data) is kept while the customer's agreement is active, and deleted as set out in DPA §7: after the agreement ends and a 30-day export window, or within 30 days of a customer's written deletion request. Deleting a document removes its derived text chunks and embeddings. When a desktop-agent user deletes a conversation, it is hidden from their list and kept until the customer's data is deleted or erasure is requested.
- Blackmount's own records (demo visits, outreach attribution, demo requests, account and billing records) are kept for as long as we need them for the purposes in §3, and billing records for as long as the law requires.
- We do not currently apply shorter automatic deletion periods to particular categories of data. You can ask us to delete data at any time (§7).
- Copies in database backups are removed when those backups expire in our hosting provider's ordinary backup cycle.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict our use of it (including use based on legitimate interests), and to complain to a data protection authority. If your data was collected through a company's agent, contact that company; we will assist it. Otherwise, email info@blackmount.ai. We will respond within the time the law requires and may need to verify your identity first.
8. Analytics opt-out
You can stop Google Analytics from collecting data about you by installing Google's Analytics opt-out browser add-on, or by blocking or deleting cookies in your browser settings. Google's use of the data is described in Google's privacy policy.
9. Security
Our database is accessed only by our server-side application. The tables that hold conversations, leads, documents, accounts and desktop task data have database row-level security enabled with no public access policies. Per-agent API keys are stored as hashes, and the manifests we send to the desktop application are cryptographically signed. Our public pages and APIs are served over HTTPS. No system is perfectly secure, and we do not currently hold third-party security certifications. DPA Annex 2 describes our measures in more detail.
10. Children
The Services are for businesses and are not directed at children under 16. We do not knowingly collect personal data from children.
11. Changes
We will post updates on this page with a new effective date, and notify customers by email of material changes.
12. Contact
Blackmount.ai Inc — info@blackmount.ai (privacy, security and legal).