# Privacy Policy

Last updated and effective: October 10, 2026. Operated by Polygala, Inc.

This policy explains what personal information **Polygala, Inc.** ("BoxLite", "we", "us") collects when you use boxlite.ai and BoxLite Cloud (the "Service"), and what we do with it.

We treat two kinds of data differently:

- **Account and usage data** — information about *you* as our customer. We decide how it is used and this policy covers it.
- **Customer Content** — the code and data you run inside your Boxes. It is yours. We process it only to run the Service for you (section 3). Where applicable law requires processor terms, those terms must be agreed before we process Customer Content containing personal data; contact privacy@boxlite.ai to arrange them.

### 1. Information we collect

| What | Examples | Source |
|---|---|---|
| Account | name, email address, sign-in identity | you; your sign-in provider (e.g. Google) via Auth0 |
| Billing | billing name and address, subscription and wallet history, last four digits of card | you and Stripe. **Your full card number goes to Stripe, not to us.** |
| Usage and metering | Boxes created, size and running time, API requests, logs needed to meter and bill | the Service |
| Security | IP addresses, request metadata, signals used to detect abuse and fraud | the Service |
| Product analytics | pages and features used in the console, device and browser type — collected only after you opt in | PostHog |
| Communications | messages you send to support or sales | you |
| Website analytics | aggregated, cookieless page views on boxlite.ai | Vercel Web Analytics |

### 2. How we use it

- to provide, operate, meter and bill the Service;
- to secure the Service and enforce the Terms of Service, including detecting cryptocurrency mining, attacks and fraudulent sign-ups;
- to support you and send service messages (billing, security, changes to our terms);
- to send product updates and announcements — every such email has an unsubscribe link, and service messages are not affected by unsubscribing;
- to understand how the Service is used and improve it;
- to comply with legal obligations and enforce our agreements.

We rely on performance of our contract with you, our legitimate interests (security, fraud prevention, product improvement), your consent where required, and compliance with law.

We do not sell personal information and do not share it for cross-context behavioural advertising.

### 3. Customer Content

We process Customer Content only on your instructions to provide the Service. We do not access the contents of your Boxes or volumes except where needed to operate or secure the Service, to respond to your support request, to investigate a suspected violation of the Terms of Service, or to comply with law. Staff access is limited to engineers with an operational need and is logged.

### 4. Who we share it with

Service providers who process personal information for us, under contracts that restrict their use of it. They are:

| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | infrastructure running Boxes and storing Customer Content | USA (us-east5) |
| Stripe | payment processing | USA |
| Auth0 (Okta) | sign-in and authentication | USA |
| Resend | transactional email | USA |
| PostHog | console product analytics, only after you opt in | USA |
| Google Analytics | analytics on blog.boxlite.ai | USA |
| Vercel | hosting boxlite.ai; cookieless web analytics | USA |
| Google Workspace | company email and support mailbox | USA |

We may also disclose information when required by law or legal process, to protect the rights, property or safety of BoxLite, our customers or the public, to enforce our agreements, or in connection with a merger, acquisition or sale of assets (in which case this policy continues to apply).

### 5. International transfers

We are based in the United States and store account data and Customer Content in the United States. If you are in the EEA, UK or Switzerland, your data is transferred to the US. Where such transfers require safeguards, we put in place the European Commission's Standard Contractual Clauses with the UK Addendum and Swiss adaptations; contact privacy@boxlite.ai for information.

### 6. Retention

| Data | Retained |
|---|---|
| Account data | while your account is open, then up to 30 days |
| Billing records | 7 years, as required for tax and accounting |
| Customer Content | until you delete it; removing a Box destroys its disk; all remaining content is deleted 30 days after account closure |
| Security and request logs | 90 days, longer if needed for an active investigation |
| Any data under a legal hold | as long as the law or a legal claim requires, used only for that purpose |
| Support correspondence | 2 years |

### 7. Security

Each Box runs as an isolated virtual machine with its own kernel. Data is encrypted in transit (TLS) and at rest on our infrastructure provider's storage. Access to production systems requires multi-factor authentication and is limited to staff with an operational need. Secrets you supply through our secret mechanism are substituted outside the guest rather than stored inside it. No system is perfectly secure; we will notify you of a security incident affecting your personal information as required by law. Report vulnerabilities to security@boxlite.ai.

### 8. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. To exercise these rights email privacy@boxlite.ai. We will verify your identity and respond within one month under GDPR or 45 days under CCPA, subject to legally permitted extensions with notice. California residents may request the categories and specific pieces of personal information we hold, correction and deletion, and may use an authorized agent. Withdrawing consent does not affect processing that happened before. We will not discriminate against you for exercising your rights.

### 9. Cookies

boxlite.ai uses Vercel Web Analytics, which does not set cookies. The console at app.boxlite.ai uses cookies that are strictly necessary to keep you signed in and to secure your session. PostHog product analytics is off by default and runs only after you opt in under Account settings → Privacy preferences, where you can also withdraw consent at any time without losing access to the Service. Our blog at blog.boxlite.ai uses Google Analytics cookies, which are set for the boxlite.ai domain; the console does not read them.

### 10. Children

The Service is not directed to anyone under 18 and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact privacy@boxlite.ai and we will delete it.

### 11. Changes

We will post changes here and update the date above. For material changes we will notify you by email or in the console at least 30 days before they take effect.

### 12. Contact

Polygala, Inc.
131 Continental Dr, Suite 305, Newark, DE 19713, USA
privacy@boxlite.ai

## Pages

- [BoxLite — The managed cloud for AI agents](https://boxlite.ai) — Hosted microVMs for AI agents: compute, networking, a filesystem and a database, on BoxLite's fleet or your own.
- [BoxLite Open Source — the local-first embedded runtime for AI agents](https://boxlite.ai/oss) — Apache 2.0 microVMs as a library. No daemon, no cloud, no root — on your laptop, your cluster, or your customer's machine.
- [About BoxLite](https://boxlite.ai/about) — What BoxLite is, how the open-source runtime and the managed cloud relate, and who builds it.
- [Contact BoxLite](https://boxlite.ai/contact) — Support email, Discord, GitHub issues and sales — every channel that reaches the BoxLite team.
- [Terms of Service](https://boxlite.ai/legal/terms) — The agreement that governs BoxLite Cloud: accounts, credits and payment, acceptable use, refunds, copyright complaints and liability.
- [Privacy Policy](https://boxlite.ai/legal/privacy) — What personal information BoxLite collects, how it is used and shared, where it is stored, and the rights you have over it.

## Machine-readable files

- [/llms.txt](https://boxlite.ai/llms.txt) — Site summary and links, llms.txt format
- [/agent.md](https://boxlite.ai/agent.md) — Full guide for coding agents using BoxLite Cloud
- [/sitemap.xml](https://boxlite.ai/sitemap.xml) — All indexable pages
- [/robots.txt](https://boxlite.ai/robots.txt) — Crawl policy

## Elsewhere

- [Documentation](https://docs.boxlite.ai)
- [Console](https://app.boxlite.ai)
- [GitHub](https://github.com/boxlite-ai/boxlite)
- [Discord](https://go.boxlite.ai/discord)
