Privacy Policy
Our commitment to protecting your privacy and securing your data.
Last Updated: August 6, 2026
Introduction
At BishopTech, operated by Matthew Bishop ("we," "our," or "us"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website bishoptech.dev, use our services, or communicate with us.
Our Core Privacy Commitment: We NEVER sell your data to third parties. Your information is used solely to provide our services and communicate with you about our offerings.
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the website or use our services.
Ascend Flow iOS App
This section applies specifically to Ascend Flow, BishopTech's open-source iOS conversation companion. It supplements the general website and service disclosures above. Ascend does not require an account and does not use the BishopTech website database to store conversation history.
Ascend is designed for an active, user-started conversation session. The app shows microphone and transcription status on the iPhone and, when a compatible Meta display is connected, sends a short MIC ON status card to the display. Users should start a session only after the people whose voices may be captured know about the microphone and agree to the conversation being transcribed, and only where recording or transmission is permitted.
Data used by Ascend
- Microphone audio: The iPhone microphone is used only during an active session. Audio buffers are passed to Apple's on-device speech-recognition path for the live transcript. Ascend does not save an audio recording and does not send microphone audio to its gateway or OpenAI.
- Transcript and analysis: The transcript, session analysis, topics, suggestions, and Vibe Check results are saved in the app's local SwiftData store on the iPhone when the user ends a session with detected speech. They are not synced to a BishopTech account or cloud database.
- Knowledge base: Text that the user enters as a knowledge reference is stored locally on the iPhone. The user can select on-device retrieval or a network-backed OpenAI embedding path.
- OpenAI coaching: OpenAI coaching is enabled by default in the release configuration. When a network-backed OpenAI feature is used, the app sends transcript text and selected knowledge-reference text—not microphone audio—over HTTPS to the Ascend gateway. The gateway keeps the provider key server-side, does not persist request bodies, and forwards the request to OpenAI. OpenAI's current API data-controls documentation says API inputs and outputs may be retained for up to 30 days for abuse monitoring; API data is not used to train models unless the API customer explicitly opts in. See OpenAI's API data controls for the current provider policy.
- Meta wearable display: The Meta Wearables Device Access Toolkit is used only to register compatible glasses, maintain the display connection, and render the user's cards. The app opts out of the toolkit's analytics and crash reporting settings. Meta's own privacy policy and developer terms apply to information Meta processes through its platform.
Ascend controls and deletion
- Starting and stopping listening is always user initiated. The app stops listening when the session ends or is paused.
- Users can switch live coaching and knowledge retrieval to On-device in Output & AI settings to keep transcript text and reference text on the iPhone.
- Users can delete individual conversations, knowledge references, or all Ascend data from the iPhone in the app. Sharing is an explicit action through the iOS share sheet and may send the selected content to a destination chosen by the user.
- Users can revoke microphone and speech-recognition permission in iOS Settings and can stop a session at any time. Because Ascend does not retain conversation request bodies on its gateway, there is no Ascend cloud conversation archive to delete. Any provider-side retention of a network request is governed by the current OpenAI API policy linked above.
What Ascend does not do
Ascend does not access the user's contacts, create contact records, send follow-ups, schedule reminders, create CRM records, initiate outreach, use conversation content for advertising, or track users across apps and websites. Doctor Visit mode organizes questions and observations but does not provide medical advice or diagnosis. Vibe Check evaluates observable transcript signals and is not a determination of another person's emotion, identity, consent, safety, or intent.
Questions about Ascend's data handling can be sent to matt@bishoptech.dev.
Information We Collect
We may collect information about you in a variety of ways. The information we may collect includes:
Personal Data
Personally identifiable information that you voluntarily provide to us when using our website or services, such as:
- Name, email address, phone number, and other contact details
- Information provided when filling out forms or questionnaires
- Information provided when requesting a consultation or quote
- Information shared in communication with us
Technical Data
When you visit our website, our servers may automatically log standard data provided by your web browser. This may include:
- Your computer's IP address
- Browser type and version
- Pages you visit and time spent on those pages
- Referring website addresses
- Other technical information
How We Use Your Information
We may use the information we collect from you in the following ways:
- To provide, operate, and maintain our services
- To improve, personalize, and expand our services
- To understand and analyze how you use our services
- To develop new products, services, features, and functionality
- To communicate with you directly or through partners, including for customer service, updates, and other information related to the services
- To process transactions and send related information, including confirmations
- To find and prevent fraud
Data Protection and Security
We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. We use Supabase as our database provider, which provides enterprise-grade security including:
- Data encryption at rest and in transit
- Regular security assessments and compliance monitoring
- Role-based access controls and authentication
- Automated backups and disaster recovery
- SOC 2 Type II compliance
While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. No method of electronic transmission or storage is 100% secure.
Website Builds & Management Privacy Terms
Website Builds & Management deployments are operated with a privacy-first model. We only request access needed to configure, test, and maintain the website and agentic bot workflows defined in your statement of work.
- Agentic Bot Data: Proprietary bots process only data required to run agreed site improvements and optimizations.
- Access control: role-based permissions, explicit approvals for high-impact actions, and session-level controls.
- Operational logs: workflow and maintenance actions may be logged for reliability, QA, and incident response.
- Client data scope: we process only data required to run agreed automations and site operations.
- No unauthorized resale: client data processed by our systems is never sold to third parties.
- Retention and deletion: site configurations and bot prompts are retained only per active service agreement and purged upon termination.
Data Retention and Deletion
We retain your personal information only as long as necessary to provide you with our services and for legitimate business purposes. Here's our data retention policy:
- Active Accounts: Data is retained while your account is active and you are receiving our services
- Account Termination: When you terminate your account or our service relationship ends, your personal data is deleted within 30 days
- Complete Data Purge: All personal information, files, and account data are permanently removed from our systems
- Supabase Deletion: Final deletion of data from our database provider (Supabase) is handled according to their enterprise deletion policies
- Backup Retention: Encrypted backups containing your data are purged within 90 days of account termination
We may retain some information for longer periods only if required by law or for legitimate business purposes such as preventing fraud.
Third-Party Disclosure and Data Sales
WE NEVER SELL YOUR DATA. We do not sell, trade, rent, or otherwise transfer your personally identifiable information to third parties for commercial purposes. Your data is never sold, period.
We may share your information only in the following limited circumstances:
- Service Providers: To trusted service providers (like Supabase for database hosting) who assist us in operating our website and providing services, provided they agree to keep this information confidential and secure
- Legal Requirements: To comply with legal requirements, such as a law, regulation, court order, subpoena, or similar legal process
- Protection: To protect against legal liability, to defend our rights or property, or to protect the safety of our users or the public
In all cases, we maintain strict controls over who has access to your data and ensure it is used only for the stated purposes.
Newsletter and Marketing Communications
If you request information, submit a form, or otherwise opt in to updates, we may send newsletters, service updates, or marketing communications from BishopTech. This includes:
- Email Communications: Updates about our services, new offerings, industry insights, and promotional content
- SMS Communications: Occasional text messages about important updates, service announcements, or promotional offers (where you have provided your phone number)
- Current and Future Campaigns: Marketing messages from our current service offerings and any future business ventures we may launch
Opt-Out: You can unsubscribe from marketing communications at any time by clicking the unsubscribe link in any email, replying "STOP" to SMS messages, or contacting us directly. Unsubscribing from marketing communications will not affect transactional emails related to services you have purchased.
Your Rights
You have certain rights regarding your personal information. These may include:
- The right to access personal information we hold about you
- The right to request correction of inaccurate personal information
- The right to request erasure of your personal information
- The right to object to processing of your personal information
- The right to request restriction of processing your personal information
- The right to data portability
To exercise any of these rights, please contact us using the information provided at the end of this Privacy Policy.
Cookies
We use first-party cookies and related browser storage to keep the site functional, support demo limits, and measure how the public site is used. Third-party analytics and tracking tools may also store identifiers or read browser data according to their own policies. For the current, specific list of browser storage behavior, see our Cookie Policy.
Children's Privacy
Our services are not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and you believe your child has provided us with personal information, please contact us so that we can delete such information.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: matt@bishoptech.dev
- Phone: (417) 629-7373
- Business Name: Matthew Bishop d/b/a BishopTech