Legal

Privacy

Short, because there is little to say. This site has no analytics, no cookies of its own, no accounts and no third-party resources.

Controller

What happens when you read a page

Pages are rendered by our own server and delivered over HTTPS. Fonts, styles and scripts are served from this domain - there is no Google Fonts request, no analytics script, no tag manager, no advertising pixel and no embedded content from other sites. Nothing is stored in your browser: this site sets no cookies of its own and needs no consent banner, because there is nothing to consent to.

The web server writes standard access logs - IP address, time, requested path, referrer and user agent - which are needed to operate and secure the service and are retained only as long as required for that purpose. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a functioning and secure website.

The developer tools

Four tools on this site do something beyond displaying text. What each one does with data differs, so they are listed separately.

ToolLeaves your browser?What is stored
Widget generatorNoNothing. The API key you type stays in the page and is never transmitted.
Prompt reviewerNoNothing. The analysis runs in your browser; no model is called.
Voice latency testTiming requests only No audio is recorded, transmitted or stored. Microphone access, if you grant it, is used to time acquisition and is released immediately. The timing requests are ordinary requests to this server and appear in the access log like any other.
Webhook testerYes, by design Whatever is sent to the inbox URL you created - headers and body - is held in memory on our server for at most 30 minutes, capped at the newest 25 requests and 64 KB of body each, and is lost on any restart. Cookie and forwarding headers are discarded on arrival. It is never written to disk and never passed to anyone.
The webhook tester is a public inbox

Anyone who has the URL can read what arrives at it. It exists to inspect a test delivery, not to receive production traffic. A real bitpull conversation delivery contains a caller's number, name and transcript - personal data under the GDPR - and sending that here would make you the controller of a disclosure you did not intend. Learn the payload shape, then point the webhook at your own endpoint.

The status page

The status page triggers a request from our server to the bitpull.ai health endpoint. It is made by us, not by your browser: your IP address is not disclosed to that service, and the result is cached and shared between visitors.

Outbound links

Links to bitpull.ai, neob.ai, neob.dev and third-party documentation are ordinary links. Nothing is loaded from those sites while you are on this one, and they are only contacted if you click. Their own privacy statements apply once you do.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna). Requests go to info@bitpull.ai.

Note that a webhook tester inbox cannot be looked up on request - it is identified only by a random id held in memory, we have no way to link one to a person, and it disappears within thirty minutes regardless.

The bitpull.ai service

This statement covers the bitpull.io website only. If you use the bitpull AI agent platform, the processing of conversations, transcripts and caller data is governed by the privacy statement and data processing agreement published on bitpull.ai. Those documents, not this page, are the ones that matter for your deployment.