PRIVACY, PLAINLY
A clear look at
what Bodhi keeps.
Bodhi is an AI surf specialist in a small California pilot. This page explains the information used to run the pilot and the choices you have.
Joining the first 25
Signup asks for a California home region, Personal or Crew access, and acknowledgement of the pilot limits. A short-lived join code verifies access through the phone number that sends it to Bodhi. Opening the form does not reserve a place. Codes expire after 15 minutes; their hashed records are cleared after expiry. The code is excluded from Bodhi’s conversation history and model input.
We retain a protected identifier linked to your sending number, your pilot access type, home region and linked chat permissions for the duration of this pilot. These admission records keep the 25-person limit and your access working across restarts. They remain when you use “forget me”; that command clears surf memories and logs, rather than resetting your admission or daily allowance. Per-person usage counts and signup-notice limits expire after 31 days. We do not display phone numbers or chat messages on the public signup page.
Reports run only after you ask and Bodhi confirms a saved schedule. Say “cancel my daily report” to stop one. Incomplete routine setup details expire after ten minutes. Messages you send are handled by the services described below; no message is sent on your behalf by submitting the website form.
Early-access requests
The form collects your email, home waters, personal or crew preference, and your interest at the proposed price. For a crew, it also asks for size and payment-sharing preference. We save which proposed offer you saw and a broad referral category when present in the link. We use these details to understand demand and review pilot requests, retaining each request for up to 90 days. Interest is not a purchase, and your email is not verified by this form.
The optional checkbox lets us email you about pilot access and a short feedback conversation. Leaving it unchecked still saves your request. No automatic email, enrollment, subscription or charge happens on submission.
After saving, you receive a private removal link. Keep it to remove that individual request, including its contact permission and preferences, from the active waitlist. Repeated submissions are separate requests with separate removal links. Avoid sharing your private link; it controls that request.
Understanding interest in Bodhi
We count page views, plan-button clicks and form starts by day and broad referral category. These are event counts, not a list of individual visitors. The counts contain no email, visitor ID, full referring URL or browsing history. We use no analytics cookies, browser fingerprinting or advertising trackers. Our page skips these event reports when your browser signals Global Privacy Control or Do Not Track.
Aggregate events are kept for 90 days and cannot be traced back to an individual request for deletion. We briefly use network address information in memory to limit abuse; we do not save it in these metrics. Hosting and network providers may keep their own access logs. Request summaries use the latest active submission for each email to reduce duplicates; they measure stated interest, not revenue.
Your crew and your personal profile
In the pilot, Bodhi processes messages addressed to him and relevant surf conversation according to the chat’s settings. He keeps useful surf context for each chat, such as stated preferences, gear and goals, and can log completed sessions people report. A session log is not proof of every time someone surfed.
Your optional personal profile is linked to your phone identity. If you turn it on, your enabled surf preferences can follow you between chats. Each crew’s conversations and session journal stay separate. Group messages and answers are visible to people in that group; a new participant may see context if the messaging provider keeps the same group identity.
Ask Bodhi for “memory” or “profile” to view the relevant saved details. “profile off” stops cross-chat profile sharing. “memory off” stops remembering you in that chat. “forget me” clears your linked personal and crew records from the active application and disables relearning. These controls do not erase existing messages on other people’s phones or provider systems.
Photos and sources
Photo analysis uses images supplied in the current addressed message. Unmentioned group photos are not analyzed. Supported photos are resized and stripped of metadata before their pixels are sent for model analysis. Image bytes are not saved in Bodhi’s conversation database; when memory is on, a text marker and the answer may remain.
Image-derived guesses are not automatically saved as personal surf facts. Bodhi can research surf and product questions using web search; he is instructed to keep private chat details out of search queries. The current release does not independently redact every generated search query.
Operating the pilot
A private dashboard shows aggregate surfer, chat, message, session and waitlist counts, along with service and model usage. It does not expose conversations, phone numbers or email addresses. Incoming and accepted-reply totals have no individual identifiers and remain after message cleanup; daily message counts are kept for 90 days. These anonymous totals cannot be attributed back to an individual for deletion. Separate provider-usage metadata contains token counts, model and date, with no chat text or person identifiers.
Dashboard access uses an essential, read-only browser cookie that expires after seven days. It is not an analytics cookie. A private access link expires after ten minutes and works once. Signing out clears the viewing cookie from that browser.
How long records stay
Ordinary messages, completed jobs and outbound message content expire from active application storage after 30 days. Durable surf facts expire after a year without updates. Reported sessions remain until you delete them or use the applicable memory/deletion controls.
Managed backups are kept on the persistent disk. After successful runs, retention keeps up to seven copies less than seven days old. A backup failure can preserve older good copies longer. Deleting an active record does not rewrite prior backups; a restoration requires later deletion requests to be reapplied before service resumes.
The services behind Bodhi
Photon transports iMessage conversations, OpenAI processes model requests, and Render hosts Bodhi and its persistent storage. These providers have their own processing and retention rules, separate from Bodhi’s application records. OpenAI requests use store: false; that is not a promise of zero provider retention.
Read the provider details: Photon privacy, OpenAI data controls and Render privacy.
Optional connections come later
Apple Health and calendar connections are planned, and are not connected by this website or a text message. A future connection will ask each person for the required account or device permission, with separate choices about sharing information with a crew. One person’s request cannot grant access to another person’s account.
Updated September 8, 2026.