Privacy Policy

1. Responsible Party

Bonus Service BS GmbH Dorotheenstr. 5, 45130 Essen, Germany

The responsible party decides alone or jointly with others on the purposes and means of processing personal data.

2. Overview

The following information provides an overview of what happens to your personal data when you use BonusFlow. BonusFlow is a voice-based personal AI assistant for managing todos, reminders, calendar entries, life areas, and personal knowledge (Second Brain).

Personal data is any information that can be used to personally identify you.

3. Data Collection

3.1 Registration and User Account

Data collected:

  • Name
  • Email address
  • Password (stored encrypted)

Purpose: Provision of the BonusFlow service and management of your user account pursuant to Art. 6 (1) (b) GDPR (contract performance).

Retention: As long as your user account is active. After account deletion, your data will be deleted within 30 days, unless statutory retention requirements apply.

3.2 Authentication and Login

BonusFlow uses Better Auth for authentication — a self-hosted solution that runs entirely on our own servers in Germany. We do not use third-party authentication services. Login is possible via email/password.

Legal basis: Art. 6 (1) (b) GDPR (contract performance).

3.3 Voice Input and Transcription (Speech-to-Text)

How it works: Your voice recordings are transmitted (TLS-encrypted) to Mistral AI Voxtral and converted to text there. Mistral AI is a European company headquartered in France.

Provider: Mistral AI SAS, 16 Passage Jouffroy, 75009 Paris, France (EU)

What is transmitted: Your microphone audio recording.

Processing location: Primarily EU (France). In exceptional cases, Mistral may use sub-processors outside the EU; in such cases, EU Standard Contractual Clauses apply under Art. 46 GDPR.

Retention at Mistral: According to Mistral's own privacy policy, input and output data is retained for a maximum of 30 rolling days for abuse monitoring, then automatically deleted. As paid API customers, we have contractual assurance that your data is not used to train AI models.

Speech output (Text-to-Speech): The app's voice responses are generated entirely locally on your device using your operating system's native speech synthesis (Web: Browser Speech API, Mobile: expo-speech, Desktop: OS-native speech). No data leaves your device during speech output.

Legal basis: Art. 6 (1) (b) GDPR (contract performance).

Mistral privacy details: https://legal.mistral.ai/terms/privacy-policy

3.4 Text Processing via AI (Intent Recognition)

After transcription, the resulting text (your spoken commands) is transmitted to a separate Mistral API endpoint for intent recognition and structuring.

Provider: Mistral AI SAS, 16 Passage Jouffroy, 75009 Paris, France (EU)

What is transmitted: The transcribed text of your voice recording.

Processing location: Primarily EU (France), analogous to transcription.

Purpose: Understanding your intent and extracting structured data (todos, reminders, calendar entries, lists) pursuant to Art. 6 (1) (b) GDPR (contract performance).

Retention at Mistral: As in 3.3 — 30 rolling days for abuse monitoring, no use for model training.

Mistral privacy details: https://legal.mistral.ai/terms/privacy-policy

3.5 Todos, Reminders, and Calendar Entries

Data collected:

  • Todo items (title, description, due date, status)
  • Reminders (text, date/time)
  • Calendar entries (title, date/time, notes)

Purpose: Core function of BonusFlow — managing your personal tasks and schedule pursuant to Art. 6 (1) (b) GDPR (contract performance).

Storage: Your data is stored on our servers at Hetzner Online GmbH in Germany.

Retention: As long as your account is active. You can delete individual items at any time.

3.5a Calendar Integration (ICS Feed and Google Calendar)

ICS Feed: BonusFlow generates a personal ICS calendar feed URL that you can subscribe to with any calendar application (Apple Calendar, Outlook, etc.). The ICS feed contains your calendar entries and reminders. The feed URL contains a unique, non-guessable token. No authentication data of third-party calendar apps is transmitted to us.

Google Calendar (optional): If you choose to connect Google Calendar, BonusFlow uses Google OAuth 2.0 to obtain read/write access to your Google Calendar. This connection is entirely optional and requires your explicit consent.

Data exchanged with Google:

  • Calendar events (title, date/time, description) are synced between BonusFlow and Google Calendar
  • Your Google account email is used for identification only

Legal basis: Art. 6 (1) (a) GDPR (consent) for the optional Google Calendar connection. You can revoke access at any time in your account settings or in your Google account settings.

Google's privacy policy: https://policies.google.com/privacy

3.6 Life Areas and Personal Knowledge

Data collected:

  • Life areas (e.g., shopping list, sports, health, supplements)
  • Items within life areas (content, notes, dosage information)
  • Personal facts (e.g., allergies, contacts, preferences — only when you actively store them via "remember" commands)

Purpose: Organization of your daily life in thematic areas pursuant to Art. 6 (1) (b) GDPR (contract performance).

Storage: Your data is stored on our servers at Hetzner Online GmbH in Germany.

Retention: As long as your account is active. You can delete individual items at any time.

Note on health data: Information about medications, supplements, or health-related facts that you voluntarily store may qualify as special categories of personal data (Art. 9 GDPR). Processing is based on your explicit consent (Art. 9 (2) (a) GDPR), which you provide by actively storing such information.

3.7 Semantic Search (Second Brain)

How it works: To enable semantic search across your data, the text content of your entries (todos, reminders, calendar entries, life areas, personal facts) is converted into vector representations (embeddings).

Embedding provider: Mistral AI SAS (EU, France) — identical to the AI text processing described in section 3.4. Only the text of your entries is transmitted, no audio data.

Vector storage: The computed vector data is stored in a self-hosted Qdrant vector database on our server at Hetzner in Germany. No data is shared with third parties.

Purpose: Enables intelligent, meaning-based search across all your data (e.g., "When was my last doctor's appointment?") pursuant to Art. 6 (1) (b) GDPR (contract performance).

Availability: This feature is only available on the Pro plan and during the trial period.

Deletion: When your account is deleted, all vector data is completely removed along with your other data.

3.8 Trial Period, Subscription Management and Account Deletion

How the trial works: Upon registration, new users receive a free 14-day trial with access to all features and up to 200 voice commands per day. No payment information is required for the trial.

Data collected:

  • Trial start date
  • Trial expiration date
  • Current subscription plan and status

Purpose: Managing your subscription and ensuring access to the correct features pursuant to Art. 6 (1) (b) GDPR (contract performance).

After the trial ends: If you do not choose a paid plan, your account remains intact — you can still log in and view previously stored data. Voice commands and the creation of new entries are paused until you select a plan. There is no automatic downgrade to a free plan, no automatic charge, and no automatic account deletion. You will not be charged without your explicit action.

Manual account deletion: In Settings → "Danger Zone" you will find the "Delete account" button. Upon confirmation, all your personal data is permanently and irrevocably deleted: user account, todos, notes, reminders, calendar entries, life areas, stored facts, vector embeddings, subscription history and usage statistics. Deletion takes effect immediately and cannot be reversed. Statutory retention obligations (e.g., for invoice records under tax law) remain unaffected — such mandatory records are stored separately and permanently deleted after the statutory period expires.

3.9 Payment Data

Data collected:

  • Payment information is collected and processed directly by our payment processor Stripe (with EU data processing agreement)
  • We do not store credit card numbers or bank details

Purpose: Processing payments for BonusFlow subscriptions pursuant to Art. 6 (1) (b) GDPR (contract performance).

Privacy details: https://stripe.com/de/privacy

3.10 Server Log Files

Automatically collected information:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname of the accessing computer
  • Time of server request
  • IP address

No merging with other data sources. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in technically error-free presentation and optimization). Retention: 7 days.

4. Cookies

Technically Necessary Cookies

  • Session cookie: Required for authentication and maintaining your login
  • Locale cookie: Stores your language preference

We use no tracking cookies, no advertising cookies, and no analytics cookies.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest) — no cookie consent banner required for technically necessary cookies only.

5. Hosting and Technical Service Providers

5.1 Server Hosting

Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

Server location: Germany

Legal basis: Art. 6 (1) (f) GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place.

Privacy details: https://www.hetzner.com/de/rechtliches/datenschutz

5.2 AI Voice Processing (Audio + Text)

Provider: Mistral AI SAS, 16 Passage Jouffroy, 75009 Paris, France (EU)

What is processed: Audio recordings of your voice commands (a few seconds long, transcribed to text by the Voxtral Small model and then immediately discarded — no audio is stored at Mistral), the resulting transcript text, and — if you use semantic search (Pro plan only) — vector embeddings of your notes, facts and reminders.

Server location: EU (France)

Legal basis: Art. 6 (1) (b) GDPR (contract performance). A data processing agreement pursuant to Art. 28 GDPR is in place.

5.3 Vector Database (Semantic Search)

Provider: Qdrant (open-source software), self-hosted on our Hetzner server in Germany

What is processed: Vector representations (numerical representations) of your text content. The original content cannot be reconstructed from the vectors.

Server location: Germany (Hetzner)

Legal basis: Art. 6 (1) (b) GDPR (contract performance). No data is shared with third parties — the entire vector database is operated exclusively on our own infrastructure.

5.4 Payment Processing

Provider: Stripe, Inc. (with EU data processing agreement)

Legal basis: Art. 6 (1) (b) GDPR (contract performance).

5.5 Google Calendar (optional)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

What is processed: Calendar events (title, date/time, description) — only when the user actively connects Google Calendar via OAuth.

Server location: EU (Ireland)

Legal basis: Art. 6 (1) (a) GDPR (consent). The user can revoke access at any time.

Safeguards: EU-US Data Privacy Framework, Standard Contractual Clauses (SCC).

5.6 Email Service

Provider: ALL-INKL.COM - Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany

Server location: Germany

Purpose: Account confirmation, password reset, service notifications

Legal basis: Art. 6 (1) (b) GDPR (contract performance).

6. SSL/TLS Encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by "https://" in the URL bar.

7. Your Rights

You have the following rights regarding your personal data:

  • Right to information (Art. 15 GDPR) – What data do we store about you?
  • Right to rectification (Art. 16 GDPR) – Correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) – Deletion of your data ("right to be forgotten")
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR) – Export of your data in a machine-readable format
  • Right to object (Art. 21 GDPR) – Against processing based on legitimate interest
  • Right to withdraw consent (Art. 7 (3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

To exercise your rights, contact us at: datenschutz@bonusflow.de

8. Right to Lodge a Complaint with a Supervisory Authority

In case of violations of the GDPR, you have the right to lodge a complaint with the competent supervisory authority. The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestr. 2-4, 40213 Düsseldorf https://www.ldi.nrw.de

A list of all data protection authorities in Germany can be found at: https://www.bfdi.bund.de

9. Data Security

We implement the following technical and organizational measures:

  • SSL/TLS encryption for all data transmissions
  • Encrypted storage of passwords (bcrypt)
  • Speech output (Text-to-Speech) runs entirely on the user's device
  • Transcription and AI processing via Mistral AI, server location EU (France)
  • Server infrastructure for structured user data in Germany (Hetzner)
  • Regular security updates and access controls

10. Data Minimization

BonusFlow is designed with data minimization in mind:

  • Transcription and intent recognition run at Mistral AI in France (EU) — no US providers, no data transfer to third countries (except exceptional cases with EU Standard Contractual Clauses)
  • Mistral retains audio and text inputs for a maximum of 30 rolling days for abuse monitoring and does not use them for model training
  • Speech output (text-to-speech) runs entirely locally on your device — no data leaves the device here
  • We store only what is necessary to provide the service
  • No analytics or tracking of your behavior

11. Data Retention Periods

Data CategoryRetention Period
User account data (name, email)Until account deletion + 30 days
Todos, reminders, calendar entriesUntil deleted by user or account deletion + 30 days
Life areas and personal factsUntil deleted by user or account deletion + 30 days
Vector data (embeddings)Until account deletion + 30 days
Voice/audio data (at Mistral Voxtral)Max. 30 rolling days for abuse monitoring, then automatic deletion
Speech output (Text-to-Speech)Runs entirely locally on the device — nothing stored
Server log files7 days
Payment data (at Stripe)Per Stripe's retention policy; we do not store payment details
Trial period dataUntil account deletion + 30 days
Invoices and billing records10 years (German tax law, §§ 147 AO, 257 HGB)

After account deletion, all personal data is permanently deleted within 30 days, unless statutory retention obligations (e.g., tax law) require longer storage.

12. Changes to this Privacy Policy

Last updated: March 2026

This privacy policy may be updated as our service evolves or due to changes in legal requirements. The current version is always available on our website. We will notify registered users of significant changes by email.