Privacy Policy
Last updated: 2026-09-14
Who We Are
Volkan Suner (trading as Bilg) ("we," "us") operates Bilg (the "Service"). You can reach us at [email protected].
We process personal data in two different roles:
- As controller for your account, authentication, technical, and subscription data. We decide how and why this data is processed, and this policy describes that processing.
- As processor for personal data contained in the content that you or your organization add to projects (documents, roadmap data, and comments). We process that data only to provide the Service, on the instructions of the customer who controls the project. If your personal data appears in a project that belongs to someone else, please contact that customer first; we will help them respond to your request.
Data We Collect
We collect the following categories of data:
- Account data: your name and email address.
- Authentication data: session records, including your IP address and user agent, used to keep you signed in and secure your account.
- Content data: documents you upload (Markdown, PDF, DOCX), document version history, roadmap data (epics, tasks, decisions, open questions), and comments. The search queries you run are processed to return results and are not stored.
- Technical data: audit log entries recording actions taken in your account, server logs, and error reports sent to our error monitoring provider (Sentry), with credentials and email addresses removed.
- Subscription data: we mirror your subscription status (plan, renewal date, active or cancelled) and the Paddle customer and subscription identifiers that link it to your account. We never receive or store your card details.
How We Use Data
We use this data to provide and operate the Service (including document storage, semantic search, and roadmap features), to maintain account security, to communicate with you about your account or the Service, to manage your subscription, and to comply with legal obligations.
Legal Bases
Where the General Data Protection Regulation or a similar law applies, we process your data on the following legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (such as securing accounts), and compliance with a legal obligation (such as tax record-keeping).
Subprocessors
We use the following subprocessors to provide the Service:
- Hetzner Online GmbH
- Google LLC
- Cloudflare, Inc.
- Resend, Inc.
- Functional Software, Inc. (Sentry)
Document text excerpts and search queries are sent to Google LLC through the Gemini API to create text embeddings for semantic search. We use Gemini as a paid API service. Under Google's terms for paid services, Google does not use this content to improve its products or to train its models, and may keep it only for a limited period to detect abuse, as described in the Gemini API Additional Terms of Service.
A full list with purpose, data shared, and location is maintained on our Subprocessors page.
Payment Provider
Payments are handled by Paddle.com Market Limited, which acts as our Merchant of Record. Paddle is not our subprocessor: it processes your name, email address, billing address, and payment details as an independent controller, under its own privacy notice. Paddle keeps its own transaction records, including where tax law requires it to. Requests about data that Paddle holds should be sent to Paddle; if you contact us instead, we will forward them.
International Transfers
Some of our subprocessors are located outside the European Union: Google LLC, Cloudflare, Inc., and Resend, Inc. Functional Software, Inc. (Sentry) stores our error reports in the EU but is a US company. Where personal data is transferred outside the EU/EEA, we rely on the data processing terms of these providers, which incorporate the European Commission's standard contractual clauses or an equivalent safeguard.
Retention
Documents you delete are soft-deleted and permanently removed after 30 days. Archived versions of binary files (PDF, DOCX) are retained for 90 days. A password account that never verifies its email is deleted after 7 days. In-app notifications are deleted 30 days after you read them, and 90 days after they were created in any case. Audit log entries are kept while your account exists. Server logs are kept for up to 30 days, and error reports in Sentry for up to 90 days.
You can close your account yourself from Settings → Account. Closing your account is permanent: we cancel any active paid subscription immediately and delete your account data shortly after you confirm the request. This includes the projects you own, your comments, your project memberships and assignments, your audit log entries, and the subscription data we mirror from Paddle. Documents, tasks, and other roadmap items you added to projects owned by someone else stay in those projects, because other members rely on them. If you want personal data in that content removed, contact us and we will review the request together with the project's owner. Deleted data can still remain in our backups until those backups themselves age out, for up to 8 weeks (daily backups are kept 14 days, weekly backups 8 weeks).
You can also export your data from Settings → Account. The export is a ZIP file containing your account information and the projects you own (documents, roadmap data, and their metadata); we send the download link by email and show it on the page. The exported file is kept for 7 days and then deleted.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw your consent where we rely on it. You can exercise most of these rights yourself from Settings → Account (see Retention above); for anything else, contact us at [email protected].
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work.
Security
We use technical and organizational measures, including encrypted transport and access controls, to protect your data. No system is completely secure, and we cannot guarantee absolute security.
Children
The Service is intended for people aged 18 or older, and we do not knowingly collect personal data from anyone under 18.
Changes to This Policy
We may update this Privacy Policy from time to time. If a change is material, we will provide notice, such as by email or an in-product notice, before it takes effect.
Contact
- Operator: Volkan Suner (trading as Bilg)
- Email: [email protected]