Bubble Research Privacy Policy
1. Who we are
Bubble Research B.V. ("Bubble", "we", "us") provides a B2B SaaS platform for structured research workflows, available at https://app.bubble-research.ai (the "Bubble Platform"). Customers upload interview transcripts and business documents, and AI workflows produce research reports with verbatim citations.
Bubble Research B.V. Joos Banckersweg 25 2 1056 ER Amsterdam, Netherlands Dutch Chamber of Commerce (KvK): 97554413
Privacy contact: privacy@bubble-research.ai Support contact: support@bubble-research.ai
Bubble has not designated a data protection officer. For every question or request about personal data, contact privacy@bubble-research.ai.
2. What this policy covers
This policy explains how Bubble handles personal data:
- when you use the Bubble Platform or hold an account on it,
- when you or your organization communicate or do business with Bubble, and
- when Bubble processes research content on behalf of its customers.
It also lists your rights and the controls you have.
3. Bubble's two roles under the GDPR
The GDPR distinguishes two roles. A controller decides why and how personal data is processed. A processor handles personal data on a controller's instructions.
Bubble has both roles, for different data:
- Part A: Bubble as controller. For account data, security and audit records, usage and billing data, support correspondence, and the aggregated-insights purpose described in section 6, Bubble decides why and how the data is processed.
- Part B: Bubble as processor. For the research content that customers upload to the platform ("Customer Data") and the reports generated from it ("Deliverables"), the customer decides why and how the data is processed. The customer is the controller. Bubble processes that content only on the customer's instructions.
Part A: Data Bubble processes as controller
4. Data categories, purposes, legal bases, and retention
In the table below, "performance of the agreement" refers to Article 6(1)(b) GDPR, "legal obligation" to Article 6(1)(c) GDPR, and "legitimate interest" to Article 6(1)(f) GDPR.
| Category | What it includes | Why we process it | Legal basis | How long we keep it |
|---|---|---|---|---|
| Account data | Name, business email address, hashed password, role and workspace membership, records of connected applications you have authorized | Creating and securing your account, signing you in, controlling access, operating your organization's workspace | Performance of the agreement; legitimate interest in administering accounts that a customer creates for its own users | Duration of the agreement between Bubble and your organization, plus 90 days, then deleted. Earlier erasure on request, see section 15 |
| Security and audit records | Login history, IP address, browser and device information (user agent), security events such as failed logins and lockouts, access records including support-access (impersonation) sessions | Keeping accounts and workspaces secure, preventing abuse, investigating incidents, giving each customer a verifiable history of who accessed what | Legitimate interest in securing the platform and being able to demonstrate what happened; legal obligation where record-keeping is required | Kept live for 12 months, then archived for up to 5 years, about 6 years in total |
| Usage data | Workflow runs started, credits consumed, features used, operational metadata about workspace activity | Operating the service, credit accounting, troubleshooting, capacity planning, improving the products | Performance of the agreement; legitimate interest in running and improving the service | Duration of the agreement plus 90 days, except entries that are part of the audit log, which follow the audit schedule above |
| Billing and contract data | Customer company details, Order Forms, invoices, billing contact details, payment records, VAT details | Invoicing, payment administration, accounting | Performance of the agreement; legal obligation under tax and accounting law | As long as tax and accounting law requires, in the Netherlands generally 7 years |
| Support correspondence | Emails to support@bubble-research.ai and privacy@bubble-research.ai, messages through chat or in-app channels where made available, and our replies | Answering questions, resolving issues, handling requests | Performance of the agreement; legitimate interest in providing support | Duration of the agreement between Bubble and your organization, plus 2 years |
| Technical logs | Short-lived server and application logs that can include IP addresses, request details, and email addresses (for example around failed logins and account lockouts) | Keeping the service running and diagnosing faults | Legitimate interest in operating the service | 30 days, then deleted |
You need an account to use the Bubble Platform. Without the account data above, Bubble cannot give you access.
Where the data comes from: we receive account data from you, or from your organization's administrator when they invite you to the workspace. We receive billing and contract data from your organization.
5. Transactional email
Bubble sends account and service emails: workspace invitations, password resets, service, security, and billing notices, and feedback and error-report emails, which can include technical error details. These are delivered through our email provider Resend, configured for European Union sending (region eu-west-1). Resend processes the email content and delivery metadata as a processor for Bubble; see section 12.
6. Product improvement, aggregated insights, and model training: your choice
Bubble may analyze data from customer workspaces, including research content, metadata, and account attributes (for example, company size in relation to research topics), to improve the products, to produce aggregated insights, and to train models.
What we never do:
- Every published or derived output is aggregated. It never identifies a person or a company.
- Bubble does not train models on data that can identify a person or a company. Before any model training takes place, the data used for it is irreversibly anonymized.
- Bubble does not sell personal data.
You control this. Your organization chooses to participate or not when it signs the Order Form, and can opt out at any time by email to privacy@bubble-research.ai. Opting out excludes your organization's data from these analyses.
To be transparent about how this works: producing aggregated insights means Bubble processes data from your organization's workspace, which can include research content containing personal data, for Bubble's own purposes. For that processing Bubble is the controller. The data comes from your organization's workspace; Bubble does not use it to single out or identify individuals, and the outputs never identify anyone. The legal basis is Bubble's legitimate interest in improving its products, balanced by the aggregation safeguards and the opt-out above. Individuals can object at any time, see section 15.
7. Cookies and local storage
The Bubble Platform uses only storage that is strictly necessary to provide the service:
- a session cookie (httpOnly) used to keep you signed in, and
- browser localStorage entries holding session tokens.
The platform sets no advertising cookies and no third-party analytics or tracking cookies. Because only strictly necessary storage is used, the platform shows no cookie consent banner: consent is not required for storage that is strictly necessary to deliver the service you request.
The marketing website at bubble-research.ai is a separate surface, built on HubSpot (EU data center) and served through Cloudflare. It uses (verified 2026-07-13):
- strictly necessary cookies that need no consent: Cloudflare security and bot protection, HubSpot cookies required for the site to function, and the cookie that remembers your consent choice;
- optional cookies in three categories (Analytics, Advertisement, Functionality), all off by default and set only if you accept them through the cookie banner. If you decline, the website works normally and a single preference cookie remembers your choice. You can change your choice at any time through the cookie settings on the website;
- HubSpot forms and the meeting scheduler, which process the contact details you choose to submit (name, email, and whatever you enter) so we can respond or hold the meeting.
You can review and change your cookie choices at any time through the cookie settings on the website. HubSpot, Inc. (EU hosting region) processes website visitor data for us as a processor. Website visitor data is not combined with Bubble Platform account data. The website template additionally loads fonts from Google's global font service, which transmits your IP address to Google when a page loads; we are working to self-host these fonts, and this notice will be updated when that lands.
8. No analytics or advertising trackers
The Bubble Platform contains no third-party analytics tools and no advertising trackers. Bubble does not use personal data for advertising and does not share personal data with advertisers or data brokers.
The platform does currently load its fonts from an external service, Google Fonts, which receives your IP address when a page loads. This is not a tracker, but it is a disclosure of your IP address to Google; see section 12.
Part B: Customer Data and Deliverables, where Bubble is processor
9. What Customer Data and Deliverables are
Customer Data is the research content that a customer or its users upload to or submit on the Bubble Platform: interview transcripts and business documents (PDF, TXT, MD, DOCX). The reports and other outputs generated from Customer Data, including verbatim citation excerpts, are called Deliverables. Both belong to the customer, and both often contain personal data, for example the names and statements of interview participants. In this Part B, what is said about Customer Data applies equally to the personal data inside Deliverables.
10. The customer is the controller
For personal data inside Customer Data and Deliverables, the customer is the controller and Bubble is the processor:
- Bubble processes Customer Data only on the customer's documented instructions, under the data-processing section (a data processing agreement within the meaning of Article 28 GDPR) in the Bubble Terms and Conditions.
- The customer decides what to upload, which workflows to run, who sees the results, and when data is deleted or exported.
- The customer is responsible for having a lawful basis for the personal data in its research content and for informing its own data subjects.
- The Terms prohibit uploading special categories of personal data (such as health, biometric, or genetic data) and criminal-offence data, unless specific written safeguards have been agreed.
If you are a data subject whose personal data appears in a customer's research content (for example, you were interviewed): please contact the organization that ran the research. That organization is the controller and decides on your request. If your request reaches Bubble, we forward it to that organization without undue delay and assist it as the data processing agreement requires.
11. How Customer Data is handled
- Customer Data is hosted and processed in the European Union: Google Cloud (region europe-west1) for hosting and storage, and Google Vertex AI in EU regions for AI analysis using Gemini models.
- Bubble does not permit its AI infrastructure provider to use Customer Data or Deliverables for the provider's own purposes, including training the provider's models, beyond what is strictly necessary to provide the Bubble Platform.
- Staff access: normal support access to a customer workspace happens through an audited, time-boxed impersonation session that is visible to the customer in its own access log. Outside impersonation, Bubble staff can access operational metadata, and, for troubleshooting under the diagnostics clause in the Terms, run content at database level. All access is logged.
- Retention and deletion: Customer Data is retained for the duration of the agreement. After termination, the customer's tenant data is retained for 90 days and then deleted. The customer can request earlier deletion, or an export in a common machine-readable format, in writing at any time; exports are provided within 10 working days of a written request.
- Deletion has honest limits: verbatim quotes already embedded in generated reports remain until those reports are deleted; audit and access logs follow the retention schedule in section 4; and short-lived infrastructure backups age out on their own cycle.
Applies to both parts
12. Recipients of personal data
Bubble shares personal data only with the following recipients:
Processors working for Bubble. These providers process personal data on Bubble's instructions:
- Google Cloud EMEA Limited: hosting, storage, and AI processing (Google Vertex AI), in the European Union.
- Resend Inc.: transactional email, European Union sending region (eu-west-1).
Bubble announces additions to its sub-processors at least 1 week in advance, and customers can object under the mechanism in the data-processing section of the Terms.
Connected applications you direct data to. A customer administrator can enable connections to third-party applications, such as AI assistant applications, for its workspace (the feature is off by default). Each user then authorizes their own connection and can revoke it at any time; revocation takes effect from the next request. Through such a connection, the platform serves completed reports and library artifacts, including citation excerpts, and never raw uploaded files, to the connected application at the user's direction. The provider of a connected application receives that content under your organization's own agreement with that provider; connected applications are not Bubble sub-processors, and content already delivered to them is governed by that provider's agreement with your organization, including where that provider stores it. The currently supported applications are shown in the Bubble Platform.
Font delivery (Google Fonts). The platform currently loads its fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When a page loads, your browser requests the font files directly from Google, so Google receives your IP address and standard browser request data. Google may process these requests on servers outside the EU. Bubble intends to serve fonts from its own infrastructure; once that change ships, this disclosure will be removed.
Authorities. Bubble discloses personal data to competent authorities where the law requires it.
Beyond the recipients listed in this section, Bubble does not share personal data with any other recipients.
13. Where data is processed, and international transfers
All customer data processing by Bubble (hosting, storage, AI analysis) happens in the European Union: Google Cloud region europe-west1, Vertex AI EU regions, and transactional email through Resend's EU sending region. In normal operation, Bubble transfers no personal data outside the European Economic Area, with one exception that exists today: when a page loads, your browser sends your IP address directly to Google Fonts to fetch font files (section 12), and Google may process those requests outside the EU. This exception ends when Bubble serves fonts from its own infrastructure.
If a transfer outside the EEA ever becomes necessary, it will take place only with the safeguards the GDPR requires: an adequacy decision of the European Commission or standard contractual clauses.
One case is under your organization's own control: content that a user directs to a connected application (section 12) goes to that provider under your organization's agreement with it. Depending on that agreement, the provider may process the content outside the EU.
14. Security
Bubble protects personal data with technical and organizational measures that include: TLS/HTTPS encryption with HSTS for all external traffic; tenant isolation enforced through row-level security in the database; bcrypt password hashing with a complexity policy; account lockout and login throttling; short-lived access tokens with rotating refresh tokens and reuse detection; application-level encryption (AES-256-GCM) of stored third-party AI provider credentials; secrets kept in a managed secret store; an append-only audit log; audited, time-boxed, customer-visible support impersonation; daily automated database backups with point-in-time recovery; infrastructure located entirely in the EU; dependency scanning; deploy gates with staged rollout and automatic rollback; and security headers.
Further information on Bubble's security measures is available on request via support@bubble-research.ai.
If a personal data breach occurs, Bubble notifies the competent authority and affected individuals as the GDPR requires, and, for Customer Data, notifies the affected customer without undue delay after becoming aware, with the information the customer needs for its own notification duties.
15. Your rights
For the data described in Part A, you have the following rights under the GDPR:
- Access: ask what personal data Bubble holds about you and receive a copy.
- Rectification: have incorrect data corrected.
- Erasure: have your personal data deleted.
- Restriction: have processing of your data limited while a question about it is resolved.
- Objection: object to processing based on legitimate interest, including the aggregated-insights purpose in section 6.
- Portability: receive data you provided in a machine-readable format.
To exercise a right, email privacy@bubble-research.ai. We will verify your identity and answer within one month. Verified erasure requests are fulfilled within 30 days. Erasure has honest limits: records that the law requires us to keep (for example invoices) and audit records within their retention schedule are kept; your personal identifiers are removed or anonymized everywhere else.
If your personal data appears inside a customer's research content, the customer is the controller: contact that organization (see section 10). We forward any request we receive to the customer without undue delay.
You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority of the EU country where you live or work.
16. Your choices and controls
- Aggregated insights and model training: your organization chooses in or out at signing and can opt out at any time by email; individuals can object at any time (sections 6 and 15).
- Connected applications: the feature is off by default; a customer administrator enables it; each user authorizes their own connection and can revoke it at any time, effective from the next request; the administrator can disable the feature for the whole workspace.
- Export: your organization can request an export of its data in a common machine-readable format at any time; exports are provided within 10 working days of a written request.
- Deletion: individuals can request erasure (fulfilled within 30 days); customers can request deletion of their tenant data at any time, and tenant data is in any case deleted 90 days after the agreement ends.
17. No automated decision-making
Bubble does not make automated decisions about you that have legal or similarly significant effects. The platform generates research reports on the customer's instruction; the reports are decision-support material that people review and act on.
18. Amy
The Free plan gives access to Amy, a product-marketing agent package that is used inside the customer's own account with a third-party AI assistant or large language model (LLM) service of the customer's choice (for example Anthropic's Claude, OpenAI's ChatGPT or Google Gemini). Conversations with Amy take place in the customer's own account with that provider, under the customer's agreement with that provider. They never touch Bubble's systems, and Bubble receives none of that conversation data.
19. Audience
The Bubble Platform is a business tool for professional users. It is not directed at children.
20. Changes to this policy
When this policy changes, Bubble publishes the new version with a new version number and date.