Logo research large
Product Services Pricing About us Blog
Log in Book a call
Product Services Pricing About us Blog Log in Book a call

Bubble Research Privacy Policy

Version 1.0, dated 2026-07-13.

1. Who we are

Bubble Research B.V. ("Bubble", "we", "us") provides a B2B SaaS platform for structured research workflows, available at https://app.bubble-research.ai (the "Bubble Platform"). Customers upload interview transcripts and business documents, and AI workflows produce research reports with verbatim citations.

Bubble Research B.V. Joos Banckersweg 25 2 1056 ER Amsterdam, Netherlands Dutch Chamber of Commerce (KvK): 97554413

Privacy contact: privacy@bubble-research.ai Support contact: support@bubble-research.ai

Bubble has not designated a data protection officer. For every question or request about personal data, contact privacy@bubble-research.ai.

2. What this policy covers

This policy explains how Bubble handles personal data:

  • when you use the Bubble Platform or hold an account on it,
  • when you or your organization communicate or do business with Bubble, and
  • when Bubble processes research content on behalf of its customers.

It also lists your rights and the controls you have.

3. Bubble's two roles under the GDPR

The GDPR distinguishes two roles. A controller decides why and how personal data is processed. A processor handles personal data on a controller's instructions.

Bubble has both roles, for different data:

  • Part A: Bubble as controller. For account data, security and audit records, usage and billing data, support correspondence, and the aggregated-insights purpose described in section 6, Bubble decides why and how the data is processed.
  • Part B: Bubble as processor. For the research content that customers upload to the platform ("Customer Data") and the reports generated from it ("Deliverables"), the customer decides why and how the data is processed. The customer is the controller. Bubble processes that content only on the customer's instructions.

Part A: Data Bubble processes as controller

4. Data categories, purposes, legal bases, and retention

In the table below, "performance of the agreement" refers to Article 6(1)(b) GDPR, "legal obligation" to Article 6(1)(c) GDPR, and "legitimate interest" to Article 6(1)(f) GDPR.

CategoryWhat it includesWhy we process itLegal basisHow long we keep it
Account dataName, business email address, hashed password, role and workspace membership, records of connected applications you have authorizedCreating and securing your account, signing you in, controlling access, operating your organization's workspacePerformance of the agreement; legitimate interest in administering accounts that a customer creates for its own usersDuration of the agreement between Bubble and your organization, plus 90 days, then deleted. Earlier erasure on request, see section 15
Security and audit recordsLogin history, IP address, browser and device information (user agent), security events such as failed logins and lockouts, access records including support-access (impersonation) sessionsKeeping accounts and workspaces secure, preventing abuse, investigating incidents, giving each customer a verifiable history of who accessed whatLegitimate interest in securing the platform and being able to demonstrate what happened; legal obligation where record-keeping is requiredKept live for 12 months, then archived for up to 5 years, about 6 years in total
Usage dataWorkflow runs started, credits consumed, features used, operational metadata about workspace activityOperating the service, credit accounting, troubleshooting, capacity planning, improving the productsPerformance of the agreement; legitimate interest in running and improving the serviceDuration of the agreement plus 90 days, except entries that are part of the audit log, which follow the audit schedule above
Billing and contract dataCustomer company details, Order Forms, invoices, billing contact details, payment records, VAT detailsInvoicing, payment administration, accountingPerformance of the agreement; legal obligation under tax and accounting lawAs long as tax and accounting law requires, in the Netherlands generally 7 years
Support correspondenceEmails to support@bubble-research.ai and privacy@bubble-research.ai, messages through chat or in-app channels where made available, and our repliesAnswering questions, resolving issues, handling requestsPerformance of the agreement; legitimate interest in providing supportDuration of the agreement between Bubble and your organization, plus 2 years
Technical logsShort-lived server and application logs that can include IP addresses, request details, and email addresses (for example around failed logins and account lockouts)Keeping the service running and diagnosing faultsLegitimate interest in operating the service30 days, then deleted

You need an account to use the Bubble Platform. Without the account data above, Bubble cannot give you access.

Where the data comes from: we receive account data from you, or from your organization's administrator when they invite you to the workspace. We receive billing and contract data from your organization.

5. Transactional email

Bubble sends account and service emails: workspace invitations, password resets, service, security, and billing notices, and feedback and error-report emails, which can include technical error details. These are delivered through our email provider Resend, configured for European Union sending (region eu-west-1). Resend processes the email content and delivery metadata as a processor for Bubble; see section 12.

6. Product improvement, aggregated insights, and model training: your choice

Bubble may analyze data from customer workspaces, including research content, metadata, and account attributes (for example, company size in relation to research topics), to improve the products, to produce aggregated insights, and to train models.

What we never do:

  • Every published or derived output is aggregated. It never identifies a person or a company.
  • Bubble does not train models on data that can identify a person or a company. Before any model training takes place, the data used for it is irreversibly anonymized.
  • Bubble does not sell personal data.

You control this. Your organization chooses to participate or not when it signs the Order Form, and can opt out at any time by email to privacy@bubble-research.ai. Opting out excludes your organization's data from these analyses.

To be transparent about how this works: producing aggregated insights means Bubble processes data from your organization's workspace, which can include research content containing personal data, for Bubble's own purposes. For that processing Bubble is the controller. The data comes from your organization's workspace; Bubble does not use it to single out or identify individuals, and the outputs never identify anyone. The legal basis is Bubble's legitimate interest in improving its products, balanced by the aggregation safeguards and the opt-out above. Individuals can object at any time, see section 15.

7. Cookies and local storage

The Bubble Platform uses only storage that is strictly necessary to provide the service:

  • a session cookie (httpOnly) used to keep you signed in, and
  • browser localStorage entries holding session tokens.

The platform sets no advertising cookies and no third-party analytics or tracking cookies. Because only strictly necessary storage is used, the platform shows no cookie consent banner: consent is not required for storage that is strictly necessary to deliver the service you request.

The marketing website at bubble-research.ai is a separate surface, built on HubSpot (EU data center) and served through Cloudflare. It uses (verified 2026-07-13):

  • strictly necessary cookies that need no consent: Cloudflare security and bot protection, HubSpot cookies required for the site to function, and the cookie that remembers your consent choice;
  • optional cookies in three categories (Analytics, Advertisement, Functionality), all off by default and set only if you accept them through the cookie banner. If you decline, the website works normally and a single preference cookie remembers your choice. You can change your choice at any time through the cookie settings on the website;
  • HubSpot forms and the meeting scheduler, which process the contact details you choose to submit (name, email, and whatever you enter) so we can respond or hold the meeting.

You can review and change your cookie choices at any time through the cookie settings on the website. HubSpot, Inc. (EU hosting region) processes website visitor data for us as a processor. Website visitor data is not combined with Bubble Platform account data. The website template additionally loads fonts from Google's global font service, which transmits your IP address to Google when a page loads; we are working to self-host these fonts, and this notice will be updated when that lands.

8. No analytics or advertising trackers

The Bubble Platform contains no third-party analytics tools and no advertising trackers. Bubble does not use personal data for advertising and does not share personal data with advertisers or data brokers.

The platform does currently load its fonts from an external service, Google Fonts, which receives your IP address when a page loads. This is not a tracker, but it is a disclosure of your IP address to Google; see section 12.

Part B: Customer Data and Deliverables, where Bubble is processor

9. What Customer Data and Deliverables are

Customer Data is the research content that a customer or its users upload to or submit on the Bubble Platform: interview transcripts and business documents (PDF, TXT, MD, DOCX). The reports and other outputs generated from Customer Data, including verbatim citation excerpts, are called Deliverables. Both belong to the customer, and both often contain personal data, for example the names and statements of interview participants. In this Part B, what is said about Customer Data applies equally to the personal data inside Deliverables.

10. The customer is the controller

For personal data inside Customer Data and Deliverables, the customer is the controller and Bubble is the processor:

  • Bubble processes Customer Data only on the customer's documented instructions, under the data-processing section (a data processing agreement within the meaning of Article 28 GDPR) in the Bubble Terms and Conditions.
  • The customer decides what to upload, which workflows to run, who sees the results, and when data is deleted or exported.
  • The customer is responsible for having a lawful basis for the personal data in its research content and for informing its own data subjects.
  • The Terms prohibit uploading special categories of personal data (such as health, biometric, or genetic data) and criminal-offence data, unless specific written safeguards have been agreed.

If you are a data subject whose personal data appears in a customer's research content (for example, you were interviewed): please contact the organization that ran the research. That organization is the controller and decides on your request. If your request reaches Bubble, we forward it to that organization without undue delay and assist it as the data processing agreement requires.

11. How Customer Data is handled

  • Customer Data is hosted and processed in the European Union: Google Cloud (region europe-west1) for hosting and storage, and Google Vertex AI in EU regions for AI analysis using Gemini models.
  • Bubble does not permit its AI infrastructure provider to use Customer Data or Deliverables for the provider's own purposes, including training the provider's models, beyond what is strictly necessary to provide the Bubble Platform.
  • Staff access: normal support access to a customer workspace happens through an audited, time-boxed impersonation session that is visible to the customer in its own access log. Outside impersonation, Bubble staff can access operational metadata, and, for troubleshooting under the diagnostics clause in the Terms, run content at database level. All access is logged.
  • Retention and deletion: Customer Data is retained for the duration of the agreement. After termination, the customer's tenant data is retained for 90 days and then deleted. The customer can request earlier deletion, or an export in a common machine-readable format, in writing at any time; exports are provided within 10 working days of a written request.
  • Deletion has honest limits: verbatim quotes already embedded in generated reports remain until those reports are deleted; audit and access logs follow the retention schedule in section 4; and short-lived infrastructure backups age out on their own cycle.

Applies to both parts

12. Recipients of personal data

Bubble shares personal data only with the following recipients:

Processors working for Bubble. These providers process personal data on Bubble's instructions:

  • Google Cloud EMEA Limited: hosting, storage, and AI processing (Google Vertex AI), in the European Union.
  • Resend Inc.: transactional email, European Union sending region (eu-west-1).

Bubble announces additions to its sub-processors at least 1 week in advance, and customers can object under the mechanism in the data-processing section of the Terms.

Connected applications you direct data to. A customer administrator can enable connections to third-party applications, such as AI assistant applications, for its workspace (the feature is off by default). Each user then authorizes their own connection and can revoke it at any time; revocation takes effect from the next request. Through such a connection, the platform serves completed reports and library artifacts, including citation excerpts, and never raw uploaded files, to the connected application at the user's direction. The provider of a connected application receives that content under your organization's own agreement with that provider; connected applications are not Bubble sub-processors, and content already delivered to them is governed by that provider's agreement with your organization, including where that provider stores it. The currently supported applications are shown in the Bubble Platform.

Font delivery (Google Fonts). The platform currently loads its fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When a page loads, your browser requests the font files directly from Google, so Google receives your IP address and standard browser request data. Google may process these requests on servers outside the EU. Bubble intends to serve fonts from its own infrastructure; once that change ships, this disclosure will be removed.

Authorities. Bubble discloses personal data to competent authorities where the law requires it.

Beyond the recipients listed in this section, Bubble does not share personal data with any other recipients.

13. Where data is processed, and international transfers

All customer data processing by Bubble (hosting, storage, AI analysis) happens in the European Union: Google Cloud region europe-west1, Vertex AI EU regions, and transactional email through Resend's EU sending region. In normal operation, Bubble transfers no personal data outside the European Economic Area, with one exception that exists today: when a page loads, your browser sends your IP address directly to Google Fonts to fetch font files (section 12), and Google may process those requests outside the EU. This exception ends when Bubble serves fonts from its own infrastructure.

If a transfer outside the EEA ever becomes necessary, it will take place only with the safeguards the GDPR requires: an adequacy decision of the European Commission or standard contractual clauses.

One case is under your organization's own control: content that a user directs to a connected application (section 12) goes to that provider under your organization's agreement with it. Depending on that agreement, the provider may process the content outside the EU.

14. Security

Bubble protects personal data with technical and organizational measures that include: TLS/HTTPS encryption with HSTS for all external traffic; tenant isolation enforced through row-level security in the database; bcrypt password hashing with a complexity policy; account lockout and login throttling; short-lived access tokens with rotating refresh tokens and reuse detection; application-level encryption (AES-256-GCM) of stored third-party AI provider credentials; secrets kept in a managed secret store; an append-only audit log; audited, time-boxed, customer-visible support impersonation; daily automated database backups with point-in-time recovery; infrastructure located entirely in the EU; dependency scanning; deploy gates with staged rollout and automatic rollback; and security headers.

Further information on Bubble's security measures is available on request via support@bubble-research.ai.

If a personal data breach occurs, Bubble notifies the competent authority and affected individuals as the GDPR requires, and, for Customer Data, notifies the affected customer without undue delay after becoming aware, with the information the customer needs for its own notification duties.

15. Your rights

For the data described in Part A, you have the following rights under the GDPR:

  • Access: ask what personal data Bubble holds about you and receive a copy.
  • Rectification: have incorrect data corrected.
  • Erasure: have your personal data deleted.
  • Restriction: have processing of your data limited while a question about it is resolved.
  • Objection: object to processing based on legitimate interest, including the aggregated-insights purpose in section 6.
  • Portability: receive data you provided in a machine-readable format.

To exercise a right, email privacy@bubble-research.ai. We will verify your identity and answer within one month. Verified erasure requests are fulfilled within 30 days. Erasure has honest limits: records that the law requires us to keep (for example invoices) and audit records within their retention schedule are kept; your personal identifiers are removed or anonymized everywhere else.

If your personal data appears inside a customer's research content, the customer is the controller: contact that organization (see section 10). We forward any request we receive to the customer without undue delay.

You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority of the EU country where you live or work.

16. Your choices and controls

  • Aggregated insights and model training: your organization chooses in or out at signing and can opt out at any time by email; individuals can object at any time (sections 6 and 15).
  • Connected applications: the feature is off by default; a customer administrator enables it; each user authorizes their own connection and can revoke it at any time, effective from the next request; the administrator can disable the feature for the whole workspace.
  • Export: your organization can request an export of its data in a common machine-readable format at any time; exports are provided within 10 working days of a written request.
  • Deletion: individuals can request erasure (fulfilled within 30 days); customers can request deletion of their tenant data at any time, and tenant data is in any case deleted 90 days after the agreement ends.

17. No automated decision-making

Bubble does not make automated decisions about you that have legal or similarly significant effects. The platform generates research reports on the customer's instruction; the reports are decision-support material that people review and act on.

18. Amy

The Free plan gives access to Amy, a product-marketing agent package that is used inside the customer's own account with a third-party AI assistant or large language model (LLM) service of the customer's choice (for example Anthropic's Claude, OpenAI's ChatGPT or Google Gemini). Conversations with Amy take place in the customer's own account with that provider, under the customer's agreement with that provider. They never touch Bubble's systems, and Bubble receives none of that conversation data.

19. Audience

The Bubble Platform is a business tool for professional users. It is not directed at children.

20. Changes to this policy

When this policy changes, Bubble publishes the new version with a new version number and date.

Bubble Research

Keep it bubbly.

Jan van Galenstraat 335
1061 AZ Amsterdam
The Netherlands

KVK: 97554413
support@bubble-research.ai


Explore

  • Home
  • Product
  • Services
  • Pricing
  • Blog

Company

  • About us
  • Privacy statement
  • Terms & Conditions
  • Book a call

Follow

LinkedIn

© 2026 Bubble Research. All rights reserved.

Made in Amsterdam.