Privacy Policy
Bonnet is designed so that generated scripts execute locally on the user's computer. The desktop app stores button metadata, execution state, and preferences in a local SQLite database.
Prompt data
When you create or refine a button, the prompt and related generation context are sent to your configured AI provider — through Bonnet's relay for API-key providers, or directly from the desktop app for account sign-in providers. Those prompts are necessary to generate the button.
Local data
Button definitions, saved inputs, approvals, and execution history are stored locally in the app’s data directory. In the browser version, they are stored in that browser’s local storage. Shared buttons exported from the app intentionally exclude local execution history.
Accounts
Signing in is optional. The desktop app works with a license key alone, and the browser version can be used without an account. If you do sign in with Google or GitHub, Bonnet receives a provider account identifier and your verified email address, and stores the identifier as a keyed hash. It does not receive your password, and it requests no access to your files, repositories, or contacts.
Library sync
Sync is off by default and must be turned on explicitly. While it is on, the buttons you have chosen to sync — including their scripts, icons, images, and the pages and layouts they sit in — are stored on Bonnet’s servers so the same library appears everywhere you sign in. Execution history, saved input values, approvals, and AI provider keys are never uploaded. Turning sync off stops further uploads; deleting a button removes it from the server, with a deletion record retained for up to 30 days so that other signed-in devices learn it was deleted.
Billing data
Stripe processes the one-time purchase. Bonnet does not store raw card details; it only stores the billing email and Stripe purchase identifiers required to deliver and verify licenses. License keys are stored as keyed hashes rather than plaintext.
Public shares
Publishing a button uploads its script, prompt history, and portable configuration to a public link. Anyone with that link can read it. Shares expire after the published retention period and can be removed earlier using the private deletion capability returned to the publishing app.
Questions
Questions about privacy can be sent to hello@bonnet.app.