BigBoring Get started

Privacy policy

Last updated 5 September 2026. This explains what personal data BigBoring handles, why, and what rights you have. It covers two groups of people: our customers, and the prospects our customers contact.

If you are a customer

We hold your email address, your name if you gave it, the audiences you describe, the messages you write, your campaign history, and technical records such as sign-in times and IP addresses. We use this to run your account, send you sign-in links, deliver the service, keep it secure, and contact you about your account. The legal basis is performance of our contract with you and, for security records, our legitimate interest in running a safe service.

If you buy a paid plan, Paddle collects your payment details and billing address as merchant of record. We never see your card number. Paddle's handling of your data is covered by Paddle's privacy policy.

If you are a prospect who received an email

A BigBoring customer chose to write to you because of your professional role. The record we hold about you is typically your name, job title, company, and work email address, drawn from professional sources, along with whether an email was sent, opened, or replied to. Our customer is the controller for that outreach; we process the data on their instructions.

The lawful basis relied on for business-to-business outreach of this kind is legitimate interest. You can object at any time by clicking the unsubscribe link in any email, which needs no login and takes effect immediately across every customer using the service. Once you unsubscribe, your address is placed on a permanent suppression list so that no BigBoring customer can contact you again. That list exists only to honour your request; it is not used for anything else.

To ask what we hold about you, correct it, or have it deleted, email hello@bigboring.com. We answer within 30 days.

Where data goes

We use a small number of providers to run the service, each processing data only on our instructions:

Some of these providers are outside the country you are in. Where data leaves the UK or EU, it is covered by standard contractual clauses or an equivalent lawful transfer mechanism.

Cookies

We set one cookie, to keep you signed in. It is not used for tracking or advertising. Emails sent through the service include a small image that records when a message is opened; this is standard in email software and is reported only to the customer who sent the message.

How long we keep things

Customer account data is kept while the account is open and deleted within 30 days of closure, unless the law requires otherwise. Prospect records are deleted when the customer deletes them or closes their account. Suppression records are kept indefinitely because deleting them would defeat their purpose. Security logs are kept for 90 days.

Security

Sign-in tokens, session tokens and API keys are stored only as cryptographic hashes, so a copy of our database cannot be used to sign in. Data is encrypted in transit. Access to production systems is limited to the people who operate the service.

Your rights

Depending on where you live, you may have the right to access, correct, delete or restrict the use of your personal data, to object to processing, to data portability, and to complain to a supervisory authority. To exercise any of these, email hello@bigboring.com.

Changes

If this policy changes in a way that affects you, we will tell customers by email and update the date at the top of this page.

Contact

BigBoring, hello@bigboring.com.