Legal
Privacy Policy
Last updated August 20, 2026. Version 2026-08-20.
This policy explains what BonHand does with personal data: yours as a professional using it, and your clients' as records you keep inside it. It is written to the UK and EU GDPR standard and applies wherever you are.
1. Two roles, and why the difference matters
BonHand is operated by Po Yan Wong, a sole trader based in the United Kingdom, and is therefore subject to the UK GDPR. Privacy questions and data requests go to [email protected].
BonHand holds two different kinds of personal data, and our responsibility differs for each.
- Your own data, such as your account, settings and billing. Here we are the controller: we decide why and how it is used, and this policy is our notice to you.
- The records you enter about your clients. Here you are the controller and we are your processor: we hold that data on your behalf and act on your instructions. The processing terms are in the Terms of Service.
It follows that if you are a client of a professional who uses BonHand, the professional decides what is recorded about you. Start with them. We will help them respond.
2. What we collect about you
When you use BonHand as a professional, we hold:
- Account details: name, email address, username, password (stored only as a hash), and any passkey or two-factor credentials you register. If you sign in with Google, we receive your name, email address and profile picture from Google.
- Practice settings: timezone, language, currency, country, working hours, professions, rates, locations and the content of your public page, if you publish one.
- Billing data: your plan, subscription status, invoices, and the billing name, address and country you give Stripe. We never see or store your card number.
- Content you create: your client records, sessions, notes, payment records, to-dos and any files you upload.
- Technical data: IP address, browser and device information, log and error records, and, if you enable notifications, a push subscription identifying your browser to its push service.
3. What you record about your clients
You decide this, not us. In practice it usually includes a name, contact details, session history, what was paid and what is owed, notes you write, and any files you attach. In the tutoring context it may include information about a child, entered by the adult responsible for them.
We do not buy client data, we do not enrich it from other sources, and we do not read your client messages: BonHand has no way to receive incoming messages at all. The only exception to "you enter everything" is listed in the next two sections.
4. What your clients can enter themselves
If you enable a portal link, your client can write exactly five things, and nothing else:
- A password for their own link, which they may also decline to set.
- Their own profile photo, which they may remove again.
- A payment they say they made, which stays pending and changes nothing until you confirm it.
- The language they want their portal in.
- Their timezone, so the times you quote them are right.
5. What we collect from visitors to a public page
A public page can be read without giving us anything. If a visitor sends an enquiry through the contact form, we collect the name, contact details and message they type, and pass them to the professional whose page it is.
We also process the sender's IP address and a Cloudflare Turnstile token to block automated submissions and enforce rate limits. An enquiry is a message from a stranger, never a client record: it does not enter anyone's timeline and does not affect any balance.
6. Why we use it, and on what legal basis
For the data where we are the controller:
- To provide the service, including your account, your data and your subscription. Basis: performance of our contract with you.
- To take payment and keep the records that go with it. Basis: contract, and legal obligation for tax and accounting records.
- To keep the service secure, which covers rate limits, bot defence, error logs and abuse investigation. Basis: our legitimate interest in a service that is not abused.
- To support and improve the product, using aggregate usage and error data. Basis: our legitimate interest in a product that works.
- To send service email such as verification, password resets, payment problems and material changes. Basis: contract. These are not marketing and cannot be switched off while your account is open.
- To send browser notifications, if you turn them on. Basis: your consent, which you can withdraw in your browser or in settings at any time.
We do not sell personal data, we do not share it with advertisers, and we do not use it to build profiles or take automated decisions that produce legal effects.
7. AI processing
When you ask BonHand to summarise a client's history or draft a message, the content needed for that request is sent to an AI provider. That can include the client's name, session history and the notes you have written about them.
What this means in practice:
- Requests are sent with retention switched off, so the provider does not store them after the response and does not use them to train models.
- We use OpenAI as the primary provider and Anthropic as an automatic fallback when the first is unavailable. Both are listed as subprocessors below.
- The features are yours to use or not. If you do not use them, nothing about your clients is sent to an AI provider.
10. International transfers
BonHand is a global service and the providers below operate internationally, so personal data may be processed outside the country you are in, including in the United States and the European Union.
Where data leaves the EEA or the UK, transfers rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, as applicable to the provider concerned.
11. How long we keep it
We keep your account and the data in it for as long as your account is open, because that is the point of it. After that:
- When you close your account, your data is deleted within 30 days, and encrypted backups holding it age out within a further 30 days.
- Billing and tax records are kept for seven years, because the law requires it.
- Enquiries from a public page are kept until the professional deletes them, and are removed with the account.
- Security and error logs are kept for up to 90 days.
You can delete individual client records at any time, with one exception that protects your own history: a session that has already been logged cannot be edited or deleted, because your record of what happened is meant to be reliable.
12. How we protect it
Everything travels over encrypted connections. Passwords are hashed and never stored in readable form, and card details never reach our servers at all. You can add two-factor authentication or a passkey to your account, and we recommend you do.
Access to production data is limited to the people who need it to operate and support the service. Portal links are unguessable tokens that you can revoke, and are revoked automatically when you archive a client. No system is perfectly secure, so please tell us at once if you suspect a problem.
13. Your rights
Over the data where we are the controller, you may ask us to:
- Give you a copy of it, or a portable export of it.
- Correct it if it is wrong.
- Delete it, subject to the retention periods above.
- Restrict or object to a use of it that relies on our legitimate interests.
- Withdraw a consent you gave, without affecting what was done before you withdrew it.
Write to [email protected] and we will respond within 30 days. You may also complain to the data protection authority where you live, or to the Information Commissioner's Office (ICO), which supervises us.
14. If you are a client, not a professional
The records held about you were entered by your professional, who decides what they contain and how long they are kept. To see, correct or delete them, ask that professional directly. It is their decision to make, and they can act on it immediately.
If you cannot reach them, write to [email protected] and we will help identify the right account and pass the request on. We cannot change another person's records for them without their instruction.
15. Children
BonHand accounts are for adults, and we do not knowingly let anyone under 18 create one. A professional may hold records about a child, such as a tutor recording lessons a parent has booked. In that case the professional is the controller and must have the consent of a parent or guardian.
If you believe a child's information is held in BonHand without that consent, write to [email protected].
16. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how your data is used, we will tell you by email or in the app before it takes effect.