- We do not use your identifiable content to train AI models. Not ours, not anyone’s.
- Our providers are contractually barred from training on it too. Those are two separate commitments; see below.
- Almost all AI processing runs on Google Vertex AI, covered by our signed Business Associate Agreement.
- AI quality monitoring retains request and response text for a limited period. That is the one thing on this page most people do not expect, so it has its own section.
- AI runs on content you capture, as part of features you can see, including automatic steps like note titles, text extraction from uploads, and search indexing. It is never used for anything unrelated to the product in front of you.
Which AI providers we use
For the authoritative, always-current list of every service that processes data on our behalf, see the sub-processor list.
Every AI feature in Bower routes to Google Vertex AI, which is covered by a signed Business Associate Agreement (BAA). That is true for all workspaces, not only those in Restricted mode: Restricted mode adds the other protections described below, but AI inference is already inside the BAA boundary everywhere.
Is my data used to train AI models?
There are two separate claims here and they protect different things. Both are true. Neither implies the other. 1. Bower does not train on your identifiable data. We will not use identifiable customer content to train, fine-tune, benchmark, or otherwise develop any AI model, including our own. This is a commitment in the Terms. 2. Our provider does not train on it either. Google does not use Vertex AI inputs or outputs to train its models, and we require any AI provider that receives your content to be contractually barred from training on it, or retaining or logging it for human review beyond what is needed to return a result.What about de-identified data?
The De-identified data section of the Terms reserves a right to use data that has been de-identified and stripped of your substantive research content. Both tests must pass. De-identifying a person does not make your science ours, and your results, findings, and inventions are excluded from that right entirely. Today that right covers operational telemetry that is de-identified by construction, such as usage counts, feature adoption, timing, and error rates. It does not cover your free text, audio, images, or video, because we do not yet operate a pipeline that can de-identify those to the standard the Terms set. If that changes we will update this page before relying on it.Where does my data go in transit?
Every call to an AI provider is made server-to-server from Bower’s backend over TLS. Your browser or device never talks to an AI provider directly. Your stored data stays in the US (us-central1), and speech-to-text and live voice mode run there too. The newest Gemini text and vision models are served from Google’s global endpoint, which may process a request in another region while it is in flight; the request still stays inside the Vertex AI BAA boundary.Where is my data stored?
Two different things, kept separate:- Your research data (notes, files, transcripts, embeddings) is stored in Bower’s database and file storage in Google Cloud’s
us-central1region (Iowa, USA). It stays there until you delete it. See Data privacy for retention and deletion. - The AI providers receive your content only to produce a result:
- Google Vertex AI: no retention for training; data stays within our BAA boundary.
AI quality monitoring, and what it retains
This is the part worth reading twice. To keep AI features reliable, Bower retains records of AI requests and the responses to them in a third-party observability service, named on the sub-processor list with its processing location and current agreement status. Those records contain the request and response text itself, and it is not de-identified. We use them to find quality failures, evaluate changes before shipping, and investigate incidents you report. What improves from them is Bower itself: our prompts, our product code, and our configuration. Nothing is learned into any model’s weights. To be explicit about what this is and is not:- It is service operation, covered by the narrow license you grant us in the Terms.
- It is not de-identified data, and it is not used under the de-identified-data right described above.
- It is not used to train, fine-tune, or benchmark any model.
Locking it down further
If you work with especially sensitive material (protected health information, confidential or unpublished research, trade secrets, regulated data), enable Restricted mode (HIPAA-ready) on the workspace. It enforces the strictest controls:- AI processing stays on Google (Vertex AI), the provider covered by our signed BAA. Any AI route to a provider without a BAA is blocked server-side, and the block is enforced whether or not such a route currently exists.
- Content-bearing product analytics are disabled. Session replay, autocapture, and every other content-bearing analytics capture are off; the analytics events that remain carry only event names and metadata. AI quality monitoring continues, at a BAA-covered provider, as described above.
- External sharing is disabled: no new public share links.
- Connectors, external AI app access, and literature lookups are unavailable, because each sends content to a third party without a BAA.
- Word document conversion happens inside Bower rather than at a third-party service.