Privacy Policy
How Strap collects, uses, and protects your information.
Strap is a service that helps people create and maintain a structured personal context file for use with connected AI agents. This notice explains what personal information Strap collects, how it is used, who it is shared with, and the choices you have under UK GDPR.
Who this policy applies to
This policy applies to people who use Strap, including people who create an account, complete onboarding, connect agents, submit or review proposals, or otherwise use the service.
Who controls your information
For the purposes of UK data protection law, Strap is the controller of the personal information described in this policy.
If you have questions about how Strap handles personal information, you can contact hello@bvdm.ai.
What information Strap collects
Strap currently stores and processes the following categories of information as part of operating the service.
- name
- email address
- profile picture
- Strap file contents
- onboarding answers
- proposal history
- activity history
- connection metadata
- connection tokens
Strap does not process payments and does not store payment card details.
How Strap collects information
When you run an AI feature such as quality analysis, the relevant parts of your Strap are sent to OpenRouter to generate the result. On credits this runs on Strap's platform key; with your own key (BYOK) it runs on your key.
- directly from you when you sign in, complete onboarding, edit your Strap, manage connections, or use account features
- from Google Auth when basic account information is provided during sign-in, such as your name, email address, and profile image
- from connected agent activity when an agent reads Strap through a tokenised endpoint or submits a proposal back through a tokenised endpoint
Why Strap uses information
Strap uses personal information to provide and run the service, including to create and manage accounts, authenticate users, generate and maintain Strap files, run AI features such as quality analysis, support connected agent reads and proposals, store proposal and activity history, manage tokens and connections, respond to support requests, and comply with legal obligations.
Under UK GDPR, the main lawful bases Strap is likely to rely on are performance of a contract where processing is needed to provide the service you asked for, legitimate interests where processing is needed to run and secure the service in a proportionate way, and legal obligation where processing is needed to comply with applicable law.
Where a specific activity depends on consent, Strap will rely on consent for that activity.
Agent access and proposal endpoints
Strap provides tokenised endpoints that let connected agents interact with a user's Strap.
- A valid read token allows an agent to read the relevant Strap payload.
- A valid proposal token allows an agent to submit a proposal back to Strap.
- Proposal submissions may include the agent name, section information, the reason for the proposed change, and draft content.
- Connection metadata may be recorded so Strap can show connection status and recent activity.
These tokens are secrets and should be treated carefully. Strap currently stores connection tokens in plain text so the service can verify and use them. Users can rotate tokens, and rotating a token will break existing agent connections that depend on them.
Retention
Strap keeps personal information for as long as it is reasonably needed to provide the service, maintain the account, keep proposal and activity history available to the user, and meet legal or operational requirements.
- Account and Strap data are normally kept while your account remains active.
- If you ask for deletion, Strap will delete your account and associated data, subject to any limited retention that may be required for legal, security, fraud-prevention, or administrative reasons.
- If you want a copy of your data before deletion, you can request export first.
Your rights
Depending on the circumstances, UK GDPR gives you rights over your personal information.
- ask for access to your personal information
- ask for incorrect information to be corrected
- ask for your information to be deleted
- ask for export of your data
- object to certain processing
- ask for processing to be restricted
- withdraw consent where processing depends on consent
To make a privacy request, contact hello@bvdm.ai. Strap also provides account deletion and data export functionality as part of the service.
Contact and complaints
If you have questions about this policy or how Strap handles personal information, contact hello@bvdm.ai.
If you are unhappy with how Strap handles your personal information, please contact Strap first so there is a chance to help.
You also have the right to complain to the UK Information Commissioner's Office (ICO). Information about how to do that is available at ico.org.uk.
Changes to this policy
Strap may update this Privacy Policy from time to time to reflect changes to the service, legal requirements, or how personal information is handled.

