Privacy Policy
Last updated on 18/04/2026
Bukios ('we,' 'our,' or 'us') is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed by Bukios.
This Privacy Policy applies to our website bukios.com, our mobile applications (iOS and Android), our browser extension, and their associated subdomains (collectively, our 'Service').
By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy.
Legal Basis for Processing
We process your personal data under the following legal bases pursuant to GDPR Article 6:
- Performance of contract: to provide you with Bukios services, manage your account, and process your subscriptions.
- Consent: for sending promotional communications, use of analytics and marketing cookies, and processing your content using AI.
- Legitimate interest: for service security, fraud prevention, continuous product improvement, and technical error monitoring.
- Legal obligation: to comply with tax, legal, and regulatory requirements.
Information We Collect
We collect information from you in several ways:
- Account information: email address, username, and password when you create an account.
- Usage data: information about how you interact with our service, including bookmarks saved, readlists created, tags applied, and features used.
- Device information: browser type, operating system, IP address, and device identifiers.
- Bookmark data: URLs, titles, descriptions, and tags of content you save.
- Payment information: when you subscribe to a premium plan, payment details are processed directly by Stripe (web) or through Apple App Store/Google Play (mobile). Bukios does not store your credit card numbers or financial account information.
- AI-derived data: when articles are processed, we generate semantic embeddings using OpenAI's API (text-embedding-3-small model, 1536 dimensions), extract entities and concepts using spaCy NER on our own servers, and compute cognitive profile scores. This data is derived from the content you save and is stored on our servers.
- Interaction data: reCAPTCHA verification data for bot protection, and anonymized error reports for service improvement.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services.
- Personalize your experience and deliver content relevant to your interests.
- Send you notifications, updates, and promotional communications (with your consent).
- Detect and prevent fraud, abuse, and security incidents.
- Process your saved content using AI to generate semantic search capabilities, knowledge graphs, insights, and cognitive profiles (Premium features). No automated decisions with legal effects are made about you. The cognitive profile is an informational tool designed to help you understand your reading patterns.
- Monitor and diagnose technical issues through anonymized error tracking and session replay recordings (Sentry). Session replays are anonymized and do not capture passwords or sensitive personal data.
Data Sharing and Third-Party Services
We do not sell your personal information. We may share your data with the following categories of service providers:
- Stripe: processes payments securely for premium subscriptions (web). Stripe's privacy policy governs the handling of your payment data.
- Apple App Store and Google Play: if you subscribe through a mobile app, transaction data is managed by Apple or Google respectively, under their own privacy policies. Bukios only receives a transaction identifier and subscription status.
- OpenAI: article text content is sent to OpenAI's API (located in the USA) to generate semantic embeddings. Only article text is shared — no personal data, account information, or browsing history is transmitted. This international transfer is covered by EU Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
- Sentry: receives anonymized error reports and performance data to help us diagnose and fix technical issues. Session replays may be collected but are anonymized.
- Google: reCAPTCHA v3 for bot protection and Google Analytics for anonymous usage statistics.
- Amazon Web Services (AWS): provides cloud infrastructure in the EU region (eu-west-1, Ireland), including storage (S3) and content delivery (CloudFront) for media files. Your data is stored within the European Economic Area.
- When required by law or to respond to legal requests.
- With your explicit consent.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide you services. You can delete your account at any time from your settings.
AI-derived data (embeddings, concepts, cognitive profiles) is retained alongside your account data and is deleted when you delete your account. Embeddings sent to third-party AI providers are not stored by those providers beyond the processing request.
After account deletion, your data is kept in a soft-deleted state for 30 days, allowing you to recover your account if desired. After that period, data is permanently deleted from our active systems. Backups that may contain your data are deleted within a maximum of 90 days.
Artificial Intelligence Transparency
In accordance with the EU Artificial Intelligence Act (Regulation 2024/1689, Article 50), we inform you that Bukios uses AI systems in the following features:
- Semantic search and related articles: your articles are processed with OpenAI's model (text-embedding-3-small) to generate vector representations that enable meaning-based searches.
- Concept extraction: spaCy NER (natural language processing) is used on our own servers to identify entities and key concepts in your articles.
- Cognitive profile: your reading patterns are analyzed to generate breadth, depth, and diversity scores. This profile is purely informational and has no legal effects, nor is it used to make automated decisions about you (GDPR Article 22).
- AI Chat: chat responses are generated by a large language model (LLM). Responses are automatic and may contain errors.
You have the right to object to automated processing and to request human review of any result that significantly affects you.
Your Rights
In accordance with GDPR and applicable privacy laws, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate personal data.
- Request deletion of your personal data, including all AI-derived data.
- Request a copy of your data in a portable format.
- Object to or restrict the processing of your personal data.
- Not be subject to decisions based solely on automated processing, including AI-derived profiling, that produce legal or similarly significant effects (GDPR Article 22). Our cognitive profiling features are informational tools designed to help you understand your reading patterns and do not make automated decisions that affect your rights.
Children's Privacy
Bukios is not directed at minors under the minimum age established by each country's data protection legislation (14 in Spain and Italy, 15 in France, 16 in Germany). We do not knowingly collect personal data from minors under these ages. If we detect that a minor has registered without required parental consent, we will proceed to delete their account and associated data.
Data Protection Contact
For any inquiries related to the protection of your personal data, exercising your rights, or to file a complaint, you can contact us at privacy@bukios.com.
Supervisory Authority
You have the right to file a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or with the data protection authority of your country of residence, if you believe that the processing of your personal data does not comply with applicable regulations.
Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption in transit (TLS), secure authentication, and access controls across our infrastructure.
Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you at least 30 days in advance by email and by posting a prominent notice on the Service. If you continue to use the Service after the effective date, we will consider that you accept the modifications.
Contact Us
If you have any questions about this Privacy Policy, please contact us at contact@bukios.com.