Straight answers about Bosly, your data, and how it all works.
No. Everything you put into Bosly is encrypted on your device before it reaches our servers. We hold ciphertext, not plaintext. Even the founder, with full database access, cannot read a single invoice, contact, or health record.
It means we can't see your data even if we wanted to. Your data is encrypted in your browser using a key derived from your recovery phrase. The key never leaves your device. What reaches our servers is unreadable without it.
No. We don't train any model — ours or anyone else's — on your encrypted data. When you use the Bosly bot, it works on data the browser has decrypted locally; your invoices, contacts, calendar, and health records are never sent to the AI. What does reach our AI provider is the text of your chat messages, so the bot can answer you. Nothing else.
No. We don't sell it, share it, or hand it to third parties for advertising. There are no ads on Bosly. We count anonymous page views and use consent-gated analytics to know which pages are visited — no third-party ad tracking, no tracking pixels.
You recover your account with your 24-word recovery phrase. Enter the phrase on a new device and your keys are reconstructed — same keys, same data. Nothing is lost as long as you still have the phrase.
The recovery phrase is 24 words generated at signup. It's the master key to your account. You write it down and keep it somewhere safe. Bosly shows it to you once, at signup, and never again. Yes — you really need it.
If you also chose to set up the PIN backup, you can recover with your PIN. If you didn't, and you lose the phrase, your encrypted data is unrecoverable. That's the cost of zero-access encryption: nobody — not us, not you, not anyone — can undo it.
In settings you can optionally create a second recovery phrase, called a duress phrase. If you're ever forced to open Bosly under pressure, entering the duress phrase unlocks a decoy vault instead of your real one. The real vault stays hidden.
Bosly is a private workspace for freelancers, sole traders, and self-employed people. It combines calendar, email, invoices, finances, contacts, health tracking, and social media drafting in one place. Everything is encrypted on your device.
Freelancers and sole traders who are tired of juggling five apps and want their data private by default. It's designed with ADHD in mind — calm, one thing at a time, no engagement tricks — but it works for anyone who wants a quiet place to run their business.
Yes. Calendar, email, invoices, contacts, finance, and health are all free, indefinitely. No signup required for the free invoice tool. No credit card required to use the workspace.
The Accord plan. It unlocks the Bosly bot — an AI assistant you talk to, which books appointments, drafts emails, tracks expenses, sends invoices, and scans your inbox for things you might miss. It also unlocks the Social pill, which drafts and schedules social media posts in your tone. Everything else stays free.
No. Bosly runs in your browser. On a phone, you can add it to your home screen so it opens like a native app. We deliberately don't list on the app stores — see our transparency page for why.
Yes. Bosly is designed mobile-first. On iPhone, open it in Safari and use "Add to Home Screen." On Android, use "Install" in Chrome. It works in any modern browser.
Yes, any time, from your settings. No cancellation fees, no minimum term. If you cancel, you keep access to the free tier and all your data stays yours.
On servers in the UK. The encrypted blobs live on our database; the keys never leave your device.
We follow UK GDPR principles: you have the right to access, correct, export, and delete your data at any time, from the settings page. If you have concerns, you can contact the Information Commissioner's Office (ICO) at ico.org.uk.
Yes. From settings you can export everything you've entered. It comes out encrypted, which proves we can't read it — the export is only useful to you, using your own key.
From settings. Deletion removes your account, your encrypted data, and every row tied to it — in a single transaction, so it either all goes or none does. It's a permanent action and it happens immediately.
Bosly never sends an email without your explicit approval. Every AI-drafted reply goes through a 5-minute outbox delay, and every action can be undone within 60 seconds. There is no auto-send mode.
Because most software wants your attention and Bosly doesn't. No red badges, no unread counters, no nags, no streaks to keep up. Notifications are opt-in and off by default. The interface uses one colour, no motion, no surprises.
It's one place for everything. No switching between apps, no losing track of which tool has which thing. The bot handles the boring parts — remembering, chasing, scanning, organising. And it's designed not to shame you: no "you haven't logged in for 5 days" messages, no guilt-inducing dashboards.
No. Notifications are off by default and opt-in. You choose what reaches you, when, and how. Nothing nags you.
AES-256-GCM, derived from your recovery phrase via HKDF. The PIN backup uses PBKDF2 with 210,000 iterations. All of this happens in your browser, using the Web Crypto API.
Yes. Open your browser's developer tools, go to the Network tab, and watch what leaves your device when you save something. You'll see ciphertext, not plaintext. That's the encryption working in front of you.