Boosthis — Terms of Service & Privacy Policy
This single page contains both the Terms of Service (Part A) and the Privacy Policy (Part B) for Boosthis, a private, invite-only developer performance toolkit ("Boosthis", "we", "us", "our"). By installing, enabling, or otherwise using Boosthis, you ("you", the "User") agree to this entire document. If you do not agree, do not install or use Boosthis.
Part A — Terms of Service
1. Acceptance and eligibility
- By installing, enabling, configuring, or using Boosthis — including adding it to source code, running its runtimes, calling its APIs, or connecting to its servers — you accept these Terms.
- You may use Boosthis only if you can form a binding contract with us and are at least 16 years old. Boosthis is a developer tool and is not intended for children.
- To purchase a paid subscription you must additionally be of the age of majority where you live, or be acting with the authority of an organization that is.
- If you use Boosthis on behalf of an organization, you represent that you have authority to bind it, and "you" includes that organization.
2. Definitions
- "Boosthis" / "the Service" — the Boosthis software (the React Native, Node.js, Python, Web, Java, and Go runtimes, and any other runtimes), the rule book, the CLI tools, the MCP and HTTP servers, the hosted telemetry API, the developer and admin dashboards, and all related documentation.
- "Telemetry" — everything your app sends to Boosthis: the always-on issue signatures and fix-resolution signals, and any optional full performance samples you choose to enable (detailed in Part B).
- "Invite Key" — a credential the maintainer issues that allows a registered app to participate in the invite-only telemetry program.
- "Maintainer" — the creator, owner, and operator(s) of Boosthis.
- "Protected Parties" — the Maintainer together with Boosthis's owner, creator, administrator(s), operator(s), contributors, and licensors, and each of their respective affiliates, officers, employees, and agents. Every disclaimer, limitation, release, and indemnity below runs in favour of all Protected Parties.
- "Paid Plan" — an optional paid subscription to the hosted Boosthis service (described in Section 15).
- "Payment Processor" — the third-party payment platform (currently Moyasar) that hosts checkout and processes subscription payments on the Maintainer's behalf.
3. Invite-only access and Invite Keys
- Boosthis is private and invite-only. Access is granted at the Maintainer's sole discretion and may be refused, limited, suspended, or revoked at any time, for any reason, without notice or liability.
- Invite Keys are personal to the app or organization they were issued to. You must not share, resell, sublicense, publish, or transfer an Invite Key, and you are responsible for all activity under your Invite Key and install ID.
- We may rotate, disable, or revoke Invite Keys at any time, and are not liable for any consequence of a revoked or expired key.
4. License to use Boosthis, and restrictions
The Boosthis software is licensed to you under the project LICENSE (Apache License 2.0), which governs your rights to use, copy, and modify the code. These Terms govern your use of the Service (including the hosted telemetry API and the invite-only program). Where both apply, the Apache License controls your rights in the code and these Terms control your use of the Service; nothing here limits, modifies, or adds conditions to the rights the Apache License grants in the code. Except as permitted by the LICENSE — and in every case when interacting with the Service — you must not:
- use Boosthis or its servers unlawfully or in violation of these Terms;
- probe, scan, overload, rate-abuse, or attempt unauthorized access to the telemetry API, admin dashboard, or any Boosthis infrastructure;
- attempt to bypass, disable, or weaken the PII guard, the privacy chokepoint, or any access control;
- tamper with, remove, disable, or circumvent — or assist or direct anyone or anything (including any AI agent or automated tool) to tamper with, remove, disable, or circumvent — the Service's activation, entitlement, kill-switch, or integrity-verification mechanisms, or misrepresent your install's identity, version, or integrity state to the Service;
- submit false, poisoned, automated, or bulk telemetry intended to corrupt the rule book or analytics;
- remove, obscure, or misrepresent any notice, license, or attribution; or
- use Boosthis to build a competing dataset or service from telemetry you do not own.
5. Acceptable use
You are solely responsible for your own application, source code, data, users, and for what you place into route names, labels, metadata, and exception messages. You must not use Boosthis to process, transmit, or expose unlawful content or to violate any third party's rights.
6. Boosthis intellectual property
As between you and the Maintainer, the Maintainer owns all right, title, and interest in and to Boosthis — including the software, the rule book, the detectors, the scoring model, the documentation, the name "Boosthis", and all associated logos and trademarks — except for the rights expressly granted to you under the LICENSE. Nothing here transfers any Boosthis intellectual property to you.
7. Ownership and assignment of Telemetry
By installing, enabling, or otherwise using Boosthis with a registered app, you agree that everything your app sends to Boosthis — the issue signatures, the fix-resolution signals, and any optional full performance samples you turn on (together, the "Telemetry") — is assigned to Boosthis: you waive, and irrevocably assign to the Maintainer, all right, title, and interest you may have in the Telemetry and in any rules, thresholds, aggregated statistics, models, or other improvements derived from it, and you will not claim ownership of — or any compensation for — the Telemetry or anything built from it. This applies whether or not you turn on full data mode (enableTelemetry()) — enabling full samples does not give you any ownership claim over what you send.
This expressly includes every issue, error, bug, and fix. When an issue, error, bug, defect, crash, or performance problem is surfaced by the Telemetry your app sends, or is identified, reproduced, diagnosed, derived, or generated by Boosthis — together with every fix, patch, workaround, rule, remediation, signature, insight, or rule-book entry Boosthis creates from or about it — all right, title, and interest in that Telemetry, finding, fix, rule, and rule-book entry belongs to the Maintainer, and you irrevocably waive and will not assert any ownership, authorship, inventorship, royalty, or other claim over them. This is about Boosthis's record and remediation of the problem, not the underlying defect in your own code: as below, the assignment never reaches your source code, diffs, file contents, or application, which remain entirely yours.
This covers only what you send — the data described in Part B (issue & fix signals, plus, in full mode, route labels, durations, and ratings). Boosthis never receives your source code, diffs, file contents, or your application, and this assignment gives the Maintainer no rights over any of them. Your code and your app remain entirely yours. The assignment survives erasure and termination: running forget stops future Telemetry but does not claw back rules already derived and shipped.
8. Feedback
If you send the Maintainer any feedback, ideas, suggestions, or bug reports, you grant a perpetual, irrevocable, worldwide, royalty-free license to use them for any purpose, without obligation or compensation to you.
9. AI-generated suggestions are not approvals
Boosthis surfaces performance rules and AI-assisted fix suggestions through its MCP server, HTTP API, and documentation. These are suggestions, not approvals. You are solely responsible for reviewing, testing, and deciding whether to apply any suggested change before you ship it.
10. Third-party dependencies and services
Boosthis may rely on third-party software, registries, AI providers, and hosting platforms. Your use of those is subject to their own terms, and the Maintainer is not responsible for them.
11. Disclaimer of warranties
Boosthis is provided "as is" and "as available," with all faults and without warranty of any kind, whether express, implied, or statutory, including without limitation implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, and accuracy. No Protected Party warrants that Boosthis will be uninterrupted, timely, error-free, secure, or free of harmful components, that any defect will be corrected, or that the PII guard will catch every identifier or secret — it is a best-effort defence, not a guarantee. You assume the entire risk as to quality, performance, and results, and use Boosthis entirely at your own risk. Boosthis is not designed, intended, or licensed for use in high-risk activities — including medical or life-support systems, aviation, nuclear facilities, weapons systems, or any other environment where a failure could lead to death, personal injury, or severe physical or environmental damage — and no Protected Party is liable for any use of Boosthis in such activities. This restates and supplements the warranty disclaimer in the LICENSE (Apache License 2.0, Section 7); to the extent of any conflict, the broader disclaimer applies to your use of the Service. Some jurisdictions do not allow some exclusions, so they may not apply to you.
12. Limitation of liability, assumption of risk, and release
Use at your own risk — no liability. You use Boosthis entirely at your own risk. To the maximum extent permitted by law, none of the Protected Parties (defined in Section 2 — including the owner, creator, and administrator of Boosthis, its maintainers and contributors) will have any liability of any kind to you or anyone else for any loss or damage arising from or relating to Boosthis — including any data exposure, leak, loss, corruption, downtime, security incident, or business loss. This clause works together with Sections 11–13. If you do not accept this, do not install or use Boosthis.
No liability. To the fullest extent permitted by law, in no event will any Protected Party (including the owner, creator, and administrator of Boosthis) be liable to you or any third party for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, business, data, goodwill, or other intangible losses, or for any data exposure, leak, loss, corruption, downtime, security incident, or regulatory penalty, arising out of or related to Boosthis or these Terms — whether based on warranty, contract, tort (including negligence), strict liability, statute, or any other theory, whether or not advised of the possibility, and even if a remedy fails of its essential purpose.
Liability cap. To the extent any liability cannot be fully excluded, the Protected Parties' total aggregate liability for all claims will not exceed the greater of (a) the amount you actually paid the Maintainer for Boosthis in the prior twelve months and (b) SAR 100. This cap is aggregate across all claims, not per-incident. For any no-charge product the lower cap in Section 16 applies instead.
Assumption of risk & release. You knowingly and voluntarily assume all risk arising from your use of Boosthis and any change you make in reliance on it, and you release and forever discharge the Protected Parties from all claims, known or unknown, arising out of or related to Boosthis, the Telemetry, or any AI-suggested change. This restates and supplements the limitation of liability in the LICENSE (Apache License 2.0, Section 8); to the extent of any conflict, the broader limitation applies to your use of the Service. Some jurisdictions do not allow certain limitations, so some may not apply to you; in that case the Protected Parties' liability is limited to the minimum permitted by law.
13. Indemnification
To the fullest extent permitted by law, you agree to defend, indemnify, and hold harmless the Protected Parties from and against any claims, damages, liabilities, losses, and expenses (including reasonable legal fees) arising out of or related to: (a) your use of Boosthis; (b) your application, source code, data, or users; (c) the data you place into route names, labels, or metadata; (d) your violation of these Terms or any law; or (e) your violation of any third party's rights.
14. Term, suspension, and termination
- These Terms apply for as long as you use Boosthis.
- The Maintainer may suspend or terminate your access (including your Invite Key and telemetry participation) at any time, with or without notice, for any reason, without liability.
- Tampering is a material breach. Tampering with, removing, disabling, or circumventing the Service's activation, entitlement, kill-switch, or integrity-verification mechanisms (or assisting or directing anyone or anything to do so) is a material breach of these Terms and results in immediate termination of your access, Invite Key, and telemetry participation, without notice or liability. The Maintainer may also pursue any remedy available at law or in equity for such breach; no remedy is exclusive, and declining to pursue a remedy is not a waiver.
- You may stop at any time: disable optional samples, set
BOOSTHIS_DISABLED=1, or runforget(see Part B). - Non-payment is a freeze, never deletion. If a Paid Plan lapses, your account and data are frozen, not deleted: growth actions pause, but everything you already collected stays viewable, nothing is erased, and everything unlocks the moment payment resumes (see Section 15).
- Revocation or suspension starts a deletion countdown. If your access is revoked or suspended, a 60-day countdown to deletion of the associated stored data begins. Restoring your access before it ends cancels the countdown. Running
forgetdeletes immediately at any time. Learning signals survive deletion only in permanently de-identified form, as described in Section 7 and Part B. - Sections that by their nature should survive — including 6, 7, 8, 11, 12, 13, 15 (for fees already owed), 16, 17, 20, 22, and 26 — survive termination.
15. Subscriptions, billing, and payment
Boosthis offers optional Paid Plans — monthly subscriptions that unlock higher limits and additional features on the hosted service. The plans, prices, and what each includes are shown on the billing page at the time of purchase.
- Payment is handled by the Payment Processor. Checkout happens on the Payment Processor's own hosted pages, under its own terms and privacy policy. Your card details go to the Payment Processor and never touch Boosthis's servers. Boosthis stores which plan you are on, a reference to your subscription, and — so renewals work and you can recognize the card — your card's brand, its last four digits, and a reusable payment token issued by the Payment Processor (never the card number itself).
- Plans renew automatically each month until you cancel. You can cancel at any time from the billing page or with the Payment Processor; cancellation takes effect at the end of the current billing period, and you keep the paid features until then.
- Fees are paid in advance and are non-refundable, except where a refund is required by applicable law or granted by the Maintainer at its discretion.
- Taxes. All Fees are stated and charged in Saudi Riyal (SAR). The price displayed at purchase is the total amount charged, and it includes VAT and any similar taxes where they apply under the laws of the Kingdom of Saudi Arabia. If the Maintainer is or becomes VAT-registered with the Zakat, Tax and Customs Authority (ZATCA), VAT will be charged and invoiced in accordance with ZATCA regulations at the then-current rate. If you purchase from outside Saudi Arabia, you are responsible for any taxes, levies, or duties imposed by your own jurisdiction.
- Price changes. The Maintainer may change plan prices or features; changes take effect at your next renewal, and material price increases will be communicated before they apply. Continued renewal after a change means you accept it.
- Non-payment never deletes your data. A lapsed subscription only pauses growth actions (such as adding new projects or new connections); everything already collected stays viewable, and full access returns instantly on payment (see Section 14).
- A Payment Processor outage never downgrades you. If the Payment Processor cannot be reached, your last known plan state remains in effect.
- Complimentary access. The Maintainer may grant free or complimentary access at its discretion; such access is a no-charge product under Section 16 and may be modified or withdrawn at any time.
16. Free, beta, and no-charge products
Parts of Boosthis may be provided at no charge — including free features, trials, beta or pre-release versions (such as TestFlight builds of the mobile app), and complimentary or maintainer-granted access (together, "No-Charge Products").
- No-Charge Products are provided "AS IS", with no warranty, no support commitment, and no availability commitment. They may be changed, limited, suspended, or discontinued at any time, and may never become generally available.
- Beta and pre-release versions are by definition unfinished and may contain defects; do not rely on them for production-critical decisions.
- NOTWITHSTANDING SECTION 12, THE PROTECTED PARTIES' TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO ANY NO-CHARGE PRODUCT WILL NOT EXCEED SAR 50.
17. Confidentiality, publicity, and benchmarks
- Boosthis is private and invite-only. Non-public information you receive through it — including the contents of the rule book and fix corpus, non-public documentation, Invite Keys, dashboards, roadmaps, pricing not publicly listed, and the fact and terms of your invitation — is Confidential Information of the Maintainer.
- You will use Confidential Information only to use Boosthis as permitted by these Terms, and will not disclose or publish it.
- You will not publicly disclose benchmarks or comparative analyses of Boosthis, and will not publicly announce or advertise your use of Boosthis (in marketing, press, talks, or public repositories), without the Maintainer's prior written consent.
- These obligations do not apply to information that becomes public through no fault of yours, or that you are required to disclose by law (with prior notice to the Maintainer where lawful). This Section survives termination.
18. Export controls and sanctions
You represent that you are not located in, or ordinarily resident in, any country or territory subject to comprehensive sanctions or embargoes, and that you are not on any government sanctions or denied-party list. You agree to comply with all applicable export-control and sanctions laws in your use of Boosthis.
19. Changes to Boosthis and to these Terms
The Maintainer may modify, suspend, or discontinue any part of Boosthis at any time without liability, and may update these Terms; the "Last updated" date will change and material changes will be noted in the release. Continued use after a change means you accept the updated Terms. A new consent is requested for any new use of telemetry beyond rule-book improvement.
20. Governing law and dispute resolution
- These Terms are governed by the laws of the Kingdom of Saudi Arabia, without regard to conflict-of-laws rules.
- Informal resolution first. Before filing any claim, you agree to contact the Maintainer and attempt in good faith to resolve the dispute informally for at least 30 days.
- Binding arbitration. Any dispute, claim, or controversy arising out of or relating to Boosthis or these Terms that is not resolved informally will be finally settled by binding arbitration administered by the Saudi Center for Commercial Arbitration (SCCA) under its Arbitration Rules, before a single arbitrator, seated in Riyadh, Kingdom of Saudi Arabia, conducted in English unless the parties agree otherwise. The award is final and binding, and judgment on it may be entered in any court of competent jurisdiction.
- Equitable relief. Nothing in these Terms prevents the Maintainer from seeking injunctive or other equitable relief in any court of competent jurisdiction to protect its intellectual property or confidential information.
- Attorneys' fees. In any action or proceeding to enforce these Terms, the prevailing party will be entitled to recover its reasonable attorneys' fees and costs, in addition to any other relief awarded.
- Time limit on claims. To the fullest extent permitted by law, any claim arising out of or related to Boosthis or these Terms must be filed within twelve (12) months after the claim accrued; otherwise it is permanently barred.
21. Severability · 22. No waiver · 23. Assignment · 24. Force majeure · 25. Entire agreement · 26. Notices
- Severability. If any provision is unenforceable, it will be limited or removed to the minimum extent necessary and the rest remains in force.
- No waiver. The Maintainer's failure to enforce any provision is not a waiver of its right to do so later.
- Assignment. You may not assign these Terms or your Invite Key without the Maintainer's written consent. The Maintainer may assign freely, including in a merger, acquisition, or sale of assets.
- Force majeure. The Maintainer is not liable for delay or failure caused by events beyond its reasonable control.
- Entire agreement. These Terms (with the
LICENSEand Part B) are the entire agreement regarding Boosthis and supersede any prior understanding. - Notices. Notices to the Maintainer must be given in writing through the contact channel in Part B (the maintainer who provided your invitation) and are deemed given when received. The Maintainer may give you notice by email to your account address, in-product messages or dashboard banners, or release notes; such notice is deemed given when sent or posted.
Part B — Privacy Policy
Boosthis is a private, invite-only developer toolkit. It runs inside your own app on your own machine. This part explains exactly what a registered app reports back to this server, what it never reports, and how to stop it. Separately from the toolkit, invited developers can create an optional developer account (email + password) to use the hosted web and mobile dashboards and manage billing — what we store for an account is described under "Account data" below, and it is never merged with telemetry.
Use at your own risk — no liability for data exposure
Boosthis is provided "as is," with no warranty of any kind, and you use it entirely at your own risk (see Part A, Sections 11–12). Boosthis is a library that runs inside your application's own process — you remain solely responsible for the data your app handles, for what you place into route names and metadata, and for reviewing any AI-suggested change before you ship it. The PII guard is a best-effort defence against common identifier and secret field names, not a guarantee.
Two kinds of data — please read
- Issue & fix signals — always on for registered apps. Once your app is registered Boosthis automatically reports tiny, anonymous, privacy-safe signatures describing that a class of performance issue recurred, and that one later improved. It is not a per-app on/off setting and cannot be turned off from inside the app — it stops only if you erase your data (
forget) or set the kill-switchBOOSTHIS_DISABLED=1. - Full performance details — optional, off unless you turn it on. You may switch on fuller per-route samples (route label, duration, rating). This is the only part controlled by
enableTelemetry()/disableTelemetry(). Turning telemetry "off" does not stop the always-on issue & fix signals.
What we use your data for
We use opted-in telemetry for one purpose only — to improve the Boosthis rule book (new rules, refined thresholds, recurring patterns). We do not sell it, share it with advertisers or data brokers, use it for advertising/profiling, train general-purpose AI/LLMs on it, link it to your identity, or combine it with other sources. New uses require a new consent in a new major version.
Ownership of what you send
Everything you send to Boosthis (the "Telemetry") is assigned to Boosthis — you waive any ownership claim over the issue & fix signals and the optional full samples, and over any rules or improvements derived from them, even if you turn on full data mode. This covers only what you send, never your source code or application. The full clause is Part A, Section 7.
What an issue / fix signal contains
- Anonymous install ID — a UUIDv4 generated on your machine. Not linked to your IP, email, account, hostname, or anything else.
- Issue signature —
<detector-kind>:<severity-bucket>:<count-bucket>, e.g.ghost-mount:med:<10. The screen / route name is deliberately dropped. - Fix signal — the same rule kind plus a before→after rating bucket (good / needs-work / poor) when an issue later improves. Never the fix itself: no source code, diffs, file paths, screen names, or values.
- Package version + runtime — e.g.
boosthis 0.2.0 (py). - Anonymous daily reach tag (React Native) — a small random value your device mints fresh each calendar day, never derived from your device, user, account, or install ID. The server folds it into a coarse rolling estimate of roughly how many distinct devices hit the same issue this week ("≈1", "≈2–9", "≈10+") and never stores the tag itself. Because it rotates daily it cannot track a device across days, and erasing your data (
forget) also deletes the tag on your device.
What the optional full-details mode adds
- Route label — the code-defined name of the function or route you instrumented (e.g.
/api/users,get_orders). The PII guard refuses to transmit it if it contains an email, IP, JWT, phone number, or other identifier. - Duration in milliseconds and rating (good / needs-work / poor).
- Rule ID (optional) — if you attached a Boosthis rule to the sample.
What a crash report contains
Crash reports are part of the always-on signals for a registered app. When your app hits an uncaught error, an unhandled promise rejection, or a render crash, Boosthis records only the crash's code — the minimum needed to identify and fix it. It is the crash's code, not your users' data, your values, your message text, or your source. Like every other finding, a crash and the fix Boosthis derives from it become a Boosthis rule (see Part A, Section 7).
- Error type — e.g.
TypeError(always on). Never the message text. - Redacted code location — the top stack frame reduced to a function name + file basename + line number. Never an absolute path, URL, query string, argument, or value.
- Hashed signature + occurrence count — the signature is derived only from those code-defined tokens, never from the error message; the occurrence count is just how many times that same crash recurred. The server keeps one row per
(install, signature); repeats add to a running total. - Optional detailed crash mode (opt-in, per app) — adds the first line of the message only if it passes the PII guard (otherwise the whole line is dropped, never partially redacted), plus sanitized frames (function + file basename + line/column). Still no source code, no raw stack, no values; the PII guard runs on every field first.
- You can read these back, read-only — the "potential crashes" feed. An AI agent you connect (the dev-only "Connect your AI" card, or "Connect AI" in the web dashboard) can read your app's own recorded crash codes back, newest first, joined with your app's stability (app-not-responding) signal, so it can flag what is most likely to crash and what to harden first. This reads the same crash data already collected — no new categories — scoped to your own install, read-only, same PII guard on every read.
- What a tool reply can contain — the exact identifier categories. A reply served to a connected AI is limited to: your anonymous install ID (the same UUID described above — the connection-status tool lists it per app so you can tell your installs apart and match the “Connect your AI” card); trace and span correlation IDs (a random 32-character hex value minted inside your app purely to stitch one user action's spans into a waterfall — never derived from your device, user, account, or install ID); code-defined route/screen labels; durations, ratings, and scores; crash signatures (error type plus a redacted code location); coarse timestamps (when a sample or crash was recorded, and when an app last checked in); connection-status facts (each install's coarse connection status, when it was registered, whether it has ever checked in, and a yes/no of whether server-side credentials are on file — never any credential value itself); rule IDs and fix guidance from the rule book; and — inside the integration-kit reply only — an echo of the same invite key that connection itself presented (so the kit can self-register; never anyone else's key or any other credential). Tool replies never include account data, emails, IP addresses, internal database row IDs, or any other install's data.
Learning from experience — new bugs, issues & fixes
When Boosthis runs into a slow or buggy pattern it doesn't yet have a rule for, it may send a small, privacy-safe note about the kind of problem — the runtime, a coarse category, a severity bucket, a timing bucket, a hashed signature, and a recurrence count. Exactly like an issue signature, this is buckets and a hash, never a screen name, a value, your users' data, or your source. It is part of the always-on signals for a registered app.
- If you've connected your own AI, that AI may also attach a suggested rule — a short title, when it applies, and a suggested fix. Every part of a suggestion passes the same PII / secret / URL guard before it leaves your device, and it is treated as feedback under Part A, Section 8.
- Nothing a consumer sends ever becomes a live rule automatically. A suggestion only lands in the maintainer's private review queue; a human decides whether to hand-write it into the rule book. See Part A, Sections 7–9.
Account data (the optional developer account)
If you create a developer account to use the hosted web or mobile dashboard, we store — separately from telemetry, and only to operate your account:
- Your email address and a password hash. The password itself is never stored, only a secure one-way hash. Sign-in uses short-lived, single-use one-time codes (emailed, or from an authenticator app if you enroll one), also stored only as hashes.
- AI connection credentials (OAuth sign-in and “Connect AI” tokens). If you connect an AI assistant through the OAuth sign-in flow, or mint an account AI token from your dashboard, we store that authorization so the assistant can act with its own revocable, read-only credential instead of your password or invite key. These credentials are stored only in protected form (hashed, or encrypted where the sign-in flow requires it) — never as plain text — and they inherit your invite key's status: revoking the invite key they were authorized with immediately ends that assistant's access (dashboard-minted AI tokens can additionally be revoked individually from your dashboard). They grant no more than the read-only tool access described in the sections above.
- AI read events (for the “AI impact” view). When a connected AI assistant actually reads a project's data with one of the credentials above, we record the time of that read (collapsed so bursts count once per hour) together with a snapshot of the project's open crash-group counters at that moment. This exists solely to power the dashboard's honest before/after “AI impact” view; it contains only identifiers and counters we already store — no new content, and never anything about what the AI itself said or did. These events are deleted with the project's other operational data on erasure and pruned after a year.
- Session records and essential cookies. The web dashboard sets only essential sign-in cookies (your session, and a short-lived cookie during the one-time-code step). There are no advertising, analytics, or cross-site tracking cookies. The dashboard uses a small amount of your browser's own storage for convenience — for example, remembering that you dismissed the “update available” banner — not for tracking.
- Account emails. We send account emails — a welcome note when you sign up, sign-in codes, password resets, plain-language notices when your access or plan changes, performance-alert emails if you turn alerts on, and occasional low-frequency update notes about the toolkit — through a third-party email delivery provider, which processes your email address for delivery only.
- Billing status. If you subscribe to a Paid Plan, we store which plan you are on, a reference to your subscription with the Payment Processor, and — so renewals work and you can recognize the card — your card's brand, its last four digits, and a reusable payment token issued by the Payment Processor (never the card number itself). Your card details never touch Boosthis's servers — checkout happens on the Payment Processor's own hosted pages under its own privacy policy (see Part A, Section 15).
- A security log. Sensitive account and maintainer actions are recorded in an append-only security log (including the acting IP address) so we can investigate abuse. It is a security record, not telemetry, and is never shown to other users.
Account data is never merged with telemetry: telemetry is keyed to anonymous install IDs, account data to your email, and we do not join them for profiling, advertising, or any other purpose. To delete your account, contact the maintainer who provided your invitation; forget erases your telemetry at any time.
The "Ask Boosthis" assistant (AI processing)
The dashboard includes an optional assistant you can ask plain-English questions about your app's performance. When you use it, two things — and only those two things — are processed by a third-party AI provider to generate the answer:
- Your typed question. It is checked first: a question containing personal data or a link is rejected rather than sent.
- A privacy-safe digest of your app's already-uploaded performance snapshot — numbers, ratings, and code-defined labels only. Free-form prose and anything identifier-shaped is dropped or blocked before it leaves the server, and the answer that comes back is screened again before you see it.
Nothing new is collected for the assistant, it runs only when you ask a question, and nothing sent to the AI provider is used to train AI models.
Rule drafting on our side. Separately from the assistant, the Maintainer uses the same third-party AI provider on a schedule to help draft candidate rules from the aggregated, privacy-safe signals described above — rule kinds, severity and timing buckets, redacted code locations, and occurrence counts; never route labels from full samples, never your question, and never anything identifier-shaped. Drafts only ever land in the maintainer's private review queue, and a human decides what ships (see "How candidate rules become real rules"). This is rule-book improvement — the single purpose described above — and none of it is used to train AI models.
What we never collect
- IP addresses — never as part of telemetry, and never used to identify you or joined to your telemetry. (Like nearly every web service, the server does briefly count requests per connecting IP address purely for abuse-prevention rate limiting, and keeps routine, short-lived operational request logs; both expire automatically and are never used for profiling or joined to telemetry.)
- User IDs, emails, names, phone numbers, addresses, device IDs, or any other identifier — the PII guard blocks them at both ends. (The one email we ever hold is the one you give us if you create an optional developer account — stored separately, never joined to telemetry; see "Account data" above.)
- Request bodies, response bodies, query strings, headers
- Raw stack traces, raw error messages, or log lines — a crash report records only a redacted code location (function + file basename + line) plus the error type, and, only if you opt an app into detailed crash mode, the first line of the message and only if it passes the PII guard; never a raw stack, never a value
- Source code, diffs, file paths, hostnames, environment variables
- Screen contents, screenshots, video, audio
Defense in depth
The same 83-entry PII denylist runs on the client AND on this server. A malicious or out-of-date client cannot bypass the guard by renaming fields — both layers reject the batch on the first hit. The PII guard runs even when the kill-switch (BOOSTHIS_DISABLED=1) is active, so disabling the runtime can never smuggle PII past the chokepoint.
Retention
Full performance samples and cross-runtime traces (the waterfall view) are retained while your install participates in the program — deleted immediately by forget, and by the 60-day countdown after a revocation or suspension; spans are additionally capped per trace so no trace grows without bound. Dashboard snapshots keep only the latest snapshot per app — each upload replaces the previous one. Issue & fix signatures are kept while your install participates in the program — the server keeps one row per install and signature, and repeats just add to a counter; they are not deleted on a fixed schedule or when a rule ships. If you erase your data (forget), issue & fix signatures, crash signatures (with any opt-in detailed fields removed), and learned rules are retained but permanently de-identified — your install ID is replaced with a random anonymous key that cannot be traced back to you (see Part A, Section 7). Aggregated counts with no install ID may be retained longer for trend analysis. Account data (email, password hash, sessions, billing status) is kept while your account is active — ask the maintainer to delete your account. If your access is revoked or suspended, the associated stored data is deleted after the 60-day countdown in Part A, Section 14 (restoring access cancels it; forget is immediate). Short-lived operational rows (sessions, one-time codes, rate-limit counters, checkout working state) expire and are pruned automatically within hours to days. Routine backups of the operational database are kept for up to 30 days and rotate out automatically — data you erase disappears from backups as they rotate. Boosthis runs on cloud infrastructure that may be located outside your country (currently a US-based cloud provider); by using Boosthis you consent to processing there.
How to stop reporting / delete your data
Stop the optional full samples: call boosthis.disable_telemetry() / disableTelemetry(). The always-on issue & fix signals keep flowing for registered apps.
Stop everything immediately: set the emergency kill-switch BOOSTHIS_DISABLED=1 in your app's environment. The whole runtime — issue signals included — goes silent at once. The kill-switch always wins.
Delete everything: run boosthis telemetry forget (Python) or npx boosthis telemetry forget (JS). This calls POST /api/installs/forget with your install ID; we delete the install row and every sample, snapshot, trace, and alert tied to it, and permanently de-identify the aggregated learning signals (signatures, resolutions, crash signatures with detailed fields removed, learned rules) by replacing your install ID with a random anonymous key. After erasure nothing we hold can be linked to you or your app. Irreversible. (Per Part A, Section 7, the assignment survives erasure: de-identified learning signals and rules already derived are retained.)
Children
Boosthis is a developer tool. It is not intended for users under 16, and we do not knowingly collect data from anyone under 16.
Changes & contact
If we change this document, we will bump the version of Boosthis and note it in the release. Your existing consent remains valid only for the version you opted into. Boosthis is an invite-only, private toolkit — for any terms or privacy question, contact the maintainer who provided your invitation, or email support@boosthis.com. If you email support, we keep your message (address, subject, and text) so we can reply and keep a record of the request; support mail is never joined to telemetry.