1. Who we are
This policy covers the ComputeBD website, dashboard and AI Computer service (the “Service”), operated by ComputeBD (“we”). Questions about privacy: [email protected].
2. What we collect
- Account: name, email, mobile number (if you sign in by phone) and your password — stored only as a hash; we never see the password itself. If you sign in with Google, Google gives us your name and email.
- Waitlist form: name, email, phone, role, what you want to build, preferred AI Computer, expected hours and budget, notes, GitHub link, how you heard about us, and any invite or promo code.
- Payments and wallet: top-up amounts, the bKash number and Transaction ID (TrxID) you give us, bKash payment IDs, receipts, and every credit and charge in your wallet. We never ask for or receive your bKash PIN.
- AI Computer sessions: which AI Computer, when it started and stopped, how long it ran, what it cost, and which cloud provider and region ran it.
- Your files: notebooks you save (.ipynb), files and data links in “My data”, and results you save with “Save data”. Other files inside a session are deleted when the session stops.
- Offers: your invite code, who invited you and whom you invited, promo codes you used, student credit.
- Usage and security data: IP address (stored in logs as a keyed hash), browser type, pages visited, where you came from (UTM/referrer), error logs, and an audit log of actions on your account. To stop abuse we keep some signals (such as many accounts from one device) in hashed form.
- Email: whether our emails were delivered, bounced, opened or clicked — reported by our email provider.
- Support: whatever you write to us.
3. Why we use it
- To create your account, sign you in and provide the Service — start AI Computers, save and restore notebooks.
- To bill by the minute, verify top-ups, issue receipts and make refunds.
- Security: to prevent fraud, abuse and unauthorised access, and to find and fix problems.
- To send service messages (email verification, sign-in codes, receipts, session ended, security alerts) — these cannot be turned off.
- To send news and offers — only if you opted in. Every such email has a one-click unsubscribe link.
- To understand which features are useful and improve the Service, and to meet legal duties (such as accounting and tax).
We do not sell your data, and we do not train AI models on your notebooks or files.
4. Who we share it with
Trusted companies process data on our behalf to run the Service, and may use it only for that purpose:
- Cloud AI Computer providers (such as Modal, and others when needed) — your session and the files in it run on their computers, which are usually outside Bangladesh (for example in the United States).
- Hosting and network: our servers run on cloud hosting and reach the internet through Cloudflare; these may also be outside Bangladesh.
- Email delivery (such as Brevo) and SMS providers — to send emails and sign-in codes.
- bKash — to process payments.
- Google — if you sign in with Google.
- Meta (Facebook) — if the advertising measurement pixel is switched on for our public pages; it does not run on the dashboard or sign-in pages.
- Backups: encrypted database backups, stored on Google Drive if an admin enables it.
We may disclose data when required by law or a court order, or to protect someone’s life or property. If the business is sold or merged, data moves only under this policy.
5. Data outside Bangladesh
Because of the providers above, your data may be processed and stored outside Bangladesh. We use providers that follow recognised security standards and send them no more than they need. By using the Service you agree to this.
6. How long we keep it
- Account, notebooks and “My data”: while your account exists; deleted when you ask (see below).
- Other files inside a session: deleted when the session stops.
- Payments, receipts and wallet records: as long as Bangladeshi accounting and tax law requires.
- Security and audit logs: as long as needed to prevent fraud and resolve disputes; they are kept tamper-evident.
- Website usage statistics: usually 180 days.
- Database backups: encrypted, usually deleted after 14 days.
- Marketing list: if you have not opened any email for 180 days, we ask once and then remove you.
7. Cookies and browser storage
We use essential cookies to keep you signed in and to protect forms. Your browser’s local storage holds your language, an invite-link code (30 days) and a random visitor ID we use to count website visits. If the Meta pixel is on, Meta may set its own cookies. You can clear these in your browser settings, but you cannot sign in without the essential cookies.
8. Security
Passwords are strongly hashed, connections are encrypted (HTTPS), backups are encrypted, and admins use two-step sign-in with every admin action audit-logged. No system on the internet is perfectly secure. Report security issues to [email protected].
9. Your rights
You can ask at any time for a copy of your data, to correct it, to delete your account and data, to stop marketing email, or object to a use. Write to [email protected] from your account’s email address; we reply within 30 days. When we delete an account we still keep what the law requires (such as payment records).
10. Children
The Service is for people aged 18 or over. If you are under 18 you may use it only with a parent’s or guardian’s permission. We do not knowingly collect data from children under 13; tell us and we will delete it.
11. Changes to this policy
We will update this policy when needed and tell you about important changes by email or on the dashboard. The date at the top shows the last update. See also: Terms of Service, Refund Policy.