Integrity is our baseline. This policy explains how BoxSight LLC ("we," "our," or "us") manages your information across our ecosystem. We prioritize local processing and transparency in all AI-driven interactions.
1. Information We Collect
Direct Submission
- Account Credentials: Email addresses and profile metadata provided during registration.
- Application Data: Content you send to our servers through an app so that it can do its job.
- Inquiries: Information shared during support requests or technical consultations.
Automated Collection
- Technical Telemetry: Device identifiers, OS versions, and network performance metrics.
- Usage Analytics: Feature engagement patterns and diagnostic logs to maintain service stability.
These are the general terms and they apply to every BoxSight app. Individual apps may collect less than this. Where section 2 describes different practice for a particular app, that description governs for that app.
2. Where individual apps differ
One policy covers every BoxSight app. This section lists only the places where a particular app does something the general terms above do not already describe. All four current apps — SpendCity, LIITOS, LIITOS-AI and Topos — are described below.
SpendCity (Expense Tracking)
SpendCity runs entirely on your device, and none of your data reaches us. Receipts you photograph, the merchant, date and line items read from them, and everything else you record are stored only in an encrypted database on your phone; captured images are kept as encrypted containers, with no plaintext copy left on the device. Reading and categorising a receipt happens on the phone itself — using Apple's on-device models on iOS and Google ML Kit on Android — not on a server.
There is no SpendCity account and we operate no server that receives this data. We cannot read your receipts, and we could not produce them if we were asked to. The app contains no analytics and no crash-reporting SDK, and the only request it makes over the network is for foreign-exchange rates, which carries none of your information. Consequently the collection described in section 1 and the third-party processing in section 3 do not apply to SpendCity, and section 6 has no server-side data to reach: removing the app, or clearing your data from inside it, is the deletion.
LIITOS (Sustainability Research)
LIITOS is an account-based social platform, and it stores more about you than the other apps. Your account holds your email address and a hashed password, your name, and whatever you choose to add to your profile: university or institution, country, role, a short biography, an avatar, and an ORCID identifier. If you upload a CV we store the text extracted from it.
Because LIITOS is a place where researchers publish and talk to each other, we also store what you do there: your submissions, comments, likes and votes, who you follow, the items you save and watchlist, which articles you have read, your expert profile and any endorsements, research projects and applications to them, your notification and email preferences, and private messages you exchange with other users. Those messages are stored on our servers and are not end-to-end encrypted, so we are technically able to read them. Whether your profile is publicly visible is your choice and is off unless you turn it on.
The job-matching feature sends personal data to Google Gemini. When you ask LIITOS to assess how well you fit a posting, your name, country, biography, institution, expertise areas and the text of your CV are sent to the Gemini API to produce that assessment. Gemini is also used to enrich article summaries and produce the weekly video pieces. Job listings themselves are fetched from Adzuna and other job boards — nothing about you is sent to them.
The LIITOS app contains no analytics SDK, no crash-reporting SDK, and no advertising identifier.
LIITOS-AI (News Briefings)
LIITOS-AI signs you in through BoxSight's shared sign-in and stores your email address, the focus areas you pick, your preferred delivery time and time zone, whether you have finished onboarding, your bookmarks and notification records, when you were last active, and the platform and app version last seen on the account.
Briefings are produced by processing published articles with the Google Gemini API. The focus areas you have chosen are included in that request so the briefing matches your interests; your name, email and account identifier are not.
The LIITOS-AI app contains no analytics SDK, no crash-reporting SDK, and no advertising identifier.
Topos (Nearby-Places Finder)
No account required. Topos identifies a signed-out installation with an anonymous session token issued by our server, held in your device's secure keychain/keystore. It is used for rate-limiting and to keep your saved activity separate from anyone else's. It is not your name or email, and Topos contains no advertising identifier.
- Precise location (GPS): Collected only while the app is in use (foreground), at the moment you search, to find nearby places and calculate travel times. We do not collect background location and do not track movement between searches. Your coordinates are sent to our backend and to our mapping/places providers to perform the search you requested; we store the search origin only in coarsened form (rounded to approximately 110 metres) for coverage analytics — never your exact coordinates.
- Search and place activity: Each search is recorded with what you searched for — the category, the situation bundle, or the text you typed — along with the coarsened origin described above, the time radius, the transport mode, how many results came back and which places they were, and the platform, OS version, device model and app version that made the request. Opening or saving a place records a similar entry for that place. When you are signed in these records carry your account identifier and are linked to you; signed out, they carry only the session token.
- If you create a Topos account: your email address, and the content you choose to save — favorites (a place's name, address and coordinates), saved searches (the category or text you searched for, the time radius and the transport mode), and multi-stop itineraries. This content is linked to your account rather than to a session token, and is removed when you delete the account. We also keep on the account the platform, OS version and app version last seen on it, and the time it was last active.
- Device & diagnostics: Platform, OS version, device model and app version, sent with each request, plus IP/connection metadata for security and abuse prevention. Our backend records which endpoint each request reached, and logs server-side errors (endpoint, status code, error type) so we can keep the service working. Topos performs no on-device crash reporting and no on-device usage analytics — there is no analytics or crash-reporting SDK in the app, and no analytics or crash telemetry is sent to any third party.
- Third-party processors: Mapbox (map tiles), Google Maps Platform (place search, details, and travel times), and Google Gemini (short place descriptions — we send only a place's name, address, and category, never your identity or location history; not used to train Google's models).
Retention and deletion (Topos): Used signed out, these records are tied only to the anonymous session token described above, not to a name or an account. Used signed in, they are linked to your Topos account — deliberately, so that deleting your account reaches the records written from every device you have used it on. Each record is automatically deleted 180 days after it is created. You may also erase all of your captured search activity at any time from the in-app My Activity screen ("Clear my activity"), which permanently deletes every search-origin record associated with your session token — the account-free equivalent of the account-deletion right described in section 6 ("Account Deletion"). That section's 7-day purge window applies to our account-based products; for Topos, records are purged on your in-app request (or on deletion of a Topos account, where one is used) and otherwise expire automatically at 180 days.
3. Third-Party AI Processing
Consent Management: AI features require explicit activation. You may opt-out or withdraw consent at any time within your Application Settings.
We utilize enterprise-grade AI services for specific cognitive tasks:
LLM Reasoning & Insights
We use the Google Gemini API to generate briefings, summaries and other written output. What is sent depends on the app and is described in section 2; for one feature in LIITOS it includes personal information you have provided. All processing is governed by specific enterprise terms that prohibit the use of your data for base model training.
4. Security & Data Sovereignty
We implement structural safeguards to protect your intellectual and personal property:
- End-to-end encryption for data in transit (TLS 1.3) and at rest (AES-256).
- Hierarchical access controls and multi-factor authentication.
- Strategic data residency in accordance with international sovereignty frameworks.
5. Your Rights & Data Portability
You maintain full control over your digital footprint. You have the right to request access to, correction of, or permanent deletion of your data. For portability requests or CCPA/GDPR inquiries, contact us at privacy@boxsight.ai.
6. Account Deletion
Upon initiating account deletion, all associated data—including saved content and metadata—is purged from our active systems within 7 days. This process is irreversible.