Legal
Privacy Policy
Last updated July 22, 2026
BotMarket (“we,” “us”) runs a subscription service that hosts configurable Highrise bots on your behalf. This page explains what personal data we collect through the dashboard and your bot instances, why we collect it, and the choices you have.
We built this product for a Highrise audience that skews young, so we’ve tried to write this in plain language rather than dense legal boilerplate. If anything here is unclear, email us — see “Contact” below.
Who we are
BotMarket is an independent, unofficial project, operated by CodeSwift (codeswift.com.br). We are not affiliated with, endorsed by, or sponsored by Highrise or Pocket Worlds — “Highrise” is referenced only to describe what our bots connect to.
We’re a Brazil-based company. We’ll publish our registered legal name, CNPJ, and business address on this page once they’re finalized; until then, you can reach us at the contact address below, or at codeswift.com.br.
What we collect
- Account info: your email address, and if you sign in with Google, the name and profile photo Google shares with us.
- Age attestation: a timestamp confirming you told us you’re 18 or older — we don’t collect your birthdate or an ID.
- Billing details: handled by Stripe. We never see or store your full card number; we keep your Stripe customer ID, subscription status, and invoice history.
- Your bot’s access token: encrypted the instant it reaches our servers. It’s write-only — we display only the last 4 characters, and no one, including us, can read it back out in full.
- Room activity your bot generates: chat and event data needed for the features you turn on (for example, moderation logs or greeting history), linked to Highrise user IDs, not to our own accounts.
- Product usage: which pages and features you use, so we can tell what’s working. Session recording is off, and we never capture what you type into the token field.
- Your language preference, so emails and the dashboard show up in the right locale.
Why we collect it
- To run the service: connect your bot, apply your configuration, and show you its status.
- To bill you and prevent fraud, through Stripe.
- To email you things you actually need to know: sign-in links, a payment problem, or your bot going down.
- To enforce our Terms and keep the platform we run on healthy — including suspending instances used for harassment or spam.
- To meet our own tax, accounting, and legal obligations.
How long we keep it
Room event logs are kept for 90 days, then reduced to anonymized daily counts — the detailed rows are deleted, not just archived.
Account and configuration data is kept for as long as your account is active.
Delete your account and we cancel your subscriptions, stop your bot instances, and destroy your bot token immediately. The rest of your personal data is deleted within 30 days.
Stripe keeps payment records for as long as it’s legally required to, independent of what we do on our side.
Your rights
- Access or export the personal data we hold about you.
- Correct inaccurate account details.
- Delete your account and data — self-serve from Account settings, or by emailing us.
- Object to non-essential email — though today, we only send you email your account actually needs (sign-in, billing, status alerts).
- If you’re in Brazil, these rights are protected under the LGPD (Lei Geral de Proteção de Dados). We apply the same rights to everyone who asks, regardless of where you live.
Age requirement
BotMarket is for adults: you must be 18 or older, or the age of majority where you live, and you confirm this when you sign up.
If we learn an account belongs to someone under that age, we refund the current billing period and suspend the account.
Security
Your bot token is encrypted the moment it reaches us and is never returned by any part of the dashboard or API — only a last-4 reference is ever shown.
Traffic to and from BotMarket is encrypted in transit (TLS). Access to production systems is limited to what each part of our service actually needs — for example, the servers that run your bot don’t have access to billing data.
No system is perfectly secure, and we can’t promise otherwise — but token handling is the one thing we’ve deliberately over-engineered, because it’s the one thing that matters most here.
International data transfers
Our company is Brazil-based, and some of the providers listed above (like Stripe, Google, PostHog, and Sentry) process data outside Brazil, including in the United States. Where that happens, we rely on those providers’ own safeguards for cross-border transfer.
By using BotMarket, you understand your data may be processed outside the country you live in.
Changes to this policy
If we make a material change to how we handle your data, we’ll update the date at the top of this page and, for significant changes, email you before they take effect.
Contact
Questions about this policy, or want to exercise one of the rights above? Email botmarket@codeswift.com.br.