My Bad Boss AI (“the app”) is made by LuxWaveLabs LLC (“we,” “us”). This policy explains what information the app uses, where it goes, and the choices you have.
The short version: My Bad Boss AI is an adaptive alarm and timing assistant that helps you plan when to wake up, prepare, and leave based on your routines, destinations, timing preferences, traffic, weather, and other available conditions. If your plan changes or you are running behind, it can also prepare a message for you — but you always review and send it yourself. We collect only the limited information needed to provide these features, as explained below, and we never upload your full contacts list — your alarms, schedules, and contacts live on your phone, not on our servers.
Location is the heart of a commute-aware alarm. The app uses your device's location to:
To calculate routes and traffic, your coordinates are sent to Google Maps Platform (Google LLC) as part of the route request. We do not store your location on our servers, and the app does not track or log your movements. Background location, if you grant it, is used only for brief pre-wake and leave-window checks tied to alarms you created. You can use the app without location — it falls back to the home and work addresses you type in, and plain alarms work with no location at all.
If you add people to your roster (a boss, a team lead), the app stores only the contacts you explicitly pick — on your device. Your contact list is never uploaded to us. Messages to your contacts are sent through your own SMS or WhatsApp app, by you.
Shift schedules, routines, alarm preferences, and commute settings are stored on your device. The only schedule data saved server-side is the basic timing of work routines you set up (label, start time, days of the week, timezone — never coordinates or addresses), which powers commute protection under your account.
When you ask the app to draft a running-late message, the context needed to write it (for example: how late you are, your estimated arrival time, the recipient's role and first name, and the tone you chose) is processed by our server and a large-language-model provider (Google Gemini) solely to generate your draft. Drafts are never sent to anyone automatically — you always review and press send yourself, in your own messaging app.
When you use the call-intercept flow, the delay category and the draft text are stored under your account so the app can avoid repeating the same excuse. The main Send Update flow keeps your message history on your device only.
Some features let you speak instead of type (voice confirmation, voice-filled setup). The microphone is used only while you actively use those features, audio is processed to transcribe what you said, and recordings are not retained by us.
The app creates a lightweight account identity automatically the first time a feature needs our servers (a route lookup, an AI draft, or a purchase): a random user ID with no name, email, or password. Our backend provider (Supabase) stores that identity, your profile with Pro entitlement state, service-usage counters (daily AI and maps allowances), the work-routine times described above, and the call-intercept draft logs. You can optionally “secure” the account later by adding an email — that keeps the same ID and simply lets you recover your subscription on a new phone.
Subscriptions are processed by Google Play. Our subscription-management provider (RevenueCat) receives purchase tokens and subscription state so the app knows whether Pro is active. Purchases are made under your app account's random user ID — no name or email is required — so your subscription is tied to that account and follows it. We never see your payment card details.
If the app crashes, technical diagnostics (device model, OS version, stack trace) are collected via Sentry to help us fix bugs. This data is not used for advertising.
The free version currently displays a static, first-party placeholder banner only — no third-party ad network is embedded, and no advertising identifiers are collected. If we add a real ad network in a future update, we will update this policy and the Play Store data safety form first.
The app relies on these processors, each receiving only what its job requires: Google Maps Platform (routes/traffic), Google Gemini (draft generation and voice transcription), Supabase (account identity, entitlement state, usage counters), RevenueCat (subscription state), Sentry (crash reports), Open-Meteo (weather for the wake briefing — approximate coordinates only), and Google Play (payments and app distribution).
Delete everything in the app: Settings → Delete account & data removes your account and all server data immediately, and wipes the app's on-device data (routines, contacts, history, settings, wake-screen photo). Full instructions: Account & data deletion.
If you can't access the app, email support@mybadboss.app and we will delete your account within 30 days. On-device data also disappears if you uninstall the app or clear its storage. Accounts that never added an email and have been inactive for about 90 days are deleted automatically; accounts with an active paid subscription are never auto-deleted.
Data in transit is encrypted with HTTPS/TLS. Account data is protected by our backend provider's row-level security. No method of storage or transmission is 100% secure, but we design so that the most sensitive data — where you sleep and who you message — never needs to leave your phone in the first place.
The app is intended for people 13 years and older. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13.
If we change this policy, we will post the new version at this address and update the effective date. Material changes (for example, adding an ad network) will be called out in the app's release notes.
LuxWaveLabs LLC
Email: support@mybadboss.app