Skip to content
BOCY
Terms of service

Legal

Privacy

Last updated2026-09-01

This describes what the BOCY platform actually does with your data, established by reading the code that runs it. Where we do not have a mechanism, this document says so rather than describing one.

Contents

  1. 01What this document covers
  2. 02What we collect, and where it goes
  3. 03If you request access
  4. 04If you sign in
  5. 05What you type into Mesh
  6. 06Companies that receive or observe your data
  7. 07Fonts are loaded from Google on every page
  8. 08Cookies and what stays in your browser
  9. 09How long we keep data, and how to have it deleted
  10. 10Security — what we actually do
  11. 11What this document does not yet establish
  12. 12Changes and contact
01

What this document covers

It covers the BOCY website and the Mesh platform at www.bocy.io, operated by [to be confirmed — legal entity name and registered address]. In this document, “we” means that entity and “you” means anyone who visits the site, requests access, or signs in.

Mesh is an invite-only research platform for professional investors. Most of the site is behind a sign-in gate. The public part is the homepage, the use-case pages, the request-access page, the sign-in page, and this document.

02

What we collect, and where it goes

This is the complete list. Sections 3 to 8 explain each row.

Personal data · destination · retention
WhatWhere it goesHow long
Your name, work email, firm, and the free text you write in “what are you trying to build”Emailed to our desk through Resend, our email provider, and stored in our database (Neon)Indefinitely. We have no automatic deletion.
Your role and company website, if you use the /request-access pageSame as aboveIndefinitely.
Your Google account details, if you sign in with GoogleHeld by Supabase, our authentication provider. We request no Google permissions beyond basic sign-in.For as long as your account exists.
The email address you type at the VC & partner doorStored in a signed cookie on your device, and recorded alongside anything you create while signed inThe cookie lasts 7 days. The record is kept indefinitely.
The theses, research questions and notes you type into the platformStored in our database, and sent to Anthropic to be processed by a language modelIndefinitely.
Your IP addressRead by our servers to rate-limit abuse; held in memory only, never written to our database. Also received by Vercel (our host) and by Google (fonts) — see section 7.In our own memory, under a minute. Vercel and Google keep their own logs.
A push-notification subscription, if you enable notificationsStored in our databaseUntil you turn notifications off, which deletes the record.
03

If you request access

The form on the homepage asks for four things: your name, your work email, your firm, and — optionally — what you are trying to build. The older request-access page also asks for your role and your company website. Nothing else is captured, and the form does not read anything from your device.

When you submit it, three things happen:

  • We email the details to our desk, with your address set as the reply-to so a reply goes straight back to you. The email is sent through Resend.
  • We send you a confirmation email, also through Resend.
  • We store the same details as one row in our database, as a backup we can search. If the database is unreachable the request still goes through by email.

We reject personal email addresses at this form and ask for a work address instead. That is a qualification check, not a data-collection one — we do not do anything else with the domain.

The subscribe field in the footer does not send us anything. It has no server behind it. Pressing the arrow opens your own email client with a message addressed to us and your address in the body; the send is yours, from your own outbox, and we only receive it if you actually send it. There is no mailing list and no stored address.

04

If you sign in

There are two doors, and they store different things.

Google sign-in. You are sent to Google, you authorise the sign-in there, and Google returns a code we exchange for a session. Your identity is held by Supabase, our authentication provider — we do not keep our own copy of your password, and we never see it. We request no Google permissions beyond the basic sign-in scope. Because access is invite-only, we check the returned email address against a list of approved addresses; if it is not on that list you are signed out immediately and sent back to request access.

During onboarding we save four things to your Supabase profile: the role you pick, the theme you pick, the first company you enter, and a flag recording that you finished onboarding.

The VC and partner door. This is a shared email-and-password credential issued to a specific firm. The password is checked against a value held in our server configuration; we do not store the password you type. On success we set a signed cookie containing the email address you typed and an expiry, valid for seven days. That email address becomes your identifier inside the platform, so it is recorded alongside anything you create.

Failed sign-in attempts at this door are counted against your IP address to slow down password guessing. That count lives in the server’s memory for one minute and is never written to a database.

05

What you type into Mesh

The product works by taking an investment thesis in your own words and building an ecosystem from it. That means the text you type is the input, and you should know exactly where it goes.

  • It is stored. The thesis you submit is saved in our database against your account, so the build can be resumed, deduplicated and re-tested later. Research questions and the answers to them are saved the same way.
  • It is sent to Anthropic. Building an ecosystem and answering a research question both call a language model operated by Anthropic. Your text is sent to their API to be processed and the result comes back to us.
  • Our own logs do not contain it. We log the model used, how many tokens a call consumed and how long it took. We do not log the content of the prompt.

If a thesis is commercially sensitive, treat typing it here the same way you would treat typing it into any hosted research tool.

06

Companies that receive or observe your data

We do not sell data and we do not share it for advertising. There is no analytics product, no advertising tag and no tracking pixel anywhere on this site. These are the companies that necessarily see something because of how the platform is built.

Third parties · what each one receives
CompanyRoleWhat it receives
VercelHostingEvery request to the site, including your IP address, browser and the page requested.
NeonDatabaseAccess requests, the theses and questions you type, and your account identifier.
SupabaseAuthenticationYour identity when you sign in with Google, and your session.
GoogleSign-in and fontsYour Google identity when you choose to sign in with Google. Separately, your IP address on every page load — see section 7.
AnthropicLanguage modelThe text you type into the platform, when it is processed.
ResendEmail deliveryYour name, email, firm and message when you request access, so the emails can be sent.
SlackInternal alertsIf configured, an internal notification containing your email address when you request an account upgrade.

Each of these companies stores data under its own terms and in its own locations. We have not established where each one stores it, and this document does not claim to know — see [to be confirmed — storage regions and data-processing terms for each provider above].

07

Fonts are loaded from Google on every page

Every page of this site, including this one, loads its typefaces directly from Google ’s font servers. That is a request from your browser to Google, and it happens before you sign in, before you click anything, and on the public marketing pages as well as inside the product.

As a result Google receives your IP address, your browser and operating system, and the address of the page you were on, every time you load a page here. We do not send Google anything else, and this is not analytics — it is how the fonts arrive. But it is a disclosure to a third party on every visit and it would be dishonest not to name it.

We are aware this can be avoided by serving the fonts from our own servers, and we regard the current arrangement as something to fix rather than something to defend.

08

Cookies and what stays in your browser

We set no advertising or analytics cookies. There are two cookies and both exist to keep you signed in:

  • A session cookie set by Supabase when you sign in with Google. It identifies your session.
  • A cookie named vc_access, set only if you use the VC and partner door. It holds the email address you typed and an expiry, is cryptographically signed so it cannot be forged, cannot be read by scripts on the page, and expires after seven days. Signing out clears it.

Separately, the app saves a few preferences in your browser’s local storage — your colour theme, the last few things you looked at, whether the map legend is open, your current theme selection, and any portfolio weights you have adjusted. These stay on your device and are never sent to us. Clearing your browser storage removes them.

The app also installs a service worker that caches a few pages so it opens when your connection is poor. That cache is on your device.

09

How long we keep data, and how to have it deleted

We do not currently delete anything on a schedule. There is no automatic expiry, no retention timer, and no periodic purge in the platform. An access request you send today is still in our database next year unless a person removes it. We would rather state that plainly than name a retention period we do not enforce.

The two exceptions, both under your control:

  • Turning off push notifications deletes your notification subscription immediately.
  • Your seven-day sign-in cookie expires on its own, and signing out clears it.

To have your data deleted, email us at hello@bocy.io. A person will remove your records from our database and our email records. This is a manual process today, not an automated one, and we will confirm when it is done. We are not, in this document, claiming a statutory response time — see section 11.

10

Security — what we actually do

We will only describe measures that exist in the running system. These do:

  • Every page and every data endpoint is closed by default. A route is only reachable without signing in if it has been explicitly added to a public list, so a new page is protected unless someone deliberately opens it.
  • Signing in is required for the data, and being signed in is not enough — your address must also be on the approved list. The check is enforced on the data endpoints themselves, not only in the interface.
  • The partner cookie is signed, cannot be read by page scripts, and is only sent over HTTPS in production. A forged or expired one is rejected.
  • Credentials are compared in constant time, and repeated failures from one address are throttled.
  • Pages are served with headers that stop the site being framed by another site and stop browsers guessing content types.
  • Anything you type that we put into an email is escaped before it is sent.

What we are not claiming. We have not completed a security audit, a penetration test or a formal certification, and we are not asserting one. We have not verified how each provider above encrypts data at rest. We do not yet run a full content-security policy on the application. No system is perfectly secure, and we will not suggest otherwise.

11

What this document does not yet establish

These are open, and listed rather than glossed over. Each one is a fact we do not yet have, not a fact we are withholding.

  • [to be confirmed — the legal entity, its registered address and its jurisdiction] — and therefore which country’s data-protection law governs this document.
  • We make no claim of compliance with the GDPR, the UK GDPR, the CCPA or any other data-protection regime, and nothing here should be read as one. If you need a specific compliance position before using Mesh, ask us and we will answer honestly about where we are.
  • [to be confirmed — a named data-protection contact]. Until there is one, privacy questions go to hello@bocy.io and a person answers them.
  • [to be confirmed — data-processing agreements with the providers in section 6].
  • There is no consent banner. Google’s font servers are contacted before you can express any preference — see section 7. We consider this a defect to fix in the product, not a position to defend in a document.
12

Changes and contact

When the platform changes what it collects, this document changes with it, and the date at the top moves. We will not backdate it. Where a change is material — a new company receiving your data, or a new category of data collected — we will say so here rather than adjust a sentence quietly.

For anything in this document, including a deletion request, email hello@bocy.io.

Questions about this document: hello@bocy.io

Terms of service · Home