BuddyBase

Privacy Policy

Last updated: November 27, 2025

1. Introduction

BuddyBase ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI chatbot widget platform and related services.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email address)
  • Organization details (company name, website URL, custom link)
  • Payment information (processed securely through Stripe)
  • Knowledge base content (website content you authorize us to scrape, uploaded documents)
  • Widget customization preferences

2.2 Information Collected Automatically

  • Usage data (features used, time spent, interactions)
  • Device information (browser type, operating system)
  • Log data (IP address, access times, pages viewed)
  • Conversation analytics (aggregated, anonymized chat statistics)

2.3 Information from Third Parties

  • Authentication data from Google (if using Google Sign-In)
  • Payment status from Stripe

3. How We Use Your Information

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send administrative information and updates
  • Respond to customer service requests
  • Analyze usage patterns to improve user experience
  • Detect, prevent, and address technical issues
  • Comply with legal obligations

4. AI and Your Data

BuddyBase uses artificial intelligence to power chatbot responses. We want to be transparent about how your data is used:

  • We do not use your data to train AI models. Your knowledge base content and conversation data are not used to develop, improve, or train generalized AI or machine learning models.
  • We use Retrieval-Augmented Generation (RAG) technology, which means your data is kept separate and only used to answer questions specific to your chatbot.
  • Your knowledge base content is processed by Google Gemini solely to provide responses to your chatbot users.
  • Conversation data may be stored to provide chat history features and analytics, but is never used for model training.

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your information with:

  • Service Providers: Third parties that help us operate our platform (see Sub-processors below)
  • AI Partners: Google Gemini for processing knowledge base queries
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

5.1 Sub-processors

We use the following third-party service providers to operate BuddyBase:

  • Supabase: Database hosting and authentication (United States)
  • Railway: Application hosting (United States)
  • Google Gemini: AI processing for chatbot responses (United States)
  • Stripe: Payment processing (United States)

6. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit (TLS/SSL)
  • Secure data storage with access controls
  • Regular security assessments
  • Rate limiting and DDoS protection

7. Data Retention and Backup

We retain your information for as long as your account is active or as needed to provide services. You may request deletion of your data at any time. Some data may be retained for legal compliance purposes.

Backup Responsibility: You are responsible for maintaining your own backups of important data. While we take reasonable precautions, we do not guarantee against data loss in the event of service issues, account cancellation, or downgrade.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent

To exercise these rights, contact us at [email protected].

9. Cookies and Tracking

We use essential cookies to maintain your session and preferences. We may use analytics cookies to understand how our service is used. You can control cookie preferences through your browser settings.

10. Children's Privacy

Our service is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in the United States and other countries. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses where required.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also notify you via email.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at: