Privacy policy
Last updated: 22 September 2026. A plain-language draft for the launch.
What we collect
- Account data: name, email, hashed password, organisation membership and role, sign-in times.
- Content: bot definitions, conversations, tasks, files, skills, connector settings and credentials (encrypted at rest in the vault), usage events.
- Billing data: Stripe customer and subscription ids, plan, invoices โ card numbers stay with Stripe.
- Technical data: request logs with IP address and user agent for 30 days, error reports.
Why
To run the service, to bill you, to send the emails you expect (invites, approvals, billing), to keep the service secure and to answer support requests. We do not sell personal data and do not use your content to train models.
Who sees it
The model providers you choose receive the prompts bots send them. Composio receives the OAuth tokens for the apps you connect through the catalogue. Stripe receives billing data. Resend receives your email address and the emails we send you. Hosting providers store the data in the region you chose.
How long
Until you delete it, or 7 days after you delete your organisation. Backups are kept for 30 days. Usage and billing records are kept for as long as tax law requires.
Your choices
Export or delete everything from Settings โ Data. Turn off notification emails in Settings. Ask questions at privacy@buddybots.app.
Cookies
One session cookie (bb_sid) and the theme preference. No advertising cookies, no third-party trackers.