Privacy Policy
Last updated: March 26, 2026
1. Introduction
BuddyAI ("we", "our", or "us") operates the following AI-powered platforms:
- TicketBuddy — AI-powered customer support and ticket management
- ReviewBuddy — AI-powered Google review management and response generation
- KeywordBuddy — AI-powered keyword research and SEO analysis tool
All platforms are accessible via ticketbuddy.ai.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use any of our platforms.
By creating an account or using any of our platforms, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
- First name, last name, and display name
- Email address and profile picture (from Google OAuth if used)
- Role within your team (Admin, Agent, or User)
- Onboarding status and step progress
- Invitation origin (if you were invited by another user)
2.2 Authentication & Security Data
- Hashed passwords (bcrypt, 12 rounds — we never store plain-text passwords)
- Email verification tokens and expiry timestamps
- Password reset tokens and expiry timestamps
- Google OAuth ID and provider type (for Google sign-in users)
- JWT session tokens (7-day expiry, stored as browser cookies)
2.3 Email Integration Data (TicketBuddy)
When you connect a Gmail account for support email integration on TicketBuddy, we store:
- Gmail OAuth access tokens and refresh tokens (encrypted in our database)
- Token expiry metadata
- The linked support email address and display name
- Company name and support inbox configuration
2.4 Ticket & Support Data (TicketBuddy)
- Email content (subject lines, body, HTML-formatted threads)
- Sender and recipient email addresses
- Attachment file names and metadata
- Ticket status, priority, tags, and confidence scores
- Agent assignment and team collaboration data
2.5 Review & Business Profile Data (ReviewBuddy)
When you connect your Google Business Profile on ReviewBuddy, we access and store:
- Google Business Profile location IDs and display names
- Customer review content, star ratings, and reviewer names
- AI-generated reply drafts and your edited/published responses
- Review response history and publication timestamps
2.6 Keyword & Search Data (KeywordBuddy)
- Keyword queries and search terms you submit for analysis
- Keyword metrics, volume estimates, and difficulty scores returned by our AI
- Saved keyword lists and project names
- Export history and report generation logs
2.7 Knowledge Base Content (TicketBuddy)
- Uploaded documents (PDFs, text files)
- Website content provided for scraping
- Direct text entries submitted for AI training
- Processed and extracted content stored for RAG (Retrieval-Augmented Generation)
2.8 Subscription & Billing Data
- Stripe Customer ID and Subscription ID
- Subscription status (trialing, active, canceled, past_due)
- Trial start and end dates
- Payment method status (managed by Stripe — we do not store card numbers)
2.9 Usage & Technical Data
- Account creation and update timestamps
- Log data for application monitoring and error reporting
- Browser cookies for session management (see Section 7)
2.10 CMS Site Integration Data (KeywordBuddy)
When you connect a WordPress, Shopify, or Wix site to KeywordBuddy via our official plugin or app, we collect and store the following:
Data read from your connected site:
- Existing blog post and article titles, slugs, and URLs (used solely to check for duplicate content before publishing)
- Blog and article IDs required to target the correct publishing destination
- Site URL, shop subdomain (Shopify), or site ID (Wix)
Data written to your connected site:
- AI-generated blog post title, HTML content body, and URL slug
- SEO metadata: title tag and meta description (written to Yoast SEO or Rank Math fields on WordPress)
- Publication status (published or draft, as selected by you)
Credentials and configuration stored on KeywordBuddy servers:
- WordPress: API key generated by the KeywordBuddy plugin (stored in your WordPress database and on our servers), or application password (username + app password) if using manual connection
- Shopify: OAuth access token issued by Shopify, shop subdomain, and target blog ID
- Wix: OAuth access token and refresh token issued by Wix, site ID, and member ID
- Publishing history: post ID on the external site, publish status, and timestamps
Authentication:
- WordPress connections use a single-use 15-minute token handshake during setup, then an HMAC-validated API key for ongoing requests
- Shopify connections use Shopify's standard OAuth flow; tokens are validated with HMAC-SHA256
- Wix connections use Wix's OAuth flow; tokens are validated with HMAC-SHA256 against your Wix app instance
Disconnection and data removal:
- When you disconnect a site from KeywordBuddy, the site connection is deactivated and credentials are no longer used
- On WordPress, the plugin removes its stored API key from your WordPress database on deactivation
- You can permanently delete a connected site and all associated credentials from the KeywordBuddy dashboard at any time
2.11 Messaging Channel Data (TicketBuddy — WhatsApp, Messenger & Instagram)
When you connect a WhatsApp Business number, Facebook Page, or Instagram professional account to TicketBuddy, and when your customers message that number or account, we receive and process the following through Meta's APIs:
- Your customer's phone number (WhatsApp), page-scoped sender ID (Messenger), or Instagram-scoped sender ID (Instagram)
- Your customer's profile name, where Meta makes it available
- The content of messages sent to and received from your customers
- Basic identifying information about your connected Page or Instagram account (e.g. name, username, ID)
- Page access tokens and app credentials needed to send and receive messages on your behalf
We explicitly commit that:
- This data is used only to operate the customer support features you configured — receiving customer messages, generating AI-assisted replies, and letting your support team reply from TicketBuddy
- We do not sell, share, or use this data for advertising or marketing purposes
- We do not use this data to train general-purpose AI models
- You can disconnect any of these integrations at any time from TicketBuddy Settings → Integrations, which removes our stored access
- If a person who connected an account via Meta login requests deletion of their data through Facebook's own account settings, we automatically remove the associated integration and credentials and notify the affected account owner
3. How We Use Your Information
- To create and manage your account and team workspace across our platforms
- TicketBuddy: To convert incoming emails into organised support tickets and send replies on your behalf via your connected Gmail account
- ReviewBuddy: To fetch your Google reviews, generate AI reply drafts, and publish responses to your Google Business Profile
- KeywordBuddy: To run keyword analysis, return SEO metrics, generate research reports, and publish AI-generated blog posts to your connected WordPress, Shopify, or Wix site
- To power AI features such as auto-tagging, priority assignment, and knowledge base queries
- To send transactional emails (account verification, password reset, trial notifications)
- To process subscription payments and manage billing via Stripe
- To enforce role-based access controls and team permissions
- To improve the reliability and accuracy of our platforms
- To comply with applicable legal obligations
4. Google API Services & Data Usage
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.1 Gmail (TicketBuddy)
When you connect your Gmail account, we request the following OAuth scopes:
gmail.readonly— to read incoming support emails and create ticketsgmail.send— to send replies from your Gmail addressgmail.compose— to compose new support emailsgmail.modify— to archive or update email labels
4.2 Google Business Profile (ReviewBuddy)
When you connect your Google Business Profile, we request access to:
- Read your business locations and associated reviews
- Post replies to reviews on your behalf
We explicitly commit that across all Google API integrations:
- Google data is used only to operate the specific features you configured
- We do not sell, share, or use Google data for advertising purposes
- We do not use Google data to train general-purpose AI models
- You can disconnect your Google account at any time from the Settings page
- Revoking access will delete your stored Google OAuth tokens from our database
5. Third-Party Services
Our platforms integrate with the following third-party services. Each service operates under its own privacy policy.
| Service | Purpose | Used by |
|---|---|---|
| Google OAuth 2.0 | User authentication and Gmail / Google Business Profile integration | All platforms |
| Google Business Profile API | Fetching reviews and posting AI-generated replies | ReviewBuddy |
| Meta Graph API (WhatsApp, Messenger & Instagram) | Sending and receiving customer messages via your connected WhatsApp number, Facebook Page, or Instagram account | TicketBuddy |
| Azure OpenAI | AI-powered ticket analysis, review reply generation, and keyword research | All platforms |
| Fly.io | Application hosting for TicketBuddy backend services | TicketBuddy |
| Cloudflare Pages | Frontend/dashboard hosting | TicketBuddy |
| Cloudflare R2 | Storing knowledge base documents (PDFs, text files, scraped content) | TicketBuddy |
| Supabase (PostgreSQL) | Primary database for TicketBuddy user, ticket, and account data | TicketBuddy |
| Amazon SES | Transactional and support email delivery | TicketBuddy |
| Stripe | Subscription billing and payment processing | All platforms |
| Resend | Transactional email delivery (verification, password reset) | All platforms |
| WordPress REST API | Reading existing posts for deduplication and publishing AI-generated blog content to connected WordPress sites | KeywordBuddy |
| Shopify Admin API | Reading existing articles for deduplication and publishing AI-generated blog content to connected Shopify stores | KeywordBuddy |
| Wix Blog API | Reading existing posts for deduplication and publishing AI-generated blog content to connected Wix sites | KeywordBuddy |
We do not sell your personal data to any third party for marketing or advertising purposes.
6. Data Storage & Security
- TicketBuddy application data is hosted on Fly.io with a Supabase (PostgreSQL) database and Cloudflare R2 for document storage; other platforms may use Microsoft Azure infrastructure
- Passwords are hashed using bcrypt with 12 salt rounds — plain-text passwords are never stored
- All data in transit is encrypted using TLS/HTTPS
- Database connections use SSL encryption
- OAuth tokens are stored in the database and access is protected by JWT-based authentication
- Role-based access control (RBAC) restricts data access to authorised team members only
- UUIDs are used as primary keys to prevent ID enumeration attacks
7. Cookies & Session Tokens
Our platforms use browser cookies to maintain your authenticated session. No third-party advertising or tracking cookies are used.
| Cookie | Purpose | Expiry |
|---|---|---|
token | JWT authentication token | 7 days |
userId | User identifier for API calls | 7 days |
email | Logged-in user email | 7 days |
role | User role for access control | 7 days |
name | Display name | 7 days |
8. Data Retention
- Account data is retained for the duration of your subscription and a reasonable period thereafter
- TicketBuddy ticket and thread data is retained while your account is active
- ReviewBuddy review response history is retained while your account is active
- KeywordBuddy saved keyword lists and reports are retained while your account is active
- Knowledge base documents are retained until you delete them or close your account
- Gmail and Google Business Profile OAuth tokens are deleted immediately when you disconnect your account
- KeywordBuddy CMS integration credentials (WordPress API keys, Shopify access tokens, Wix OAuth tokens) are deactivated when you disconnect a site; you may permanently delete all associated data from the KeywordBuddy dashboard
- AI-generated blog posts saved in KeywordBuddy are retained while your account is active; published posts on your connected site remain on your site and are not affected by disconnection
- You may request complete data deletion by contacting us at info@ticketbuddy.ai
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate or incomplete data
- Deletion — Request deletion of your personal data ("right to be forgotten")
- Portability — Request an export of your data in a machine-readable format
- Withdrawal of Consent — Disconnect Google access or close your account at any time
- Objection — Object to certain types of data processing
To exercise any of these rights, contact us at info@ticketbuddy.ai.
10. Government & Law Enforcement Data Requests
This section governs how we respond to requests from government agencies, law enforcement, or other public authorities for personal data of our users, including data made available to us by Meta through our WhatsApp, Facebook Messenger, and Instagram integrations. It applies to any formal request from a public authority (law enforcement, a court, a government agency, or a regulator) seeking personal data about a TicketBuddy user or a user's customer. It does not apply to search warrants or court orders connected to criminal investigations, which are handled under separate legal counsel guidance on a case-by-case basis.
10.1 Legal Review Before Any Disclosure
We do not disclose personal data to a public authority unless the request is accompanied by valid legal process appropriate to the requesting jurisdiction (for example, a subpoena, warrant, or court order). Every request is reviewed by a designated responsible person before any response is sent, to confirm:
- The request is legally valid and properly issued
- The requesting authority has jurisdiction over TicketBuddy or the data in question
- The request is not manifestly overbroad or unclear in scope
If a request does not meet these criteria, we will not comply until the requesting authority provides adequate legal process, or we will seek legal advice before responding.
10.2 Data Minimization
When a request is determined to be valid, we disclose only the minimum data specifically and legally required by that request — never more. General account or business data unrelated to the specific request is not disclosed.
10.3 Documentation
Every request received is logged, recording:
- The requesting authority and date of the request
- The legal basis provided (e.g., subpoena number, court order reference)
- The data disclosed, if any
- Who at TicketBuddy reviewed and handled the request
This record is retained for internal accountability and can be produced if required by law or by a platform partner (e.g., Meta) as evidence of this policy being followed. Questions about this policy, or a request from a public authority, should be directed to info@ticketbuddy.ai.
11. Children's Privacy
TicketBuddy, ReviewBuddy, and KeywordBuddy are not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of TicketBuddy, ReviewBuddy, or KeywordBuddy after changes are posted constitutes your acceptance of the revised policy.
13. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy, please contact us:
- Email: info@ticketbuddy.ai
- Website: ticketbuddy.ai