Legal
Privacy policy
Last updated
In one paragraph
Busymate AI is a platform that businesses use to run an AI assistant for their own customers. That means two very different groups of people are involved, and this policy keeps them apart the whole way through. When you sign up and run a workspace, we decide how your account data is handled — we are the controller. When your customers talk to the assistant you configured, you decide what happens to that conversation — you are the controller and we are your processor, acting on your instructions. Everything below says which of the two it is talking about.
Who we are
Busymate AI is operated by Sergiu Toderascu, trading as Busymate AI, at busymate.ai. You can reach us through the contact page at busymate.ai/contact or by email at mr.serebano@gmail.com — the same address published for our Shopify app. If you are in the EU or the UK and you want to raise something formally, use either channel and say so; we answer from the same place.
This policy covers the busymate.ai website, the Console, the assistant (publicly called bro), the hosted chat pages on your own subdomain or domain, our REST and MCP interfaces, and our iOS, Android and macOS apps. It does not cover the separate Busymate DevTools product, which has its own policy.
What we collect from operators
An operator is a person who signs in to run a workspace: an owner, an admin, or an agent working an inbox. From you we hold:
- Account identity — the email address you sign in with, and a display name and preferred name if you set one. Sign-in through Apple or Google gives us the identifier and email that provider releases, and nothing else.
- Workspace records — the workspaces you belong to, your role in each, and which one you are currently working in.
- What you configure — your assistant's instructions, knowledge sources, connectors, macros, automations, notification preferences and locale.
- Operational records — audit entries for changes made in the Console, usage counts per model and per workspace, and support conversations you have with us.
- Security records — sign-in events and the technical metadata every web server writes (IP address, user agent, timestamps), kept to detect abuse.
We do not ask for card numbers. Where a plan is paid, the payment is handled by the payment provider and we hold only the plan state and the identifiers it gives back.
What we process for your customers
An end customer is a person who talks to the assistant you published. For them we process, on your behalf and on your instructions:
- Conversation content — the messages exchanged with the assistant, any files attached, and the answers produced.
- Whatever the conversation carries — if your customer types an order number, an address or a phone number, that text is part of the conversation. We do not ask for it and we do not enrich it.
- Identity, only when you enable it — if you use identified visitors, we receive the identifier your own system signs for that person so the assistant can act for the right customer. The browser is never trusted to say who it is.
- Delivery metadata — the channel the conversation came in on, timestamps, and the technical metadata needed to serve the page.
You choose what the assistant may reach, and what it may do without asking. We do not use your customers' conversations to build a product of our own.
What we never do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the CCPA/CPRA that means there is nothing to opt out of, because there is no sale and no sharing.
- We do not train our own models on your data or your customers' conversations, and our agreements with the model providers listed below prohibit them from training on it either.
- We do not load any third-party analytics inside our iOS, Android or macOS apps. Analytics on the public website is Google Analytics 4, it is off by default, it runs only after you say yes in the consent bar, and Google signals and ad personalisation are disabled. If you never answer, it never runs.
How we measure the apps, and what we do not do
Inside our macOS, iOS and Android apps there is no third-party analytics tool at all. In its place we keep a small first-party record of how the app is used, so that we can tell whether it works: the app was opened, how long the window stayed open, that a notification was shown or held back because you paused them, that a link opened the app, that the badge count changed, that a preference was changed, which app version and which operating system.
Those events go to our own servers, on our own domain, and nowhere else. There is no advertising identifier, no cross-app identifier, no SDK belonging to anyone else, and none of it is sold, shared or exported. We attach your account and your workspace so that you can see your own team's activity in the Console — and so can we, for the platform as a whole. We do not record the pages you visit, the text of any conversation, your IP address or your device's browser fingerprint.
In App Store terms this is Usage Data of the kind "Product Interaction", collected for App Functionality and Analytics, linked to your account, and **not** used for tracking — Apple's "tracking" means linking your data with data from other companies' apps or websites for advertising or a data broker, which is exactly what we do not do.
Why we are allowed to process it
Under the GDPR and the UK GDPR, for operator data we rely on: performance of a contract (running the account you asked for), our legitimate interests (keeping the service secure and workable, and answering support), and consent where consent is the right basis — website analytics being the clearest case. For end-customer data we do not choose a basis at all; you do, as the controller, and we act on your instructions under Article 28.
Who else sees the data (sub-processors)
We use a small set of providers, each for one job:
- Supabase — the database, authentication, file storage and the serverless functions behind them. Account records, workspace configuration and conversation content live here.
- DigitalOcean — the servers that run busymate.ai and the tenant hosts, and the DNS for our domains. Our production machine is in London.
- AI model providers — Anthropic, OpenAI and xAI, plus any OpenAI-compatible endpoint you add yourself. A workspace only ever reaches the providers on its own allowed list, and conversation text goes to a provider only when a model of that provider answers. If you run a self-hosted model through Ollama, nothing leaves your own infrastructure for that step.
- Stripe — plan and payment processing where a plan is paid. Card details go to Stripe, never to us.
- Twilio — telephone numbers and call transport, only for workspaces that switch on voice.
- Telegram — only for workspaces that connect a Telegram hand-off, and only for the conversations routed through it.
- Apple and Google — app distribution and push notifications for the mobile and desktop apps.
- Google Analytics — the public website only, consent-gated as described above. It is not present in the apps, and no other analytics provider is either: in-app measurement is first-party, described in "How we measure the apps" above.
Adding a sub-processor that touches conversation content is a change to this list, and this page is where it is published.
Where the data is
Our primary infrastructure is in the European Union and the United Kingdom. Some sub-processors — the model providers, Stripe, Apple, Google — process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses together with the provider's own supplementary measures. If you need transfers restricted further, choose a model provider that matches your requirement; the allowed list is yours to set.
How long we keep it
- Account records live for as long as the account exists, and are deleted with it.
- Workspace configuration lives for as long as the workspace exists.
- Conversations follow the retention you set for your workspace. Where you have not set one, we keep them for as long as the workspace exists so that you can answer your own customers.
- Audit and security records are kept for up to 12 months, because a security question is often asked long after the event.
- App usage events are kept for 12 months and are deleted with the account or the workspace they belong to.
- Backups roll off within 30 days. A deletion is applied to live systems immediately and reaches backups as they expire.
Deleting your account, and deleting your customers' data
You can delete your account yourself, from inside the product, with no email to us and no waiting: open the account menu, go to Settings, then Account, and use the delete option. In the macOS app, Busymate AI › Account… opens the same panel directly. Deleting an account removes the account record, the devices it owns, and its profile and tokens. It cannot be undone.
If you are an end customer and you want your conversation with a business's assistant deleted, ask that business — they are the controller for it. If you contact us instead, we will pass the request on and tell you we have.
Your rights
Wherever you are, you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or object to a use of it, and ask for it in a portable form. In the EU and UK these are GDPR Articles 15 to 21; in California these are the CCPA/CPRA rights of access, deletion, correction and non-discrimination; comparable rights exist in the UK, Switzerland, Brazil and elsewhere and we honour them the same way. We do not charge for any of this and we do not treat you differently for asking.
We answer within 30 days. If you are not satisfied, you can complain to your data protection authority.
Children
The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, tell us and we will remove it.
Security
Sign-in is handled by our authentication provider, and every read of a row is checked against the identity making it — a workspace cannot read another workspace's rows even if the request asks for them. Credentials you give us for your own systems are write-only: you can set them and rotate them, and nobody, including us, can read them back. Before the assistant connects to a new address we check that address cannot reach anything internal. If you find a security problem, our security.txt at busymate.ai/.well-known/security.txt tells you where to send it.
Changes to this policy
If we change something that matters — a new sub-processor, a new purpose, a different retention — we update this page and change the date shown at the top. Continuing to use the service after a change means you accept it; if you do not, delete the account, which you can do yourself at any time.
How to reach us
Contact page: busymate.ai/contact. Email: mr.serebano@gmail.com. Security reports: busymate.ai/.well-known/security.txt.