Legal
Privacy policy
Last updated
In one paragraph
Busymate AI is a platform that businesses use to run an AI assistant for their own customers. That means two very different groups of people are involved, and this policy keeps them apart the whole way through. When you sign up and run a workspace, we decide how your account data is handled — we are the controller. When your customers talk to the assistant you configured, you decide what happens to that conversation — you are the controller and we are your processor, acting on your instructions. Everything below says which of the two it is talking about.
Who we are
Busymate AI is operated by Antreprenor Independent „SERGIU TODERAȘCU”, a registered sole proprietorship (IDNO 1026023024336; D-U-N-S 933919838) at 21/1, apt. 74, Nicolae Dimo str., Chisinau, MD-2068, Republic of Moldova, trading as Busymate AI, at busymate.ai. You can reach us through the contact page at busymate.ai/contact, or directly by email at hi@busymate.ai — put "Privacy" in the subject for a data request or a question about this policy, and "Security" for a security report, so it reaches the right person faster. If you are in the EU or the UK and you want to raise something formally, use either channel and say so; we answer from the same place.
This policy covers the busymate.ai website, the Console, the assistant (publicly called your mate), the hosted chat pages on your own subdomain or domain, our REST and MCP interfaces, and our iOS, Android and macOS apps. It does not cover the separate Busymate DevTools product, which has its own policy.
What we collect from operators
An operator is a person who signs in to run a workspace: an owner, an admin, or an agent working an inbox. From you we hold:
- Account identity — the email address you sign in with, and a display name and preferred name if you set one. Sign-in through Apple or Google gives us the identifier and email that provider releases, and nothing else.
- Workspace records — the workspaces you belong to, your role in each, and which one you are currently working in.
- What you configure — your assistant's instructions, knowledge sources, connectors, macros, automations, notification preferences and locale.
- Operational records — audit entries for changes made in the Console, usage counts per model and per workspace, and support conversations you have with us.
- Security records — sign-in events and the technical metadata every web server writes (IP address, user agent, timestamps), kept to detect abuse.
We do not ask for card numbers. Where a plan is paid, the payment is handled by the payment provider and we hold only the plan state and the identifiers it gives back.
What we process for your customers
An end customer is a person who talks to the assistant you published. For them we process, on your behalf and on your instructions:
- Conversation content — the messages exchanged with the assistant, any files attached, and the answers produced.
- Whatever the conversation carries — if your customer types an order number, an address or a phone number, that text is part of the conversation. We do not ask for it and we do not enrich it.
- Identity, only when you enable it — if you use identified visitors, we receive the identifier your own system signs for that person so the assistant can act for the right customer. The browser is never trusted to say who it is.
- Delivery metadata — the channel the conversation came in on, timestamps, and the technical metadata needed to serve the page.
You choose what the assistant may reach, and what it may do without asking. We do not use your customers' conversations to build a product of our own.
What we never do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the CCPA/CPRA that means there is nothing to opt out of, because there is no sale and no sharing.
- We do not use your data or your customers' conversations to train models that we develop or operate. When a workspace sends content to an external AI provider it has enabled, that provider handles it under its own terms and settings; see the provider details below.
- We do not load any third-party analytics inside our iOS, Android or macOS apps. Analytics on the public website is Google Analytics 4, it is off by default, it runs only after you say yes in the consent bar, and Google signals and ad personalisation are disabled. If you never answer, it never runs.
SMS and text messaging
If you text our support number, +1 607 669 2331, the conversation is a customer-support conversation with Busymate AI's support assistant and, where it hands off, our support team — the same purpose as any other support channel we offer, and nothing else.
We collect your mobile phone number, the messages you send us and your SMS opt-in consent only to answer you in that conversation.
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except the service providers we need to deliver the messages themselves (our SMS delivery provider and the carriers), who receive them solely to deliver them.
Message frequency varies by conversation. Message and data rates may apply. Reply STOP to a conversation at any time to opt out, or HELP for help; our support contact is hi@busymate.ai. See busymate.ai/sms for the full program description, and the SMS terms for the program's terms.
How we measure the apps, and what we do not do
Inside our macOS, iOS and Android apps there is no third-party analytics tool at all. In its place we keep a small first-party record of how the app is used, so that we can tell whether it works: the app was opened, how long the window stayed open, that a notification was shown or held back because you paused them, that a link opened the app, that the badge count changed, that a preference was changed, which app version and which operating system.
Those events go to our own servers, on our own domain, and nowhere else. There is no advertising identifier, no cross-app identifier, no SDK belonging to anyone else, and none of it is sold, shared or exported. We attach your account and your workspace so that you can see your own team's activity in the Console — and so can we, for the platform as a whole. We do not record the pages you visit, the text of any conversation, your IP address or your device's browser fingerprint.
In App Store terms this is Usage Data of the kind "Product Interaction", collected for App Functionality and Analytics, linked to your account, and not used for tracking — Apple's "tracking" means linking your data with data from other companies' apps or websites for advertising or a data broker, which is exactly what we do not do.
Why we are allowed to process it
Under the GDPR and the UK GDPR, for operator data we rely on: performance of a contract (running the account you asked for), our legitimate interests (keeping the service secure and workable, and answering support), and consent where consent is the right basis — website analytics being the clearest case. For end-customer data we do not choose a basis at all; you do, as the controller, and we act on your instructions under Article 28.
Who else sees the data (sub-processors)
We use providers for distinct purposes. A workspace reaches only the services it enables. The locations below identify the deployment region we confirmed or the locations a provider publishes; they do not establish every processing or remote-access location, or guarantee that data stays in one country.
- Supabase — GoTrue account authentication, support-admission and route authority, the support database, and handoff Edge Functions. The owned project’s primary storage region is Ireland (`eu-west-1`); the support database can hold paused support-message text and provider IDs. The main native conversation and workflow store is separate and runs on our DigitalOcean host in London. Supabase Edge Functions execute globally near requesters by default; our current integration does not pin an invocation region, and we have not verified the region of each invocation. The current account’s contracting entity and complete international processing locations have not been confirmed here. See Supabase regions and Edge Function regional invocations.
- DigitalOcean, LLC — hosts the servers that run busymate.ai and workspace hosts, including native PostgreSQL workflow, channel and conversation state, and provides DNS for our domains. The confirmed host deployment is London, United Kingdom (`lon1`). DigitalOcean lists United States-based subprocessors for infrastructure backups, platform security and support; this host location does not establish every processing or remote-access location. See DigitalOcean’s subprocessor list.
- AI model providers — a workspace can enable Anthropic, OpenAI, xAI, an OpenAI-compatible endpoint or a self-hosted model; content is sent only when the selected provider answers. Anthropic documents global default inference routing (which can include the United States, Europe, Asia and Australia) unless workspace settings or instructions restrict it, and says data is stored in the United States. Our Anthropic adapter does not set a per-request inference region, and we have not confirmed workspace-level restrictions. OpenAI publishes processing across multiple countries; its affiliate list includes the United States, Ireland, the United Kingdom and Japan, and certain conditional moderation processing can include the United States, Canada and the Philippines. We have not established the exact routing or residency settings for our provider account. For a self-hosted model, processing depends on the infrastructure you operate. See Anthropic’s data-residency documentation, Anthropic’s location notice, and OpenAI’s subprocessor list. Locations and terms for xAI and customer-supplied endpoints depend on the selected provider and account.
- TypeSafe AI, Inc. — its decision model (Jev) helps route a conversation: when our own quick checks are unsure, it receives a short excerpt of the latest message (at most 2,000 characters, never the earlier conversation, your instructions or any credential) and answers which kind of task it is, which decides the model that replies. It also receives a summary of a web page's language signals and up to 1,500 characters of its visible text when those signals disagree, to tell which language the page is shown in. It returns a label; on our side we log the decision with a shortened excerpt, emails, phone numbers and long numbers masked, for 30 days. Its own retention follows its privacy policy. TypeSafe states that its services are hosted in the United States; its complete remote-access locations have not been established. See TypeSafe’s privacy policy.
- Stripe, Inc. — plan and payment processing only where a plan is paid. Card details go to Stripe, never to us. Apple Inc. and Google LLC provide app distribution and push notifications. These services are used only for the relevant purchase, app or notification; their processing locations and applicable terms depend on the service and account.
- Twilio Inc. — telephone numbers and call transport only for workspaces that switch on voice. Telegram receives data only for workspaces that connect a Telegram hand-off, and only for conversations routed through it. Google LLC (Google Analytics) is used on the public website only, after analytics consent; in-app measurement is first-party as described above. Each of these services is conditional on the relevant feature or consent, and its processing locations and applicable terms depend on the service and account.
Adding a sub-processor that touches conversation content is a change to this list, and this page is where it is published, with the date at the top of this page updated. We do not currently use Cloudflare or any other CDN/WAF in front of busymate.ai or a workspace host — DigitalOcean above is the complete infrastructure list; if that changes, this list changes with it, not after.
Where the data is
Our confirmed primary deployments are in London, United Kingdom (DigitalOcean `lon1`) and Ireland (the Supabase project’s primary storage region, `eu-west-1`). Supabase Edge Functions are not region-pinned by our integration and execute globally near requesters. External AI and other enabled providers may process data in additional countries as described above and in their current notices and settings. These deployment facts do not mean all processing or remote access is limited to the EU or UK. The exact provider-account routing, full remote-access locations and applicable transfer terms have not been confirmed for every service. Choose only providers and workspace settings that meet your requirements, and consult the terms applicable to each provider.
How long we keep it
- Account records live for as long as the account exists, and are deleted with it.
- Workspace configuration lives for as long as the workspace exists.
- Conversations follow the retention you set for your workspace. Where you have not set one, we keep them for as long as the workspace exists so that you can answer your own customers.
- Audit and security records are kept for up to 12 months, because a security question is often asked long after the event.
- App usage events are kept for 12 months and are deleted with the account or the workspace they belong to.
- Backups roll off within 30 days. A deletion is applied to live systems immediately and reaches backups as they expire.
Deleting your account, and deleting your customers' data
You can delete your account yourself, from inside the product, with no email to us and no waiting: open the account menu, go to Settings, then Account, and use the delete option. In the macOS app, Busymate AI › Account… opens the same panel directly. Deleting an account removes the account record, the devices it owns, and its profile and tokens. It cannot be undone.
If you are an end customer and you want your conversation with a business's assistant deleted, ask that business — they are the controller for it. If you contact us instead, we will pass the request on and tell you we have.
Your rights
Wherever you are, you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or object to a use of it, and ask for it in a portable form. In the EU and UK these are GDPR Articles 15 to 21; in California these are the CCPA/CPRA rights of access, deletion, correction and non-discrimination; comparable rights exist in the UK, Switzerland, Brazil and elsewhere and we honour them the same way. We do not charge for any of this and we do not treat you differently for asking.
We answer within 30 days. If you are not satisfied, you can complain to your data protection authority.
Children
The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, tell us and we will remove it.
Security
Sign-in is handled by our authentication provider, and every read of a row is checked against the identity making it — a workspace cannot read another workspace's rows even if the request asks for them. Credentials you give us for your own systems are write-only: you can set them and rotate them, and nobody, including us, can read them back. Before the assistant connects to a new address we check that address cannot reach anything internal. If you find a security problem, our security.txt at busymate.ai/.well-known/security.txt tells you where to send it.
Changes to this policy
If we change something that matters — a new sub-processor, a new purpose, a different retention — we update this page and change the date shown at the top. Continuing to use the service after a change means you accept it; if you do not, delete the account, which you can do yourself at any time.
How to reach us
Contact page: busymate.ai/contact. Email: hi@busymate.ai — subject "Privacy" for anything about this policy or a data request. Security reports: hi@busymate.ai with subject "Security", or busymate.ai/.well-known/security.txt. Developer: https://serebano.com/.