Buzzy is a read-only marketing analytics product. You connect the social and advertising accounts you already own, and Buzzy reads their performance data so you can see it in one place.
Buzzy cannot post. It never publishes, schedules, edits or deletes anything on your accounts, and it never reads your direct messages, private messages or contacts. It requests read-only analytics permissions and nothing else. This is a property of the product, not a policy promise — the ability to publish was deliberately removed.
This policy explains what we collect, why, who it is shared with, and how to get it back or have it deleted. It applies to the Buzzy web application and the Buzzy mobile application, operated by [LEGAL ENTITY NAME] ("Buzzy", "we", "us"), [REGISTERED ADDRESS].
When you connect an account, Buzzy stores an access token issued by that platform and reads the following on your behalf:
We do not collect the content of messages, comment threads, contact lists, or any personal data about the people who interact with your posts. Metrics are aggregate counts, not individual-level records.
Payments are processed by Paddle, which acts as the merchant of record. We never see or store your card details. We receive a customer identifier, a subscription identifier, and the status of your subscription.
Standard server logs: IP address, request path, timestamp and user agent. Authorization codes, tokens, cookies and authentication headers are stripped from logs before they are written.
We do not sell your data. We do not use it to train machine-learning models. We do not use it for advertising. Your platform data is not pooled with other customers' data or used to produce benchmarks without your explicit, separate consent.
These are our only subprocessors. Each receives the minimum needed to do its job.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication, database and file storage | Account details, encrypted platform tokens, collected metrics |
| Paddle | Merchant of record — payments, invoicing, sales tax | Name, email, billing country, payment details (held by Paddle, not by us) |
| Resend | Transactional email | Email address, message contents |
| Expo | Mobile push notifications | Device push token |
| [HOSTING PROVIDER] | Application hosting | All of the above in transit and at rest |
The platforms you connect — such as Meta, TikTok, Google and LinkedIn — receive requests from Buzzy on your behalf. Their handling of your data is governed by their own privacy policies, not this one.
We disclose data to law enforcement only where legally compelled, and we will tell you unless we are prohibited from doing so.
Platform access tokens are encrypted at rest with AES-256-GCM using a key held separately from the database. They are never returned to the application, never included in an export, and never written to a log. Automated tests assert this on every build. Disconnecting a platform erases the stored token.
You can exercise all of these from inside the product, not only by asking us.
Our subprocessors may process data outside your country. Where personal data leaves the UK or EEA, transfers rely on the appropriate safeguards offered by that subprocessor, including Standard Contractual Clauses.
Buzzy is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.
If we change this policy materially — particularly the categories of data we collect or the subprocessors we use — we will email account holders before the change takes effect.
privacy@buzzy.app
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]