Buzzy

Privacy Policy

Last updated: 12 August 2026

Before publishing: replace the bracketed placeholders below with the operating legal entity, its registered address and its governing jurisdiction, and have this reviewed by a solicitor in that jurisdiction. Everything else describes Buzzy's real behaviour and has been checked against the code.

Buzzy is a read-only marketing analytics product. You connect the social and advertising accounts you already own, and Buzzy reads their performance data so you can see it in one place.

Buzzy cannot post. It never publishes, schedules, edits or deletes anything on your accounts, and it never reads your direct messages, private messages or contacts. It requests read-only analytics permissions and nothing else. This is a property of the product, not a policy promise — the ability to publish was deliberately removed.

This policy explains what we collect, why, who it is shared with, and how to get it back or have it deleted. It applies to the Buzzy web application and the Buzzy mobile application, operated by [LEGAL ENTITY NAME] ("Buzzy", "we", "us"), [REGISTERED ADDRESS].

1. What we collect

1.1 Account information

1.2 Connected platform data

When you connect an account, Buzzy stores an access token issued by that platform and reads the following on your behalf:

We do not collect the content of messages, comment threads, contact lists, or any personal data about the people who interact with your posts. Metrics are aggregate counts, not individual-level records.

1.3 Billing information

Payments are processed by Paddle, which acts as the merchant of record. We never see or store your card details. We receive a customer identifier, a subscription identifier, and the status of your subscription.

1.4 Technical data

Standard server logs: IP address, request path, timestamp and user agent. Authorization codes, tokens, cookies and authentication headers are stripped from logs before they are written.

2. Why we use it

We do not sell your data. We do not use it to train machine-learning models. We do not use it for advertising. Your platform data is not pooled with other customers' data or used to produce benchmarks without your explicit, separate consent.

3. Legal bases (UK/EU GDPR)

4. Who we share it with

These are our only subprocessors. Each receives the minimum needed to do its job.

SubprocessorPurposeData involved
SupabaseAuthentication, database and file storageAccount details, encrypted platform tokens, collected metrics
PaddleMerchant of record — payments, invoicing, sales taxName, email, billing country, payment details (held by Paddle, not by us)
ResendTransactional emailEmail address, message contents
ExpoMobile push notificationsDevice push token
[HOSTING PROVIDER]Application hostingAll of the above in transit and at rest

The platforms you connect — such as Meta, TikTok, Google and LinkedIn — receive requests from Buzzy on your behalf. Their handling of your data is governed by their own privacy policies, not this one.

We disclose data to law enforcement only where legally compelled, and we will tell you unless we are prohibited from doing so.

5. Access tokens

Platform access tokens are encrypted at rest with AES-256-GCM using a key held separately from the database. They are never returned to the application, never included in an export, and never written to a log. Automated tests assert this on every build. Disconnecting a platform erases the stored token.

6. How long we keep it

7. Your rights

You can exercise all of these from inside the product, not only by asking us.

8. International transfers

Our subprocessors may process data outside your country. Where personal data leaves the UK or EEA, transfers rely on the appropriate safeguards offered by that subprocessor, including Standard Contractual Clauses.

9. Children

Buzzy is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.

10. Changes

If we change this policy materially — particularly the categories of data we collect or the subprocessors we use — we will email account holders before the change takes effect.

11. Contact

privacy@buzzy.app
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]