Privacy Policy
Last updated: August 2026 ยท Buddy AI, a Buddy Corporation product
This Privacy Policy explains what data Buddy AI ("we", "us") collects, how we use it, and the choices you have. By using the Service you agree to the practices described here, together with our Terms of Service.
1. What we collect
- Account data: when you sign in with GitHub, we receive your GitHub username, numeric user ID, and the creation date of your GitHub account (used for the 60-day anti-abuse gate).
- API keys: stored only as a SHA-256 hash. The raw key is displayed once at creation and is never stored or transmitted again.
- Usage data: per-key and per-chat daily counters (to enforce quotas), timestamps, and model selections.
- Chat content: messages you send are forwarded to the selected model provider to generate a response, and kept in memory for the duration of the request. We do not build profiles from it.
- Technical data: IP address (used for anonymous-chat quotas and abuse prevention), browser language, and theme preference (stored in your browser).
2. What we do NOT collect
- We do not sell your personal data to anyone.
- We do not use your prompts or conversations to train our own models.
- We do not store raw API keys, and we cannot recover them.
- We do not require or store payment card details โ payments are handled entirely by PayPal.
3. How we use your data
- To provide, operate, and secure the Service (routing requests, enforcing quotas, preventing abuse).
- To show you your usage (keys, quotas, premium status).
- To communicate service-relevant information if needed.
4. Third-party processors
- GitHub โ authentication (OAuth).
- Cloudflare โ hosting (Pages), database (D1), bot verification (Turnstile).
- Model providers โ Groq, NVIDIA NIM and others receive your messages to generate responses. Most do not train on your data; a few (currently DeepSeek) flag that prompts may be used for training โ those models are marked with a visible "trains" badge so you can avoid them.
- PayPal โ subscription payments. We never see or store your card details.
- ipwho.is โ IP geolocation used for anti-VPN protection.
5. Anti-VPN protection
To keep the free tier fair and protected from abuse, we detect VPN/proxy usage. When a VPN is detected, the site shows a 30-second warning during which you can disable it. No permanent record of the detection is kept beyond that session.
6. Cookies & local storage
We use a signed session cookie after sign-in, and your browser's localStorage for UI preferences (language, theme, thinking toggle). Cloudflare Turnstile may set its own cookies for bot detection. You can clear these at any time in your browser settings.
7. Data retention
- Daily usage counters: retained for a rolling period (approximately 30 days).
- API key hashes: retained while the key is active; hashes of revoked keys are deleted.
- Chat content: not stored on our servers beyond request handling.
- Account data: retained while your account exists. You can request deletion at any time (see Contact).
8. Your rights
Depending on your jurisdiction (e.g. GDPR in the EU), you may have the right to access, correct, or delete your personal data, and to object to or restrict processing. To exercise these rights, contact us (see below).
9. Children
The Service is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Security
We use industry-standard measures: hashed keys, signed sessions, HTTPS everywhere, and Cloudflare's security features. No method of transmission is 100% secure, but we work to protect your data.
11. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected here with an updated date.
12. Contact
Questions about this policy or data requests: reach out via the Buddy Router GitHub repository or the community channels listed on the website.