Privacy Policy
Effective Date: January 1, 2025 · Last Updated: May 2026
BuddyCallAI ("BuddyCallAI," "we," "our," or "us"), operated by Brash3d Media Group, is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our telephone-based AI assistant service, website at www.buddycallai.com, and related services (collectively, the "Services").
Please read this policy carefully. If you do not agree with its terms, please discontinue use of our Services immediately.
1. Information We Collect
1.1 Information You Provide Directly
- Account registration data: full name, email address, password (stored encrypted)
- Contact information: phone number(s) registered to your account
- Billing information: payment method details (processed by Stripe — we do not store raw card data)
- Country and preferred language
- Communications you send us via contact forms or support channels
1.2 Information Collected Automatically
- Call records: date, time, duration, originating phone number, and country of calls made through our Service
- Voice audio during calls: processed in real time to provide the AI assistant (not sold to advertisers)
- Call transcripts: text transcriptions of your voice conversations generated by automated speech recognition (e.g., Deepgram)
- Call recordings (if enabled): audio recordings retained only for the limited periods in Section 4 below
- Usage data: features accessed, plan type, time remaining queries, recharge events
- Device and technical data: IP address, browser type, operating system, referral URL
- Cookies and similar tracking technologies (see Section 6)
1.3 Information from Third Parties
- Payment confirmation and fraud signals from Stripe
- Call metadata from Twilio (call SID, call status, duration)
- Voice synthesis session logs from ElevenLabs
- Speech recognition session data from Deepgram
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery
- To identify your account when you call any BuddyCallAI number
- To route your call to the appropriate AI processing pipeline
- To track your call time balance and deduct minutes correctly
- To send SMS alerts to your registered phone number when your time is low (5 minutes, 2 minutes, and at expiry)
- To deliver call transcripts to your registered email address after each call
2.2 Account Management
- To process payments and manage your subscription via Stripe
- To send account-related transactional emails (welcome, receipt, password reset)
- To enable you to view your call history, transcripts, and usage in your dashboard
2.3 Service Improvement
- To analyze aggregated, anonymized usage patterns to improve AI response quality
- To monitor service performance, uptime, and latency
- To detect and prevent fraud, abuse, and unauthorized access
2.4 Legal Compliance
- To comply with applicable laws in the United States and Canada, and other laws that apply to you based on where you access our website
- To respond to lawful government requests, court orders, or legal process
- To enforce our Terms of Service and protect our rights
3. How We Share Your Information
IMPORTANT NOTICE: We do not sell your personal information to third parties. We do not allow advertisers to target you based on your call content.
We share information only in the following limited circumstances:
| Third Party | Category | Purpose |
|---|---|---|
| Twilio, Inc. | Telecommunications | Routing calls, sending SMS notifications |
| ElevenLabs, Inc. | Voice AI | Generating spoken AI responses |
| Deepgram, Inc. | Speech AI | Transcribing caller voice to text |
| OpenAI / Anthropic / Google | AI Processing | Generating AI conversation responses |
| Stripe, Inc. | Payment Processing | Billing, subscription management |
| Amazon Web Services | Cloud Infrastructure | Hosting, storage, email delivery |
| Law Enforcement | Legal / Compliance | Only when legally required by court order |
All third-party providers are contractually required to protect your data and may only use it to perform services on our behalf.
4. Data Retention
| Data Type | Retention Period |
|---|---|
| Account profile data | Duration of account + 90 days after deletion request |
| Call transcripts | 12 months from call date, then permanently deleted |
| Call recordings (if any) | 30 days, then permanently deleted |
| Payment records | 7 years (required by financial regulations) |
| SMS logs | 12 months |
| Server logs / IP addresses | 90 days |
| Anonymized usage analytics | Indefinitely (no personal identifiers) |
5. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Right to Access | Request a copy of all personal data we hold about you |
| Right to Correction | Request correction of inaccurate or incomplete data |
| Right to Deletion | Request deletion of your account and personal data (subject to legal retention obligations) |
| Right to Portability | Receive your data in a structured, machine-readable format (JSON/CSV) |
| Right to Object | Object to processing of your data for certain purposes |
| Right to Restrict | Request restriction of processing in certain circumstances |
| Opt-Out of SMS | Reply STOP to any SMS message; or update preferences in your dashboard |
| GDPR (EU/UK) | All above rights apply; supervisory authority complaints may be filed in your jurisdiction |
| CCPA (California) | Right to know, delete, and opt out of sale (we do not sell data) |
| PIPEDA (Canada) | Access, correction, and complaint rights under Canadian privacy law |
To exercise any of these rights, contact us at: privacy@buddycallai.com or use the form at www.buddycallai.com/contact. We will respond within 30 days.
6. Cookies & Tracking Technologies
We use cookies and similar technologies on our website for the following purposes:
- Essential cookies: Required for login sessions, security tokens, and account authentication
- Functional cookies: Remember your language preference and display settings
- Analytics cookies: Google Analytics 4 — tracks page views and feature usage (anonymized)
- Performance cookies: Monitor website loading speed and error rates
You may control cookies through your browser settings. Disabling essential cookies will prevent login functionality. We do not use advertising or tracking cookies to serve targeted ads.
For a dedicated overview, see our Cookie Policy.
7. Data Security
- All data transmitted between your device and our servers is encrypted using TLS 1.3
- Passwords are hashed using bcrypt with a minimum of 12 salt rounds — never stored in plain text
- Payment card data is never stored on our servers — all payment processing is handled by Stripe (PCI DSS Level 1)
- Call transcripts and recordings are stored encrypted at rest using AES-256 on Amazon S3
- Phone numbers in our database are stored with column-level encryption
- Access to production systems is restricted to authorized personnel with MFA required
- We conduct regular security audits and penetration testing
Despite our best efforts, no method of electronic transmission or storage is 100% secure. In the event of a data breach that affects your personal information, we will notify you within 72 hours as required by applicable law.
8. Children's Privacy
IMPORTANT NOTICE: Our Services are not directed to children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us immediately at privacy@buddycallai.com and we will delete such information promptly.
9. International Data Transfers
BuddyCallAI is operated from the United States. Our primary service area for telephone AI is the United States and Canada. Infrastructure may be hosted on Amazon Web Services (AWS) and other providers in the U.S. and other regions.
- We have Data Processing Agreements (DPAs) or equivalent contractual protections with processors (Twilio, ElevenLabs, Deepgram, Stripe, AWS, and AI providers)
- Canada: We comply with PIPEDA and applicable provincial privacy laws
- United States: We comply with applicable federal and state privacy laws (including CCPA/CPRA where applicable)
- If you access our website from the EU/UK or other regions, additional rights may apply under local law; contact privacy@buddycallai.com
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will: (1) notify registered users by email at least 14 days before the change takes effect; (2) update the "Last Updated" date at the top of this policy; and (3) display a prominent notice on our website.
Your continued use of the Services after the effective date constitutes your acceptance of the updated policy.
11. Contact Us
For privacy inquiries, data requests, or complaints:
- Privacy: privacy@buddycallai.com
- General: info@buddycallai.com
- Form: www.buddycallai.com/contact
- Mail: Brash3d Media Group — BuddyCallAI, Orlando, Florida, USA (contact us by email for a mailing address if required for your request)
