Privacy Policy
Last updated: September 9, 2026
Overview
This Privacy Policy explains how Bubagent collects, uses, and shares personal information. It covers two different groups of people, because Bubagent plays two different roles:
- Customers — businesses and individuals who sign up for a Bubagent account. For Customer account data, Bubagent is the data controller.
- End Visitors— people who chat with a Customer’s AI agent embedded on the Customer’s own website. For End Visitor data, the Customer is generally the data controller (it’s their website and their relationship with their visitor), and Bubagent acts as their data processor / service provider, as described further in our Data Processing Agreement.
If you’re an End Visitor and want to exercise a privacy right, your first stop should usually be the business whose website you chatted on — but you’re welcome to contact us directly at privacy@bubagent.comand we’ll assist or route your request.
Information we collect
From Customers
- Account information: name, email address, password (stored as a salted hash, never in plain text), company name.
- Billing information: handled directly by Stripe — we receive subscription/payment status but never see or store full card numbers.
- Content you configure: agent settings, knowledge-base material, team member invites, webhook URLs, and similar configuration.
- Support communications you send us.
From End Visitors, through a Customer’s embedded agent
- Chat messages sent to and received from the agent.
- Name and email address, only if the Customer has enabled lead-capture and the visitor chooses to provide it.
- Files or images voluntarily uploaded to the chat (subject to the Customer’s plan limits).
- A randomly generated visitor identifier and conversation identifier stored in the visitor’s own browser (see Cookies & local storage) — not a real-world identity by itself.
- Basic technical data (IP address, browser user-agent) used transiently for rate-limiting, abuse prevention, and security logs.
How we use information
- To operate the Service — routing chat messages to the AI provider a Customer has selected and returning the generated reply.
- To send transactional and account emails — welcome messages, password resets, billing receipts, usage alerts, and any instant-alert or digest notifications a Customer has configured for their own agents.
- To detect and prevent abuse, enforce rate limits and plan quotas, and keep the Service secure.
- To monitor, diagnose, and fix errors (via Sentry).
- To improve the Service and develop new features.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use End Visitor chat content to train our own foundation models. Chat content is sent to our AI sub-processors (Anthropic, OpenAI) solely to generate a reply. Submissions through each provider’s commercial API are governed by that provider’s own API/business terms, which — unlike their free consumer chat products — generally exclude API inputs and outputs from being used to train the provider’s models by default; see each provider’s own terms for specifics and any options a Customer may separately negotiate with them.
International data transfers
Bubagent and the sub-processors listed above are based in the United States. If you’re located in the European Economic Area, United Kingdom, or Switzerland, your personal information will be transferred to and processed in the United States and potentially other countries whose laws may differ from your own. Where required, such transfers are made on the basis of the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), and/or a sub-processor’s own certification under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), to the extent each sub-processor participates in that framework. Contact privacy@bubagent.comif you’d like more detail on the transfer mechanism used for a specific sub-processor.
Data retention
- Customer account data is retained for as long as the account is active, and for a reasonable period afterward (to allow reactivation and meet backup/legal-retention needs) before deletion.
- Conversation and message history is retained until the Customer deletes it or closes their account, subject to the same post-closure grace period.
- Billing records are retained as long as required by tax and accounting law.
- Deleting a conversation, bot, or account removes the underlying records, though recent backups may retain a copy for a limited time before they age out.
Your privacy rights
Depending on where you live, you may have some or all of the following rights. To exercise any of them, email privacy@bubagent.com— we may need to verify your identity first, and we’ll respond within the timeframe required by the law that applies to your request (commonly around 30 days).
EU / UK GDPR
Right to access, rectify, erase, or restrict processing of your personal information; right to data portability; right to object to processing (including profiling); right to withdraw consent where processing is based on consent; and the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA)
Right to know what personal information we’ve collected, right to delete it, right to correct inaccurate information, right to limit use of sensitive personal information, and the right to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
Brazil (LGPD)
Right to confirmation of processing, access, correction, anonymization, portability, and deletion of your personal information, and the right to lodge a complaint with the ANPD.
Canada (PIPEDA) & Australia (Privacy Act)
Right to access and request correction of your personal information, to withdraw consent where applicable, and to complain to the Office of the Privacy Commissioner of Canada or the Office of the Australian Information Commissioner (OAIC), respectively.
If you’re in a jurisdiction not listed above, contact us — we aim to honor equivalent rights under your local law regardless.
AI transparency
Every agent built with Bubagent discloses, persistently in its chat header, that End Visitors are talking with an AI system rather than a human. This disclosure is part of the Service itself and can’t be disabled by a Customer, consistent with transparency obligations under Article 50 of the EU AI Act and California’s Bolstering Online Transparency Act (SB 1001).
Agent replies are generated by the AI provider a Customer has configured (Anthropic or OpenAI) based on the Customer’s own knowledge base and instructions — not by a human reviewing each message in real time, and not by Bubagent itself.
Children's privacy
The Service is not directed at children, and Customer accounts require the account holder to be old enough to form a binding contract in their jurisdiction. We don’t knowingly collect personal information from children under 16. If you believe a child has provided us personal information through the Service, contact privacy@bubagent.comand we’ll delete it.
Security
We use industry-standard safeguards, including encryption in transit (TLS) across the Service, encryption at rest for particularly sensitive stored credentials, and access controls limiting who can reach production data. No method of transmission or storage is 100% secure, and we can’t guarantee absolute security — but we work to keep these protections current and will notify affected Customers of any breach as required by applicable law.
Changes to this policy
We may update this Privacy Policy from time to time. We’ll post the revised version here with an updated “Last updated” date, and for material changes we’ll provide at least 14 days’ notice by email or in-product notice before they take effect.
Contact us
Questions about this Privacy Policy, or a privacy right you’d like to exercise? Email privacy@bubagent.com. For a copy of our Data Processing Agreement or a signed addendum, email legal@bubagent.com.
