Privacy Policy
Last updated: 29 September 2026
This policy explains what personal data BuzzBomb collects when you visit buzzbomb.com or use our AI marketing agents, why we collect it, who we share it with, and the rights you have under the UK GDPR and Data Protection Act 2018. The short version: we collect what we need to run your marketing team, we never sell it, we never train AI on it, and you can export or delete it whenever you like.
01Who we are
BuzzBomb is operated by [Company legal name], a company registered in England and Wales with its registered office at [Registered address] (“BuzzBomb”, “we”, “us”). ICO registration number: [ICO registration number, if applicable].
We are the controller of personal data about visitors to buzzbomb.com and about the people who create BuzzBomb accounts. For customer content that our agents process on your behalf (for example, leads you upload or replies drafted to your audience), we act as your processor and our Terms of Service, including the data processing terms in them, govern that processing.
Questions, requests or complaints: privacy@buzzbomb.com.
02What we collect
Information you give us
- Account data: name, work email, password (hashed), company name, the website URL you paste in, and your plan and billing status.
- Workspace content: briefs, brand voice settings, guardrails, drafts you edit, comments, approvals and rejections.
- Connected accounts: when you connect a social, ads, search or analytics account (for example LinkedIn, Meta, X, Google Ads, Reddit) via OAuth, we store the access tokens, the account identifiers and the data those platforms return that we need to plan, draft, publish and report. We never see or store your passwords for those platforms.
- Support and sales: anything you send us by email, chat or on a call, including the setup and strategy calls on the Autopilot plan.
Information we collect automatically
- Usage data: pages viewed, features used, approvals made, timestamps, referring URL, and error logs.
- Device data: IP address, browser type and version, operating system, screen size, language, and cookie or local-storage identifiers.
Information from other sources
- Your public website and public web pages we read (via Firecrawl) to understand your positioning, products and audience.
- Public information about competitors and prospects that our Competitor and Outbound agents gather from public sources so they can research and draft for you. This may include the business contact details of third parties. See “Third-party data our agents process” below.
- Payment status from Stripe (whether a payment succeeded, the last four digits of the card, expiry date). Full card numbers never touch our systems.
03How we use it and our lawful bases
Under the UK GDPR we need a lawful basis for each use of personal data. Ours are:
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, workspace and agents; publishing work you approve | Performance of a contract (our Terms) |
| Taking payment, invoicing, preventing fraud, keeping accounting records | Contract; legal obligation |
| Researching your market and drafting marketing using AI models | Contract |
| Product analytics, fixing bugs, improving agents and the site | Legitimate interests (running and improving our service) |
| Sending service emails: approvals, weekly reports, billing, security notices | Contract; legitimate interests |
| Sending marketing emails about BuzzBomb | Consent, or legitimate interests for existing customers, always with one-click unsubscribe |
| Ads attribution via Meta Pixel on buzzbomb.com | Consent (only set after you accept optional cookies) |
| Responding to legal requests, enforcing our Terms, protecting users | Legal obligation; legitimate interests |
We do not sell personal data and we do not use your workspace content to train AI models. Anthropic processes your content under a commercial agreement that prohibits training on it.
04How our AI agents handle your data
BuzzBomb agents read your website and connected accounts, plan work, draft content, and (only after you approve it, or within guardrails you set on Autopilot) publish to your channels. To do that we send relevant content to our AI sub-processors listed below. Specifically:
- Text drafting, research and planning are performed by Anthropic’s Claude models. Prompts and outputs are retained by Anthropic only as needed to provide the service and for abuse monitoring, then deleted under their retention policy.
- Image and video creative is generated by fal.ai from prompts and brand assets you provide.
- Website reading is performed by Firecrawl on public URLs only. We do not read pages behind a login.
Nothing is published without your approval, except on the Autopilot plan where you explicitly enable auto-publishing within an allowlist of channels, a trained brand voice and daily caps. The Reply agent is approve-first on every plan. You can pause any agent at any time.
05Third-party data our agents process
Some agents work with personal data about people who are not our customers: the prospects your Outbound agent researches, people who reply to your posts, or named individuals at competitors. For that data you are the controller and we are your processor. You are responsible for having a lawful basis (typically legitimate interests for B2B outreach), honouring opt-outs, and complying with PECR and the rules of the platforms you connect.
We help by:
- Limiting research to publicly available, business-context information.
- Rate-limiting outreach and replies, and keeping the Reply agent approve-first on every plan.
- Honouring suppression lists you provide and deleting third-party data when you ask us to, or when your workspace is deleted.
If you are one of these people and want to know what a BuzzBomb customer holds about you, contact that customer directly, or email privacy@buzzbomb.com and we will pass your request on.
07International transfers
Our primary database and authentication run in Supabase’s EU region (eu-central-2). Some sub-processors, notably Anthropic, fal.ai, Firecrawl, Resend, Stripe and Vercel, process data in the United States.
When personal data leaves the UK or EEA we rely on one or more of:
- UK adequacy regulations (for example, for the EEA and, where covered, the EU–US Data Privacy Framework’s UK Extension).
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).
- The EU Standard Contractual Clauses for EEA-origin data.
We assess each transfer and apply supplementary measures (encryption in transit and at rest, access controls, data minimisation) where needed. Copies of the relevant safeguards are available on request.
08How long we keep data
- Account and workspace data: for as long as your account is active, then deleted within 30 days of you closing it or asking us to delete it. See our Data Deletion page.
- Connected-account tokens: revoked and deleted immediately when you disconnect an integration or delete your account.
- Billing records: 6 years after the transaction, as required by UK tax and company law.
- Server logs and analytics: up to 12 months, after which they are deleted or aggregated.
- Backups: encrypted database backups roll off within 30 days of deletion.
- Support correspondence: up to 3 years so we can handle follow-ups and disputes.
10Security
We protect data with encryption in transit (TLS 1.2+) and at rest, encrypted storage of OAuth tokens, row-level security in our database, least-privilege access for staff, audit logging and regular dependency and vulnerability reviews. Payment card details are handled entirely by Stripe, which is PCI DSS Level 1 certified.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the ICO within 72 hours where required and tell affected users without undue delay.
11Your rights
Under the UK GDPR (and the EU GDPR if you are in the EEA) you have the right to:
- Access the personal data we hold about you and get a copy.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”) where there is no overriding reason to keep it.
- Restrict or object to processing, including objecting to direct marketing at any time.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time where consent is our lawful basis, without affecting processing already carried out.
- Not be subject to solely automated decisions with legal or similarly significant effects. BuzzBomb agents draft and recommend; a human (you) approves.
To exercise any right, email privacy@buzzbomb.com from the address on your account, or use the export and delete options in the app. We respond within one month, extendable by two further months for complex requests, and we may ask you to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Right to complain
If you are unhappy with how we handle your data, we would like the chance to put it right first: contact privacy@buzzbomb.com. You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint, telephone 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If you are in the EEA you may complain to your local data protection authority.
12Children
BuzzBomb is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
13Changes to this policy
We will post any changes here and update the “Last updated” date. If a change materially affects how we use your personal data, we will email account owners at least 14 days before it takes effect. Continuing to use BuzzBomb after that date means you accept the updated policy.
14Contact
Privacy requests: privacy@buzzbomb.com
General: hello@buzzbomb.com
Post: [Company legal name], [Registered address]