Privacy Policy
Bud — a personal assistant on WhatsApp
Last updated: 9 September 2026
Bud is a personal assistant you reach over WhatsApp. It connects to your Google account so it can read your calendar, manage your tasks, and send email on your behalf. This policy explains exactly what data that involves, where it goes, and how to get rid of it.
We have tried to write this so it is actually readable. If anything here is unclear, ask us — the contact address is at the bottom.
1. Who we are
Bud is operated by the team behind mybud.life. For any question about your data, or to exercise any right described below, contact privacy@mybud.life.
2. What we collect
From WhatsApp
- Your phone number. This is your identity in Bud — we have no separate account or password.
- Your WhatsApp profile name, so Bud can address you properly.
- The messages you send Bud, and Bud's replies.
- Voice notes you send, which are transcribed to text.
From your Google account
Only if you choose to connect it, and only the following:
| What | Why |
|---|---|
| Your Google account email address | So Bud can tell you which account is connected |
| Calendar events — read and write | To show your agenda, create and move meetings |
| Calendar free/busy times | To find open slots without proposing a time you are already booked |
| Google Tasks — read and write | To list, add and complete tasks |
| Permission to send email as you | To send messages you ask Bud to send |
Bud cannot read your email. We deliberately do not request any permission that would let us search, read, or open your Gmail — not even message headers or subject lines. Bud can only send new messages you explicitly ask it to send. It also has no access to Google Drive, Docs, Sheets, Photos or Contacts.
Created as you use Bud
- Conversation history, so Bud remembers the thread rather than starting fresh every message.
- Your preferences — timezone, and when you want your morning brief and evening wrapup.
- Operational records — which features were used, errors, timings. These contain no message content.
3. What we do with it
We use your data for one purpose: running the assistant you asked for. Concretely:
- Understanding what you asked and doing it
- Reading your calendar and tasks to answer you and to compose your scheduled brief and wrapup
- Sending email, creating events and managing tasks when you ask
- Keeping the service working and diagnosing faults
We do not sell your data, use it for advertising, use it for credit or lending decisions, or share it with data brokers.
4. Google user data — Limited Use
Bud's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
In practice, that means all of the following are true:
- Google data is used only to provide the features you can see in Bud — your agenda, your tasks, sending your mail, your brief and wrapup.
- It is never used for advertising, and never transferred to anyone for advertising.
- It is never sold, and never used for credit assessment.
- It is never used to train or improve generalised AI or machine-learning models. See section 5 on how we hold our AI providers to this.
- No human reads your Google data, except where you have explicitly asked us to look at something specific, where it is necessary for security or to fix a fault you reported, or where the law requires it.
5. Who else your data reaches
Bud is built on services run by other companies. Your data reaches only these, and only for the purposes described:
| Service | What reaches it | Why |
|---|---|---|
| Meta (WhatsApp Business Platform) | Your messages and Bud's replies | WhatsApp is how you talk to Bud |
| Google — Workspace APIs | Calendar and task requests; emails you ask Bud to send | To perform the actions you request |
| Google — Gemini API | Your message, plus the calendar and task details relevant to it | To understand your request and write Bud's reply |
| Anthropic | The same, if we switch AI provider | Standby provider so Bud keeps working during an outage |
| Sarvam AI / Deepgram | Voice notes you send | To convert speech to text |
| MongoDB Atlas | Conversation history and preferences | Storage |
| Google Cloud | Hosts the service (Mumbai, India) | Infrastructure |
On AI providers and training
Bud sends your message and relevant calendar and task details to an AI model in order to understand you and reply. We use these services on paid commercial terms under which the provider does not use your prompts or the responses to train or improve their models, and does not subject them to human review for model improvement. This is a requirement for us, not a preference — it is what section 4 above obliges us to guarantee.
6. How long we keep it
- Conversation history: 90 days, then deleted automatically. Bud only ever refers back to your recent messages, so older history serves no purpose.
- Operational records: 180 days, then deleted automatically. These contain no message content.
- Your profile and preferences: for as long as you use Bud.
- Google access tokens: until you disconnect, or until Google expires them.
- Google calendar and task content is not stored. It is fetched when needed to answer you and not retained afterwards, beyond appearing in the conversation history covered above.
7. Your choices
Everything here you can do by simply messaging Bud:
- Disconnect Google. Say "disconnect my Google account". Bud revokes its own access at Google immediately. Your calendar, tasks and mail are untouched — only Bud's permission goes away.
- Delete everything. Say "delete all my data". We erase your conversation history, profile and settings, and revoke the Google connection. This is immediate and irreversible.
- Turn off the brief or wrapup. Say "stop the morning brief", or change the time whenever you like.
- Stop entirely. Block the number in WhatsApp, or ask us to delete your data.
You can also revoke Bud's access directly from your Google account at myaccount.google.com/permissions.
Depending on where you live you may have additional rights — to access, correct, export or restrict processing of your data. Write to privacy@mybud.life and we will act on it.
8. Security
- All traffic runs over HTTPS.
- Google tokens and service credentials are held in restricted files readable only by the service account that needs them, never in source control.
- The database is access-controlled and not exposed to the public internet.
- Access to production systems is limited to those who operate the service.
No system is perfectly secure. If you believe your account or data has been compromised, contact us at privacy@mybud.life and we will investigate promptly.
9. Children
Bud is for working professionals and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has used Bud, contact us and we will delete the data.
10. International transfers
Bud runs in India (Google Cloud, Mumbai). The services in section 5 may process data in other countries, including the United States. Where required, transfers rely on the standard safeguards those providers offer.
11. Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle your data — for example requesting a new Google permission — we will tell you in WhatsApp before it takes effect.