PRIVACY POLICY
Last Updated: May 13, 2026
This is our promise to you about how we handle your data. We have written it as plainly as we can. Where the law requires precise wording, we have used it — and explained it. If anything here is unclear, please write to privacy@heibuddy.ai.
1. What Data We Collect (and Why)
Things You Tell Us
- Your name and phone number — to create your account.
- Your address — to deliver services to you.
- Your payment information — to process payments. Card numbers are tokenised. We do not see them.
- Your preferences — your usual order, favourite providers, dietary needs.
Things We Collect When You Use the App
- Your voice when you talk to HeiBuddy — processed on your device whenever possible.
- Your location — only when needed to provide a service.
- Device information — model, OS version, language, network type — to keep the app working.
- Usage information — what features you use, what works, what does not — to improve the product.
Things We Never Collect
- Continuous audio. We only listen when you say ‘HeiBuddy’ or tap the mic.
- Contents of your messages on other apps.
- Your photos, files, or anything outside HeiBuddy.
- Health information beyond what is needed for a specific service you requested.
2. How We Use Your Data
- To run the service — bookings, payments, confirmations.
- To improve the product — by learning what works and what does not.
- To keep you safe — fraud detection, abuse prevention, security.
- To follow the law — when required by a court or regulator.
We do not use your data to train AI models without your clear consent. We do not sell your data. Ever.
3. Who We Share Data With
- Service partners — only the information they need to fulfil your order.
- Payment providers — only the information they need to process your payment.
- Trusted infrastructure providers — for cloud hosting, security, and analytics. Bound by strict contracts.
- Government authorities — only when legally required and only the minimum necessary.
We never share your data for advertising. We do not run ads in our app.
4. Data Retention
- Account data — until you delete your account, plus a short period required by law.
- Order and payment records — kept as long as legally required (usually 7 years).
- Voice recordings — kept only as long as needed to complete your request, then deleted automatically.
- Device logs — usually 30 to 180 days depending on the type of log.
You can ask for early deletion at any time. We will honour it where the law allows.
5. Your Rights
Under the India DPDP Act 2023
- You can ask what data we hold about you.
- You can ask us to correct or update it.
- You can ask us to delete it.
- You can withdraw consent at any time.
- You can nominate someone to exercise these rights on your behalf.
- You can raise a grievance with our Grievance Officer.
Under the EU and UK GDPR
- Right of access.
- Right to rectification.
- Right to erasure.
- Right to data portability.
- Right to restrict processing.
- Right to object.
- Rights related to automated decision-making.
Under US State Privacy Laws
- Right to know.
- Right to delete.
- Right to correct.
- Right to opt out of sale or sharing.
- Right to limit use of sensitive personal information.
- Right to non-discrimination.
If you live somewhere not listed here, you still have rights — write to privacy@heibuddy.ai.
How to use your rights:
Open Settings → Privacy in the app or write to privacy@heibuddy.ai.
6. Security
We use industry-leading encryption, on-device processing, and continuous monitoring to protect your data.
7. Children's Privacy
HeiBuddy is intended for adults. For children below the legal age in your country, a parent or guardian must give verifiable consent.
8. Cross-Border Data
Some of our systems run on cloud infrastructure outside your country. When your data crosses borders, we use approved legal mechanisms including Standard Contractual Clauses and equivalent protections.
Payment data for Indian users is stored within India as required by RBI regulations.
9. Cookies and Tracking
On our website, we use a small number of cookies — essential ones to keep the site working and optional analytics cookies only if you allow them.
10. Marketing Communication
We will only send you marketing messages if you ask us to. You can unsubscribe anytime.
Service-related messages such as order confirmations, payment receipts, and security alerts are part of the service.
11. Changes to This Policy
If we change this policy, we will notify you in the app and by email at least 30 days before important changes take effect.
12. Contact Us
Data Protection Officer: dpo@heibuddy.ai
Privacy Questions: privacy@heibuddy.ai
Grievance Officer (India): grievance@heibuddy.ai
HeiBuddy · Just say HeiBuddy.