Privacy Policy
This policy explains how Meet Buddie L.L.C. collects, uses, stores and protects information when people create accounts, administer groups, or use the Buddie iMessage service. Meet Buddie is available only to people aged 18 or over. When an administrator registers, we verify that they control a United States phone number. We do not independently verify the location or residence of other group participants.
Information we collect
- Account information, including email address, password credentials managed by our authentication provider, and the verified phone number of a group administrator.
- Group settings, administrator assignments, member display names, phone numbers, consent records and plan information.
- Contact and messaging identifiers, including phone numbers and any Apple ID email address a participant’s device presents in a group, together with the association between identifiers belonging to the same participant. We use these to identify who is in a group, preserve each participant’s consent state across the identifiers they message from, and route messages to the right person. An association is recorded only after the participant confirms it from a number that has already consented, or an administrator attests to it. These records are held separately from the de-identified crisis referral records, and are never combined with them.
- Message content, timestamps, active personality, generated memory notes and operational logs needed to provide the service.
- Technical data used for security, reliability, abuse prevention and cost controls.
How we use information
We use this information to authenticate users, administer groups, send and receive requested messages over iMessage, generate context-aware Buddie responses, maintain group memory, enforce consent and opt-out choices, provide support, secure the service and meet legal obligations.
An administrator’s email address may be used for transactional account and billing notifications, including group opt-out alerts and notices when a plan lapses. These notices are separate from marketing communications and are not sent to individual group members.
Mobile information
No mobile information or phone numbers will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers will not be sold or shared for marketing. A third-party messaging infrastructure provider receives message content, sender and participant identifiers, group and assigned-line information, and delivery metadata. A phone verification provider receives a group administrator’s phone number for administrator verification.
Group-chat opt-in consent
A group administrator shares the supplied advance warning before adding Buddie to the chat. Buddie posts a versioned disclosure in that group, and each current participant must personally reply YES, or YES NO MEMORY to join without Buddie saving details about them, before Buddie participates. Messages from members who have not joined are received by a third-party messaging infrastructure provider and transiently by Meet Buddie so we can identify the sender and recognize consent, opt-out, and identity-confirmation messages. The provider receives the message content, sender and participant identifiers, group and assigned-line information, and delivery metadata. Meet Buddie does not add the message content to its message database, send it to an AI provider, run crisis or reply-moderation classification on it, use it for memory or response generation, or include the content in analytics. We may keep content-free operational records tied to the member and group. The service keeps an append-only consent ledger, and the operational records it keeps are identified records tied to the member and the group rather than de-identified ones. If a new participant joins later, Buddie pauses and repeats the same disclosure and consent process.
Age review and participants we believe are minors
If we have reason to believe an account holder or group participant is under 18, we suspend any associated account and pause Buddie in any groups that account created while we review the person’s age. During that review, we stop all product processing of that person’s messages, including generation, memory, awards, personalisation and analytics, in every group they are in. We continue only a narrowly limited crisis-safety check intended to identify an immediate risk of harm. That check may transmit the message to Anthropic and is subject to the provider-side retention described under AI provider retention. This restriction follows the person across every group they are in, including groups run by other administrators. We resolve an age review within 30 calendar days after the restriction is first applied. Unless the person is verified as at least 18 years old, we then close any associated account and delete the affected member’s data.
Where we have clear reason to believe a participant is under 13, we immediately stop all processing of that person’s messages, including the crisis-safety check, and provide static crisis resources instead without reading or transmitting any new message. The 30-day deadline above continues to run from the date the restriction was first applied. Unless the person is verified as at least 18 years old, we close any associated account and delete the affected member’s data, including their messages, memory notes, membership records and consent records. We unlink their account reference from the retained billing record within 30 days after closure. If a refund is pending, we retain the linkage only as long as needed to complete the refund and delete it within 30 days after the refund is completed.
Opting out
Reply STOP, UNSUBSCRIBE, CANCEL, END or QUIT to stop Buddie messages. Reply START or UNSTOP to opt back in. Reply HELP for assistance. Opting out applies to that phone number across all Buddie groups.
Third-party providers and recipients
A third-party messaging infrastructure provider receives message content, sender and participant identifiers, group and assigned-line information, and delivery metadata. It uses that information to transmit and route messages, associate messages with the correct group and line, report delivery status, and provide its messaging infrastructure. Its public terms may permit additional use to improve its systems, so we do not describe this provider as processing information strictly on our behalf. We also use a cloud database and authentication provider, a phone verification provider, Anthropic for AI processing, an application hosting provider, a payment processor for billing, and a transactional email provider for account emails. These third parties handle information under their own terms and privacy commitments.
Retention and security
We keep information for the periods below and delete it automatically when they expire, unless a pending dispute, audit, legal hold or other legal obligation requires longer retention.
- Group messages: 30 days from the date the message was sent.
- Memory notes: while the group is active, so Buddie can preserve context. Deleted when the group or the member is deleted, and immediately on request by texting FORGET.
- Consent records: five years from the date consent ends, as evidence that participants agreed to take part.
- Crisis referral records: a de-identified record of the referral, containing no message content and nothing that identifies a person, retained indefinitely for safety reporting. We take reasonable measures to prevent these records from being associated with a person and will not attempt to reidentify them.
- Delivery records: when a message reaches us we keep an operational record that it arrived, containing delivery metadata such as the messaging provider’s reference for it and timing information, and not the message itself. Thirty days, the same period as the message it describes.
- Billing records: we retain a minimal billing record for seven years after the last transaction for accounting, tax, chargeback, fraud-prevention, and legal-compliance purposes. The record may include Stripe customer, subscription, and transaction references, plan information, transaction dates and amounts, and an internal account identifier, but not the account’s name, email address, phone number, messages, or group content. We delete the record automatically when that period expires unless a pending dispute, audit, legal hold, or other legal obligation requires longer retention. The references that could link that record back to an identified person are deleted 18 months after the last financial activity. For an account confirmed to belong to someone under 13, we delete the linkage within 30 days after closure. If a refund is pending, we retain the linkage only as long as needed to complete the refund and delete it within 30 days after the refund is completed.
- Backups: our database provider retains daily backups for seven days. Deleted content may persist in a backup until it ages out.
We use access controls, row-level database security and server-side credentials, but no online service can guarantee absolute security.
AI provider retention
Buddie’s replies are generated by Anthropic. To generate a reply, we send Anthropic the relevant group-message text and any memory notes used as context. Separately, our crisis-safety check sends the text of one inbound message to Anthropic for classification, without a phone number, member identifier, group identifier, name, pseudonymous identifier or conversation history. Crisis-classification results are not used to generate group replies. Anthropic acts as our processor: its commercial terms incorporate a data processing addendum and prohibit training on customer content. Those terms also permit Anthropic to process content to enforce its usage policies, which is processing we do not direct and cannot switch off.
Anthropic states that it ordinarily deletes API inputs and outputs within 30 days of receiving them. Where content is flagged as a usage policy violation, Anthropic may retain the inputs and outputs for up to two years, and related trust and safety classification scores for up to seven years. Anthropic separately retains feedback submitted through its interfaces for five years; we submit no feedback.
These are Anthropic’s periods, set by Anthropic and applied on Anthropic’s systems, and they run independently of ours. Content may still be held by Anthropic after we have deleted our copy, including after an account is closed. Deleting your account removes active copies of your account content from our systems, subject to the specific retention periods and seven-day backup cycle described above. Texting FORGET deletes the memories we have saved about you and stops new ones being saved. Neither reaches content Anthropic already holds.
Your choices and rights
You may request access, correction or deletion of eligible personal information by contacting us. Some records may be retained where required for security, billing, dispute resolution or legal compliance.
Contact
Meet Buddie L.L.C.
Email privacy and data requests to privacy@meetbuddie.com.
