Privacy Policy
Effective July 29, 2026
Buddhi AI (“we,” “us,” or “our”) provides an access-controlled memory layer for AI agents (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
- Account information: name, email address, and organization details you provide when signing up or being invited to a workspace.
- Authentication data: when you sign in with Google or another OAuth provider, we receive the profile fields that provider shares with your consent (typically name, email, and profile picture).
- Content you store: memories, facts, documents, and other data you or your connected agents write into the Service.
- Usage data: API calls, access logs, audit trails, and diagnostic information generated as agents and users interact with the Service.
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and secure the Service, including identity verification and policy enforcement.
- Generate audit logs of agent and user access for your organization's compliance needs.
- Communicate with you about your account, invitations, and Service updates.
- Improve reliability, performance, and features of the Service.
3. Google User Data
If you connect Buddhi AI to your Google Account, we request the following read-only scopes, and access only what you explicitly authorize during Google's OAuth consent flow:
- Gmail (read-only): we read the content of email messages you authorize and ingest relevant text into your organization's governed memory layer, so your team's AI agents can answer questions with a citation back to the original email. We never send, modify, or delete email, and never use Gmail content for advertising.
- Google Drive (read-only): we read the content of Drive files you authorize and ingest relevant text into your organization's governed memory layer, with the same citation-back behavior. We never create, modify, delete, or share Drive files, and never use Drive content for advertising.
- Basic profile (email, profile, openid): used only to identify the connected Google account and label it in your workspace's connector settings.
Google user data is used solely to operate the features described above, is stored under the same encryption and role-based access controls as the rest of your organization's memory (see Section 5), and is never sold or used for advertising. Our access and use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke Buddhi AI's access to your Google account at any time from Google Account permissions, or by disconnecting the connector from your workspace's settings.
4. Data Sharing
We do not sell your personal information. We share data only with subprocessors who help us operate the Service (e.g., cloud hosting and email delivery providers), under contractual confidentiality obligations, or when required by law.
5. Data Retention & Security
We retain account and content data for as long as your organization's workspace is active, or as needed to comply with legal obligations. Data is encrypted in transit and at rest, and access is restricted by the same role-based policies the Service enforces for your own agents.
6. Your Rights
You may request access to, correction of, or deletion of your personal data by contacting us at support@askbuddhi.com. Workspace administrators can also revoke a member's access at any time from the team settings page.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above, and where appropriate, communicated directly to workspace administrators.
8. Contact Us
Questions about this policy can be sent to support@askbuddhi.com.