How your data is protected
On the way to us
Every connection to startbuddi uses HTTPS, so what you send and receive is encrypted in transit. The app also tells browsers to refuse plain, unencrypted connections (HSTS) and sends a content security policy and other browser security headers.
When it is stored
Your workspace data lives in a Postgres database run by Supabase, and the files you upload are stored in Cloudflare R2. Both providers encrypt stored data; you can read how on Supabase's security page (opens in a new tab) and Cloudflare's trust hub (opens in a new tab).
We add our own layer for the most sensitive items. The access tokens for apps you connect, such as Google, Microsoft, Meta and WhatsApp, are encrypted by startbuddi (AES-256-GCM) before they are saved, so they can't be read straight from the database.
Who can see it
The app checks who you are and which workspace you belong to before it shows or changes anything, and each workspace's data is kept separate. Messages that other services send us, from Meta, Stripe, Paystack and Resend, are checked for the sender's signature before we read them.
Accounts and access
Signing in
You can sign in with your email and password, with a one-time code sent to your email, or with Google. Signing in with Google only confirms who you are: connecting Gmail or Google Calendar is a separate step you approve.
- Passwords need at least 8 characters, including an uppercase letter and a number. Sign-in is handled by Supabase Auth, so startbuddi never stores your password itself.
- After 5 wrong passwords or codes for one account, sign-in is locked for 15 minutes. If it keeps happening the lock grows to 1 hour, then 24 hours. There are also limits per internet address.
- Password reset emails are limited to 3 an hour for each address.
Roles
Everyone in a workspace has a role: Owner, Admin, Manager, Member or View only. Clients you invite to a project get a Client role that only opens the projects they were added to. Only the owner can manage billing and delete the workspace.
Audit log
Owners and admins can see an audit log under Settings, Audit logs. It records sensitive actions, such as data exports, changes to security and privacy settings, ownership transfers and new payment connections, with who did it and when. It doesn't record every change in the workspace yet.
Payments
Payments for your startbuddi plan, and the payments your customers make on your invoices and payment links, are processed by Stripe (opens in a new tab) and Paystack (opens in a new tab). Card details are entered on their payment pages and forms and go straight to them. startbuddi never receives or stores full card numbers: we keep the payment reference, the amount and its status.
Chip and your data
Chip, our AI assistant, runs on Anthropic's Claude models, with OpenAI as a backup when Claude isn't available. Chip's voice features use OpenAI's realtime speech service. We call these providers from our own servers, and our API keys never reach your browser.
- What is sent. Your request and the workspace information Chip needs to answer it. Chip only works inside your own workspace and with the tools it has been allowed to use.
- Training. We don't use your workspace data to train AI models. Under their business API terms, Anthropic says (opens in a new tab) it may not train models on customer content, and OpenAI says (opens in a new tab) data sent to its API isn't used for training unless the customer opts in. How long each provider keeps API data is set by those terms.
- A record of what Chip did. Every action Chip takes in your workspace, like sending a message or updating a record, is logged.
- Website chat. Before Chip replies to a visitor on your website, the reply is checked. Things like card numbers are removed, and a reply that would reveal a secret key is blocked.
Where your data lives
Our main database runs in Supabase's EU (Ireland) region, and the app runs on Vercel in Frankfurt, Germany. Some of the services below, including the AI providers, process data in the United States. You can't choose a different region yet.
These are the companies that process data for us, and what for. Each one only gets what it needs for that job.
| Company | What we use it for | Their page |
|---|---|---|
| Vercel | Runs the startbuddi app and its servers | Security (opens in a new tab) |
| Supabase | Database and sign-in | Security (opens in a new tab) |
| Cloudflare R2 | Stores the files you upload | Trust hub (opens in a new tab) |
| Resend | Sends email from startbuddi and from your workspace | Security (opens in a new tab) |
| Upstash (QStash) | Schedules background jobs, like sending a campaign later | Privacy (opens in a new tab) |
| Pusher | Live updates in the app, like new messages | Security (opens in a new tab) |
| Sentry | Error reports, so we know when something breaks | Security (opens in a new tab) |
| Anthropic | Chip, our AI assistant (main AI model) | Commercial terms (opens in a new tab) |
| OpenAI | Chip's backup AI model and voice features | Your data (opens in a new tab) |
| Stripe | Card payments and subscriptions | Security (opens in a new tab) |
| Paystack | Card, bank transfer and mobile money payments in Africa | Terms (opens in a new tab) |
| Mixpanel | Product analytics, only if you accept analytics cookies | Security (opens in a new tab) |
| Google Analytics | Website and app analytics, only if you accept analytics cookies | Data safeguards (opens in a new tab) |
| Brevo | startbuddi's own newsletter list | Privacy (opens in a new tab) |
| Brandfetch | Finds a company's logo and colours from its website address | Privacy (opens in a new tab) |
| Exa | Web search when you use Prospecting | Privacy (opens in a new tab) |
| Only when you connect them | ||
| Meta | WhatsApp, Messenger, Instagram and Facebook | Privacy (opens in a new tab) |
| Sign in with Google, plus Gmail, Calendar and Drive | Privacy (opens in a new tab) | |
| Microsoft | Outlook email and calendar | Privacy (opens in a new tab) |
| Twilio | SMS and phone calls | Security (opens in a new tab) |
Backups and availability
Supabase, our database provider, takes a backup of the database every day. If we ever had to restore, the database would go back to its most recent daily backup. You can read how these backups work in Supabase's backup guide (opens in a new tab).
Errors in the app are reported to us automatically through Sentry.
Your controls
- Export. Owners and admins can download a copy of the workspace's data as a file from Settings, Danger zone.
- Delete. The owner can delete the workspace from Settings, Danger zone. It is removed from our live database straight away. Copies can stay in the daily database backups until those backups expire.
- Roles and members. Give each person the smallest role they need, and remove people who leave from Settings, Team.
- Privacy requests. Settings, Privacy & data shows where personal data is stored in your workspace and helps you track requests from people who ask to see, correct or delete their data.
Reporting a vulnerability
If you think you have found a security problem in startbuddi, please tell us privately first.
- the page, link or feature affected;
- the steps to reproduce it;
- what you expected, and what happened;
- how we can reach you.
While you look into it, please only use your own accounts and data, don't access or change anyone else's data beyond what you need to show the problem, and don't run tests that slow the service down or send spam. Give us a reasonable time to fix the problem before you share it publicly.
We'll confirm we've received your report and keep you updated. If you act in good faith and follow these guidelines, we won't take legal action against you over your research. We don't run a paid bug bounty.