New: Chip can now take voice calls from your website chat (beta). Hear how it works

The founding cohort is open: 6 months free for the first 20 teams, picked by hand. Apply

Security

How we keep your business data safe.

What startbuddi does to protect your account and your customers' data and which companies help us run it.

Last updated 28 September 2026

In place today
  • Encrypted connections (HTTPS) everywhere
  • Tokens for the apps you connect are encrypted before they are saved
  • Sign-in lockout after repeated wrong passwords
  • Roles for every teammate, and an audit log for sensitive actions
  • Card details go straight to Stripe or Paystack
  • Export or delete your workspace yourself

How your data is protected

On the way to us

Every connection to startbuddi uses HTTPS, so what you send and receive is encrypted in transit. The app also tells browsers to refuse plain, unencrypted connections (HSTS) and sends a content security policy and other browser security headers.

When it is stored

Your workspace data lives in a Postgres database run by Supabase, and the files you upload are stored in Cloudflare R2. Both providers encrypt stored data; you can read how on Supabase's security page (opens in a new tab) and Cloudflare's trust hub (opens in a new tab).

We add our own layer for the most sensitive items. The access tokens for apps you connect, such as Google, Microsoft, Meta and WhatsApp, are encrypted by startbuddi (AES-256-GCM) before they are saved, so they can't be read straight from the database.

Who can see it

The app checks who you are and which workspace you belong to before it shows or changes anything, and each workspace's data is kept separate. Messages that other services send us, from Meta, Stripe, Paystack and Resend, are checked for the sender's signature before we read them.

Accounts and access

Signing in

You can sign in with your email and password, with a one-time code sent to your email, or with Google. Signing in with Google only confirms who you are: connecting Gmail or Google Calendar is a separate step you approve.

  • Passwords need at least 8 characters, including an uppercase letter and a number. Sign-in is handled by Supabase Auth, so startbuddi never stores your password itself.
  • After 5 wrong passwords or codes for one account, sign-in is locked for 15 minutes. If it keeps happening the lock grows to 1 hour, then 24 hours. There are also limits per internet address.
  • Password reset emails are limited to 3 an hour for each address.

Roles

Everyone in a workspace has a role: Owner, Admin, Manager, Member or View only. Clients you invite to a project get a Client role that only opens the projects they were added to. Only the owner can manage billing and delete the workspace.

Audit log

Owners and admins can see an audit log under Settings, Audit logs. It records sensitive actions, such as data exports, changes to security and privacy settings, ownership transfers and new payment connections, with who did it and when. It doesn't record every change in the workspace yet.

Payments

Payments for your startbuddi plan, and the payments your customers make on your invoices and payment links, are processed by Stripe (opens in a new tab) and Paystack (opens in a new tab). Card details are entered on their payment pages and forms and go straight to them. startbuddi never receives or stores full card numbers: we keep the payment reference, the amount and its status.

Chip and your data

Chip, our AI assistant, runs on Anthropic's Claude models, with OpenAI as a backup when Claude isn't available. Chip's voice features use OpenAI's realtime speech service. We call these providers from our own servers, and our API keys never reach your browser.

  • What is sent. Your request and the workspace information Chip needs to answer it. Chip only works inside your own workspace and with the tools it has been allowed to use.
  • Training. We don't use your workspace data to train AI models. Under their business API terms, Anthropic says (opens in a new tab) it may not train models on customer content, and OpenAI says (opens in a new tab) data sent to its API isn't used for training unless the customer opts in. How long each provider keeps API data is set by those terms.
  • A record of what Chip did. Every action Chip takes in your workspace, like sending a message or updating a record, is logged.
  • Website chat. Before Chip replies to a visitor on your website, the reply is checked. Things like card numbers are removed, and a reply that would reveal a secret key is blocked.

Where your data lives

Our main database runs in Supabase's EU (Ireland) region, and the app runs on Vercel in Frankfurt, Germany. Some of the services below, including the AI providers, process data in the United States. You can't choose a different region yet.

These are the companies that process data for us, and what for. Each one only gets what it needs for that job.

CompanyWhat we use it forTheir page
VercelRuns the startbuddi app and its serversSecurity (opens in a new tab)
SupabaseDatabase and sign-inSecurity (opens in a new tab)
Cloudflare R2Stores the files you uploadTrust hub (opens in a new tab)
ResendSends email from startbuddi and from your workspaceSecurity (opens in a new tab)
Upstash (QStash)Schedules background jobs, like sending a campaign laterPrivacy (opens in a new tab)
PusherLive updates in the app, like new messagesSecurity (opens in a new tab)
SentryError reports, so we know when something breaksSecurity (opens in a new tab)
AnthropicChip, our AI assistant (main AI model)Commercial terms (opens in a new tab)
OpenAIChip's backup AI model and voice featuresYour data (opens in a new tab)
StripeCard payments and subscriptionsSecurity (opens in a new tab)
PaystackCard, bank transfer and mobile money payments in AfricaTerms (opens in a new tab)
MixpanelProduct analytics, only if you accept analytics cookiesSecurity (opens in a new tab)
Google AnalyticsWebsite and app analytics, only if you accept analytics cookiesData safeguards (opens in a new tab)
Brevostartbuddi's own newsletter listPrivacy (opens in a new tab)
BrandfetchFinds a company's logo and colours from its website addressPrivacy (opens in a new tab)
ExaWeb search when you use ProspectingPrivacy (opens in a new tab)
Only when you connect them
MetaWhatsApp, Messenger, Instagram and FacebookPrivacy (opens in a new tab)
GoogleSign in with Google, plus Gmail, Calendar and DrivePrivacy (opens in a new tab)
MicrosoftOutlook email and calendarPrivacy (opens in a new tab)
TwilioSMS and phone callsSecurity (opens in a new tab)

The services in the last group only receive data after someone in your workspace connects them. Our privacy policy and data processing agreement explain how we handle personal data.

Backups and availability

Supabase, our database provider, takes a backup of the database every day. If we ever had to restore, the database would go back to its most recent daily backup. You can read how these backups work in Supabase's backup guide (opens in a new tab).

Errors in the app are reported to us automatically through Sentry.

Your controls

  • Export. Owners and admins can download a copy of the workspace's data as a file from Settings, Danger zone.
  • Delete. The owner can delete the workspace from Settings, Danger zone. It is removed from our live database straight away. Copies can stay in the daily database backups until those backups expire.
  • Roles and members. Give each person the smallest role they need, and remove people who leave from Settings, Team.
  • Privacy requests. Settings, Privacy & data shows where personal data is stored in your workspace and helps you track requests from people who ask to see, correct or delete their data.

Reporting a vulnerability

If you think you have found a security problem in startbuddi, please tell us privately first.

Send your report to Use our contact form

Choose Support and start your message with "Security".

Please include
  • the page, link or feature affected;
  • the steps to reproduce it;
  • what you expected, and what happened;
  • how we can reach you.

While you look into it, please only use your own accounts and data, don't access or change anyone else's data beyond what you need to show the problem, and don't run tests that slow the service down or send spam. Give us a reasonable time to fix the problem before you share it publicly.

We'll confirm we've received your report and keep you updated. If you act in good faith and follow these guidelines, we won't take legal action against you over your research. We don't run a paid bug bounty.

Questions about security

Does Chip train on my data?

We don't use your workspace data to train AI models. Chip runs on Anthropic and OpenAI through their business APIs. Anthropic's commercial terms say it may not train models on customer content, and OpenAI says data sent to its API is not used for training unless the customer opts in.

Does startbuddi store card numbers?

No. Card details are entered on Stripe's or Paystack's own payment pages and forms and go straight to them. startbuddi keeps the payment reference and amount, never the card number.

Where is my data stored?

Our main database runs in Supabase's EU (Ireland) region and the app runs on Vercel in Frankfurt. Some of the services we use, including the AI providers, process data in the United States. You can't choose a different region yet.

Can I take my data with me, or delete it?

Yes. Owners and admins can download the workspace's data as a file, and the owner can delete the workspace. Both are under Settings, Danger zone.

Something we haven't covered? Ask us, or read our legal documents.