Privacy Policy
கடைசியாக புதுப்பிக்கப்பட்டது: October 2, 2026
1. Who is responsible for your data
BusyBee.Day is operated by NeoPixel s.r.o., which is the data controller for the personal data described in this policy. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. You can reach a human at the addresses below.
- NeoPixel s.r.o., Wuppertálska 57, 040 23 Košice, Slovak Republic
- Company ID (IČO): 47079908 · Tax ID (DIČ): 2023793387 · VAT ID (IČ DPH): SK2023793387
- Commercial Register of the Municipal Court Košice, Section: Sro, Insert No. 32572/V
- Contact: via the contact form at busybee.day/contact, or by post at the address above.
2. What we collect
We collect only what the service needs in order to work:
- Account data: your email address, name, password (stored only as a bcrypt hash), language and theme preference, and - if you enable two-factor authentication - an encrypted TOTP secret. If you sign in with Google, we also receive your Google account ID, email address, name and profile picture.
- Content you create: tasks, projects, comments, documents, whiteboards, mindmaps, databases, habits, labels, and any files you attach.
- Bot conversations and work: the messages you send to bots, the tasks and comments you hand them, what they produce (answers, documents, files, tasks), the steps of each bot run (which tools were used and what came back) and, when a bot uses its computer, screenshots of that computer.
- Bot memory: short facts a bot keeps about a project, about how you like the work done in it, and a profile of how you like to work in general, plus the skills and rules your projects teach bots. You can read, change and delete every entry.
- Connected services: when you connect a service to a bot (for example Gmail, Google Calendar, Notion, ClickUp, Canva or Stripe), the sign-in tokens or keys for it, stored encrypted, and the data the bot reads or writes there while doing what you asked.
- Your own AI keys, if you add them: stored encrypted and used only for your requests.
- Team data: which teams and projects you belong to, your role, and activity logs showing who changed what.
- Usage and technical data: sign-in timestamps, IP address and user agent at authentication, the credits each bot run used and on which model, and server logs kept for security and debugging.
- Billing data: your plan, subscription status, billing period, credit purchases and the invoices we issue. Card details are entered directly with Stripe and never reach our servers.
- Integration data, only if you connect it yourself: Google Calendar events, Gmail messages, or content you import from Notion or ClickUp.
3. Why we process it, and on what legal basis
Article 6 GDPR requires a lawful basis for each purpose. Ours are:
- Providing the service, your account and your workspace - performance of a contract, Art. 6(1)(b).
- Running the bots you start, including their memory, computer, web search and the services you connect to them - performance of a contract, Art. 6(1)(b), since every bot run starts from your message, a task you hand over or a schedule you set.
- Counting the credits your bots use and billing them - performance of a contract and legal obligation, Art. 6(1)(b) and (c).
- Billing, invoicing and statutory accounting records - performance of a contract and legal obligation, Art. 6(1)(b) and (c).
- Transactional email such as sign-in links, password resets, security alerts and notices from your bots - performance of a contract, Art. 6(1)(b).
- Keeping the service secure, preventing abuse of bots and computers, and debugging faults - legitimate interests, Art. 6(1)(f).
- Connecting Google Calendar, Gmail, Notion, ClickUp or another service - your consent, Art. 6(1)(a), which you can withdraw at any time by disconnecting it.
4. How AI processing works
Bots and the AI features send text to an AI model to produce an answer. This is what happens to it:
- We send the model only what the work needs: your instructions, the task, document or chat in question, the relevant memory, and the results of the tools the bot used.
- Requests go through OpenRouter, Inc. to the provider of the model you or your bot use. We instruct OpenRouter to route them only to providers that do not store or train on the data they receive (its "data_collection: deny" setting), and OpenRouter itself does not store prompts unless asked to.
- We do not use your content to train AI models, and the providers we route to may not either.
- If you add your own AI key, requests on that key go directly to that provider under your own agreement with it.
- Some quick checks during bot work go to Cloudflare Workers AI instead of a language model: whether the screen of a bot's computer shows a sign-in, a CAPTCHA, a payment form, an error or finished work; whether outside content holds instructions aimed at AI; and whether a finished run has anything worth learning. Cloudflare does not use this content to train models or to improve its services.
- When a bot searches the web, the search query goes to Perplexity or Brave Search. Pages a bot reads are fetched from the public web.
- A bot computer is an isolated cloud machine run by FoundryLabs, Inc. (E2B) for one project. It pauses after 5 minutes without use. Files on it stay until the project's computer is deleted.
- Content that comes from outside BusyBee.Day - emails, web pages, connected services - is treated as untrusted: after a bot has read it, changes to its memory need your approval, and by default actions that change something in a connected service wait for your approval.
- Bots are AI systems. Their messages, files and changes are marked as coming from a bot, so you always know what an AI produced.
5. How long we keep it
Retention is tied to purpose, not kept open-ended:
- Account and content data: for as long as your account exists. Delete your account and it is removed.
- Bot chats, runs and the files bots made: for as long as the chat or project exists. Screenshots of a bot computer are kept with the run and may be deleted earlier to save space.
- Bot memory, skills and rules: until you or a bot remove them, or the project is deleted.
- Tokens and keys for connected services and your own AI keys: until you disconnect or remove them, or delete your account.
- Items you move to Trash: retained for the retention window shown in the app, then purged automatically.
- Accounting and invoicing records: 10 years, as required by Slovak Act No. 431/2002 Coll. on Accounting.
- Server and security logs: up to 12 months.
6. Who else processes your data
We do not sell your data and we do not use it for advertising. The companies that process data for us, under data processing agreements, are listed on our Subprocessors page (busybee.day/subprocessors): hosting, file storage, email, payments, AI routing and models, web search and bot computers. Services you connect to a bot yourself are not our processors - the bot accesses them on your instruction, and their own terms and privacy policies apply.
7. Transfers outside the EU
Your account data, content and attachments are hosted inside the EU. Several processors - among them the AI model providers, OpenRouter, E2B and the web search providers - are established in the United States or other countries outside the EU. Where personal data reaches them, the transfer relies on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards in place.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out. Most of these you can exercise yourself: export or delete your data in Settings, delete bot memory entries, disconnect services, and delete chats or projects. For anything else contact us through busybee.day/contact and we will respond within one month.
9. Complaining to a supervisory authority
If you believe we are handling your data unlawfully, you can lodge a complaint with the Slovak supervisory authority, or with the authority in your own country of residence:
- Úrad na ochranu osobných údajov Slovenskej republiky
- Galvaniho 16130/7B, 821 04 Bratislava - Ružinov, Slovak Republic
- dataprotection.gov.sk
10. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects for you. Bots work on what you or your team ask them to do; they never make decisions about your account, your access or your billing.
11. Google user data
BusyBee.Day's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. In practice:
- What we receive: your Google profile (name, email, picture) if you sign in with Google; calendar events and calendar lists if you connect Google Calendar; email messages, labels and drafts if you connect Gmail to the inbox feature or to a bot.
- What we use it for: only the features you turned on - signing you in, showing your calendar, turning emails into tasks, and letting your bot read, search, label or draft in your mailbox or calendar when you ask it to.
- Sharing: Google user data is sent to an AI model provider only to carry out the request you made, through the no-storage, no-training routing described in section 4. It is not sold, not used for advertising, not used for credit decisions, and not transferred to anyone else except as needed to provide these features, for security, or to comply with the law.
- AI training: Google user data is never used to develop, improve or train generalized AI or machine-learning models.
- Human access: our staff do not read your Google data unless you ask us to (for example in a support request), it is needed for security reasons, or the law requires it.
- Stopping it: disconnect the service in BusyBee.Day, or remove access at myaccount.google.com/permissions; we then delete the tokens we hold for it.
12. Children
BusyBee.Day is not directed at children under 16. We do not knowingly collect their data. If you believe a child has created an account, contact us through busybee.day/contact and we will delete it.
13. Changes to this policy
When we make material changes we will update the date above and notify account holders by email before the change takes effect.
This document is published in English, which is the authoritative version.