Privacy Policy
Last updated: August 2026
This privacy policy explains how BuzzCraft handles personal data during the public beta. BuzzCraft is a prompt workspace for building, saving, and reusing structured AI workflows.
1. Controller
Controller: Johanna Hemmerich, Rüttenscheider Straße 161, 45131 Essen, Germany
Email: hello@buzzcraft.ai.
2. Data we collect
- Account data: name, email address, profile image, authentication identifiers, and login status.
- Workspace data: saved prompts, saved skills, prompt history, prompt outputs, labels, templates used, Hive/workflow state, and optional Memory keywords if Memory is enabled.
- Plan, payment, and usage data: Explorer, Creator, or God Mode status, quota usage, rate-limit events, Stripe checkout/payment status, BYOK provider status, and masked key status.
- Technical data: IP address, browser/device metadata, request timestamps, error logs, and security events.
- Local app data: local settings, cached prompt library data, usage counters, and UI preferences stored in the browser.
- Extension data: extension profile sync status, temporary extension user token metadata, authenticated-plan usage counters, saved extension prompts, and local extension settings.
- Extension guest-trial data: a randomly generated installation identifier stored in Chrome extension storage; the corresponding number of successful guest generations and any later one-time claim by a signed-in account stored on our servers; and a keyed, pseudonymous hash derived from the request IP address for rate limiting and abuse prevention.
- Extension in-page data: while using the Chrome extension on chatgpt.com, the draft text you are actively typing is read by the extension and sent to BuzzCraft's servers to generate suggestions, as described in Section 3.
- Waitlist data: if you submit your email address to request updates about an upcoming extension, including a future Claude version, without creating an account, we store that email address and the waitlist source.
3. Why we process data
- To create and secure your BuzzCraft account.
- To provide the prompt builder, prompt library, Hive workflows, saved prompts, and history features.
- To enforce beta quotas, plan access, rate limits, and abuse protection.
- To provide the Chrome extension guest trial, count only successful guest generations, prevent repeated use of the one-time allowance, and credit prior guest usage once if you later sign in.
- To process paid Creator and God Mode checkout through Stripe and activate plan access after confirmed payment.
- To route AI requests through BuzzCraft-hosted Groq for Explorer and Creator users, or through your connected provider for God Mode (BYOK) users.
- To provide optional Memory, which can reuse a small set of recurring keywords as context for future prompt suggestions and executions.
- To generate real-time Structure and Enhanced suggestions in the Chrome extension: the draft text you are typing on chatgpt.com is sent to our servers and passed to the active AI provider for that request only.
- To restructure a saved prompt into a reusable "skill" document when you use the Convert to Skill feature: the prompt's content is sent to the active AI provider for that request only.
- To send you transactional emails (e.g. waitlist confirmation, account welcome emails) through our email provider, and to notify us internally when a new waitlist signup or account is created.
- To improve reliability, debug beta issues, and respond to support or deletion requests.
Chrome extension guest trial
If you use the Chrome extension without signing in, the extension creates a random UUID using your browser's cryptographic random-number generator. This installation identifier is stored in Chrome extension local storage and sent to BuzzCraft with guest-generation requests. It is not a BuzzCraft account, is not generated from your name or email address, and is not used to create a device fingerprint.
BuzzCraft stores the installation identifier and the number of successful guest generations on its servers so that the guest allowance can be enforced. Failed generation requests are not counted. The guest usage total is not stored as the authoritative counter in the extension. If you later sign in, the installation record may be linked once to your BuzzCraft user ID so that prior guest usage is included in the applicable account quota.
For additional abuse prevention, BuzzCraft derives a keyed HMAC value from the request IP address and uses it with a rolling 24-hour rate-limit window. The raw IP address is not stored in the guest-usage database table, although hosting and security providers may process IP addresses in technical request or security logs. The installation identifier and HMAC value are pseudonymous identifiers, not anonymous data.
4. Legal basis
Account and workspace processing is generally necessary to provide the requested beta service. Security, quota, logging, and abuse-prevention processing is based on BuzzCraft's legitimate interest in operating a stable and secure product. Optional communications or future marketing will use consent or another applicable legal basis.
5. Where data is stored and processed
BuzzCraft currently uses Clerk for authentication (including Google as an optional sign-in provider) and Supabase for application data such as prompts, history, Hive state, optional Memory keywords, entitlements, usage, guest-trial installation and rate-limit records, waitlist entries, and BYOK connection metadata. AI requests may be processed by Groq, OpenAI, or Anthropic depending on the active plan and selected provider. Resend is used to deliver transactional email. Several of these providers (including Clerk, Supabase, Vercel, Groq, OpenAI, Anthropic, Stripe, and Resend) may process data outside the EU/EEA, in particular in the United States. Where that happens, we rely on the provider's Standard Contractual Clauses and/or EU-U.S. Data Privacy Framework certification as the transfer safeguard.
6. Service providers and recipients
BuzzCraft uses the following service providers or provider categories where needed to operate, secure, analyse, and improve the beta:
- Clerk: authentication, account management, sessions, and login security.
- Google: only if you choose "Sign up/Sign in with Google" - Google acts as the OAuth identity provider and shares your name, email address, and profile image with Clerk to create your account.
- Supabase: database storage for prompts, prompt history, Hive/workflow state, optional Memory keywords, user entitlements, hosted AI usage, guest-trial installation and pseudonymous rate-limit records, waitlist entries, and encrypted BYOK credential records.
- Vercel: website and application hosting, serverless runtime, deployment infrastructure, and technical request logs.
- Cloudflare: DNS, content delivery, security, firewall and access protection, traffic routing, related security logs, Cloudflare Web Analytics, Real User Measurement, and Cloudflare Turnstile for protection against automated access, spam, and abuse.
- Groq: hosted AI processing for Explorer and Creator Mode, and for real-time Chrome extension suggestions unless you're on God Mode with a connected BYOK provider.
- OpenAI and Anthropic: AI processing only when you select or connect these providers through BYOK or supported provider settings.
- Resend: delivery of transactional email, such as waitlist confirmations, account welcome emails, and internal signup notifications. Processes the recipient email address and message content only.
- Chrome browser / Chrome extension storage: local extension settings, profile sync data, saved extension prompts, authenticated usage data, temporary extension token records, and the random guest-trial installation identifier. The authoritative guest-generation count is stored on BuzzCraft's servers.
- GitHub: source code and deployment workflow infrastructure. User workspace content is not intentionally stored in GitHub as part of normal product use.
- Stripe: payment checkout, subscription billing, one-time God Mode purchases, invoice/payment status, and webhook confirmation for plan activation.
7. Cookies, local storage, analytics, and consent
BuzzCraft uses cookies, localStorage, and Chrome extension storage where needed for authentication, security, session handling, product settings, quota enforcement, extension synchronisation, the guest-trial installation identifier, and other core functionality.
The processing of these technologies is based on our legitimate interest in operating a secure, functional, and reliable online service pursuant to Art. 6(1)(f) GDPR, or, where applicable, on the performance of a contract pursuant to Art. 6(1)(b) GDPR.
Cloudflare Turnstile
BuzzCraft uses Cloudflare Turnstile to protect security-sensitive functions, forms, and access points against automated requests, spam, abuse, and malicious traffic.
Turnstile may run an invisible challenge in the background of your browser and process technical signals relating to your browser, device, and browser environment in order to distinguish legitimate users from automated traffic.
Cloudflare states that the signals processed by Turnstile are used for bot detection and website security purposes. Where these signals constitute personal data, the processing is based on our legitimate interest in protecting BuzzCraft and its users against abuse and automated attacks pursuant to Art. 6(1)(f) GDPR.
Further information about the processing carried out through Turnstile is available in Cloudflare'sTurnstile Privacy AddendumandPrivacy Policy.
Cloudflare Web Analytics and Real User Measurement
BuzzCraft uses Cloudflare Web Analytics and Real User Measurement to understand aggregate website traffic and technical performance.
Cloudflare Web Analytics is configured to exclude visitor analytics data originating from the European Union. Consequently, analytics data for visitors located within the EU is not collected through this service.
For visitors outside the European Union, Cloudflare states that Web Analytics does not use cookies or localStorage for analytics purposes and does not fingerprint visitors for analytics reporting.
The analytics service is used solely to measure aggregate website traffic and technical performance. It is not used to create advertising profiles, deliver personalised advertising, retarget visitors, or track them across unrelated websites.
Further information is available in Cloudflare'sWeb Analytics informationandPrivacy Policy.
BuzzCraft currently does not intentionally use marketing cookies, advertising pixels, retargeting technologies, heatmaps, behavioural session-recording tools, or similar tracking technologies. If technologies requiring consent are introduced in the future, they will not be activated until the necessary consent controls have been implemented.
8. API keys and BYOK
If you connect your own AI provider key, BuzzCraft stores it server-side in encrypted form and never shows it again after saving. The browser receives only masked connection status. You can replace or delete connected keys from the app settings.
9. Retention
Account and workspace data is kept while your account is active or while needed to provide the beta service. Prompt history, saved prompts, and optional Memory keywords remain stored until you delete or clear them, disable/clear the relevant feature, or request account deletion. Guest-trial installation records are retained according to the criteria necessary to enforce the one-time guest allowance, apply prior guest usage after sign-in, prevent abuse, and handle security investigations. The IP-derived HMAC record contains a rolling 24-hour rate-limit window and may be retained where needed for those security and abuse-prevention purposes. Security and operational logs may be retained for a limited period to investigate abuse, errors, or billing disputes.
10. Your rights and deletion requests
You may request access, correction, export, restriction, objection, or deletion of your personal data. To request deletion, email hello@buzzcraft.ai with the email address used for your account and the subject "BuzzCraft data deletion". We will delete or anonymize account and workspace data unless retention is required for legal, security, or billing reasons. If you believe our processing of your data violates applicable data protection law, you also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
11. Beta note
BuzzCraft is in active beta. Features, storage behavior, providers, and data flows may change as the product evolves. Material privacy changes will be reflected in this policy.
BuzzCraft’s use and transfer of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension user data is used only to provide or improve BuzzCraft’s disclosed prompt-building and prompt-management features. It is not sold, used for personalized advertising, used for creditworthiness or lending decisions, or transferred for purposes unrelated to the extension’s disclosed functionality. Human access to extension user data is prohibited except where expressly permitted by the Chrome Web Store User Data Policy, such as with the user’s explicit consent, for security or abuse investigations, or where required by law.