Privacy Policy

Last updated: August 2026

This privacy policy explains how BuzzCraft handles personal data during the public beta. BuzzCraft is a prompt workspace for building, saving, and reusing structured AI workflows.

1. Controller

Controller: Johanna Hemmerich, Rüttenscheider Straße 161, 45131 Essen, Germany
Email: hello@buzzcraft.ai.

2. Data we collect

3. Why we process data

Chrome extension guest trial

If you use the Chrome extension without signing in, the extension creates a random UUID using your browser's cryptographic random-number generator. This installation identifier is stored in Chrome extension local storage and sent to BuzzCraft with guest-generation requests. It is not a BuzzCraft account, is not generated from your name or email address, and is not used to create a device fingerprint.

BuzzCraft stores the installation identifier and the number of successful guest generations on its servers so that the guest allowance can be enforced. Failed generation requests are not counted. The guest usage total is not stored as the authoritative counter in the extension. If you later sign in, the installation record may be linked once to your BuzzCraft user ID so that prior guest usage is included in the applicable account quota.

For additional abuse prevention, BuzzCraft derives a keyed HMAC value from the request IP address and uses it with a rolling 24-hour rate-limit window. The raw IP address is not stored in the guest-usage database table, although hosting and security providers may process IP addresses in technical request or security logs. The installation identifier and HMAC value are pseudonymous identifiers, not anonymous data.

4. Legal basis

Account and workspace processing is generally necessary to provide the requested beta service. Security, quota, logging, and abuse-prevention processing is based on BuzzCraft's legitimate interest in operating a stable and secure product. Optional communications or future marketing will use consent or another applicable legal basis.

5. Where data is stored and processed

BuzzCraft currently uses Clerk for authentication (including Google as an optional sign-in provider) and Supabase for application data such as prompts, history, Hive state, optional Memory keywords, entitlements, usage, guest-trial installation and rate-limit records, waitlist entries, and BYOK connection metadata. AI requests may be processed by Groq, OpenAI, or Anthropic depending on the active plan and selected provider. Resend is used to deliver transactional email. Several of these providers (including Clerk, Supabase, Vercel, Groq, OpenAI, Anthropic, Stripe, and Resend) may process data outside the EU/EEA, in particular in the United States. Where that happens, we rely on the provider's Standard Contractual Clauses and/or EU-U.S. Data Privacy Framework certification as the transfer safeguard.

6. Service providers and recipients

BuzzCraft uses the following service providers or provider categories where needed to operate, secure, analyse, and improve the beta:

7. Cookies, local storage, analytics, and consent

BuzzCraft uses cookies, localStorage, and Chrome extension storage where needed for authentication, security, session handling, product settings, quota enforcement, extension synchronisation, the guest-trial installation identifier, and other core functionality.

The processing of these technologies is based on our legitimate interest in operating a secure, functional, and reliable online service pursuant to Art. 6(1)(f) GDPR, or, where applicable, on the performance of a contract pursuant to Art. 6(1)(b) GDPR.

Cloudflare Turnstile

BuzzCraft uses Cloudflare Turnstile to protect security-sensitive functions, forms, and access points against automated requests, spam, abuse, and malicious traffic.

Turnstile may run an invisible challenge in the background of your browser and process technical signals relating to your browser, device, and browser environment in order to distinguish legitimate users from automated traffic.

Cloudflare states that the signals processed by Turnstile are used for bot detection and website security purposes. Where these signals constitute personal data, the processing is based on our legitimate interest in protecting BuzzCraft and its users against abuse and automated attacks pursuant to Art. 6(1)(f) GDPR.

Further information about the processing carried out through Turnstile is available in Cloudflare'sTurnstile Privacy AddendumandPrivacy Policy.

Cloudflare Web Analytics and Real User Measurement

BuzzCraft uses Cloudflare Web Analytics and Real User Measurement to understand aggregate website traffic and technical performance.

Cloudflare Web Analytics is configured to exclude visitor analytics data originating from the European Union. Consequently, analytics data for visitors located within the EU is not collected through this service.

For visitors outside the European Union, Cloudflare states that Web Analytics does not use cookies or localStorage for analytics purposes and does not fingerprint visitors for analytics reporting.

The analytics service is used solely to measure aggregate website traffic and technical performance. It is not used to create advertising profiles, deliver personalised advertising, retarget visitors, or track them across unrelated websites.

Further information is available in Cloudflare'sWeb Analytics informationandPrivacy Policy.

BuzzCraft currently does not intentionally use marketing cookies, advertising pixels, retargeting technologies, heatmaps, behavioural session-recording tools, or similar tracking technologies. If technologies requiring consent are introduced in the future, they will not be activated until the necessary consent controls have been implemented.

8. API keys and BYOK

If you connect your own AI provider key, BuzzCraft stores it server-side in encrypted form and never shows it again after saving. The browser receives only masked connection status. You can replace or delete connected keys from the app settings.

9. Retention

Account and workspace data is kept while your account is active or while needed to provide the beta service. Prompt history, saved prompts, and optional Memory keywords remain stored until you delete or clear them, disable/clear the relevant feature, or request account deletion. Guest-trial installation records are retained according to the criteria necessary to enforce the one-time guest allowance, apply prior guest usage after sign-in, prevent abuse, and handle security investigations. The IP-derived HMAC record contains a rolling 24-hour rate-limit window and may be retained where needed for those security and abuse-prevention purposes. Security and operational logs may be retained for a limited period to investigate abuse, errors, or billing disputes.

10. Your rights and deletion requests

You may request access, correction, export, restriction, objection, or deletion of your personal data. To request deletion, email hello@buzzcraft.ai with the email address used for your account and the subject "BuzzCraft data deletion". We will delete or anonymize account and workspace data unless retention is required for legal, security, or billing reasons. If you believe our processing of your data violates applicable data protection law, you also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.

11. Beta note

BuzzCraft is in active beta. Features, storage behavior, providers, and data flows may change as the product evolves. Material privacy changes will be reflected in this policy.

BuzzCraft’s use and transfer of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension user data is used only to provide or improve BuzzCraft’s disclosed prompt-building and prompt-management features. It is not sold, used for personalized advertising, used for creditworthiness or lending decisions, or transferred for purposes unrelated to the extension’s disclosed functionality. Human access to extension user data is prohibited except where expressly permitted by the Chrome Web Store User Data Policy, such as with the user’s explicit consent, for security or abuse investigations, or where required by law.