Privacy
Last updated 8 September 2026
Buds is a personal garden of your friendships. Everything in it exists so that you remember to say hello to people you love. It is not an ads business: nothing you put in Buds is sold, shared for marketing, or used to train anything.
What Buds keeps
- Your email address, to sign you in.
- The buds you pot: names, colours, cadences, notes, important dates, and any email addresses you attach to them.
- The hellos you log, and notes you write.
- Your settings: timezone, quiet hours, display name, and a push subscription if you turn nudges on.
Google user data (if you connect Google Calendar)
What Buds accesses and how it is used. With your consent, Buds accesses your Google Calendar data with read-only scope and never writes to your calendar. From each event it collects and stores only the title, start and end times, whether it repeats, your RSVP, and invitee names and email addresses. This Google user data is used for one purpose: working out which of your calendar events were catch-ups with the friends you added, so Buds can log those hellos, show them on your shelf and in the seed tray, and surface your next planned catch-up. It is not used for advertising, profiling, or any other purpose, and it is never used to train machine-learning or artificial-intelligence models.
Sharing, transfer, and disclosure. Buds does not sell Google user data, and does not share, transfer, or disclose it to any third party. The only parties that process it are Buds' infrastructure providers, Supabase (database hosting) and Vercel (application hosting), acting solely on Buds' behalf to run the service. Google user data would only ever be disclosed beyond that if the law required it.
How it is protected. Google user data is encrypted in transit (HTTPS/TLS) and encrypted at rest by our database provider. Your Google OAuth refresh token is stored encrypted in Supabase Vault, is only ever decrypted server-side to sync your calendar, and is never sent to your browser. Every row of calendar data is protected by per-user row-level security, so it can only ever be read by your own signed-in account.
Retention and deletion. Buds syncs roughly the last 30 days of events (plus upcoming ones) and retains the stored event details while your account exists, so your watering history stays intact. Disconnecting Google Calendar in Settings immediately and permanently deletes your refresh token, and Buds can no longer access your calendar; you can also revoke Buds' access at any time from your Google Account security settings. To delete all stored Google user data (or your whole account), email lachlanbyoung@gmail.com and it will be removed within 30 days.
Buds' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where it lives
Data is stored with Supabase (database, with per-user row security) and served by Vercel, Buds' hosting providers. Analytics are Plausible: cookieless and aggregate, no individual tracking.
Taking it back
You can disconnect your calendar or delete buds, hellos, and notes in the app at any time. To delete your whole account and everything in it, email lachlanbyoung@gmail.com and it will be gone within a few days.