Legal
Privacy policy
Last updated March 4, 2026
This Privacy Policy explains how Bunzy collects, uses, shares and protects personal data when you visit our website, use our platform, or communicate with us. It forms part of the Agreement described in our Terms of Service. In short: your content and your data remain yours, we do not sell personal data, and we do not use your content to train AI models.
1. Who we are
The data controller for personal data processed under this Policy is Bunzy. You can reach our privacy contact at hello@bunzy.io. Where you connect a website or provide content that includes personal data of your own customers or visitors, you are the controller of that data and Bunzy processes it as your processor under the Terms of Service; this Policy describes how we handle it in that role as well.
2. Data we collect
Account and identity data. Your name, email address, password or sign-in token, company name, role, language, and, if you sign in with Google, the identifier and email address Google provides.
Website and content data. The URL of each website you connect, the pages, text, images and metadata we read from it, your brand voice, keywords, settings, uploads, and the articles, images and metadata the Service generates for you.
Integration data. The credentials, tokens and configuration needed to publish to your connected platforms and to read your search-performance data, stored encrypted.
Billing data. Your subscription plan, billing cycle, prices, payment status, invoices and refund history. Payment card details are collected and stored by our payment provider, not by us; we hold only a reference to the payment and the last part of the card number where the provider shares it.
Usage and technical data. Log data such as IP address, browser type, device and operating system, pages viewed, actions taken in the dashboard, referring URLs, timestamps, error reports, and identifiers set by cookies and similar technologies described in section 11.
Communications. Emails, chat messages and support requests you exchange with us, and whether emails we send you were opened or their links clicked.
Lead data. If you use a free tool on our website, such as the site audit or the blog checker, the website address you enter, your email address if you provide it, and the results generated.
3. Where the data comes from
We collect data directly from you when you create an account, subscribe, connect a website or platform, use the dashboard, or contact us; automatically from your browser and device when you use our website or platform; from the websites you connect, which we read on your instruction; from platforms you connect through an Integration, such as your content-management system or Google Search Console; and from our payment provider, which confirms payment events.
4. Why we process data and on what legal basis
Where the General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)): to create and administer your account, analyze your website, generate and publish content, operate Integrations, provide support, and bill you.
- Legal obligation (Article 6(1)(c)): to keep tax and accounting records, respond to lawful requests, and comply with consumer-protection and sanctions law.
- Legitimate interests (Article 6(1)(f)): to secure the Service and prevent fraud and abuse, to understand how the Service is used and improve it, to measure the effectiveness of our marketing, to communicate with you about your account, and to establish, exercise or defend legal claims. We balance these interests against your rights, and you may object as described in section 13.
- Consent (Article 6(1)(a)): to send marketing emails where the law requires consent, and for any non-essential cookies where the law requires it. You may withdraw consent at any time without affecting processing that took place before withdrawal.
Where other laws apply, we process data for the purposes listed above as permitted by those laws.
5. How we use data
- To provide the Service: read your website, plan topics, generate articles and images, publish them, and report on performance.
- To operate your account: authentication, billing, quota tracking, notifications and support.
- To keep the Service secure: detecting and preventing fraud, abuse, unauthorized access and attacks.
- To improve the Service: analyzing aggregate usage and errors, and testing changes.
- To communicate: transactional emails about your account, trial and subscription, and, subject to your preferences, product news and onboarding guidance.
- To market Bunzy: measuring the effectiveness of our advertising and attributing signups and purchases to campaigns.
- To comply with law and enforce the Agreement.
We do not sell personal data, and we do not use it for third-party advertising on our platform.
6. AI processing
To generate your articles and images, we send relevant inputs, including content from your website, your brand voice and keywords, and the topic being written, to the third-party AI providers that power the Service. At the date of this Policy these are Anthropic, whose models write and analyze text, and Google, whose models generate images. Our free website audit additionally uses OpenAI models to analyze the site you enter.
These providers process your content solely to return output to us. We use their commercial API services under terms that prohibit the use of your content to train their models, and we do not use your content to train models ourselves. Inputs may be retained by a provider for a limited period for abuse monitoring under its terms. Content is transmitted over encrypted connections. We do not send payment data or credentials to AI providers.
7. Who we share data with
We share personal data only with the categories of service provider below, each of which processes it on our instructions under a data-processing agreement, and only to the extent needed for the purpose stated:
- AI providers (Anthropic, Google, OpenAI): content generation and analysis, as described in section 6.
- SEO data providers (DataForSEO, Ahrefs): keyword, ranking and backlink data for the websites you connect or audit.
- Payment processing (Dodo Payments, seller of record): checkout, subscription billing, invoicing, tax collection and refunds. Dodo Payments is an independent controller of the payment data it collects, under its own privacy policy.
- Hosting and infrastructure (MongoDB Atlas for the database, Cloudflare for content delivery, media storage and bot protection, Amazon Web Services for transactional email): storing and serving your data and our application.
- Product analytics (PostHog): understanding how the website and dashboard are used.
- Advertising measurement (Meta): measuring the effectiveness of our advertising on the marketing website, as described in section 11.
- Customer support (Chatwoot, on infrastructure we operate): the in-app chat and support conversations.
- Sign-in and Search Console (Google): authentication when you choose to sign in with Google, and read-only access to your Search Console data when you connect it.
We may also disclose personal data where required by law, court order or governmental request; to protect the rights, property or safety of Bunzy, our customers or the public; and to a successor in connection with a merger, acquisition, financing or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy. We disclose no more than is necessary in each case.
8. Integrations you connect
When you connect a platform such as WordPress, Shopify, Webflow, Wix, Ghost, Framer, Notion or a webhook endpoint, we send the articles and images generated for you to that platform and may read existing content from it. When you connect Google Search Console, we read your site's search-performance data with read-only access. Each platform processes that data under its own privacy policy, and you can revoke our access at any time from your dashboard or from the platform. If you use our API or SDK to display your blog on your own site, the requests your site makes to our API include the visitor's IP address, which we use only to serve the request and to protect against abuse.
9. International transfers
Bunzy is established in the United States, and personal data is stored and processed in the United States. Some of our service providers process data in the United States, and some may process it in the European Union or other countries. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been recognized as providing adequate protection, we rely on the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where relevant, and, for providers certified under the EU-US Data Privacy Framework, on that framework. We assess each transfer and apply supplementary measures, including encryption in transit and at rest, where needed. You may request a copy of the relevant safeguards at hello@bunzy.io.
10. How long we keep data
We keep personal data only as long as needed for the purposes described above, and then delete or anonymize it. Our standard retention periods are:
- Account, website, content and integration data: for the life of your account, and for 90 days after it is closed so that you can export content and reactivate if you change your mind. Integration credentials are deleted when you disconnect the integration or close the account.
- Billing and tax records: 7 years after the transaction, as accounting and tax law requires.
- Payment-event logs received from our payment provider: 90 days after receipt.
- Support conversations and emails: 3 years after the last message.
- Security and access logs: 12 months.
- Product-analytics events: 12 months in identifiable form; aggregate statistics indefinitely.
- Free-tool lead data: 12 months after the last interaction, unless you create an account.
- Marketing preferences and unsubscribe records: for as long as needed to honor your choice.
Backups are encrypted and cycle out on a rolling schedule, so deleted data may persist in a backup for a limited period before it is overwritten. Where a legal hold or dispute requires it, we retain the relevant data until the matter is resolved.
11. Cookies and similar technologies
We use cookies, local storage and similar technologies in the following categories:
- Strictly necessary: the session cookie that keeps you signed in to the dashboard, the cookie that remembers your language choice, and the bot-protection check on our forms. These cannot be switched off without breaking the Service.
- Product analytics: PostHog sets cookies and local-storage keys on our website and dashboard to recognize returning visitors and record the pages and features used, so that we can improve the product.
- Advertising measurement: on our marketing website only, the Meta pixel sets first-party cookies and reports page views, signups and purchases to Meta so that we can measure our advertising. We also send those conversion events to Meta from our servers, together with a hashed form of your email address and, where available, your name, phone number, IP address and browser identifier, so that Meta can match them to its users. We do not run advertising measurement inside the dashboard.
- Support: the in-app chat widget stores an identifier in your browser so that your conversation persists between visits.
- Email measurement: emails we send may include a pixel and tracked links that tell us whether the email was opened and which links were clicked.
You can block or delete cookies in your browser settings, though the dashboard will not work without the strictly necessary ones. You can opt out of Meta's advertising measurement through Meta's ad settings and by using browser tracking protection, and you can ask us at hello@bunzy.io to exclude your email address from server-side conversion reporting. Analytics and advertising-measurement technologies are currently set when you visit our marketing website. If you would rather they were not, contact us at hello@bunzy.io and we will exclude you.
12. Security
We protect personal data with encryption in transit and at rest, encrypted storage of credentials, role-based access controls, passwordless sign-in, logging and monitoring, and regular review of our providers. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the competent authorities as the law requires.
13. Your rights
Depending on where you live, you have the right to access the personal data we hold about you and receive a copy in a portable format; to have inaccurate data corrected; to have data deleted; to restrict or object to certain processing, including processing based on legitimate interests and any direct marketing; to withdraw consent where processing is based on consent; and to lodge a complaint with a supervisory authority.
European Union, United Kingdom and Switzerland. The rights above apply under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection. You may complain to the supervisory authority of your habitual residence, your place of work or the place of an alleged infringement.
California and other US states. Under the California Consumer Privacy Act and comparable state laws, you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising those rights. We do not sell personal information. The advertising-measurement disclosure described in section 11 may be considered sharing under California law. To opt out, email hello@bunzy.io and we will exclude your data from advertising measurement, or block the relevant cookies in your browser as described in section 11.
To exercise any right, email hello@bunzy.io. We respond within 30 days, or within the shorter period the law requires, and may ask you to verify your identity first. You can also update most account data and your email preferences directly in your dashboard, unsubscribe from marketing emails using the link in each email, and disconnect Integrations from your dashboard at any time. To close your account, email us and we will confirm closure and the date on which your data will be deleted.
14. Children
The Service is a business product and is not directed at anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us at hello@bunzy.io and we will delete it.
15. Changes to this Policy
We may update this Policy as the Service evolves or the law changes. Material changes are notified to the account owner by email at least 14 days before they take effect, as the Terms of Service provide, and the updated date at the top of this page always reflects the current version.
16. Contact
Bunzy is operated by KLOE LLC, 30 N Gould St Ste R, Sheridan, WY 82801, US. Privacy questions and requests: hello@bunzy.io.
