Privacy Policy
Last updated: 21 July 2026 · Version 1.0
1. Who we are
AiBuddy is operated by PnG Solutions ("we", "us", "our"), a business established in Greece. AiBuddy is an AI-powered social media management platform accessible at app.aibuddy.gr.
Contact: privacy@aibuddy.gr
Data Protection Officer: dpo@aibuddy.gr
2. Data we collect
2.1 Account information
- Email address, hashed password
- Optional: full name, phone number, company name, role
- Account creation timestamp, IP address at signup, user agent
2.2 Social platform data (via OAuth)
When you connect a Facebook, Instagram, or LinkedIn account, we receive from the respective platform:
- Facebook / Meta: page ID, page name, page access token, list of Instagram Business accounts linked to the page
- Instagram: Instagram Business account ID, username, media count, access token
- LinkedIn: profile ID, name, email, organization membership, access token
Access tokens are encrypted at rest using AES-256 with keys managed by our infrastructure. We do not receive or store your Facebook, Instagram, or LinkedIn passwords.
2.3 Content you create
- Posts, captions, hashtags, images generated or uploaded through AiBuddy
- Brand information (name, description, tone, uploaded files)
- AI chat conversations and prompts
- Publishing history, scheduled dates, target platforms
2.4 Usage data
- Feature usage counts, credit consumption
- Error logs, request logs (retained 30 days)
- Login attempts (for rate limiting and abuse prevention)
3. How we use your data
- To provide the AiBuddy service (publish content, generate AI responses, analytics)
- To communicate with you (email verification, password reset, service updates)
- To process payments and manage credits (via Stripe)
- To improve the service (aggregated, anonymized usage statistics)
- To comply with legal obligations (invoicing, tax records)
- To prevent abuse and fraud (login rate limiting, IP-based blocking)
We do NOT sell your data. We do NOT use your Facebook, Instagram, or LinkedIn data for advertising or profiling.
4. Third-party services
To deliver AiBuddy, we share limited data with the following processors:
| Service | Purpose | Data shared |
|---|---|---|
| OpenAI | AI text and image generation | Prompts, brand context (no PII by default) |
| Anthropic | AI text generation (Claude) | Prompts, brand context |
| Meta Platforms | Publishing to Facebook / Instagram | Post content, media, page tokens |
| Publishing to LinkedIn | Post content, media, profile token | |
| Stripe | Payment processing | Email, billing info (Stripe never returns full card data to us) |
| Own SMTP server (mail.aibuddy.gr) | Transactional email | Email address, message body |
All processors are bound by Data Processing Agreements (DPAs). US-based providers rely on EU Standard Contractual Clauses (SCCs).
5. Data retention
- Account data: retained while your account is active + 90 days after deletion request
- Social access tokens: deleted immediately when you disconnect the account or delete your AiBuddy account
- Generated content (drafts, posts): retained while your account is active
- Payment records: retained 7 years (Greek tax law)
- Request logs: 30 days
- Login attempt logs: 90 days
6. Your GDPR rights
As a data subject under GDPR, you have the right to:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate data (via Settings or by email)
- Erasure — request deletion of your data (see Data Deletion)
- Portability — receive your data in a machine-readable format
- Restriction — ask us to stop processing while a complaint is being resolved
- Objection — object to processing based on legitimate interest
- Complaint — lodge a complaint with the Hellenic Data Protection Authority (dpa.gr)
To exercise any of these rights, email privacy@aibuddy.gr. We respond within 30 days.
7. Security
- All traffic is served over HTTPS (TLS 1.2+)
- Passwords are hashed with bcrypt (cost factor 12)
- OAuth access tokens are AES-256 encrypted at rest
- Database backups are encrypted and rotated daily
- Servers are hosted in the EU (Frankfurt / Amsterdam region)
- Access to production systems is restricted to authorized personnel and audited
8. Cookies
AiBuddy uses only essential cookies required for authentication (refresh token) and CSRF protection. We do not use tracking or advertising cookies. A small amount of data (language preference, theme) is stored in your browser's local storage.
9. Children
AiBuddy is not intended for users under 16. We do not knowingly collect data from minors. If you believe a child has provided us with data, contact us and we will delete it.
10. Meta Platform data usage
In compliance with the Meta Platform Terms and Developer Policies, we specifically confirm:
- Meta-derived data is used only to publish and manage content on behalf of the connected user
- We do not use Meta data to build user profiles or for advertising
- We do not transfer Meta data to third parties except the processors listed in Section 4
- Users can revoke access at any time via Facebook Business Integrations or the AiBuddy Accounts page
- Upon revocation or account deletion, all Meta-derived data is deleted within 24 hours
11. Changes to this policy
We may update this policy. Material changes will be notified by email at least 14 days before taking effect. The current version and effective date are always shown at the top of this page.
Questions? Contact us at privacy@aibuddy.gr.