Trust Center
Data privacy information without the usual marketing theater
This page is a plain-language overview of how BuniAI handles customer data and where the platform's current operational boundaries are.
It is not a replacement for our legal documents. It is a clearer way to understand them before you go deeper.
Plain language
1.Our privacy principles
BuniAI is designed for teams building customer-facing chatbot, automation, and USSD experiences. That means privacy is not an optional marketing layer. It is part of how the product is expected to work.
- We try to collect only the information needed to run and support the platform.
- We aim to give users clear control over integrations, analytics consent, and data flows they configure.
- We describe our current setup honestly instead of promising dedicated environments or certification coverage that is not part of the product today.
Operational data
2.What BuniAI processes
To deliver the platform, BuniAI may process account details, workflow configuration, project content, user messages, support requests, usage telemetry, billing records, and credentials or tokens for the integrations you connect.
The exact data involved depends on the features you use. A simple marketing-site visit is different from running production chatbot or USSD workflows with connected third-party services.
Sensitive data handling
4.How credentials and secrets are handled
Many BuniAI workflows depend on API keys, OAuth tokens, webhooks, or other credentials for services you connect. We treat those values as sensitive.
- Credentials are stored in encrypted form.
- They are used only by authorized service processes that need them to execute configured integrations.
- When you revoke or remove an integration, the connected automation may stop working unless fresh credentials are supplied.
Cookie controls
5.How analytics consent works
BuniAI uses necessary cookies to operate the site and application. Those are distinct from optional analytics tooling used to understand product usage and improve UX.
Product analytics and replay tooling are loaded only after consent is granted through the cookie banner. If consent is declined, those scripts are not loaded.
Where possible, sensitive areas and fields are masked or blocked from replay capture.
AI-assisted features
6.How AI providers fit into the product
BuniAI supports AI-assisted features that may involve third-party AI providers when you use model-backed capabilities inside the product.
Inputs needed to fulfill the requested feature may be sent to those providers. The exact data involved depends on the prompt, workflow context, or feature you invoke.
If you need the legally binding description of that processing, refer to the Privacy Policy.
Delivery dependencies
7.Third-party services and subprocessors
BuniAI depends on third-party services to provide hosting, payments, analytics, authentication, communications, AI requests, and optional integrations. Each of them acts as a sub-processor under Article 28(4) of the GDPR and is bound by a written agreement.
We used to describe these in categories rather than name them. We now name them, because a named list that visibly goes stale is more useful to your own compliance work than an accurate abstraction. This list is versioned, and we give 30 days' notice before adding or replacing a sub-processor that handles customer personal data.
Infrastructure
- Amazon Web Services — compute, storage, database, queueing, email delivery, logging and malware scanning. Processing location: us-east-1, United States.
- MongoDB Atlas — conversation transcripts, contact records, customer data stores and form submissions.
AI providers
Which provider handles a given request depends on your own project configuration. Message content and prompts are sent to the provider you select.
- Google — Gemini models, for intent classification and generation.
- Anthropic — Claude models, for flow generation and agent reasoning.
- OpenAI — GPT models, where selected.
- Cloudflare — Workers AI, where selected.
Messaging and voice channels
Engaged only where you connect the corresponding channel.
- Meta Platforms — WhatsApp Business Platform, Messenger, Instagram.
- Telegram and Slack — bot and app messaging.
- Twilio, Infobip, Africa's Talking, Telnyx — voice, SMS and USSD.
Platform operations
- Kinde — identity provider for account authentication.
- Amazon SES — transactional and notification email.
- Sentry — error monitoring and diagnostics.
Payments
- Stripe, Paystack, Flutterwave, and mobile money providers including MTN MoMo — subscription billing and in-flow payment collection.
Lifecycle
8.Retention, deletion, and privacy requests
Conversation transcripts and call recordings expire on a window you set. The default is 30 days, and each organisation can choose 30, 60, 90, 180 or 365 days in its own settings. Expiry is enforced automatically rather than run by hand. Reporting data — outcomes, counts, the indicators you track — is kept; the message bodies behind it are not.
Account, billing and support records are retained for the life of the account and for as long afterwards as tax and accounting law requires.
If you need help with access, correction, deletion, or a similar request, contact us at privacy@buni.ai. We respond within one month. We may need to verify identity or authority before acting on the request.
If you are an end-user of a service someone built on BuniAI, that organisation — not BuniAI — is the controller of your data, and the decision on your request is theirs. Contact us and we will route it to them, or approach them directly.