Legal

Privacy Policy

Effective date: January 22, 2026 - Last updated: October 1, 2026

QBuddy ("QBuddy", "we", "us", "our") provides an AI-powered script rehearsal service (the "Service") available at https://app.qbuddy.ai/.

This Privacy Policy explains how we collect, use, and share personal data when you use the Service. It also explains your rights under applicable data protection laws, including (where applicable) the Swiss Federal Act on Data Protection (FADP) and the EU/UK GDPR.

1) Who is responsible for your data?

The controller responsible for your personal data is Matteo Bassi, a sole proprietor based in Switzerland who operates the Service ("Operator").

Matteo Bassi
Ebnetstrasse 9
8309 Nürensdorf, Switzerland
Email: privacy@qbuddy.ai

When we incorporate a legal entity, we will update this Privacy Policy to reflect the legal entity name and address.

2) What data we collect

A) Data you provide

  • Account data: email address, name (optional), login credentials.
  • Age confirmation: that you confirmed you are 18 or older, and when. We don't ask for your date of birth.
  • User Content: scripts, role selections, rehearsal settings, and other content you upload or enter into the Service ("Content").
  • Messages you exchange with us: support requests (by email or the contact form), your replies to our emails, and your answers when Matteo writes to you personally.
  • Billing data: when you buy a plan, Stripe/Link collects your payment details, billing name and address, and email address to process the payment (see section 6). We never receive or store your full card number. We keep limited billing records: your plan, subscription status, currency and billing period, Stripe customer and subscription identifiers, and the consent you give at checkout.

B) Data collected automatically

  • Usage data: which pages and features you use, and when.
  • Log and security data: your IP address and the approximate location derived from it, device and browser information, and error logs. When you sign up, we record your IP address and compare it and your email address with other accounts. This stops people from opening many accounts to reuse the free trial. A bot check by Cloudflare Turnstile runs on the sign-up page.
  • Email data: which emails we sent you and when. If you unsubscribe, your address goes on our do-not-email list (section 12).
  • Cookies and browser storage: essential cookies to keep you signed in, cookies and browser storage that remember your language, your settings and where you left off, and, only if you allow analytics, analytics and a signup-attribution cookie (see section 10).

C) Sensitive data

We do not intentionally collect sensitive personal data. Please do not upload sensitive personal data in scripts or notes.

D) Your microphone

If you turn on Cue, your browser uses your microphone. qbuddy never receives your voice (section 11).

3) How we use your data

  • Provide qbuddy: your account, reading your scripts, generating voices, rehearsal.
  • Improve qbuddy: fix bugs, and test and improve how qbuddy reads scripts and generates voices (section 5).
  • Keep qbuddy secure and prevent abuse: sign-up checks, rate limits, logs and backups.
  • Service emails: about your account, your free trial, your voices and your subscription.
  • Product emails: tips and offers, and now and then a personal email from Matteo. You can stop these at any time (section 12).
  • Requests: answer support requests and requests about your data.
  • Outreach: contact organisations about our free library of public-domain texts (section 13).

4) Legal bases

Swiss data protection law doesn't require a legal basis for each use. Where the EU or UK GDPR applies, we rely on:

  • Contract (Art. 6(1)(b)): your account, storing and reading your scripts, generating voices, rehearsal, and the service emails about your account, trial, voices and subscription.
  • Legitimate interests (Art. 6(1)(f)): keeping qbuddy secure and preventing abuse (sign-up checks, rate limits, logs, backups); fixing bugs and improving qbuddy, including how it reads scripts (section 5); personal emails from Matteo; contacting organisations about our free library (section 13); and keeping records that show we respected your choices. You can object to any of these (section 9).
  • Consent (Art. 6(1)(a)): analytics and the signup-attribution cookie (section 10), and product emails if you agreed to them (section 12). You can withdraw it at any time.
  • Legal obligation (Art. 6(1)(c)): answering your requests about your data, and keeping the records the law requires.

Product emails follow the e-privacy rules rather than the bases above. We send them, only about qbuddy's own services, to people who agreed to them: the checkbox when you sign up, or the setting in your account. Accounts created before September 30, 2026 that haven't answered yet get them under the exception for existing customers: Art. 13(2) of the EU ePrivacy Directive and the national laws that implement it, Art. 3(1)(o) of the Swiss Unfair Competition Act, and regulation 22(3) of the UK PECR. You can refuse or withdraw at any time, free of charge: in your account settings, with the unsubscribe link in every product email, or by writing to privacy@qbuddy.ai.

5) AI processing and your scripts

To turn an upload into a rehearsal, we send your content to these AI providers. They process it for us, on our instructions:

  • Mistral AI (France) reads scanned or photographed pages (text recognition). If OpenAI declines to process a scene, Mistral reads that part of the script instead.
  • OpenAI (USA) finds the scenes, speakers and lines in the script text. It also looks at images of scanned pages to spot handwritten notes.
  • Google (USA) turns the lines into voices, through the Gemini API and Google Cloud Text-to-Speech.

What the providers do with it:

  • OpenAI, Google Cloud Text-to-Speech and Google's paid Gemini API don't use our API data to train their models.
  • The providers may keep data for a limited time to detect abuse: at OpenAI, up to 30 days.

Your scripts stay yours. We don't sell them. We use your content to provide qbuddy and to improve it, for example to test and fix how qbuddy reads scripts. We don't use your scripts to train general-purpose AI models. If you don't want your scripts used to improve qbuddy, write to privacy@qbuddy.ai.

6) Who we share data with

These providers process data for us, only on our instructions.

ProviderWhat it does for usData it receivesWhere
Google Cloud (Google)Database, file storage, servers, logs and backupsEverything qbuddy storesGermany (Frankfurt)
Google Cloud Text-to-Speech (Google)Generates voicesThe text of the lines to voiceWorldwide; may be processed outside the EU, including in the USA
Google Gemini API, paid tier (Google)Generates voicesThe text of the lines to voice, voice settingsUSA and other countries where Google runs the service
OpenAIReads scripts: scenes, speakers and lines; spots handwritten notesScript text; images of scanned pagesUSA
Mistral AIReads scanned or photographed pages; backup script readerUploaded pages; script text when used as the backupFrance
VercelHosts the website and the app; runs Web Analytics, only with your consentYour requests, IP address, cookiesUSA, plus the nearest location of Vercel's global network
Auth0 (Okta)Sign-in and account securityEmail, name, login recordsEU
ResendSends our emailsYour email address and the email's contentUSA
CloudflareBot check at sign-up (Turnstile)IP address, browser signalsCloudflare's global network (USA-based company)
Upstash (Upstash, Inc.), bought through the Vercel MarketplaceRate limits (counts requests)IP address or account ID, for up to a dayGermany (Frankfurt), on Amazon Web Services; Upstash may access it from the USA and other countries where it works
Namecheap (Private Email)Our @qbuddy.ai mailboxesEmails and contact-form messages you exchange with usUSA

Your browser's speech service (section 11) is not our provider. It works for you, under your browser's terms.

We may also share personal data with:

  • Authorities or legal requests: when required by law, or to protect rights, safety, and security.

Payments and merchant of record

Paid plans are sold by qbuddy through Stripe Managed Payments. Sold through Link, LLC (part of Stripe) is the merchant of record: it processes the payment, calculates and pays the VAT or sales tax, and sends the receipts. It is not the seller; your contract for the plan is with qbuddy. To start a purchase we share with Stripe your email address, your qbuddy account identifier and the plan you selected. Stripe/Link then processes your payment and billing data as an independent controller, for payment processing, fraud prevention, tax compliance, receipts and customer support, under the Link Privacy Policy. Requests about the data Link holds for a purchase (including deletion) can be made to Link directly.

7) International transfers

We store qbuddy's data in Germany. Some providers in section 6 process data in other countries:

  • EU (Germany, France and other EU countries): Switzerland and the UK recognise EU countries as giving adequate protection.
  • USA and global networks: where the provider is certified, we rely on the EU-US Data Privacy Framework, its UK Extension, and the Swiss-US Data Privacy Framework; otherwise, we rely on the European Commission's Standard Contractual Clauses, with the adaptations Switzerland requires.

For a copy of the safeguards for a provider, write to privacy@qbuddy.ai.

8) Data retention

DataHow long we keep it
Your account (profile, settings, usage statistics)Until you delete your account
Scripts, parsed lines and generated voicesUntil you delete them or your account. If several accounts upload the identical file, we store it once, and delete it about a week after the last of those accounts deletes it (usually within 8 days). Copies kept to improve qbuddy (section 5) are the exception.
Uploads waiting to be checked2 days
Usage events90 days
Sign-up security data (IP address, matches with other accounts)Until you delete your account
Server logs30 days
Backups14 days, so deleted data leaves the backups within 14 days
Billing records we hold (plan, status, Stripe identifiers, consent given at checkout)Until you delete your account. Link keeps its own records under the Link Privacy Policy
Do-not-email listAs long as needed to respect your choice, including after you delete your account
Your answer about product emailsUntil you delete your account (the do-not-email entry stays, as section 12 says)
Proof that an account was deleted (a one-way code made from the account ID)Kept. It can't be turned back into your account or your email address. It also stops the same login from opening a new account; write to support@qbuddy.ai if you want to come back
Support emails and contact-form messages2 years after our last exchange, or longer where a message is needed to establish, exercise or defend a legal claim, until that is resolved
Business contacts (section 13)12 months after our last exchange. If you asked us to stop, we keep only what we need so we don't contact you again

9) Your rights

Depending on where you live, you have the right to:

  • access your data and get a copy;
  • have it corrected;
  • have it deleted (you can delete your account yourself in the app);
  • restrict how we use it;
  • receive the data you gave us in a portable format;
  • object to any use based on legitimate interests (section 4);
  • withdraw consent at any time. This doesn't affect what we did before you withdrew it.

Product emails: you can object at any time. Use the unsubscribe link or write to us, and we stop at once.

How to ask:

  • Write to privacy@qbuddy.ai.
  • We answer free of charge, within 30 days (one month in the EU and UK).
  • We may ask you to confirm the request from your account's email address.

Automated decisions: we don't make decisions based solely on automated processing that have legal or similarly significant effects on you. Automated checks can block a bot sign-up, or tell you that the free trial was already used with your email address. Write to us and a person will review it.

Complaints:

  • You can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), to the data protection authority in your EU country, or, in the UK, to the Information Commissioner's Office (ICO).
  • We'd like the chance to fix it first. Write to privacy@qbuddy.ai; we acknowledge complaints within 30 days.

10) Cookies and browser storage

qbuddy sets the cookies and browser storage entries below. Only the signup-attribution cookie and analytics need your consent; the rest keeps you signed in or remembers something you chose or did.

Cookies

  • appSession, split into appSession.0, appSession.1 and so on when it is too large for one cookie (sign-in session, essential): keeps you signed in on app.qbuddy.ai. It is encrypted and set by the library of our sign-in provider, Auth0. Lifetime: 24 hours after your last visit, and at most 7 days after you signed in; signing out deletes it.
  • auth_verification (sign-in check, essential): set when you start signing in and checked when Auth0 sends you back, so a forged sign-in is refused. It is deleted as soon as you are back; it has no expiry date of its own, so after a sign-in you abandon, the browser deletes it at the end of the session. Set on app.qbuddy.ai only.
  • qbuddy_lang (language preference): remembers the language you read qbuddy in, so pages without a language in their address, including the app, open in it. It is set when you first open a page in Italian, French or German (for example qbuddy.ai/it), when you choose a language, and from your profile language once you sign in. Lifetime: 1 year. It is shared between qbuddy.ai and app.qbuddy.ai.
  • qb_currency (currency preference): the currency you chose on the pricing page, so prices show in it on your next visit. It is set only when you pick a currency yourself; until then the page shows the currency of the country your connection comes from, which we work out from your IP address on each visit and do not store. Lifetime: 1 year.
  • qb_resume (where you left off): which script you last rehearsed (its identifier, a hash of the file), the number and first 280 characters of the line you reached, when, and a fingerprint of your account ID (not the ID itself), so the dashboard offers that spot to you and not to another account on the same browser. Lifetime: 90 days. Set on app.qbuddy.ai only.
  • qbuddy_signup_source (signup attribution, only with your consent): the campaign (UTM) parameters of the link you arrived from, the address of the external site that referred you, and the first page you opened, so we know how you found qbuddy. It is set only after you choose "Allow analytics" in the cookie banner, and never from the sign-in pages. Lifetime: 24 hours, and it is deleted when you sign in; if you create an account, this information is saved with it. A copy is kept in session storage (below).

Browser storage

Local storage keeps an entry until you clear the site data in your browser; session storage is cleared when you close the tab. Both stay separate on qbuddy.ai and app.qbuddy.ai.

  • qbuddy-cookie-consent (local): your answer to the cookie banner, "essential" or "all".
  • qbuddy-first-scene-card: followed by a fingerprint of your account ID (local): that you put away the tip shown on your first rehearsal, and whether you turned on Cue or closed it. One entry per account.
  • qbuddy-rehearsal-practiced (local): that you have rehearsed on this device; it decides when to suggest installing the app.
  • qbuddy-install-prompt-dismissed-until (local): when you closed the suggestion to install the app; it stays hidden for 7 days after.
  • rehearsalSpeed (local): your playback speed.
  • voicePrivacyAcknowledged-v2 (local): that you have seen the notice about speech recognition.
  • qbuddy_signup_source (session, only with your consent): the copy of the signup-attribution cookie, for browsers that refuse it.
  • qbuddy-session-started-at (session): when this visit started; with the practice flag above, it decides when to suggest installing the app.
  • qbuddy:login-redirect-at (session): when the app last sent you to sign in, so it can stop a sign-in loop.
  • id (session): the script open in a rehearsal, so the rehearsal link keeps working in that tab.
  • voicedebug (session, administrators only): a switch for the speech-recognition debug panel.

Analytics: if you choose "Allow analytics", we use Vercel Web Analytics to count page visits and clicks on the sign-up and log-in buttons. Until you choose, and if you choose "Essential only", it does not load.

Your choice is saved in your browser's local storage, separately on qbuddy.ai and on app.qbuddy.ai, so each asks once. You can change or withdraw it at any time with Cookie settings: in the footer of the qbuddy.ai website, in your account settings in the app, or here: . Choosing "Essential only" stops analytics at once and deletes the signup-attribution cookie.

Do Not Track: qbuddy doesn't respond to browser Do-Not-Track signals, because there is no agreed standard for them. We don't use advertising cookies, and no third party collects information about your activity across other websites through qbuddy.

11) Speech recognition (Cue)

When you turn on Cue, qbuddy listens for your line so it can play the next one. It uses your browser's built-in speech recognition:

  • qbuddy never receives, records or stores your voice. The words the browser recognises also stay in the page: we don't receive them.
  • Your browser's speech service does the recognition. In Chrome, your voice is sent to Google's servers; Safari uses Apple's service, and Edge uses Microsoft's. They process it under their own privacy terms, not as our providers.
  • If you'd rather not use it, rehearse with Cue off. The other voices still play, and you move on with the controls.

12) Emails we send

Service emails are about your account, your free trial (for example, that it's ending), your voices being ready, payments and your subscription. You get these as long as you have an account. Unsubscribing from product emails doesn't stop them.

The email that tells you your voices are ready has its own unsubscribe link. It stops only those emails, and saying no to product emails doesn't stop them.

Product emails:

  • a tip, if you haven't uploaded a script a few days after signing up;
  • after your free trial ends, an email with an offer.

Every product email has an unsubscribe link. When you use it, we stop at once.

Your choice: when you sign up, you can tick "Email me tips and offers". If you leave it unticked, we don't send you product emails. You can change your answer at any time in your account settings. We record your answer, when and where you gave it, the wording you saw, your language and the country your connection came from, so we can show we respected it.

Personal emails from Matteo: Matteo, who runs qbuddy, sometimes writes to users himself from matteo.bassi@qbuddy.ai. For example, he may offer help after a problem or ask how qbuddy is working for you. Reply that you'd rather not hear from him, and he won't write again.

If you unsubscribe or say no, we keep your email address on a do-not-email list, in a one-way coded form, including after you delete your account. This is so we never send you product emails again.

13) Business contacts

This section applies if you work for a school, library, theatre or website that we contact about qbuddy's free library of public-domain texts:

  • Where we got your details: your organisation's website or a public directory.
  • What we keep: your name, role, work email, organisation, the page where we found you, and notes on our exchange.
  • Why: to propose a link or a collaboration. The legal basis is our legitimate interests.
  • Where it's stored: emails go through our mailbox provider (section 6). Our contact list is stored with our other data in Germany.
  • How long: we delete your details 12 months after our last exchange. If you ask us to stop, we keep only what we need so we don't contact you again.
  • How to stop us: reply "no thanks" to any of our emails, or write to privacy@qbuddy.ai. Your rights in section 9 apply.

14) Security

We use reasonable technical and organizational measures to protect data (for example, encryption in transit, access controls). No method of transmission or storage is 100% secure. Only named people can use admin tools, and their changes are logged.

15) Children

The Service is only for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has an account, email privacy@qbuddy.ai and we will close the account and delete its data.

16) Changes to this policy

We may update this policy from time to time and will post changes here with an updated "Last updated" date. If we incorporate a legal entity, we will update the controller/operator details.

17) Contact

Matteo Bassi, Ebnetstrasse 9, 8309 Nürensdorf, Switzerland. Email: privacy@qbuddy.ai