Legal
Effective date: January 22, 2026 - Last updated: October 1, 2026
QBuddy ("QBuddy", "we", "us", "our") provides an AI-powered script rehearsal service (the "Service") available at https://app.qbuddy.ai/.
This Privacy Policy explains how we collect, use, and share personal data when you use the Service. It also explains your rights under applicable data protection laws, including (where applicable) the Swiss Federal Act on Data Protection (FADP) and the EU/UK GDPR.
The controller responsible for your personal data is Matteo Bassi, a sole proprietor based in Switzerland who operates the Service ("Operator").
Matteo Bassi
Ebnetstrasse 9
8309 Nürensdorf, Switzerland
Email: privacy@qbuddy.ai
When we incorporate a legal entity, we will update this Privacy Policy to reflect the legal entity name and address.
We do not intentionally collect sensitive personal data. Please do not upload sensitive personal data in scripts or notes.
If you turn on Cue, your browser uses your microphone. qbuddy never receives your voice (section 11).
Swiss data protection law doesn't require a legal basis for each use. Where the EU or UK GDPR applies, we rely on:
Product emails follow the e-privacy rules rather than the bases above. We send them, only about qbuddy's own services, to people who agreed to them: the checkbox when you sign up, or the setting in your account. Accounts created before September 30, 2026 that haven't answered yet get them under the exception for existing customers: Art. 13(2) of the EU ePrivacy Directive and the national laws that implement it, Art. 3(1)(o) of the Swiss Unfair Competition Act, and regulation 22(3) of the UK PECR. You can refuse or withdraw at any time, free of charge: in your account settings, with the unsubscribe link in every product email, or by writing to privacy@qbuddy.ai.
To turn an upload into a rehearsal, we send your content to these AI providers. They process it for us, on our instructions:
What the providers do with it:
Your scripts stay yours. We don't sell them. We use your content to provide qbuddy and to improve it, for example to test and fix how qbuddy reads scripts. We don't use your scripts to train general-purpose AI models. If you don't want your scripts used to improve qbuddy, write to privacy@qbuddy.ai.
These providers process data for us, only on our instructions.
| Provider | What it does for us | Data it receives | Where |
|---|---|---|---|
| Google Cloud (Google) | Database, file storage, servers, logs and backups | Everything qbuddy stores | Germany (Frankfurt) |
| Google Cloud Text-to-Speech (Google) | Generates voices | The text of the lines to voice | Worldwide; may be processed outside the EU, including in the USA |
| Google Gemini API, paid tier (Google) | Generates voices | The text of the lines to voice, voice settings | USA and other countries where Google runs the service |
| OpenAI | Reads scripts: scenes, speakers and lines; spots handwritten notes | Script text; images of scanned pages | USA |
| Mistral AI | Reads scanned or photographed pages; backup script reader | Uploaded pages; script text when used as the backup | France |
| Vercel | Hosts the website and the app; runs Web Analytics, only with your consent | Your requests, IP address, cookies | USA, plus the nearest location of Vercel's global network |
| Auth0 (Okta) | Sign-in and account security | Email, name, login records | EU |
| Resend | Sends our emails | Your email address and the email's content | USA |
| Cloudflare | Bot check at sign-up (Turnstile) | IP address, browser signals | Cloudflare's global network (USA-based company) |
| Upstash (Upstash, Inc.), bought through the Vercel Marketplace | Rate limits (counts requests) | IP address or account ID, for up to a day | Germany (Frankfurt), on Amazon Web Services; Upstash may access it from the USA and other countries where it works |
| Namecheap (Private Email) | Our @qbuddy.ai mailboxes | Emails and contact-form messages you exchange with us | USA |
Your browser's speech service (section 11) is not our provider. It works for you, under your browser's terms.
We may also share personal data with:
Paid plans are sold by qbuddy through Stripe Managed Payments. Sold through Link, LLC (part of Stripe) is the merchant of record: it processes the payment, calculates and pays the VAT or sales tax, and sends the receipts. It is not the seller; your contract for the plan is with qbuddy. To start a purchase we share with Stripe your email address, your qbuddy account identifier and the plan you selected. Stripe/Link then processes your payment and billing data as an independent controller, for payment processing, fraud prevention, tax compliance, receipts and customer support, under the Link Privacy Policy. Requests about the data Link holds for a purchase (including deletion) can be made to Link directly.
We store qbuddy's data in Germany. Some providers in section 6 process data in other countries:
For a copy of the safeguards for a provider, write to privacy@qbuddy.ai.
| Data | How long we keep it |
|---|---|
| Your account (profile, settings, usage statistics) | Until you delete your account |
| Scripts, parsed lines and generated voices | Until you delete them or your account. If several accounts upload the identical file, we store it once, and delete it about a week after the last of those accounts deletes it (usually within 8 days). Copies kept to improve qbuddy (section 5) are the exception. |
| Uploads waiting to be checked | 2 days |
| Usage events | 90 days |
| Sign-up security data (IP address, matches with other accounts) | Until you delete your account |
| Server logs | 30 days |
| Backups | 14 days, so deleted data leaves the backups within 14 days |
| Billing records we hold (plan, status, Stripe identifiers, consent given at checkout) | Until you delete your account. Link keeps its own records under the Link Privacy Policy |
| Do-not-email list | As long as needed to respect your choice, including after you delete your account |
| Your answer about product emails | Until you delete your account (the do-not-email entry stays, as section 12 says) |
| Proof that an account was deleted (a one-way code made from the account ID) | Kept. It can't be turned back into your account or your email address. It also stops the same login from opening a new account; write to support@qbuddy.ai if you want to come back |
| Support emails and contact-form messages | 2 years after our last exchange, or longer where a message is needed to establish, exercise or defend a legal claim, until that is resolved |
| Business contacts (section 13) | 12 months after our last exchange. If you asked us to stop, we keep only what we need so we don't contact you again |
Depending on where you live, you have the right to:
Product emails: you can object at any time. Use the unsubscribe link or write to us, and we stop at once.
How to ask:
Automated decisions: we don't make decisions based solely on automated processing that have legal or similarly significant effects on you. Automated checks can block a bot sign-up, or tell you that the free trial was already used with your email address. Write to us and a person will review it.
Complaints:
qbuddy sets the cookies and browser storage entries below. Only the signup-attribution cookie and analytics need your consent; the rest keeps you signed in or remembers something you chose or did.
appSession, split into appSession.0, appSession.1 and so on when it is too large for one cookie (sign-in session, essential): keeps you signed in on app.qbuddy.ai. It is encrypted and set by the library of our sign-in provider, Auth0. Lifetime: 24 hours after your last visit, and at most 7 days after you signed in; signing out deletes it.auth_verification (sign-in check, essential): set when you start signing in and checked when Auth0 sends you back, so a forged sign-in is refused. It is deleted as soon as you are back; it has no expiry date of its own, so after a sign-in you abandon, the browser deletes it at the end of the session. Set on app.qbuddy.ai only.qbuddy_lang (language preference): remembers the language you read qbuddy in, so pages without a language in their address, including the app, open in it. It is set when you first open a page in Italian, French or German (for example qbuddy.ai/it), when you choose a language, and from your profile language once you sign in. Lifetime: 1 year. It is shared between qbuddy.ai and app.qbuddy.ai.qb_currency (currency preference): the currency you chose on the pricing page, so prices show in it on your next visit. It is set only when you pick a currency yourself; until then the page shows the currency of the country your connection comes from, which we work out from your IP address on each visit and do not store. Lifetime: 1 year.qb_resume (where you left off): which script you last rehearsed (its identifier, a hash of the file), the number and first 280 characters of the line you reached, when, and a fingerprint of your account ID (not the ID itself), so the dashboard offers that spot to you and not to another account on the same browser. Lifetime: 90 days. Set on app.qbuddy.ai only.qbuddy_signup_source (signup attribution, only with your consent): the campaign (UTM) parameters of the link you arrived from, the address of the external site that referred you, and the first page you opened, so we know how you found qbuddy. It is set only after you choose "Allow analytics" in the cookie banner, and never from the sign-in pages. Lifetime: 24 hours, and it is deleted when you sign in; if you create an account, this information is saved with it. A copy is kept in session storage (below).Local storage keeps an entry until you clear the site data in your browser; session storage is cleared when you close the tab. Both stay separate on qbuddy.ai and app.qbuddy.ai.
qbuddy-cookie-consent (local): your answer to the cookie banner, "essential" or "all".qbuddy-first-scene-card: followed by a fingerprint of your account ID (local): that you put away the tip shown on your first rehearsal, and whether you turned on Cue or closed it. One entry per account.qbuddy-rehearsal-practiced (local): that you have rehearsed on this device; it decides when to suggest installing the app.qbuddy-install-prompt-dismissed-until (local): when you closed the suggestion to install the app; it stays hidden for 7 days after.rehearsalSpeed (local): your playback speed.voicePrivacyAcknowledged-v2 (local): that you have seen the notice about speech recognition.qbuddy_signup_source (session, only with your consent): the copy of the signup-attribution cookie, for browsers that refuse it.qbuddy-session-started-at (session): when this visit started; with the practice flag above, it decides when to suggest installing the app.qbuddy:login-redirect-at (session): when the app last sent you to sign in, so it can stop a sign-in loop.id (session): the script open in a rehearsal, so the rehearsal link keeps working in that tab.voicedebug (session, administrators only): a switch for the speech-recognition debug panel.Analytics: if you choose "Allow analytics", we use Vercel Web Analytics to count page visits and clicks on the sign-up and log-in buttons. Until you choose, and if you choose "Essential only", it does not load.
Your choice is saved in your browser's local storage, separately on qbuddy.ai and on app.qbuddy.ai, so each asks once. You can change or withdraw it at any time with Cookie settings: in the footer of the qbuddy.ai website, in your account settings in the app, or here: . Choosing "Essential only" stops analytics at once and deletes the signup-attribution cookie.
Do Not Track: qbuddy doesn't respond to browser Do-Not-Track signals, because there is no agreed standard for them. We don't use advertising cookies, and no third party collects information about your activity across other websites through qbuddy.
When you turn on Cue, qbuddy listens for your line so it can play the next one. It uses your browser's built-in speech recognition:
Service emails are about your account, your free trial (for example, that it's ending), your voices being ready, payments and your subscription. You get these as long as you have an account. Unsubscribing from product emails doesn't stop them.
The email that tells you your voices are ready has its own unsubscribe link. It stops only those emails, and saying no to product emails doesn't stop them.
Product emails:
Every product email has an unsubscribe link. When you use it, we stop at once.
Your choice: when you sign up, you can tick "Email me tips and offers". If you leave it unticked, we don't send you product emails. You can change your answer at any time in your account settings. We record your answer, when and where you gave it, the wording you saw, your language and the country your connection came from, so we can show we respected it.
Personal emails from Matteo: Matteo, who runs qbuddy, sometimes writes to users himself from matteo.bassi@qbuddy.ai. For example, he may offer help after a problem or ask how qbuddy is working for you. Reply that you'd rather not hear from him, and he won't write again.
If you unsubscribe or say no, we keep your email address on a do-not-email list, in a one-way coded form, including after you delete your account. This is so we never send you product emails again.
This section applies if you work for a school, library, theatre or website that we contact about qbuddy's free library of public-domain texts:
We use reasonable technical and organizational measures to protect data (for example, encryption in transit, access controls). No method of transmission or storage is 100% secure. Only named people can use admin tools, and their changes are logged.
The Service is only for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has an account, email privacy@qbuddy.ai and we will close the account and delete its data.
We may update this policy from time to time and will post changes here with an updated "Last updated" date. If we incorporate a legal entity, we will update the controller/operator details.
Matteo Bassi, Ebnetstrasse 9, 8309 Nürensdorf, Switzerland. Email: privacy@qbuddy.ai