Privacy Policy
This policy explains what personal data YourBuddyfy handles, why, who receives it, how long it is kept and what rights you have.
In short
- Your photo is analysed and cut out on your own device, in your browser. It is not sent to any outside company for that.
- The photos, the cut out head and the face points are then stored privately in your account so your buddy can appear in the browser and in the Windows app. Only you can see them.
- One exception: if a buddy is reported, the operator may view its head image, never the original photos, solely to handle the report. Every view is logged with the reason.
- An account that breaks the rules can be suspended. Its data is then kept, not deleted, and you keep your rights over it.
- We do not identify or recognise faces, we do not use your photos to train AI, and we do not sell data or show ads.
- Only strictly necessary cookies are used. There are no analytics or tracking tools.
- We use a small number of providers: Neon for the database in Frankfurt, Netlify for hosting and file storage, Stripe for payments and Resend for service emails.
- You can export everything, delete a buddy or delete your whole account yourself, at any time.
- Privacy contact: devtaskhub@devtaskhub.com. You can complain to the Hellenic Data Protection Authority.
This summary is here to help you. The full text below is what applies.
1. Who is responsible for your data
The controller of the personal data described in this policy is ΣΙΩΖΟΣ ΘΕΟΧΑΡΗΣ ΠΑΝΑΓΙΩΤΗΣ (Siozos Theocharis Panagiotis), a sole trader trading as DevTaskHub.com, Markou Mpotsari 83, 546 44 Thessaloniki, Greece, Commercial Registry (Γ.Ε.ΜΗ.) number 186989906000, tax number 169481343 ("we", "us").
For anything about privacy write to devtaskhub@devtaskhub.com. No data protection officer has been appointed.
This policy is the information we must give you under Article 13 of the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and Greek Law 4624/2019. Section 12 is addressed to people who appear in a photo that someone else uploaded. Section 13 explains what happens when a buddy is reported and when an account is suspended.
2. What data we handle
We handle only the data needed to run the Service:
- Account data: your name, your email address, a hash of your password (never the password itself), whether your email is verified, and the date the account was created. If an account is suspended, we also hold that fact, the date and the reason. The operator may add a short internal note to an account, for example about a support request or a report.
- Session and security data: a session token stored in a cookie, the times your sessions were created and expire, and the IP address and browser type of each session. We also keep a minimal security log of events such as a password change, a linked device, the start of a checkout together with your acceptance of the terms, a data export or an account deletion. The log holds the type of event, the time and internal identifiers, never content.
- Administration log: a record of each use of an administrative power by the operator, such as viewing the head image of a reported buddy, removing a buddy, suspending an account, signing an account out, or revoking or granting a licence. It holds the action, the date and time, the administrator who acted, the account or the buddy concerned and the reason given. It holds no photos.
- Buddy data: the name and settings you give each buddy, such as who the person is to you, the language you chose for the buddy, its personality, what it does, how it is dressed, its habits and the relationships between your buddies.
- Photos: the reference photos you upload, the cut out head image produced from them, thumbnails, and the face point coordinates (the positions of points such as the eyes and mouth in the picture) used to place and animate the head. Photos show a face and are personal data of the person shown. Location and camera details embedded in a photo file are removed when it is uploaded.
- Your upload declaration: the fact that you confirmed you may use the photo, that the person is an adult and that you understand the buddy is a simulation, kept with the buddy together with the relevant times.
- Memories, only if you switch the feature on and choose to store them in your account: the notes you save for a buddy.
- Device data: the name, platform and app version of each desktop app you link, and when it was last seen.
- Usage data needed to run the Service: the free running time used per buddy, whether a buddy is running, paused or stopped in your browser or on your desktop, and counters used to apply request limits.
- Purchase data: what you bought, the amount, currency, date, status and the payment reference from Stripe, and whether a payment was disputed or returned. We never receive your full card number.
- Messages you send us, for example support or privacy requests by email.
- Reports: the content of a report or takedown request about a buddy, the contact details of the person who sent it, what we decided and why.
We do not buy data about you and we do not collect data about you from other sources, apart from the payment confirmation we receive from Stripe.
3. What happens on your own device
Photo analysis runs in your browser, on your device. This covers removing the background, cutting out the head and detecting face points. The software models for this are loaded from our own site. Your photo is not sent to any outside company for this step.
After the analysis, the reference photos, the cut out head and the face point coordinates are uploaded to your account so that the buddy can be shown on the website, in the browser on your phone, tablet or computer, and in your Windows desktop app. They are stored privately and are served only to you after sign in. The one exception is the handling of a report, described in section 13.
When a buddy runs in the browser, it is drawn on your own device. The same is true when it floats in a small Picture in Picture window: the picture in that window is produced in your browser and is not sent to us. Sound effects are switched on by default and can be turned off. They are generated on your device. No sound is recorded and none is sent to us.
By default, chat replies come from built in rules that run on our own server. Your chat messages are processed to produce the reply and are not stored by the server, and no text is sent to any outside company.
Optional context sources are off by default and each has its own switch. The Privacy centre inside the product lists for each source what is read, why, and whether anything is stored or sent. The sources are: the time of day, when you last interacted with the buddy, your quiet hours, how long the computer has been idle (a single number of seconds, never keys, windows or screen content), and short notes you type yourself. Memories that you choose to keep on your device only stay in the desktop app and are not sent to us.
4. Photos of faces and special categories of data
The GDPR gives extra protection to biometric data that is processed in order to uniquely identify a person. We have assessed our processing and concluded that it does not fall into that category: the Service does not create a biometric template, does not recognise or identify anyone, and does not compare faces. The face points are simple positions in one image, used only to place the cut out head on the drawing and to animate it. On that basis we do not treat photos or face points as special category data under Article 9 of the GDPR.
This is our own assessment and we keep it under review. Whatever the classification, we treat photos as sensitive: they are stored privately, shown only to the account that uploaded them, never used to train AI models, never sold and never used for advertising. The single exception to who sees them is the head image of a reported buddy, which the operator may view to handle the report, as section 13 explains.
5. Why we use your data and the legal basis for each purpose
- To create and run your account, store your buddies and photos, show them in the web app and the desktop app, apply free running time and licences, and answer your support requests. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).
- To handle purchases, the record of your acceptance at checkout, the purchase confirmation, payment disputes and any return of money that the law requires. Legal basis: performance of the contract (Article 6(1)(b)) and, for the record of your acceptance, our legitimate interest in being able to show that a purchase was validly made (Article 6(1)(f)).
- To keep purchase and invoicing records and to answer lawful requests from authorities. Legal basis: legal obligations under tax, accounting and other laws (Article 6(1)(c)).
- To keep the Service secure and prevent abuse: session records with IP address, the security log, request limits, and checks on uploaded files. Legal basis: our legitimate interests in running a secure and reliable service and protecting users (Article 6(1)(f)).
- To keep a record of your upload declaration, to handle reports and takedown requests, and to establish, exercise or defend legal claims. Legal basis: our legitimate interests in being able to show how content came to be stored and in protecting the rights of people shown in photos, and our legal obligations as a hosting service (Article 6(1)(f) and (c)).
- To moderate the Service: to check a report about likeness or abuse, which can include an authorised administrator viewing the head image of the reported buddy, to remove a buddy, to suspend an account or sign it out on all devices, to revoke or grant a licence, to tell the account holder what we did, and to keep a log of these actions. Legal basis: our legitimate interests in protecting the people shown in photos, other people and the Service, and in being able to show what we did and why (Article 6(1)(f)), and compliance with our legal obligations, including the notice and action duties and the duty to give reasons under Regulation (EU) 2022/2065, the Digital Services Act (Article 6(1)(c)).
- To keep simple internal statistics, such as the number of accounts, buddies and purchases, and how often a language, a role or an activity is chosen. The operator counts these from the records described above. No outside analytics service is used. Legal basis: our legitimate interests in running and improving the Service (Article 6(1)(f)).
- To store photos that show a person other than you. Legal basis: our legitimate interests, and yours, in providing the Service you asked for, relying on your declaration that the person gave permission, and balanced by private storage, the ban on misuse and the takedown procedure (Article 6(1)(f)).
- To run optional features you switch on, such as memories stored in your account, AI chat through an outside provider or hosted voices, where these are available. Legal basis: your consent, given by switching the feature on (Article 6(1)(a)). You can withdraw consent at any time by switching the feature off. This does not affect processing that took place before.
- To send product news by email, only if you switch this on in your account. It is off by default. Legal basis: your consent (Article 6(1)(a)). You can switch it off at any time.
Where we rely on legitimate interests you can ask us for more information about how we balanced them and you can object, as explained in section 10.
6. Your own role when you upload a photo
You decide which photos to process and for what personal purpose. When a private person uses photos purely for personal or household purposes, the GDPR does not apply to that person's own activity. That is a matter between you and the people shown in your photos, and you are responsible for having a lawful reason to use each photo, in practice the permission of the person shown.
This does not remove our own duties. We remain responsible under the GDPR for the processing we carry out to provide the Service, such as storing your content securely. When you upload a photo of another person, we store and display it on your instructions, as the provider of the storage, and we do not use it for any purpose of our own.
If you use a buddy outside a purely personal setting, for example by publishing a recording, data protection law may apply to you directly, and you may be liable to the person shown.
7. Who receives your data
We do not sell personal data. We do not use advertising networks, analytics services or tracking tools. Other users cannot see your buddies, photos or memories. We use the following service providers, which process data for us under a contract and only on our instructions:
- Neon (Neon, Inc., part of Databricks): hosting of the database, in the EU region Frankfurt, Germany.
- Netlify (Netlify, Inc.): hosting of the website and the server functions, and storage of uploaded files such as photos.
- Resend (Resend, Inc.): delivery of service emails such as email verification, password reset, security notices, purchase confirmations and notices about moderation, for example that a buddy was removed, when email delivery is switched on.
Inside our own operation, administrative access is limited to the operator, who is a sole trader and acts as the authorised administrator. In the administration tools the operator can see account records (name, email address, status, sessions and linked devices), purchase records and, for each buddy, its name, its settings and its free time and licence status. This is used to give support, to handle purchases, reports and abuse, and to count simple totals about the use of the Service. The administration tools do not show reference photos, memories or chat messages. The head image of a buddy is viewed only when that buddy has been reported, with a stated reason, as section 13 describes, and every view is logged.
Payments are handled by Stripe Payments Europe, Limited (Ireland). Stripe receives your payment details directly from you on its own payment page and receives from us your email address and the purchase reference. Stripe acts as our processor for part of this and as an independent controller for other parts, such as fraud prevention and its own legal duties. Stripe's privacy policy explains its processing.
No other providers are used by default. If we connect an outside AI chat provider, a hosted voice provider or a similar optional service in the future, we will name it in this policy before it is used, and it will receive data only when you switch that feature on.
We may also disclose data to courts, authorities or legal advisers where the law requires it or where it is necessary to establish, exercise or defend legal claims, and to our accountant for tax records.
8. Transfers outside the European Economic Area
The database is hosted in the EU. Some of our providers are based in the United States or use infrastructure and support staff outside the European Economic Area, so some personal data, including stored files and emails, may be processed there.
Where that happens the transfer is protected by one of the safeguards the GDPR allows: the adequacy decision of the European Commission for the Data Privacy Framework between the EU and the US, for providers certified under it, or the Standard Contractual Clauses approved by the European Commission, with additional measures where needed. You can ask us for more information about the safeguard used by a particular provider, or for a copy of it.
9. How long we keep data
- Account data: until you delete your account. A suspended account is kept as described in section 13.
- Buddies, photos, cut outs, face points and memories: until you delete them. Deleting a buddy deletes its photos, its cut out and its memories. Deleting your account deletes all buddies and everything attached to them, your devices, sessions and settings.
- Sessions: 14 days from last renewal, or until you sign out. Email verification and password reset links expire after a short time.
- Security log: kept in a minimal form. When you delete your account the entries lose their link to you and keep only the type of event and the time.
- Administration log: for as long as needed to show how a report or a measure was handled and, after that, for the limitation period of possible legal claims. After that period the entries are deleted or made anonymous.
- Purchase and invoicing records: for the period required by tax and accounting law, currently at least 5 years, even after you delete your account. After account deletion we keep these records without a link to your account. Stripe keeps its own payment records under its own legal duties.
- Emails you send us and records of reports and takedown requests: for as long as needed to handle the matter and, where relevant, for the limitation period of possible legal claims.
- Backups kept by our hosting providers are overwritten on their normal cycle, after which deleted data is gone from them as well.
10. Your rights and how to use them
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- have inaccurate data corrected;
- have your data erased;
- have processing restricted in certain cases;
- receive the data you gave us in a commonly used, machine readable format and pass it to another provider (data portability);
- object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests;
- withdraw a consent you gave, at any time, without affecting earlier processing;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects. We make no such decisions.
Most of this you can do yourself inside the product: edit your details and your buddies, export all your data from the Account page, delete a buddy, and delete your account.
You can also write to devtaskhub@devtaskhub.com. We answer within one month. In complex cases the law allows an extension of up to two more months, and we will tell you if that applies. Using your rights is free. We may ask for information to confirm that the request comes from you.
You have the right to lodge a complaint with a supervisory authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr), Kifisias 1 to 3, 115 23 Athens. You can also complain to the authority of the EU country where you live or work.
11. Whether you have to give us data
You are not obliged by law to give us any data. A name, an email address and a password are needed to create an account, and a photo is needed to create a buddy. Without them we cannot provide the Service. Payment details are needed only if you buy a licence. Everything else is optional.
12. If you appear in a photo that someone else uploaded
Users may upload a photo of another adult only with that person's permission, and they declare this before every upload. We cannot check each declaration and we cannot contact the people shown, because we do not know who they are. This policy is therefore our way of informing you.
If a user has stored a photo of you, we hold the photo, the cut out head and the face points in that user's private account, for the purpose and on the legal basis described in section 5. Only that user can see them. If you or someone else reports the buddy, the operator may view its head image to handle the report, as section 13 explains. They are kept until the user deletes them or we remove them.
You have the same rights as any data subject, including the right to object and the right to have the content erased. Write to devtaskhub@devtaskhub.com and follow the Likeness and takedown policy, which explains what we need in order to find the content. We act expeditiously and, where your objection is justified, we remove the content.
13. Reports, moderation and suspended accounts
We do not look at your photos or at the head image of your buddies as a matter of routine, and no automated tool reviews them. This section explains the one situation in which a person on our side sees content, and what happens to data when we take a measure against a buddy or an account.
When a buddy is reported for likeness or abuse, an authorised administrator may view the head image of that buddy, meaning the cut out head that the buddy shows. The original reference photos are never shown. The image is viewed solely to handle the report, for example to compare it with what the person who complains describes. Each view is recorded in the administration log with the date and time and the reason.
Who has access: only the operator, acting as administrator. The image is not passed on to the person who sent the report or to anyone else, unless the law requires it, for example an order of a court or an authority.
On the basis of a report or of a breach of the rules, the operator can remove a buddy, sign an account out on all devices, suspend an account, close an account, and revoke or grant a licence. Each of these actions is recorded in the administration log. Removing a buddy deletes the buddy together with its photos, its cut out head and its related data. When a buddy is removed, the account holder is told by email.
Suspended accounts: while an account is suspended, nobody can sign in to it and its buddies cannot be used. Its data is not deleted because of the suspension. We keep the account data, the buddies and their content, the purchase records and the logs, so that the matter can be reviewed, a counter notice can be answered and the account can be restored if the suspension is lifted.
You keep all the rights described in section 10 while your account is suspended. Because you cannot sign in, write to devtaskhub@devtaskhub.com to ask for a copy of your data or for its erasure. If you ask for erasure, we delete the account and its content. What remains is what section 9 describes: the administration log and the records of the report, which we keep for possible legal claims, and the purchase records that the law requires us to keep.
The legal basis for this processing is given in section 5. You can object to it as section 10 explains.
14. Children
The Service is for adults aged 18 and over and is not directed to anyone under 18. We do not knowingly handle data of people under 18, and photos of minors are forbidden. If we find that an account belongs to a minor, or that a photo shows a minor, we remove it. If you believe this has happened, write to us.
15. How we protect data
In plain words, these are the main measures we use:
- connections to the Service are encrypted;
- passwords are stored only as a hash, and a new account must verify its email address;
- sign in cookies cannot be read by scripts on the page and are sent only over secure connections in production;
- photos are stored under random names and are served only to the signed in owner, never from a public address;
- administrative access is limited to the operator. Viewing the head image of a reported buddy needs a stated reason, and each view and each administrative action is logged;
- uploaded images are checked and encoded again, which removes hidden data such as location;
- every request is checked against the signed in account, so one account cannot reach the content of another;
- request limits slow down guessing and abuse;
- the desktop app keeps its access token in the Windows credential store.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will inform the supervisory authority and, where required, you, as the law provides.
16. Automated decisions and profiling
We do not make decisions about you by automated means that have legal effects or similarly significant effects, and we do not build profiles of users. A buddy's behaviour is chosen by software from the settings you give it and affects only what the buddy does on your screen. Decisions about moderation, such as removing a buddy or suspending an account, are taken by a person.
17. Changes to this policy
We update this policy when the Service or the law changes, for example before a new provider is used. The new version is published on this page with a new date. If a change is important, we will also tell you by email or inside the Service before it applies.
Who we are
- Operator
- ΣΙΩΖΟΣ ΘΕΟΧΑΡΗΣ ΠΑΝΑΓΙΩΤΗΣ (Siozos Theocharis Panagiotis), sole trader, trading as DevTaskHub.com
- Address
- Markou Mpotsari 83, 546 44 Thessaloniki, Greece
- Commercial Registry (Γ.Ε.ΜΗ.)
- 186989906000
- Tax number (ΑΦΜ) and VAT
- 169481343 (EU VAT EL169481343)
- Contact
- devtaskhub@devtaskhub.com
Last updated 4 October 2026.