Privacy Policy
Last updated
Busy staffs companies with AI teammates that work inside those companies’ own accounts and tools. That means a teammate touches real business data and real conversations, so it matters that this document is specific rather than decorative. It sets out what we collect, how credentials are held, who else sees anything, and what we will not do — which includes selling data and pooling one client’s information with another’s.
Who we are, and who this policy is for
Busy is operated by Busy Industries Incorporated, doing business as Busy, Inc. (“Busy,” “we,” “our,” or “us”). This policy explains what information we collect, how we use it, and who else sees it, across our website at busy.inc and the service we provide to client companies.
Busy staffs companies with AI teammates. A teammate is a software agent assigned to one client company, directed by a named person at that company, working in the tools that company already uses — email, Slack, text, and meetings. That arrangement means information reaches us in two different ways, and they are governed differently:
- Information we hold for ourselves. Contact details of the people we deal with, demo requests submitted on busy.inc, and the records we keep to run and bill the service. For this information, Busy decides what is collected and why.
- Information a teammate touches on a client’s behalf. Everything inside the client’s own accounts, systems and conversations that the client has given the teammate access to. Here the client company decides what is collected and why, and Busy acts on its instructions. If you are an employee of, or a correspondent with, a company that uses Busy, that company’s own privacy policy governs this data, and requests about it are best directed there. We will help that company answer you.
Information we collect
Information you give us directly
- Contact and account information: name, business email address, phone number, company, and role, whether you give it to us on a call, over email, or through the demo request form on busy.inc.
- Demo requests: the email address and optional note submitted through the form on this site. These are delivered to us as an email; we do not build a marketing profile from them.
- Billing information: where a product is billed online, payment details are handled by Stripe. We do not receive or store full card numbers or bank account numbers.
- Credentials you choose to entrust to a teammate: see connected accounts and credentials below.
Information a teammate handles in the course of its work
- Messages and conversations: the content of emails, Slack and Teams messages, text messages, and meetings a teammate takes part in, including recordings and transcripts of meetings it attends.
- Business records from connected systems: whatever the client has connected and authorized — files, orders, invoices, campaign data, CRM records, project documents — read through the client’s own accounts.
- Work products: documents, drafts, reports and other artifacts the teammate produces for the client.
- Summaries and memory: we keep a written record of a teammate’s interactions, along with condensed summaries and mathematical representations of them, so the teammate can remember prior work. This is what lets a teammate carry context across months rather than starting fresh each time.
Information collected automatically
- Log and diagnostic data: IP address, timestamps, request paths and error traces produced by our servers, used to operate and debug the service.
- Usage records: which capabilities and connections a teammate used and how often, which we use for operations, support and billing.
How we use information
We use the information described above to:
- Do the work. Carry out the tasks a client’s manager assigns to a teammate, in that client’s own systems.
- Give a teammate memory. Retain and retrieve prior context so it can hold ongoing work over time rather than repeating itself.
- Run and support the service. Provision teammates, keep them available, investigate incidents, and answer support requests.
- Bill and account. Measure usage and invoice for the service.
- Communicate. Respond to demo requests, send service and security notices, and correspond about an engagement.
- Improve the service. Diagnose failures and improve how teammates work. See artificial intelligence providers for what we do and do not do with client content in this respect.
- Meet legal obligations. Respond to lawful requests and enforce our agreements.
Connected accounts and credentials
A teammate does its work through accounts the client controls. Some of those are accounts a client creates for the teammate itself — its own mailbox, its own seat in a workspace — and some are third-party services a client connects, such as Google, Slack, Shopify, Klaviyo, Dropbox, QuickBooks, Linear, Attio, Procore, Recharge or an advertising platform.
How those credentials are held:
- Tokens are held by a specialist custodian. Where a connection is made by signing in through the provider (OAuth), the resulting access and refresh tokens are held and refreshed by our credential provider, Nango. Our own records store a reference to that connection, not the token.
- Other secrets are encrypted at rest. Credentials we do hold — API keys, and passwords a client asks a teammate to use on its behalf — are stored encrypted, with the encryption keys held separately from the database.
- Credentials are fetched at the moment of use. A teammate does not keep a client credential on its machine. It presents its own identity, and the credential is added server-side for the specific call being made. Each such use is logged.
- Staff do not read them casually. There is no facility for revealing a stored client credential in plain text through our internal console. The two credential types that can be revealed — a teammate’s own workspace login and its machine token — write an audit entry naming the person who revealed them.
- You can revoke at any time. Disconnecting a service, changing a password, or suspending the teammate’s own account ends its access immediately, the same way it would for an employee.
Separation between clients
We do not pool, aggregate, or cross-reference one client’s data with another’s. There is no shared corpus, no benchmark dataset assembled from client accounts, and no product that draws on several clients at once.
This is enforced in the software rather than by policy alone. Every credential and every record is owned by exactly one client organization, and a request carries the organization of the teammate making it — there is no way to name another client’s data and be handed it. Where a request is ambiguous, it is refused rather than resolved by guessing.
Who else sees information
We do not sell personal information, and we never have. We share it in the following circumstances only.
Service providers we rely on to run the service
- Anthropic and OpenAI — the artificial intelligence models a teammate reasons with. See the next section.
- Voyage AI — converts interaction summaries into the mathematical form that makes a teammate’s memory searchable.
- Nango — holds and refreshes the credentials for connected third-party accounts.
- Telnyx — delivery of text messages and voice calls.
- MeetingBaas — joins meetings on a teammate’s behalf and returns recordings and transcripts.
- Windsor.ai — the data layer behind Busy Datalink, where a client has connected advertising or commerce platforms through it.
- ScraperAPI and fal — retrieval of public web pages and generation of images, reached through a gateway that adds our key so the teammate’s machine never holds it.
- Stripe — payment processing, governed by the Stripe Privacy Policy.
- Clerk — sign-in and account management for our client-facing applications.
- Resend — delivery of the demo request form on busy.inc to our own inbox.
- Render and Amazon Web Services — hosting, databases and file storage, located in the United States.
Other circumstances
- At the client’s direction. A teammate sends and receives messages on its client’s behalf; who it corresponds with is set by the client and constrained by the permissions the client granted it.
- Legal requirements. Where required by law, regulation, legal process, or a governmental request.
- Business transfers. In connection with a merger, acquisition, or sale of assets, information may be transferred to the acquiring entity, subject to this policy.
Text messaging (SMS)
Where you give us a mobile number for sign-in verification or to correspond with a teammate by text, we send messages to that number through Telnyx. Verification codes are sent only when you request one during sign-in or account setup, and conversational texts only within an engagement you or your company arranged. Message frequency varies; message and data rates may apply. Reply STOP to any message to stop receiving texts, and HELP (or write to jeff@busyincorporated.com) for help. Details of how consent is collected are on our SMS opt-in page.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excepting the messaging carriers and Telnyx, our delivery provider, solely as required to deliver the messages.
Artificial intelligence providers
A teammate reasons using models operated by third parties. In the ordinary course of its work, the content it is working with — message text, documents, records from connected systems — is transmitted to those providers so a response can be generated. Today those providers are Anthropic for a teammate’s general reasoning, OpenAI for live voice conversation, and Voyage AI for the representations that make a teammate’s memory searchable. This list may change as the underlying technology does, and we will update this page when it does.
We do not train models on client data. Busy does not build or fine-tune models from the content a teammate handles, and we use these providers under commercial API terms rather than consumer terms. What each provider does with data submitted to its API is governed by its own agreement with us; we encourage clients with strict requirements to raise them before an engagement begins so the arrangement can be documented.
Cookies and tracking on busy.inc
This website does not run analytics, advertising, or tracking cookies. There is no Google Analytics tag, no advertising pixel, and no cross-site tracking. The pages are static and the only information the site collects is what you type into the demo request form.
Our client-facing applications, which sit behind a sign-in, use cookies that are strictly necessary to keep you signed in. If we add analytics to this site later, we will say so here before doing it.
Security
We take reasonable administrative and technical measures to protect information. In practice that means: traffic between you, us and our providers is encrypted in transit; stored credentials are encrypted at rest with keys held outside the database, and our production systems refuse to start without them; access to a client’s data is scoped to that client in the software itself; credential use and staff credential access are logged; and each teammate runs on hardware it does not administer and cannot modify its own source code, which ships as reviewed changes.
No method of transmission or storage is completely secure, and we do not claim otherwise. You are responsible for the confidentiality of your own account credentials and for the scope of access you grant a teammate. If you believe an account or credential has been compromised, contact us at jeff@busyincorporated.com immediately.
How long we keep information
We keep information for as long as the engagement is active and afterwards as needed to provide the service, resolve disputes, meet legal and accounting obligations, and enforce our agreements.
Records of a teammate’s interactions — including message and meeting transcripts and the summaries built from them — are retained deliberately, because they are what gives a teammate continuous memory of a client’s work. They are not deleted automatically on a schedule. A client may ask us to delete all or part of its data at any time, and may ask for it back in a usable form; we will act on such a request promptly, subject to any records we are required to keep by law.
Your rights
Depending on where you live, you may have the right to ask us to do the following with personal information about you:
- Access: tell you what we hold and where it came from.
- Correct: fix information that is inaccurate or incomplete.
- Delete: erase it, subject to records we must keep.
- Port: give you a copy in a structured, machine-readable form.
- Opt out of marketing: unsubscribe from any non-transactional email, or simply reply and ask.
- Not be treated worse for asking: we will not discriminate against you for exercising any of these rights.
Write to jeff@busyincorporated.com. We will verify who you are before acting, and respond within the time applicable law requires.
Where the information in question was handled by a teammate on behalf of a client company, that company is the one that decides its use, and we will forward your request to it and support its response rather than acting unilaterally on data that is not ours to decide about.
State privacy laws. Residents of California and of other states with comprehensive privacy laws — including Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah and Virginia — have rights along the lines set out above, including the right to appeal a refusal. We do not sell personal information and we do not use it for targeted advertising or for profiling that produces legal effects. To exercise a state-law right, use the same address.
Where information is processed
Busy operates from the United States, and information is stored and processed there, including by the providers listed above. If you are outside the United States and use the service or correspond with a teammate, you should understand that your information will be transferred to and processed in the United States, where privacy law differs from that of your own country.
Children
Busy is a service sold to businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. If you believe a child’s information has reached us, write to jeff@busyincorporated.com.
Changes to this policy
We may update this policy. When we do, we will post the new version on this page and change the “last updated” date above. If a change materially affects how we handle information, we will tell affected clients directly rather than relying on the posting alone.
Contact us
Questions about this policy, or about what a teammate holds, go to one address and reach a person:
See also Terms and Conditions