Buddy
Support

Whim Studio, Inc.

Buddy Privacy Notice

How we collect, use, disclose, and otherwise process personal data when you use the Buddy mobile browser.

Last updated August 17, 2026
On this page

On this page

  1. Our role
  2. Collection and use
  3. Additional uses
  4. Disclosures
  5. Your choices
  6. Children's data
  7. Security
  8. Retention
  9. Third-party services
  10. Updates
  11. Contact

Privacy questions

privacy@whim.run

This Privacy Notice explains how Whim Studio, Inc. (“Whim,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal data in connection with the Buddy mobile browser application and any related services that reference or link to this Privacy Notice. This Privacy Notice applies solely to the Buddy mobile browser application. For information about how Whim collects, uses, discloses, and otherwise processes personal data in connection with our website, please visit our general Privacy Policy.

This Privacy Notice does not address our privacy practices relating to Whim job applicants, employees and other employment-related individuals, nor data that is not subject to applicable data protection laws (such as deidentified or publicly available information). This Privacy Notice is also not a contract and does not create any legal rights or obligations not otherwise provided by law.

Our Role in Processing Personal Data

Data protection laws sometimes differentiate between “controllers” and “processors” of personal data. A “controller” determines the purposes and means (the why and how) of processing personal data. A “processor,” which is sometimes referred to as a “service provider,” processes personal data on behalf of a controller subject to the controller’s instructions. This Privacy Notice describes our privacy practices where we are acting as the controller of personal data.

Our Collection and Use of Personal Data

The categories of personal data we process depend on how you interact with Buddy. For example, you may provide personal data when you use the AI browsing features, publish a report, save profile information, submit feedback, or contact us. Buddy also creates or receives limited service information needed to authenticate the app, operate and secure the service, enforce usage limits, and measure permitted feature use.

Personal Data Provided by Individuals

We collect the following categories of personal data that individuals provide to us:

  • AI Browsing Inputs, including text prompts, commands, and messages you submit to the AI assistant while browsing. An AI request may also include a limited amount of prior conversation, device time zone, and an available location if you have granted location permission. Whim’s ordinary backend processes these request contents transiently and is designed not to write your messages, page content, screenshots, attached photos, location, Memory, or tool transcript to its application database or ordinary application logs. The limited exception is the report or briefing title described under Request Records and Usage Counters below. We transmit this information to our third-party AI service providers — currently Anthropic and SpaceXAI (formerly xAI, the provider of the Grok models) — via their application programming interfaces (APIs) to generate responses and perform actions on your behalf. Which provider handles a given request depends on the model selected for that feature, and we may add or change providers over time. See Anthropic’s commercial API retention documentation and SpaceXAI’s API security and retention documentation for reference; both state that API inputs and outputs are generally deleted within 30 days, subject to exceptions.
  • Webpage Content, including limited page metadata, page content, screenshots, and information about actions you ask Buddy to perform. Outside Private Browsing, AI requests may include the page URL, title, open-tab information, page text, structured information about visible controls and forms, and screenshots. If Suggested Actions is enabled, Buddy may send a page observation, recent conversation context, a screenshot, and your saved Memory to generate a suggestion without a new message from you.
  • Connections, meaning the list of sites you have explicitly connected so that Buddy can open them and read your own account data. A connection is created only when you ask for one and confirm it, and it records the site’s name, its address, and what kind of account it is — never a password, and never a session token or any other credential. Signing in happens on the site’s own page in the browser, and the resulting session stays on your device in Buddy’s own storage; it is never sent to us. The list of connections itself is kept on your device. While you have connections, the list of their names, addresses and kinds is included with AI requests so the assistant knows which of your accounts it can use. It is not included in Private Browsing, and Whim’s ordinary backend processes it transiently for that request rather than keeping a copy of your connection list; the one exception, which you create deliberately, is described under Report Grounding below. You can remove a connection at any time; removing it also clears that site’s cookies and other website data on this device, which signs you out of the site — and, because that data is grouped by domain, of any other connection on the same domain.
  • Report Grounding, meaning the connected sites you choose for a recurring report. If you ask Buddy for a standing report that draws on particular connected sites, the name and address of each site you chose are stored on Whim’s servers as part of that report’s settings — at most twelve name-and-address pairs, without the kind of account and without any password, session token, or other credential — so that later editions of the report can open the same sites. Each time an edition runs, that stored list is included in the request we send to our AI provider so the assistant knows which sites to open. It stays stored until you change or clear it by editing that report, until you delete the report (which also discards that report’s past editions), or until the data linked to your Buddy ID is deleted. Removing a connection on your device does not by itself remove a site already stored with a report; change or delete the report to do that.
  • Server-Side Web Research, including short informational search queries generated from your request, report topic, or standing instructions. Buddy may use this research in an interactive AI request or while preparing an unattended recurring-report edition. Whim sends the query to Exa Labs, Inc. (“Exa”) and receives public-web results and excerpts. Exa receives the query and standard network information from Whim’s server; Whim does not send your Buddy ID, session token, or device IP address with the query. Exa states that Query Data may be used to improve its products and technology, including training and fine-tuning its models; see Exa’s Privacy Policy. Whim’s ordinary backend processes raw interactive web-search queries and results transiently and is designed not to write them to its application database or ordinary logs. A response or recurring-report edition may retain selected source links, quoted facts, summaries, and other research incorporated into the finished output. A recurring-report edition may also retain up to 24 bounded per-item image queries as retry work for its on-device image fallback; those queries follow the edition’s retention described below.
  • Recurring Report Images, including a short image-search query derived from a report’s topic and one public-web image selected for a cloud-generated edition. Exa returns candidate image and source-page addresses. Whim may request candidate bytes from the public image host, validate the file as a bounded static JPEG or PNG, strip supported EXIF, text, comment, color-profile, and related metadata fields, and retain one copy with its source-page address and descriptive text. The image host receives standard network information from Whim’s server, not your Buddy ID, session token, cookies, device IP address, or report contents. The image and attribution are stored with the private edition and removed when that edition is pruned, you delete the report, or you use Delete My Data. If you choose to publish the edition, the Shared Report Content terms below apply. A source-page link identifies where Buddy found an image; it does not mean Whim created, owns, or endorses that image or source.
  • Shared Report Content, including a report title, rendered report content, eligible report images, and a feed thumbnail that you choose to publish. A published report is available to anyone who has its capability link until you revoke it, it expires, or we remove it. If you choose public-feed visibility, Buddy also distributes it through the Trending discovery feed. Before public distribution, Buddy sends the report text and images to Anthropic to classify them for safety. Flagged reports may be reviewed by an authorized human moderator. Buddy configures report pages not to be indexed by search engines, but recipients and messaging services may fetch them to display the existing rich link preview. Do not publish information you do not want feed viewers or link recipients to see.
  • Profile Content, including a username and any display name or avatar you choose to save. Your avatar stays owner-only and is never shown to anyone else. Your username and display name are shown to other people only on reports you choose to publish with your name attached, and only on reports published after you make that choice. Buddy asks you once, the first time you publish a report publicly, and the answer applies from then on; publishing anonymously is the default until you answer, and reports published before you chose stay anonymous permanently. You can switch back to anonymous at any time in your profile, which also removes your name from every report you have already published. A username or display name shown this way is not sent through the public-report safety classifier.
  • Form and Transaction Data, including personal information (such as name, address, payment details, and other data fields) that you direct the AI assistant to input into forms or use to complete transactions on third-party websites. The AI assistant will only submit forms or complete purchases after receiving your express confirmation. We do not independently store this information; it is processed solely to fulfill your directed action on the applicable third-party website.
  • Assistant Memory, including durable facts or preferences stated during conversations and stored only on your device. Eligible Memory may be included in later non-private AI requests. You can review, edit, or delete Assistant Memory in the app.
  • Feedback, Inquiries and Support Information, including the contents of messages sent through our support channels, feedback forms, or email. We use this information primarily to investigate and respond to your inquiries and to improve our products and services.

If you choose to contact us, we may need additional information to fulfill the request or respond to your inquiry. We may provide additional privacy disclosures where the scope of the request we receive or personal data we require fall outside the scope of this Privacy Notice. In that case, the additional privacy disclosures will govern how we may process the information you provide at that time.

Personal Data Automatically Collected

Buddy automatically creates or receives the following limited service information when you use the app:

  • Pseudonymous Identity and Service Records. Buddy does not require a conventional account. An optional username is not used to sign you in. It is shown in Trending only on reports you have chosen to publish under your name; see Profile Content above. Buddy does not ask for an email address, phone number, password, social login, or biometric login. Buddy creates a random device/app identifier in the iOS Keychain. Whim’s backend associates it with a pseudonymous Buddy user ID and returns a signed session token. Apple App Attest may provide key and assertion information to help verify that requests come from a genuine copy of Buddy. Whim links the pseudonymous identifiers to service records such as subscription tier, profile information, usage counters, request metadata, product analytics, report sharing, and feedback. The Keychain identifier may persist across an app reinstall depending on iOS behavior.
  • Request Records and Usage Counters. Whim stores limited request records for cost accounting, rate limiting, reliability, and abuse prevention. A request-log row may contain the pseudonymous user ID, operation class, selected model, input/output/cache token counts, units charged, route, status, latency, time-to-first-token, estimated cost, coarse distribution and edge-region context, and timestamp. Outside Private Browsing, a row for report or briefing generation may also contain up to 120 characters of the title from the validated report document. That stored title is used only in Whim’s administrator-authenticated internal dashboard to attribute model costs to a report or briefing. It is not the prompt, webpage title, report body, or response body, and it is not exposed to other users. Request-log rows are designed not to contain prompt text, page content, screenshots, URLs, or response bodies. Whim also maintains counters needed to enforce service limits.
  • Product Analytics. Outside Private Browsing, Buddy sends Whim an allowlisted event name, timestamp, and limited properties such as task type, coarse error code, operation class, tier, duration, count, or enabled state. Events are stored under the pseudonymous Buddy user ID. This pipeline is designed not to contain page content, URLs, search queries, AI messages or answers, attached photos, or direct identifiers such as a name or email address. It is separate from the optional Help us improve setting and is disabled in Private Browsing.
  • Meta App Install Attribution Data, including device and app metadata plus install and activation events sent through Meta’s iOS SDK. We use this limited data to measure and optimize advertisements for Buddy on Meta services, including Instagram. Buddy disables Meta’s automatic App Events mode and does not send StoreKit purchases, AI messages, webpage content, browsing history, contacts, photos, or precise location through this integration.
  • Proposed TikTok and AppsFlyer Advertising Measurement Data, through a bounded hybrid integration. TikTok App Events SDK 1.5.1 would send the automatic app events InstallApp, LaunchAPP, and 2Dretention directly to TikTok. AppsFlyer Strict SDK 7.0.0 would separately measure only app install and session lifecycle signals and act as the hybrid flow’s sole SKAdNetwork conversion-value updater; TikTok SKAdNetwork updates would be disabled. Depending on the SDK and event, this information may include an SDK-generated identifier, Apple’s Identifier for Vendor (IDFV), local IP address, user agent, locale, device model and operating-system version, Buddy version and build, session data, ATT status, and event timestamp. AppsFlyer’s Strict package excludes IDFA collection and the AdSupport framework. Buddy does not request App Tracking Transparency authorization, and the TikTok SDK receives an all-zero IDFA value rather than a usable advertising identifier when authorization is unavailable. Buddy disables attribution if authorization is unexpectedly already present. Buddy would instruct AppsFlyer to share configured install and reinstall postbacks with TikTok from all media sources, including organic sources and ATT opt-out users, through AppsFlyer’s Advanced Data Sharing setting. Advanced Matching would remain off. Buddy never calls TikTok identity or custom-event APIs and does not set a TikTok external user ID or AppsFlyer customer user ID. Buddy does not send either provider email, phone number, name, custom events, purchase events, URLs, browsing history, webpage or AI content. Buddy also disables TikTok enhanced-data postback, automatic purchase capture, and SDK logging. The reviewed TikTok 1.5.1 SDK preserves the local purchase opt-out after remote configuration, but can accept server-side configuration that changes its network domain or enables diagnostics, crash collection, and debug screen capture. Because those upstream behaviors and the final AppsFlyer dashboard, privacy, and postback configuration still require approval, the protected production gate remains off. That gate selects the ordinary Buddy target, which does not link, embed, or initialize either proposed attribution SDK and contains no TikTok or AppsFlyer credentials or load-time hooks. Before the isolated hybrid target is enabled for a production release, enforceable vendor controls, required-reason API declarations, tracking domains, AppsFlyer data sharing, ATT/App Store treatment, and final dashboard configuration must be approved, and sterile validation must be completed. After the first approved enabled release, campaigns will remain off until production postbacks and campaign eligibility are validated.
  • Shared Report Interaction Data, including when a public report link is successfully fetched and whether the request appears to be a human browser visit or an automated preview, crawler, or prefetch. The retained traffic row contains the report’s internal share identifier, the report owner’s pseudonymous Buddy ID, the coarse request category, and timestamps. It does not contain the public capability or URL, visitor IP address, User-Agent, request headers, report title or content, or a visitor identifier. Human browser visits increment the lifetime view count shown to the report owner; automated fetches are counted separately and excluded from that number. This server-side public-link measurement is not controlled by the in-app Help us improve setting.
  • Report Feed Safety and Preference Data, including an internal report ID, timestamps, and coarse actions when a user reports a report, blocks a publisher, or when an authorized moderator allows or removes content or suspends or restores a publisher. Buddy derives a one-way, keyed value from the blocking or reporting user’s pseudonymous Buddy ID so it can apply that user’s preferences without storing that ID in the preference or flag row. Blocking is private: the blocked publisher is not notified. The public feed response exposes no avatar, public-profile link, or stable publisher identifier, and exposes a username and display name only for reports whose author chose to publish under their name. We use this data to personalize the feed, investigate reports, enforce our rules, and maintain the safety of the service.
  • Search Suggestion Information, including normalized text entered into the address bar when it appears to be a search rather than a URL. Remote Search Suggestions are enabled by default outside Private Browsing. When enabled, Buddy sends this text to Whim’s backend, which forwards it to Google Suggest. Google receives the query. Buddy does not forward your Buddy device ID or session token to Google.
  • Location. Buddy requests iOS When In Use location permission contextually. If you grant permission, Buddy asks iOS for a nearby fix. When Precise Location is enabled, Buddy rounds latitude and longitude to three decimal places (about 100 meters) before sending coordinates to Whim and an AI provider. If Precise Location is off or fix quality is poor, the coordinates may describe a broader area. Buddy may also send the fix’s estimated accuracy and area labels such as neighborhood, city, region, or country. Location is not sent in Private Browsing. Whim’s application database does not store the device fix; request metadata may store only the coarse edge region supplied by the hosting proxy. Network providers may process standard connection information when handling a request.
  • Crash and Error Diagnostics, including native crash reports, app-hang or watchdog reports, and selected handled failures sent to Sentry after you select the optional Help us improve choice while turning on Buddy’s AI or enable it later in Settings, and while Private Browsing is off. A report may contain the Buddy app version, iOS version, device model, crash stack, coarse error category, failed operation, and a random request ID that may be correlated with our limited request log. Buddy configures Sentry not to attach a user profile, webpage content, screenshots, view hierarchy, URLs, AI messages or responses, request or response bodies, raw backend error messages, network breadcrumbs, session replay, or performance traces. Like other network providers, Sentry may process standard connection information when receiving a report. Turning off Help us improve or entering Private Browsing stops future Sentry collection through Buddy.

We use this service information only to operate, secure, meter, support, and improve Buddy; provide paid entitlements; moderate public content; and measure campaigns promoting Buddy as described above. The request-log title copy has the narrower use described above: administrator-only report and briefing cost attribution.

Subscriptions and Payments

Buddy Plus is sold through Apple In-App Purchase. Apple processes payment instruments, billing details, refunds, and the App Store account. Whim does not receive your card number or payment method. Buddy sends signed transaction data to Whim for verification, and Apple may send signed server notifications about renewals, expirations, refunds, or revocations. Whim stores the original transaction identifier, pseudonymous user ID, last signed-event time, timestamps, and entitlement tier so it can provide and restore paid access.

Information Stored on Your Device and Private Browsing

Outside Private Browsing, Buddy stores ordinary browser data such as history, bookmarks, downloads, and up to 50 AI chat sessions only on your device. Whim does not keep server-side history, bookmark, download, or chat libraries. Saved chats can include message text, assistant responses, page titles and URLs, and attached photos. Older chats may be automatically evicted when the limit is reached. Information selected from a saved chat can still be transmitted as part of a later AI request as described above.

The IDs of Trending reports you choose to hide or mark Not Interested are also stored locally on your device so they remain hidden. Those local hide choices are not sent to Whim.

If you choose Report or Block Author, Buddy also stores the action type and the internal report ID in a small pending-safety-action outbox on your device until Whim’s backend confirms the requested action. Buddy sends that queued information to Whim when it retries the action and removes the pending entry after confirmation. A successful Delete My Data request also clears this outbox so an old action is not replayed under a new Buddy ID.

Buddy also stores Assistant Memory only on your device. Memory can include durable facts or preferences stated in conversation and verified site-structure facts. The assistant may save an unambiguous fact directly and may ask you to approve softer preferences. You can review, edit, or delete Memory in the app. Eligible Memory can be included in later non-private, page-aware AI requests and is therefore transmitted through Whim to an AI provider (Anthropic or SpaceXAI) when used, but Whim does not maintain a server-side Memory library.

In Private Browsing, Buddy uses a non-persistent WebKit data store and does not save new history, cookies, cache, or AI chats. Product analytics, Sentry diagnostics, remote Search Suggestions, Memory, and location are disabled. After AI consent, you can still submit a typed request or attached photo without sharing the private page. Sharing private-page metadata, content, or screenshots requires the separate Allow AI Page Access in Private Browsing setting. Whim’s request log does not retain report or briefing titles from Private Browsing.

Delete My Data deletes active information linked to the current pseudonymous Buddy ID from our backend. On success, Buddy also resets AI consent and clears the old Keychain identity and account-linked local state, including the cached profile, Trending hides and pending safety actions, and cached entitlement state. It does not clear local chats, Memory, history, bookmarks, or downloads, and it preserves the Search Suggestions and crash-data-sharing preferences. Public reports, recurring report settings, completed editions and lead images, and the connected sites stored with them, active publisher suspensions, report flags, server-side feed block preferences, request-log rows, and their stored report or briefing titles linked to that Buddy ID are included in backend deletion. Aggregate safety counts that no longer identify the reporting user may remain for integrity purposes. Use the relevant in-app controls, or remove the app, to clear app-container data. Removing the app may not remove the Keychain identifier; use Delete My Data before removal when possible.

Voice Input

If you use dictation, Buddy uses Apple’s Speech framework. It prefers on-device transcription, but Apple may process audio on its servers when on-device recognition is unavailable for your language or device. Whim does not receive or store the microphone audio. The resulting text follows the AI flow described above only if you submit it. Microphone and speech-recognition access require iOS permission, which you can revoke in iOS Settings.

Additional Uses of Personal Data

In addition to the primary purposes for using personal data described above, we may also use personal data we collect to:

  • Provide, operate, personalize and maintain the AI browsing features of the Buddy application, including reading and interpreting webpage content, navigating webpages, filling out forms, and completing transactions at your direction and with your express confirmation;
  • Process and transmit your AI prompts and browsing inputs to third-party AI service providers to generate responses and carry out actions on your behalf;
  • Fulfill or meet the reason the information was provided, such as to fulfill our contractual obligations, to facilitate payment for our products and services, or to deliver the services requested
  • Manage our organization and its day-to-day operations;
  • Request you provide us feedback about our product and service offerings;
  • Authenticate the Buddy installation and verify entitlement to paid features;
  • Address inquiries or complaints made by or about an individual in connection with the application;
  • Develop, operate, improve, maintain, protect, and provide the features and functionality of the application;
  • Conduct research and analytics to understand usage patterns and improve our products and services;
  • Measure and optimize advertising campaigns that promote Buddy using Meta install and activation events and, if approved, bounded TikTok app-lifecycle events, AppsFlyer install/session attribution, and Apple’s SKAdNetwork;
  • Improve Buddy using aggregate service metrics and the content-free product analytics described above;
  • Create aggregated or de-identified information that cannot reasonably be used to identify you, which information we may use for purposes outside the scope of this Privacy Notice;
  • Help maintain and enhance the safety, security, and integrity of our application, technology, assets, and business;
  • Defend, protect, or enforce our rights or applicable contracts and agreements (including our Terms of Service), as well as to resolve disputes, carry out our obligations, and protect our business interests and the interests and rights of third parties;
  • Detect, prevent, investigate, or provide notice of security incidents or other malicious, deceptive, fraudulent, or illegal activity and protect the rights and property of Whim and others;
  • Comply with contractual and legal obligations and requirements;
  • Fulfill any other purpose for which you provide your personal data, or for which you have otherwise consented.

Whim does not use your AI messages, page content, screenshots, attached photos, Memory, location, or form data to train or fine-tune AI models.

Our Disclosure of Personal Data

We disclose or otherwise make available personal data in the following ways:

  • To AI Providers: We transmit your AI browsing inputs (including prompts, commands, relevant webpage content and any other input you choose to provide) to third-party AI model providers — currently Anthropic and SpaceXAI (formerly xAI, the provider of the Grok models) — via their APIs to assess requests, website content, generate responses and perform actions on your behalf. We also transmit Shared Report Content to Anthropic for pre-publication safety classification. Owner-only Profile Content is not sent through that classifier. Which provider handles a browsing request depends on the model selected for that feature, and we may add or change providers over time. Under our agreements with these providers, they will not process your personal data to further train or refine their AI technologies. To view Anthropic’s privacy policy, please click here. To view SpaceXAI’s privacy policy, please click here.
  • To Exa for Web Research: We transmit the bounded informational queries described above to Exa’s search API so Buddy can find current public-web sources and candidate recurring-report images. We do not include your Buddy ID, session token, or device IP address. Exa’s processing of Query Data is described in its Privacy Policy.
  • To Public Image Hosts: When the cloud report worker evaluates an Exa-provided image candidate, Whim’s backend requests the image from its public host without your Buddy credentials, cookies, device IP address, or report contents. The host may receive ordinary server connection information. Whim retains only a candidate that passes the bounded raster and selected metadata-removal checks described above.
  • To Service Providers: We engage third parties to perform certain services on our behalf, such as hosting, analytics, and customer support. Depending on the applicable services, these service providers may process personal data on our behalf or have access to personal data while performing services on our behalf.
  • To Meta for Advertising Measurement: Meta’s iOS SDK sends limited device/app metadata and install or activation events so we can attribute installs and measure campaigns promoting Buddy on Meta services, including Instagram. Meta’s processing is governed by its terms and privacy policy.
  • To TikTok and AppsFlyer for Advertising Measurement: The proposed hybrid flow would send the bounded app-lifecycle and device/app context described above so that we can attribute installs and measure campaigns promoting Buddy. AppsFlyer would process install/session signals and, when Advanced Data Sharing is enabled, send configured install/reinstall postbacks to TikTok from all media sources, including organic sources and ATT opt-out users. Buddy does not intentionally supply either provider with email, phone number, name, an external or customer user ID, custom events, URLs, browsing history, webpage or AI content, or purchase events. AppsFlyer Advanced Matching would remain off. Production remains disabled while TikTok’s remotely controlled diagnostic/debug behavior and the final AppsFlyer dashboard and postback configuration are being reviewed. AppsFlyer’s handling of attribution data is described in its Services Privacy Policy.
  • To Third-Party Websites You Interact With: When you access websites through the Buddy browser or direct the AI assistant to take actions on your behalf (e.g., fill out forms or complete transactions), the personal information you have provided to the third-party websites will be provided directly to those websites. Where the AI assistant is asked to complete transactions, the information will be submitted to those third-party websites at your express direction and, where ordering or buying on your behalf, with your confirmation. We are not responsible for the privacy practices of those third-party websites.
  • In Connection with a Business Transaction or Reorganization: We may take part in or be involved with a business transaction or reorganization, such as a merger, acquisition, joint venture, or financing or sale of company assets. We may disclose, transfer, or assign personal data to a third party during negotiation of, in connection with, or as an asset in such a business transaction or reorganization. Also, in the unlikely event of our bankruptcy, receivership, or insolvency, your personal data may be disclosed, transferred, or assigned to third parties in connection with the proceedings or disposition of our assets.
  • To Facilitate Legal Obligations and Rights: We may disclose personal data to third parties, such as legal advisors and law enforcement:
    • in connection with the establishment, exercise, or defense of legal claims;
    • to comply with laws or to respond to lawful requests and legal process;
    • to protect our rights and property and the rights and property of our agents, customers, and others, including to enforce our agreements, policies, and terms of use;
    • to detect, suppress, or prevent fraud;
    • to reduce credit risk and collect debts owed to us;
    • to protect the health and safety of us, our customers, or any person; or
    • as otherwise required by applicable law.
  • With Your Consent or Direction: We may disclose your personal data to certain other third parties or publicly with your consent or direction.

Your Privacy Choices

The following privacy choices are made available to all individuals with whom we interact.

Buddy provides controls to revoke AI consent, turn Suggested Actions and remote Search Suggestions on or off, control AI page access in Private Browsing, turn future Sentry diagnostics on or off, review or clear Assistant Memory, manage iOS permissions, clear local browser/chat data, and delete data linked to the current pseudonymous Buddy ID from Whim’s backend.

Advertising Measurement

Buddy does not display third-party advertising inside the app. Meta’s iOS SDK measures installs and activations from campaigns advertising Buddy on Meta services, including Instagram. A proposed hybrid TikTok and AppsFlyer integration would separately measure campaigns that advertise Buddy. It does not ask for ATT permission or collect a usable IDFA, but TikTok’s direct lifecycle events and AppsFlyer’s install/session measurement and Advanced Data Sharing (ADS) postbacks would include other device-level and technical information described above in addition to Apple’s SKAdNetwork postbacks. AppsFlyer would be the sole SKAdNetwork conversion-value updater, and TikTok’s updater would be disabled. The production gate is off and selects the ordinary Buddy target, which does not link, embed, or initialize either proposed attribution SDK and contains no TikTok or AppsFlyer credentials or load-time hooks. Before the isolated hybrid target is enabled for a production release, enforceable vendor controls, required-reason API declarations, tracking domains, AppsFlyer data sharing, ATT/App Store treatment, and final dashboard configuration must be approved, and sterile validation must be completed. After the first approved enabled release, campaigns will remain off until production postbacks and campaign eligibility are validated.

We do not sell personal data.

Withdrawing Your Consent

Where we have your consent for the processing of your personal data, you may withdraw your consent at any time by adjusting your preferences in the application settings or by contacting us as set forth in the Contact Us section below.

Modifying or Deleting Your Personal Data

If you have any questions about reviewing, modifying, or deleting your personal data, you can contact us directly at privacy@whim.run, or use Delete My Data in Settings > Advanced. Delete My Data removes active Whim database records linked to the current Buddy ID, including public reports, recurring report settings, completed editions and lead images, and the connected sites stored with them, request-log rows and their stored report or briefing titles, active publisher suspensions, report flags, and feed block preferences. It does reset AI consent and clear the old Keychain identity, cached profile, Trending hides and pending safety actions, and cached entitlement state. It does not clear on-device chats, Memory, history, bookmarks, or downloads; cancel an Apple subscription; remove provider copies, security logs, or backups; or change the Search Suggestions or crash-data-sharing setting. Using an online Buddy feature later can create a new pseudonymous Buddy ID. We may not be able to modify or delete personal data in all circumstances permitted by law.

Device Permissions

You can manage Buddy’s camera, photo-library, location, microphone, and speech recognition permissions in iOS Settings. Revoking a permission prevents future access through that permission but does not delete information you previously chose to submit.

Children’s Personal Data

Buddy is intended and is rated 16+ on the App Store because it provides general-purpose, unrestricted web access. Our application is not directed to, and we do not intend to, or knowingly, collect or solicit personal data from children under the age of 13. If an individual is under the age of 13, they should not use our application or otherwise provide us with any personal data either directly or by other means. If a child under the age of 13 has provided personal data to us, we encourage the child’s parent or guardian to contact us to request that we remove the personal data from our systems. If we learn that any personal data we collect has been provided by a child under the age of 13, we will promptly delete that personal data. Buddy does not currently collect a date of birth or use Apple’s Declared Age Range API to gate the Trending feed. Accordingly, we do not represent that the feed is technically disabled for users under 13.

Security of Personal Data

We have implemented reasonable physical, technical, and organizational safeguards that are designed to protect your personal data. However, despite these controls, we cannot completely ensure or warrant the security of your personal data.

Retention of Personal Data

Retention depends on the category and where it is processed:

  • AI request content in Whim’s ordinary backend path: Messages, page data, screenshots, attached photos, Memory, location, and tool data are processed transiently in service memory and are not intentionally persisted by Whim’s application code. The limited exception is a report or briefing title, as described below.
  • AI inputs and outputs at AI providers: Generally deleted within 30 days under the providers’ published commercial API documentation, subject to the providers’ stated exceptions and applicable contractual settings.
  • Web-research queries and results: Whim’s ordinary backend processes raw interactive Exa queries, complete search responses, unselected results, and rejected image candidates transiently rather than keeping them in its application database or ordinary logs. Exa retains or uses Query Data under its applicable customer terms and Privacy Policy. Selected source material incorporated into a response or report follows the retention of that finished output. Bounded recurring-report image queries retained for on-device fallback follow that edition’s retention.
  • Search-suggestion cache: Positive query/result entries ordinarily expire for use after ten minutes and are removed on later access, capacity eviction, or process restart.
  • Pseudonymous service records: The Buddy user record, profile fields, usage counters, subscription mapping, App Attest records, and feedback are generally kept until Delete My Data, unless pruned earlier or retained longer when required.
  • Report grounding: The names and addresses of the connected sites you chose for a recurring report are kept with that report’s settings until you change or clear them, delete that report, or use Delete My Data.
  • Recurring-report editions and lead images: At most the newest 30 completed editions per report, including up to 24 per-item fallback image queries and a retained lead image and source-page address when one was resolved, remain on Whim’s servers. Older editions are pruned. Deleting the report or using Delete My Data removes them sooner.
  • Request records, product analytics, and public-link interaction events: Request-log records — including any bounded, non-private report or briefing title — are generally kept within the configured 12-month application-log window, then purged. Delete My Data removes a user’s request-log rows sooner. Product analytics and public-link interaction events are generally kept within the same window.
  • Trending safety and preference records: The feed-ranking view ledger is ordinarily kept for 14 days and individual reporter flag rows for 180 days. Aggregate flag and lifetime-view counts can remain after their underlying event rows expire. Feed blocks remain until cleared or Delete My Data, and a publisher suspension remains active until restored or the associated Buddy data is deleted.
  • Public reports: Available until revoked, expired, removed by a moderator, or deleted with the associated Buddy data.
  • Billing-verification failure records: Generally kept within a 90-day rolling window.
  • Sentry diagnostics: Generally kept for no more than 90 days under the applicable Sentry retention setting.
  • Local chats: Kept on the device until you delete them, remove the app, or they are automatically evicted beyond the 50-session limit.
  • Local Memory, history, bookmarks, downloads, and hidden-report IDs: Kept on the device until you delete the relevant data or remove the app, subject to the iOS Keychain behavior described above.
  • Pending feed-safety actions: The action type and internal report ID are kept on the device until Whim’s backend confirms the requested Report or Block Author action, Delete My Data succeeds, or the app’s local data is removed.
  • Infrastructure security logs and backups: Kept for limited periods based on operational, security, continuity, and legal needs.

We may retain information longer when required by law, necessary to investigate abuse or security incidents, or needed to establish or defend legal claims. When information is no longer needed, we delete it, deidentify it, or allow it to expire under the applicable system’s retention process.

Third-Party Websites and Services

Our application enables you to browse and interact with third-party websites. Third-party websites and other services may also reference or link to our websites and services. This Privacy Notice does not apply to any personal data practices of third parties. This Privacy Notice does not apply to any personal data practices of these third-party websites, plug-ins, applications, or other services. To learn about the personal data practices of third parties, please visit their respective privacy notices.

Updates to This Privacy Notice

We may update this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the date at the beginning of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify individuals by prominent posting on the application or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided.

Contact Us

If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please send an email to privacy@whim.run.

Buddy

The AI browser that lives with you.

© 2026 Buddy. · Privacy · Terms · Support · X · @buddyaibrowser