Privacy Policy
BU² Privacy Policy
Your privacy, in plain language
This is how BU² handles your data, written plainly so you can actually read it. The short version: everything you share with BU² is processed and stored within the EU/EEA, and if any data ever needs to reach a provider outside the EEA we do so only under an appropriate safeguard such as the EU Standard Contractual Clauses; the sensitive health data you choose to share is only ever processed with your explicit, separate consent, we never sell your data, we choose AI providers configured not to train their models on your data and would change provider if that changed, the media you send is purged on a short schedule, and you can download or delete all of it whenever you want.
Who we are, and how to reach us
BU² is run by DRD AS, a company registered in Norway, organisation number 930 322 032, registered at c/o Daniel Döderlein, Dalstoppen 15, 3145 Tjøme, Norway. DRD AS is the data controller for the personal data described here, which means we decide why and how it is used, and we are responsible for it.
For any question about your data, to use one of your rights, or to reach our data protection contact, email daniel@kvad.studio.
DRD AS is established in the EEA, so we are not required to appoint an Article-27 EU representative.
What data we process, why, and our legal basis
We only process what we need to be your coach and to run the service. For each kind of data, here is what it is, why we use it, and the GDPR legal basis.
- Account and identity - your phone number (your WhatsApp identity) and login. Why: to know whose account is whose and to sign you in. Legal basis: performance of our contract with you (Art 6(1)(b)).
- Coaching content you send - your messages, food and training notes, weight, sleep, mood, goals, and the photos and voice notes you choose to send. Why: to understand you, remember your history, reply to you, and coach you. Legal basis: performance of our contract (Art 6(1)(b)); for the health parts, see the special-category row below.
- Payment data - your billing email, your plan, your payment status, and your phone number (your card is entered directly with Stripe and never stored by us). Why: to run your subscription and meet our accounting duties. Legal basis: performance of our contract (Art 6(1)(b)) and our legal obligation to keep accounting records (Art 6(1)(c)).
- Special-category health data - your cycle and menstrual logs (period dates, flow, symptoms), wearable biometrics if you connect a device (heart-rate variability, resting heart rate, sleep, and workouts including workout energy and distance), and your body-progress photos. Why: to give you cycle-aware and menopause-aware coaching, to factor your recovery and training load into your plan, and to give you a body check from a photo. Legal basis: your explicit consent (Art 9(2)(a)), given by your in-conversation opt-in and by your act of providing the data (agreeing when BU2 offers the feature, connecting a wearable and granting health permissions, or choosing to send a progress photo), not by accepting these general terms. These features are optional and BU2 works fully without them, so your choice is freely given, and you can withdraw at any time, after which we stop processing that data and delete it.
- Improvement (optional) - anonymised excerpts of your conversations. Why: to spot patterns and improve the coach for everyone. Legal basis: your separate, optional consent, off unless you turn it on, withdrawable any time in settings. The excerpts must be genuinely anonymised; where an excerpt is only pseudonymised and still carries health content, it remains special-category data and we rely on Art-9-grade explicit consent for it.
- Personalisation (core coaching) - building a coaching picture of you so the coaching, your history, and your replies are relevant. Why: to deliver the coaching you signed up for. Legal basis: performance of our contract (Art 6(1)(b)). Where any of this picture is built from special-category health inputs, that part rides on your explicit consent (Art 9(2)(a)) regardless.
- Proactive messaging (the nudge increment) - reaching out with unprompted check-ins, follow-ups, and nudges beyond what you ask for. Why: to make BU² proactive, not just reactive. Legal basis: our legitimate interest in a useful, proactive coaching service (Art 6(1)(f)); a legitimate-interest assessment (LIA) is on file. You can object to this proactive messaging at any time (Art 21).
A note on special-category (health) data
Some of what you may share with BU² is sensitive: your cycle, your biometrics, and your body. We treat this as special-category data under Article 9 of the GDPR, and we only process it on the basis of your explicit consent (Art 9(2)(a)).
These features are optional. BU² works fully without them, so your choice is freely given.
We rely on your explicit consent, which you give by choosing to turn the feature on after we explain it (for example, agreeing when BU² offers cycle-aware coaching), by connecting your wearable and granting health permissions on your device, or by choosing to send a progress photo. Accepting our general Terms is not how we obtain this consent.
When we offer one of these features we tell you it involves health data, that it is processed within the EU/EEA (and only ever reaches a provider outside the EEA under an appropriate safeguard such as the EU Standard Contractual Clauses), that we use it only to coach you, that we never sell it or use it to train AI models, and that you can withdraw and delete it at any time.
We keep a record of your choice (your conversation and your settings) so both you and we can see what you agreed to, and withdrawal is as easy as telling BU² to stop, which also deletes the related data.
If you connect a wearable through HealthKit, your explicit consent covers a one-time read of up to the last 90 days of the relevant history (a backfill), so BU² can understand your recent baseline before it starts coaching you; this backfill happens within the same consent scope and for that purpose only. We collect only what the coaching actually needs, and we never use this data to predict ovulation or fertility, for contraception, or for any medical purpose.
Automated processing (and what we do not do)
How the personalisation works: we build a coaching profile of you from your logs, your messages, and (only with your consent) your biometrics, and BU² uses it to time its check-ins and to tailor the coaching to you. This profiling is AI-generated.
This is human-in-the-loop coaching support, not an automated decision that produces a legal or similarly significant effect on you. We do not make decisions about you of the kind covered by Article 22 of the GDPR. Where something genuinely worrying comes up, BU² is designed to hand you back to a professional rather than to decide anything about you.
Where your data is processed (within the EU/EEA, and no one trains on it)
This is the part most people worry about, so here it is clearly. We process and store your personal data within the EU/EEA. If any data ever needs to reach a provider outside the EEA, we do so only under an appropriate safeguard such as the EU Standard Contractual Clauses, and we keep this policy accurate.
The one nuance is the messaging channel: BU² runs on WhatsApp, and Meta operates global infrastructure. Where any data must reach a sub-processor whose infrastructure is global, such as Meta for message delivery, we rely on that provider's own transfer safeguards, including the European Commission's Standard Contractual Clauses, so your data stays protected to the EU/EEA standard.
No AI model is trained on your data, ours or anyone else's. We choose AI models and providers that are configured not to use your data to train their models, and we would change provider if those terms changed. And we never sell your data.
Who processes data for us (sub-processors)
To run BU² we rely on a few trusted companies that process data on our behalf, under contracts that bind them to protect it and use it only for our service.
- Meta Platforms (WhatsApp Cloud API) - delivers your messages. Data: text, photos, voice notes, your phone number. Region: global infrastructure; protected by Meta's own transfer safeguards (Standard Contractual Clauses).
- Twilio - sends the SMS one-time codes used to sign you in. Data: your phone number and the login code (transient).
- Stripe - processes your subscription payments (your card is entered directly with Stripe; DRD AS is the seller of record). Data: billing email, plan, payment status.
- Google Cloud Vertex AI - analyses the photos you send for a body or meal read. Data: your photos. Region: EU (europe-west4); no retention of your photos.
- Google Cloud Speech-to-Text v2 - transcribes your voice notes. Data: your voice-note audio. Region: EU; audio is not logged, and files are auto-deleted within 24 hours.
- Google Cloud Text-to-Speech (Chirp 3 HD) - generates BU²'s voice replies. Data: the text of the reply. Region: EU-pinned.
- Anthropic (Claude) - the AI provider used to generate your coaching replies (conversational language processing). Data: the conversation needed to reply to you. Processed under the EU/EEA-or-SCC commitment above; provider configured not to train on your data.
Stripe acts in two roles. When Stripe processes your subscription payments on our behalf, it is our processor. For its own fraud-prevention, risk, and legal-compliance purposes (including anti-money-laundering), Stripe acts as an independent controller under its own privacy policy (Stripe privacy policy), and that processing is governed by Stripe, not by us.
Website analytics (marketing site only)
Our public marketing website - the pages that introduce BU² and lead to sign-up (landing, plans, subscribe, and the success page) - uses Google Analytics (GA4) to understand visitor traffic, measure how well our ads bring people to the site, and see how many visitors go on to start the service. This is opt-in: it only runs if you accept it in the cookie banner, and it is configured with IP anonymization and EU data settings.
That is the only place we use analytics, and the boundary is strict. Google Analytics runs on the marketing website only. It never follows you into the service: your coaching conversation, your messages, your account, and any personal or health data are never sent to Google Analytics or to any other analytics, tracking, or telemetry provider (no Sentry, Datadog, or similar). The service pages and the service itself carry no analytics at all. Your service data is stored on our own servers hosted in Google Cloud in the EU; message media is held on local disk, the database is local, and text embeddings are computed locally with no external embedding provider.
International transfers
We process and store your personal data within the EU/EEA. If any data ever needs to reach a provider outside the EEA, we do so only under an appropriate safeguard such as the EU Standard Contractual Clauses, and we keep this policy accurate. This applies, for example, to the global messaging infrastructure described above (such as Meta/WhatsApp): where data reaches a sub-processor whose infrastructure is global, we rely on an appropriate GDPR safeguard, such as the European Commission's Standard Contractual Clauses.
How long we keep it
- Photos and voice notes you send us are automatically deleted from our servers within 24 hours of being received, once they have been used to reply to you. Voice and media we send back to you are deleted within about an hour.
- Your coaching logs and profile are kept for the life of your account, so BU² can remember you and stay useful.
- When you delete your account, or ask us to delete your data, we scrub your data on request and then hard-delete it at the 30-day point, after a 30-day grace period. The hard-delete includes your special-category health data (your cycle logs, wearable biometrics, and body-progress reads) and the related chronicle rows and embeddings; these are not kept after that point.
- Accounting records for payments are kept for as long as Norwegian bookkeeping law (bokføringsloven) requires, which is 5 years.
You can export or delete your data at any time. See your rights below.
Your rights
Under the GDPR you have full control over your data, and the main controls are built into your account page:
- Access and portability - download everything we hold about you, in a portable format.
- Erasure - delete your account and your data.
- Rectification - have anything that is wrong corrected.
- Restriction - ask us to pause certain uses of your data.
- Objection - object to a particular use of your data. In particular, you can object at any time to the proactive messaging (the unprompted check-ins and nudges) that we run on our legitimate interest under Art 6(1)(f); if you do, we stop that proactive messaging.
- Withdraw consent - withdraw any consent you gave (for your health data, or for the optional improvement use) at any time, without affecting processing that already happened before you withdrew.
To use a right that is not yet a button, email daniel@kvad.studio and we will help.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet (datatilsynet.no), if you believe we have mishandled your data.
If there is a data breach
If a personal-data breach happens, we notify the Norwegian Data Protection Authority (Datatilsynet) without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to be a risk to your rights. Where a breach is likely to result in a high risk to your rights, we also tell you, the affected users, directly and without undue delay.
Changes to this policy
If we change how we handle your data, we will update this page and the version line below, and we will tell you about any material change.
Effective date: this is version 2026-06-23-v4 of the BU² Privacy Policy. The contracting and controlling party is DRD AS (Norway), organisation number 930 322 032.
Version 2026-06-23-v4.