1. Who we are and what this covers
Bucky AI Inc. (“Bucky”, “we”, “us”) is a company incorporated in Ontario, Canada. We provide a pre-development platform that turns an address into sourced site intelligence, project analysis, and decision-ready deliverables.
This policy covers buckybuild.com, the signed-in Bucky product, the Bucky iOS app, and related communications (transactional email, newsletters, and demo booking). It does not cover third-party sites we link to, or municipal, catalogue, or open-data sources we query on your behalf.
2. Information we collect
The information we collect depends on how you use Bucky. Categories include:
- Account and profile. Email address, name, phone number if you provide one, date of birth if you provide one, user type, company, postal prefix, profile photo, social profile URLs, and sign-in method (email, Google, or Apple).
- Project and workspace. Project names, members, invites, budgets, program assumptions, notes, generated reports, and other content you create or upload in a project.
- Property and location. Addresses, map coordinates, parcel and lot identifiers, zoning and related site facts, Street View or map imagery references, approximate location from IP geocoding, and precise location when you grant the iOS or browser permission. Where public records include them, we may also store registered owner names and mailing addresses for a parcel.
- Browser extension. If you install the Bucky browser extension, it reads the page you are viewing only when you invoke it — by clicking the Bucky icon, using its keyboard shortcut, or choosing a Bucky item from the right-click menu. What it sends depends on what you asked for: a property address for a site lookup; the page URL when you save a site to a project; the page title, URL and up to 4,000 characters of page text when you send a question through Ask Bucky; and text you have highlighted when you choose to save it as a project source. The extension shows you the page context before it is sent, and it cannot read a tab you have not invoked it on.
- Files and site evidence. Documents you upload, extracted text from those files, and iOS site photos tied to a location when you allow camera, photo library, or location access.
- Payments. Stripe customer and subscription identifiers, invoices, and App Store / RevenueCat purchase records. We do not store full card numbers.
- Communications. Support emails, newsletter topic preferences, demo bookings, and, if you message @buckybuild on Instagram, participant IDs and message counts used to run that channel.
- AI content. Assist and marketing-chat prompts, relevant project context, and model replies. Marketing chat may also store IP address, user agent, and referrer.
- Device and usage. Push tokens and device metadata for iOS notifications; product analytics and session recordings when allowed; error reports; search queries; and cookie preferences.
3. How we use information
We use personal information to:
- Provide, secure, and improve the service, including authentication, project workspaces, maps, feasibility analysis, reports, and Assist.
- Process payments, trials, and subscriptions, and send transactional email (receipts, invites, security notices, product-required messages).
- Send marketing and product-update email. Creating an account currently enrols you in product updates and insights; every marketing email includes an unsubscribe link, and you can manage topics from your account.
- Book demos, respond to support requests, and operate our customer records in Attio.
- Understand product reliability and usage, including error monitoring that is not gated on analytics cookies.
- Comply with law, enforce these terms, and protect Bucky, our users, and the public.
4. How we share information
We share information with service providers who process it on our instructions, with other people you invite into a project, and when the law requires it. We do not sell personal information. Providers we use today include:
| Provider | What they do for Bucky |
|---|---|
| Supabase | Database, authentication, and file storage. |
| Vercel | Application hosting. |
| Mapbox | Address search, maps, tiles, static map images, and IP geolocation. |
| Stripe | Web payments, subscriptions, invoicing, and Connect payouts. |
| RevenueCat and Apple | iOS purchases, Sign in with Apple, push notifications, and on-device / Private Cloud Compute AI. |
| Sign in with Google; Google Analytics and Google Ads on the public marketing site. | |
| Resend | Transactional and marketing email. |
| Attio | Customer relationship records for sales and success. |
| PostHog | Product analytics and feature flags, gated on the analytics cookie on the web. |
| Microsoft Clarity | Session replay and heatmaps. On the web, recording follows the analytics cookie after the script loads. The iOS app enables Clarity analytics without a cookie banner. |
| Sentry | Error monitoring and session replay so we can fix outages. This is not treated as an analytics cookie. |
| Apollo and Ahrefs | Marketing-site visitor analytics and lead identification. These tags currently load on public pages without waiting for a marketing-cookie choice. |
| Sanity | Blog and announcement content delivery. |
| Azure and other model providers via Vercel AI Gateway | AI features such as Assist, document extraction, and report writing. |
Some providers are in the United States or other countries outside Canada. See International transfers below.
5. Cookies and similar technologies
We store a cookie named cookie:consent with your analytics and marketing choices (up to 180 days if you opt in; 7 days if you reject optional cookies, so we can ask again). Essential cookies keep you signed in and make the site work. They are always on.
Analytics cookies control PostHog on the web and Microsoft Clarity recording after the Clarity script has loaded. The marketing preference exists in that cookie, but Google Analytics, Google Ads, Apollo, and Ahrefs on the public marketing site currently load after idle time even if you have not accepted marketing cookies. We are treating that as a gap to close, not as consent.
Sentry error monitoring and Mapbox map requests are required to operate the product and are not behind the analytics toggle.
Use Manage cookie preferences on this page, or the banner when it is shown, to change optional cookies.
6. AI processing
Assist and related features send your prompt, relevant project context (which can include addresses and documents you have added), and the generated reply to model providers so they can produce an answer. iOS on-device models may keep prompts on the device, or use Apple Private Cloud Compute when that path is available.
We do not use your project content to train third-party foundation models. Providers process prompts to return a result for that request. Do not paste secrets, health information, or anyone else’s information that you are not allowed to share.
7. Property records and other people’s information
Site research uses public and licensed sources: parcel fabric, zoning, ownership rolls, and similar datasets. Those sources can include personal information about people who are not Bucky users — for example a registered owner name and mailing address.
We store that information to power project research, not to market to those owners. Access is limited in the product. If you believe we hold your information because you own a parcel someone else looked up, contact the Privacy Officer. We will review access, correction, or deletion against the public-record source and applicable law.
8. International transfers
Bucky is operated from Canada. Several processors — including PostHog, Sentry, Stripe, Mapbox, Google, Apollo, Ahrefs, Resend, Attio, Sanity, Vercel, and some AI providers — process data in the United States or other jurisdictions. When we transfer personal information outside Canada, we use contractual and organizational measures those providers offer, and we remain responsible for the information we send.
9. Retention
We keep account and project information for as long as the account is open and as long as we need it to provide the service, resolve disputes, or meet legal, tax, and accounting duties. Backups expire on their normal cycle.
If you delete your account from Settings, we run an account-deletion process that removes or anonymizes personal information we do not have to keep. Instagram interaction data can be deleted through the Data deletion page. Cookie preferences last as described above.
10. Your rights
Under PIPEDA and, where Quebec’s Law 25 applies, you may request access to the personal information we hold about you, correction of inaccuracies, deletion, a portable copy, and withdrawal of consent for optional processing. Quebec residents may also request that we stop disseminating their personal information or de-index a link we control, subject to the limits in Law 25.
Email hello@buckybuild.com with enough detail to identify you and the request. We may need to verify your identity. Use Settings to delete a Bucky account yourself. The Data deletion page is only for Instagram interaction data, not for a full account erase.
11. Children
Bucky is for people who are at least 18, or the age of majority where they live. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
12. Security
We use access controls, encryption in transit, and supplier contracts to protect personal information. No method of transmission or storage is fully secure. Tell us promptly at hello@buckybuild.com if you think your account has been misused.
13. Changes
We will post material changes on this page and update the date above. Where the law requires notice beyond posting, we will use email or an in-product notice. Continued use after the effective date means you accept the updated policy, except where a new consent is required.
14. Privacy Officer
The person responsible for the protection of personal information at Bucky AI Inc. is the Privacy Officer, who can be reached at hello@buckybuild.com. Mail: Bucky AI Inc., Ontario, Canada.
15. Governing law
This policy is governed by the laws of the Province of Ontario and the federal laws of Canada that apply there, including the Personal Information Protection and Electronic Documents Act (PIPEDA). Quebec’s Act respecting the protection of personal information in the private sector (Law 25) applies to personal information we hold about Quebec residents.