Last Updated: September 12, 2026
Bujji Ai ("Bujji Ai", "the Service") is a Chrome browser extension and companion desktop application developed and operated by ZyloConnect Technologies Pvt Ltd ("we", "us", "our", "the Company"), a company incorporated in India, with its registered address at Moosapet, Balanagar, Hyderabad, Telangana 500018, India.
This Privacy Policy applies to the Bujji Ai Chrome Extension, the Bujji Ai Web Dashboard, the Bujji Desktop Engine (optional companion desktop application), and our website. It does not apply to WhatsApp, Meta Platforms, Google, or any other third-party service you connect to through Bujji Ai — please review their respective privacy policies.
Bujji Ai is offered to users worldwide. Where a specific law (such as the GDPR, CCPA, or India's DPDP Act) gives you rights beyond what's described generally in this policy, Section 8 explains how those apply to you.
Account & identity: Email address and, if you sign in with Google, your display name and profile picture. Firebase authentication session tokens and push-notification (FCM) device tokens, used to keep you signed in and deliver in-app alerts.
Subscription & billing: Your plan/tier, quota usage, and billing status. Payment card details are never collected or stored by us — they go directly to our payment processor (Razorpay); we only receive the plan you selected, the amount, and the transaction status.
Data that stays on your device: WhatsApp contacts and phone numbers, message drafts/templates, campaign logs, saved Smart Messages, and knowledge-base documents you upload for the on-device AI assistant are stored locally in your browser (chrome.storage.local / IndexedDB) and are not transmitted to our servers, except where this policy specifically says otherwise (for example, when you use an AI feature that requires sending text for processing, or when you explicitly sync to Google Sheets/Drive).
Approximate location (IP-based): We look up your approximate country/region from your IP address, using third-party IP-geolocation services. This is used to show pricing in your local currency and for optional location-aware features (such as weather). It does not use your device's GPS or precise location, and the IP address itself is not linked to your account profile.
Google Workspace data (only if you connect it): Bujji Ai requests two Google scopes: contacts.readonly and drive.file. With contacts.readonly we import contact names and phone numbers you choose. With drive.file we can only open spreadsheets you explicitly select through Google's file picker, and files Bujji Ai itself created (for example the "Bujji AI Logs" sheet and Drive backups) — we cannot browse or read the rest of your Drive. Depending on the feature, the data involved is phone numbers, names, tags, message templates, and messaging logs. Imported records are stored locally in your browser. Google user data is never sent to any AI model or AI provider: the AI features described in Section 3 work only from WhatsApp conversation content and files you upload directly (CSV), not from anything obtained through Google APIs.
Usage analytics: Anonymized, aggregated telemetry about which features you use and error/crash events, used to improve the product. Event data is filtered to exclude message content, contact names, and phone numbers. You can disable this in Settings → Privacy → Disable Telemetry.
Device/browser information: Browser type and version, operating system, and extension version.
Cloud AI drafting and replies: When you use cloud AI drafting or enable AI-generated replies, prompt text, relevant message excerpts, and any selected knowledge-base context are sent through Bujji Ai's relay infrastructure to the AI service handling that request. The relay processes the request to obtain a response. Provider retention and processing depend on the applicable service terms and configuration; this policy does not promise that every provider offers zero data retention.
AI Auto-Responder: Message matching and configured automation rules run on your device. Cloud-generated replies require external AI processing. Relevant customer or catalog fields may be included when you enable knowledge-based replies. You can stop automatic replies by disabling the feature. Do not treat the cloud Auto-Responder as a fully offline model.
On-device knowledge base (local RAG): Local embedding and search models index and retrieve knowledge-base information on your device; this indexing is retrieval, not training a foundational AI model, and these models run in a self-hosted/offline capacity — nothing processed by them is transmitted to the model publisher for computation, training, or any secondary purpose. Selected retrieved fields can be included in a cloud AI prompt to generate a reply. The knowledge base and business catalog are built only from files you upload directly (CSV) or type in; they cannot be connected to Google Sheets or any other Google data source, so no Google user data enters this pipeline.
General-assistant question cache: If you use Bujji Ai's general question-answering assistant (separate from the knowledge-base feature above), your question text is sent to a third-party AI provider to generate a vector embedding, and the question, the AI's answer, and that embedding are cached locally on your device for up to 7 days to speed up repeat lookups.
Automated messaging: The Auto-Responder and Campaign Engine send messages on your behalf, under rules and content you configure and control. You decide which contacts are messaged, what content is used, and can disable automation at any time. We do not use these features to make automated decisions about individuals (e.g., credit, employment, or legal-eligibility decisions) that produce legal or similarly significant effects on them.
Limited Use commitment: Bujji Ai's use and transfer of raw or derived information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Google user data, including raw, aggregated, anonymized, or derived data, must not be used, transferred, or sold to create, train, or improve foundational or generalized AI/ML models. We do not authorize such use by our AI service providers. Transfers for user-facing functionality must be limited to the requested purpose, require the user's consent, and comply with these restrictions. Because Bujji Ai never passes Google user data to any AI/ML service, no AI provider receives it under any plan or configuration.
We do not sell Google user data or use it for advertising, data brokerage, or creditworthiness decisions. Human access to Google user data is limited to the exceptions permitted by Google's policy, such as your documented consent for specific support, necessary security investigations, or legal requirements. A merger, acquisition, or asset-sale transfer of Google user data requires your explicit prior consent.
Disconnecting and deleting Google data: You can revoke Bujji Ai's Google access at Google Account connections. Revoking access stops future authorized access; it does not erase records already imported. Clear the extension's local data or uninstall it to remove its browser-stored copies, and remove any separate Desktop Engine data or exported backups you retained. Files and logs in your Google account remain under your control and must be deleted there. Contact [email protected] for help with deletion requests.
If you install the optional Bujji Desktop Engine, the Chrome extension exchanges WhatsApp session and message events, and campaign commands, with it over a local connection on your own device (Chrome's native messaging API). This exchange happens between applications running on your device and lets automation continue running even when your browser is closed. The Desktop Engine is subject to this same Privacy Policy for any data it sends to our cloud services (for example, account/subscription verification).
We do not sell, rent, or trade your personal information. We share data only with the service providers necessary to operate Bujji Ai, and only for that purpose. The table below identifies our service integrations and the data involved; which AI provider receives a request depends on the enabled feature and routing, including fallback routing; if you need written confirmation of the current list at any time, contact us at [email protected].
| Provider | Purpose | Data shared |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, push notifications, hosting | Account email, auth/FCM tokens, subscription data |
| Cloudflare | AI relay, CDN, analytics ingestion, abuse/rate-limit protection | AI prompts in transit (no Google user data), request metadata, usage events |
| Google Gemini, DeepSeek, NVIDIA, OpenRouter and its downstream model hosts, OpenAI (embedding integration) | Cloud AI generation, fallback generation, and applicable embedding features | Prompts, relevant WhatsApp message text, and context from files you uploaded directly; embedding input for applicable cloud embedding requests. Never Google user data |
| Vercel | Website/API hosting and AI relay | Request metadata and API payloads, including AI prompts when routed through this service (no Google user data) |
| WhatsApp / Meta and message recipients | Message delivery | Recipient identifiers and outgoing message content, including selected imported fields used in the message |
| Razorpay | Payment processing | Payment details (handled directly by Razorpay, not us) |
| IP-geolocation providers | Regional pricing / optional weather features | Your IP address, approximate location |
The Google user-data restrictions above take precedence over the general sharing terms below. We may also disclose information if required by law or court order, to protect the safety, rights, or property of Bujji Ai or our users, or as part of a merger, acquisition, or asset sale (with notice to you before your data becomes subject to a different privacy policy).
Account & support administration: Authorized Bujji Ai staff can, through an internal administrative system, adjust a subscription's status (for example, to activate, pause, or revoke access) for legitimate purposes such as resolving billing disputes, fraud prevention, or enforcing our Terms. This capability is logged and limited to account/subscription management — it does not give staff access to your locally-stored WhatsApp data.
Data that lives exclusively on your device (contacts, message templates, campaign logs, privacy settings, AI knowledge base) is deleted when you uninstall the extension or clear your browser data.
| Data type | Retention |
|---|---|
| Account credentials | Until you delete your account |
| Subscription & billing records | As long as necessary to comply with applicable tax, accounting, and financial recordkeeping laws (typically up to 7 years, which may vary by jurisdiction) |
| Usage telemetry (anonymized) | 24 months rolling |
| Support communications | 3 years from resolution |
| Error/crash logs | 90 days |
| General-assistant Q&A cache (local, on-device) | Up to 7 days |
You can request account deletion by emailing [email protected]. We aim to acknowledge privacy requests within 15 business days and complete deletion of your account and associated cloud data within 30 days of a verified request. Account deletion removes your profile, authentication, and locally-synced cloud data — it does not shorten the retention period for subscription and billing records described above, which we are required to keep for tax, accounting, and audit purposes regardless of account deletion. Data stored only on your device is removed immediately when you uninstall the extension.
We use TLS encryption for data in transit to our servers, Firebase security rules restricting database access to your own authenticated records, and isolate API keys so they're never exposed in client-side extension code. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
| Right | How to exercise it |
|---|---|
| Access a copy of your data | Email [email protected] |
| Correct inaccurate data | Update in Settings, or email us |
| Delete your account and data | Email [email protected] |
| Export your data | Use the Drive Backup feature |
| Opt out of marketing | Unsubscribe link in any marketing email |
| Opt out of usage telemetry | Settings → Privacy → Disable Telemetry |
EU/UK users (GDPR/UK GDPR): you have the right to access, correct, delete, restrict, and port your data, to object to certain processing, to withdraw consent, and to lodge a complaint with your local data protection authority.
California and other U.S. state users (CCPA/CPRA and similar laws): you have the right to know what personal information we collect, to delete it, and to opt out of its "sale" or "sharing" — we do not sell or share personal information as defined by these laws.
India users (DPDP Act 2023): you have the right to access, correct, and erase your personal data as described above, and to nominate another individual to exercise your rights in the event of death or incapacity.
Users in other jurisdictions: we will honor equivalent data-protection rights available to you under the laws of your country to the extent required.
Bujji Ai is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us at [email protected].
Bujji Ai operates by automating interactions with WhatsApp Web, a service operated by Meta Platforms. You are subject to WhatsApp's own Terms of Service and Privacy Policy, and are solely responsible for ensuring your use of Bujji Ai complies with WhatsApp's policies, including rules against spam and bulk unsolicited messaging. Bujji Ai does not access the WhatsApp Business API and is not affiliated with or endorsed by Meta Platforms.
Bujji Ai is available globally. Our infrastructure providers (including Google Firebase/Google Cloud and Cloudflare) operate data centers in multiple regions, including the United States. Depending on your location, your data may be processed in a country other than your own, under those providers' standard contractual clauses and data-processing addenda.
We may update this Privacy Policy from time to time. For material changes, we will notify you via an in-app alert or email at least 30 days before the change takes effect. Continued use of Bujji Ai after the effective date constitutes acceptance of the updated policy.
Email: [email protected]
Postal address: ZyloConnect Technologies Pvt Ltd, Moosapet, Balanagar, Hyderabad, Telangana 500018, India