1. Introduction
Chartbuddy ("we," "us," or "our"), operated by Chartbuddy B.V., is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information when you use the Chartbuddy Services ("the Services"). By using the Services, you agree to the collection and use of information in accordance with this policy. If you do not agree to this Privacy Policy, please do not use the Services.
Chartbuddy B.V. is the data controller for the personal data described in this policy.
1.1 The products this policy covers
Chartbuddy is charting software available in these products:
- Chartbuddy Hub: a desktop application for macOS and Windows. Charts are stored on your own device.
- Chartbuddy for Google Slides™: a Chrome extension that builds and edits charts inside Google Slides.
- Chartbuddy for PowerPoint: a Microsoft Office add-in that builds and edits charts inside PowerPoint. Chart rendering runs in your Office application; the slide file stays on your device or in your Microsoft 365 account.
- Remote MCP connector: an optional hosted Chartbuddy connector for AI assistants such as Claude. It is not Chartbuddy Hub. Chart configuration sent through this connector is stored temporarily as described in Section 3.6.
Additional products we make available later are covered by this Privacy Policy when we release them, unless we publish product-specific privacy terms. Chartbuddy Embed is distributed separately as an npm package under its own package license and is not covered by this Privacy Policy. Enterprise customers who execute a Master Subscription Agreement with Chartbuddy may be subject to additional data processing terms, including a Data Processing Addendum (DPA), as set out in that agreement. Any customer can request a DPA, whether or not they have such an agreement. See our Data Processing Addendum page.
2. Data Protection Officer
If you have any questions about this Privacy Policy or how we handle your personal data, you may contact our Data Protection Officer:
- Email: tim@chartbuddy.io
3. Information Collection
3.1. Types of data
Across the Services, we process the following types of data:
- Account information: Name, email address, and organization name for authentication, billing, and support.
- Authentication data: Credentials and tokens needed to sign you in and keep a session, including where you connect a Google account.
- Google integration data: Identifiers for the Google Slides presentations you select for use with Chartbuddy for Google Slides™.
- Organization branding and templates: House style settings and chart templates configured for your organization. These are stored on Chartbuddy servers. The templates feature is intended for clean, non-sensitive chart examples, not for confidential or personal data.
- Usage analytics: Anonymized or aggregated data on how you interact with the Services. This does not include chart content or spreadsheet data.
- Diagnostic data: Crash reports and technical telemetry from Chartbuddy Hub.
For Chartbuddy Hub, Chartbuddy for Google Slides™, and Chartbuddy for PowerPoint, chart configuration and spreadsheet data are processed on your own device. Source spreadsheet data and slide text are not sent to Chartbuddy's backend. Chart images for Google Slides may be transferred briefly as described in Section 3.2. The Remote MCP connector is different: see Section 3.6.
3.2. Data transfer
Chart image transmission depends on your storage configuration:
- Chartbuddy Managed Storage (Default): Rendered chart images are temporarily transferred to Chartbuddy's Google Cloud Storage (Europe-West4, Netherlands) for approximately two seconds to enable insertion into Google Slides via signed URLs. Images are deleted immediately after insertion, with a lifecycle rule as failsafe. Your source data, spreadsheet content, and slide text are not transmitted to our backend.
- Bring Your Own Google Cloud Storage: Chart images are transmitted directly from your browser to your Google Cloud Storage bucket. Chartbuddy does not receive or process these images.
Google Slides integration: The Chrome extension communicates directly with Google Slides APIs. Your presentation content flows between your browser and Google's infrastructure. Access is limited to the presentations you select.
3.3. Chartbuddy Hub
Charts you create in Hub stay on your own device. We do not receive or store their content. Hub contacts us for sign-in, plan checks, software updates, and crash or technical telemetry.
3.4. Chartbuddy for Google Slides™
Chart configuration and spreadsheet data are processed locally in your browser. Chart image transfer for insertion into Google Slides is described in Section 3.2.
3.5. Chartbuddy for PowerPoint
Chartbuddy for PowerPoint is a Microsoft Office add-in. PowerPoint loads the add-in from our HTTPS origin and runs the chart editor in Office's webview on your device. Chart configuration is processed in that webview. You sign in to Chartbuddy to use the add-in, so we process the account and authentication data described in Section 3.1. Your chart content and the data behind your charts are not sent to Chartbuddy's backend.
Charts you create are stored in the PowerPoint file you are editing: as an image on the slide and as Chartbuddy metadata in that file (including shape tags). Microsoft hosts PowerPoint and stores files you save to OneDrive or SharePoint under your agreement with Microsoft.
Opening our support or marketing pages in a browser is covered by the rest of this policy (including cookies and analytics on the website).
3.6. Remote MCP connector
The Remote MCP connector is an optional hosted Chartbuddy service. It is not Chartbuddy Hub. If you choose it, the chart configuration you send through that connector is stored temporarily in Google Cloud in the Netherlands so later tool calls can edit the same chart.
A chart becomes inaccessible 24 hours after its most recent chart operation. Google Cloud Firestore then deletes it automatically. That physical deletion is asynchronous and may take around a further 24 hours.
Exported files are stored in a restricted bucket, become eligible for deletion one day after creation, and are not kept through Cloud Storage soft delete. The Chartbuddy-hosted download link used to retrieve an export expires after five minutes and does not require a Chartbuddy credential.
3.7. Data storage
Our backend stores account and authentication metadata needed to run the Services, and organization branding settings and templates as described in Section 3.1. Chart content and spreadsheet data from day-to-day Hub, Google Slides, and PowerPoint editing are not stored by our backend. Chart configuration sent through the Remote MCP connector is stored as described in Section 3.6. We will not sell your personal data to third parties.
4. Lawful Basis for Processing Personal Data
We process your personal data based on the following lawful bases under the General Data Protection Regulation (GDPR):
- Performance of a Contract: Processing is necessary to provide the services you have requested.
- Legitimate Interests: Processing is necessary for our legitimate interests in improving and securing the Services, provided that these interests are not overridden by your rights. We rely on this basis for crash reports and technical telemetry from the desktop application.
- Consent: Where required, we will obtain your consent before processing your personal data.
5. How We Use Your Information
We use your information for the following purposes:
5.1. Authentication
- To verify your identity when accessing the Services, and to determine which plan applies to your account.
5.2. Customer Service
- To provide you with effective and efficient customer support.
5.3. Customization
- To tailor your experience based on your preferences and your organization's settings.
5.4. Security
- To protect your account and our services from unauthorized access and security threats.
5.5. Improvement
- To enhance features and performance based on anonymized usage data, crash reports, and technical telemetry.
5.6. Research
- To conduct analysis and produce reports regarding the use of our services, based on anonymized and aggregated data.
6. Information Sharing and Disclosure
We may share your information in the following circumstances:
6.1. Legal Requirements and Protection
- We may disclose your information if required by law or subpoena, or if we believe it is necessary to:
- (a) Comply with legal obligations or requests from law enforcement.
- (b) Enforce our Terms and Conditions.
- (c) Protect the rights, property, or personal safety of our company, our users, or others.
6.2. Business Transfers
- In cases where we buy, sell, divest, or transfer the company (including shares or any combination of our products, services, assets, or business segments), your data may be transferred as part of the assets. If this occurs, we will notify you promptly of the change.
6.3. Aggregate/Anonymized Information
- We may share aggregated or anonymized data about the use of our services for analytics or marketing purposes. This data does not identify individual users and is not restricted by this Privacy Policy.
6.4. Consent
- We may disclose your information to third parties when we have your explicit consent or a legal basis other than consent.
6.5. Subprocessors
- We use carefully selected subprocessors to help deliver our backend services. For a current list of our subprocessors, please see our Subprocessors page. That page also states which subprocessors apply to which product.
6.6. Advertising Measurement
- Where you reach us through one of our advertising campaigns, we share a pseudonymised identifier with that advertising platform so we can measure whether the visit led to a signup.
7. International Data Transfers
Apart from the cases described below, all personal data is processed and stored within the European Economic Area (EEA) and we do not transfer your personal data outside the EEA. Should a further transfer become necessary, we will ensure appropriate safeguards are in place, such as standard contractual clauses, to protect your data.
Where your organization signs in with enterprise single sign-on (SAML or OIDC), authentication data is processed by our SSO provider outside the EEA. In that case we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework where the recipient is certified under it. See our Subprocessors page for the provider and location. The advertising measurement described in Section 6.6 also involves a transfer to the United States, under the same safeguards.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law. Retention periods are determined based on legal, contractual, and regulatory obligations.
9. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
9.1. Right to Access
- You have the right to request access to the personal data we hold about you.
9.2. Right to Rectification
- You have the right to request correction of any inaccurate or incomplete personal data.
9.3. Right to Erasure
- You have the right to request deletion of your personal and user-generated data. For detailed instructions on how to delete your account and data, please see our Account and Data Removal Guide.
9.4. Right to Restrict Processing
- You have the right to request the restriction of processing your personal data under certain circumstances.
9.5. Right to Data Portability
- You have the right to receive your personal data in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller.
9.6. Right to Object
- You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
9.7. Right to Withdraw Consent
- If processing is based on your consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at legal@chartbuddy.io. We will respond to your request within 30 days.
10. Artificial Intelligence and Automated Access
10.1. We do not train models on your data
We do not use your chart content, your data, or your personal data to train machine learning models, and we do not permit our providers to do so.
10.2. Connecting an AI assistant
Chartbuddy Hub. You may connect an AI assistant to Hub through the Model Context Protocol (MCP). That connection runs locally on your own device. Chartbuddy does not receive your prompt or Hub chart data.
Remote MCP connector. This is a separate, optional hosted Chartbuddy service for assistants such as Claude. It is not Hub. The connector receives the chart-tool arguments needed to perform the request, processes them in our Google Cloud environment in the Netherlands, and stores the chart configuration temporarily as described in Section 3.6. It uses a Chartbuddy access token limited to charting. The AI assistant does not receive the Google, Microsoft, enterprise SSO, or password credential you use to sign into Chartbuddy. Your organization administrator can disable Remote MCP access, and you can decline the connection on the Chartbuddy authorization screen.
10.3. Your AI provider, not ours
When you prompt an AI assistant to build a chart, your prompt and any data you give it are first handled by that assistant's provider under your own agreement with them. Chartbuddy is not a party to that agreement. For Chartbuddy Hub, Chartbuddy does not receive your prompt or chart data. For the Remote MCP connector, the assistant sends the chart-tool arguments needed to perform the request to Chartbuddy; those arguments can include chart content. If you need to know how the assistant provider handles your data before it reaches us, consult that provider's privacy notice.
10.4. Automated Decision-Making and Profiling
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
11. Data Security
11.1. Transmission Security
- All personal and sensitive user data transmitted between the Services and our servers are encrypted using HTTPS, ensuring secure data transfer.
11.2. Data at Rest
- Personal data stored on our application servers is encrypted using strong encryption methods such as RSA or AES. Those servers are located in Amsterdam, the Netherlands, within the European Union. Chart configuration stored for the Remote MCP connector is held in Google Cloud in the Netherlands, as described in Section 3.6.
12. Data Breach Notification
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify you and the relevant supervisory authorities as required by GDPR.
13. Children's Privacy
The Services are not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are under 16, please do not use the Services or provide any personal data to us.
14. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this Privacy Policy periodically.
15. Contact Information
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: legal@chartbuddy.io
16. Complaints
If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority in the European Union, particularly in your country of residence or where the alleged infringement occurred.
17. Compliance with Chrome Web Store User Data Policy
This section applies to Chartbuddy for Google Slides™, which is distributed as a Chrome extension. Our use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- Allowed Use: We only use your data to provide or improve the extension's features, in line with its purpose of helping you create charts.
- Allowed Transfer: We do not transfer your data to third parties except as necessary for the extension's functionality or as required by law.
- Prohibited Practices: We do not use your data for personalized advertising or allow unauthorized human reading of your data.
18. Information Control
18.1. Access and Update
- You can access and update your personal information by logging into your account.
18.2. Data Deletion
- You can delete your Chartbuddy account and all associated data directly from your profile settings. For step-by-step instructions, please see our Account and Data Removal Guide. If you need assistance with account deletion or have questions about data removal, please contact us at support@chartbuddy.io. In some instances, we may need to retain certain information even after a deletion request if required to fulfill legal obligations, regulatory standards, or to safeguard against fraud and abuse.
- Charts stored on your own device in Chartbuddy Hub, or already placed in your presentations, are yours and are not affected by deleting your Chartbuddy account. Chart configuration stored for the Remote MCP connector follows Section 3.6.
18.3. Managing Communications
- You can opt out of receiving promotional emails from us by clicking the "unsubscribe" link in those communications. To stop receiving essential service-related notifications (such as account verification, billing confirmations, feature updates, and security alerts), please contact us at legal@chartbuddy.io.
19. Cookies and Similar Technologies
We use cookies and similar technologies on our website to provide functionality, improve user experience, and analyze usage patterns. For detailed information about the cookies we use, how we use them, and how you can manage your preferences, please see our dedicated Cookie Policy.
20. Third-Party Services
The products you install do not themselves embed third-party services that collect personal or sensitive user data. However:
- When using Chartbuddy Managed Storage: Google Cloud Storage is used temporarily (approximately 2 seconds) to transfer chart images to Google Slides.
- Backend Services: Our web application uses the subprocessors listed on our Subprocessors page.
By using the Chartbuddy Services, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by its terms.