BPMN BuddyOpen the app

Privacy and beta data notice · July 19, 2026

Your process deserves an honest data boundary.

BPMN Buddy is currently a controlled beta. This notice explains what the service stores and when an authorized operator may review it.

What the beta stores

The service stores workspace and workflow metadata, BPMN diagrams and revisions, change provenance, conversations with Buddy, and files you deliberately upload for workflow creation. It also keeps operational records such as AI run outcomes and source-import status so failures can be diagnosed.

Google sign-in

When you choose Google sign-in, BPMN Buddy receives the stable Google account identifier and basic profile information needed to create or find your account: your verified email address, display name, and profile metadata. The service does not request access to Google Drive, Gmail, Calendar, or other Google content, and it does not retain Google access or refresh tokens for sign-in.

Limited operator review

An authorized BPMN Buddy operator may review workflow and conversation content for product research, support, reliability, or safety. Aggregate usage is shown first. Opening private content requires a stated purpose and creates a separate, immutable access record. Administrative viewing is read-only and does not become a workflow edit or provenance event.

Service providers and AI processing

BPMN Buddy uses Google for account authentication, Railway and its connected database or object-storage services to operate and store the product, and configured OpenAI services to generate workflow proposals and analyze sources you intentionally submit. Prompts, relevant workflow context, and selected document text or rendered pages may be sent to the AI provider for those requested features. BPMN Buddy does not sell this data or use Google account data for advertising.

Do not upload sensitive material

The beta is not approved for classified information, CUI, secrets, credentials, protected health information, or other regulated personal data. Use representative or redacted process material until an appropriate organizational agreement and security review are in place.

Retention and account controls

Workspace data remains available so modeling sessions can be resumed and reviewed. Uploaded binaries follow the workspace retention controls. Individual sign-in sessions can be ended from the product. Account or data-removal requests are handled by the beta operator while self-service deletion controls are developed.

Direct privacy, export, or removal requests to privacy@bpmnbuddy.com. By using the beta, you also agree to the beta terms. The in-product feedback control prepares a draft for your review; it does not transmit anything automatically.