Privacy Policy
Effective Date: March 1, 2026
1. Introduction
MVPSalesBuddy ("we," "us," or "our") operates the website and application at mvpsalesbuddy.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
By using MVPSalesBuddy, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you sign in using Google OAuth, we collect the following from your Google account:
- Email address
- Display name
- Profile photo URL
2.2 Audio and Meeting Content
- Sales call audio recordings you upload (up to 25 MB per file)
- Meeting recordings captured by our bot integration when you provide a meeting URL (Zoom, Google Meet, or Microsoft Teams)
- Meeting URLs you provide for bot deployment
2.3 Generated Content
From your audio content, we generate and store:
- Call transcriptions
- AI-generated analysis (titles, summaries, key topics)
- Performance scores across multiple categories
- Coaching feedback and improvement recommendations
2.4 Usage Data
- Minutes of audio analyzed (for free tier tracking)
- Subscription status
- Account creation date
- File metadata (name, size, duration)
2.5 Technical Data
We use Vercel Analytics for performance monitoring. Vercel Analytics is privacy-focused, does not use cookies, and does not track personally identifiable information. It collects aggregated data such as page views, performance metrics, and general browser/device type.
3. How We Use Your Information
We use the information we collect to:
- Provide the core Service: transcribe and analyze your sales calls using AI
- Deploy meeting bots to record and analyze live meetings on your behalf
- Manage your account and enforce usage limits
- Generate performance scores, coaching feedback, and cross-call insights
- Communicate with you about your account when necessary
- Monitor and improve Service performance and reliability
4. Third-Party Service Providers
We share your information with the following third-party processors to provide the Service:
Google (Firebase)
We use Google Firebase for authentication (Google OAuth) and Google Cloud Firestore for data storage. Your account information and analysis results are stored in Google Cloud infrastructure.
OpenAI
Audio files are sent to the OpenAI Whisper API for transcription. Transcripts are then sent to OpenAI GPT-4o for analysis and coaching feedback. We use OpenAI's API, which is subject to OpenAI's API data usage policies, including zero data retention for API inputs and outputs.
Recall.ai
When you use the meeting bot feature, Recall.ai deploys a bot to join your video call (Zoom, Google Meet, or Microsoft Teams), captures the recording, and provides the transcript. Your meeting URL and audio data are processed through Recall.ai's infrastructure.
Vercel
We use Vercel for hosting, serverless functions, and privacy-focused analytics. Vercel processes requests to serve the application and may collect aggregated performance data.
Each third-party provider's own privacy policy governs their processing of your data. We encourage you to review their respective policies.
5. Data Storage and Security
- All user data is stored in Google Cloud Firestore with per-user access controls. Firestore security rules ensure that users can only read and write their own data.
- All data is transmitted over HTTPS with TLS encryption.
- Firebase Authentication is used for secure access management.
- Webhook communications from third-party services are verified using HMAC-SHA256 signature validation.
- Uploaded audio files are processed in memory on serverless functions and are not persistently stored after analysis. Only the resulting transcripts and analysis are retained.
While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Account data and analysis results are retained for as long as your account is active.
- You may request deletion of your data at any time by contacting us at support@mvpsalesbuddy.com.
- Upon account deletion, all associated data — including your user profile, call analyses, transcripts, and scores — will be permanently removed from our systems.
7. Your Rights
Depending on your location, you may have certain rights regarding your personal information:
European Economic Area (GDPR)
If you are located in the EU/EEA, you have the right to:
- Access and receive a copy of your personal data
- Rectify inaccurate personal data
- Request erasure of your personal data
- Restrict processing of your personal data
- Data portability
- Object to processing of your personal data
- Lodge a complaint with your local supervisory authority
Our legal basis for processing your data is your consent (provided at sign-up) and the performance of our contract with you (providing the Service).
California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information is collected about you
- Request deletion of your personal information
- Opt out of the sale or sharing of your personal information
- Non-discrimination for exercising your privacy rights
We do not sell or share your personal information for cross-context behavioral advertising.
Canada (PIPEDA)
If you are a Canadian resident, you have the right to:
- Access your personal information held by us
- Challenge the accuracy and completeness of your data
- Withdraw your consent to the collection, use, or disclosure of your personal information
To exercise any of these rights, contact us at support@mvpsalesbuddy.com. We will respond within the timeframes required by applicable law.
8. Cookies and Tracking
- We use Firebase Authentication session tokens to maintain your login state. These are essential for the Service to function and cannot be disabled.
- Vercel Analytics does not use cookies and does not track users across websites.
- We do not use advertising cookies, third-party tracking pixels, or retargeting technologies.
9. Children's Privacy
Our Service is not directed to individuals under the age of 16 (or 13 in jurisdictions where COPPA applies). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information promptly.
10. International Data Transfers
Your data may be processed in the United States, where our third-party service providers (Vercel, OpenAI, and Recall.ai) operate. If you are located outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States. By using the Service, you consent to such transfers. For EU/EEA users, we ensure that transfers comply with applicable data protection laws, including the use of appropriate safeguards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Effective Date." Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy. We encourage you to review this page periodically.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at: support@mvpsalesbuddy.com