PUBLIC PRIVACY INFORMATION
Privacy notice.
Last reviewed: 29 September 2026
This page describes paid beta membership for adults, complimentary invitations for adults, and externally paid concierge access.
Controller and contact
A Large Company Ltd trading as Ughbusting AI, company number 17290014, is the controller.
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email privacy requests to alexander@alargecompany.com.
What the browser stores
The browser stores local copies of task-promise labels, call tasks, plans, progress, summaries, feedback, saved transcripts, diagnostics, simulated fines, and preferences.
Task-promise labels stay in account-scoped browser storage. The server receives no task label.
Local storage does not mean that all call content stays local. OpenAI processes live speech, typed turns, selected call details, and current tool values.
Saved call sheets never return to OpenAI. Optional camera video stays in the browser.
Stripe handles card and billing details. Ughbusting AI does not receive or store your full card number.
If you opt in to product analytics, the browser also stores a PostHog identifier.
What data the service uses
Account and sign-in data
- Supabase Auth stores your email address, authentication subject, and sign-in records.
- If you choose Google sign-in, Google receives the authentication request and returns your verified email address and basic profile to Supabase Auth.
- Google sign-in requests only OpenID, email, and profile access. It does not give the Calendar feature a token.
- The application database stores opaque account and invite identifiers, account state, role, session version, and timestamps.
- An invitation record states whether the administrator supplied the former UK adult attestation or issued access under the current adult service terms.
- A membership order records the exact adult statement version you accepted and that you are aged 18 or over. It records no residence claim. Older orders can hold the former UK adult attestation.
- When public registration is enabled, it records your declared country. The application derives a billing currency (GBP for GB or USD for another admitted country) from that declaration for pricing and stakes; it does not independently confirm your country from billing or IP evidence.
- If you accept it, a separate automatic-collection consent record stores its fixed version, your acceptance timestamp, and that you can withdraw it independently of your stake mandate. It contains no payment card data.
- A trial-ending, payment, or stake-event lifecycle notice records its kind, the account it belongs to, and content evidence limited to amount, currency, cap, and dates -- never free text.
- The application database stores your username, first-call schedule, first-call start boundary, and first-call completion record. The stake slider and the membership-interest step were removed on 17 September 2026; an account created before that date can still hold those older fields.
- The application database stores your selected Ugh Buddy, room, clothing, accessories, item unlocks, completed-call count, stub balance, purchases, and change revision.
- A first-call schedule contains the start time, IANA time zone, and selected 30-minute or 60-minute duration.
- The first-call record also stores whether you used the extra early-exit retry and its fixed recovery reason.
- A requested next visit stores its start time, duration, time zone, reminder choice, state, and opaque version.
- Optional reminder preferences store your time zone, quiet hours, and request for one membership reminder after seven days.
- Reminder delivery records contain opaque identifiers, due and expiry times, attempt counts, states, and provider delivery references. They contain no call content.
- A weekly plan contains your IANA time zone, weekly hour choice, call dates, start times, 30-minute or 60-minute durations, and lock time.
- A future leaderboard can show your username. No username is public in this release, and call content is never part of a leaderboard.
- Resend receives your email address and authentication-email delivery data for account creation and sign-in links.
- Current access is by invitation to adults aged 18 or over. Public registration is closed until the release gate enables it.
Optional Google Calendar connection
- Calendar connection is separate from Google sign-in. You choose it from the weekly planner and can disconnect it at any time.
- The application requests permission to read free or busy periods and to manage events on calendars that you own.
- The application asks Google for busy intervals across every calendar you own or have chosen to show in Google Calendar, not just your primary calendar. It does not ask for event titles, descriptions, locations, guests, or meeting links, and it does not ask for or store the names of your calendars.
- The application also asks Google for the list of your calendars -- their IDs only, never their names -- so it knows which calendars to check for busy time. This uses Google’s calendar.calendarlist.readonly permission.
- The application creates private events named "Ughbusting call". Each event contains its time and an opaque slot identifier. An event can also contain the normal call-page link. The link contains no sign-in secret or account identifier.
- Supabase stores connection time, granted scopes, an encrypted refresh credential, and opaque Google event references. Access tokens stay in server memory only.
- The application does not store busy intervals. Disconnect removes the connection and event references. If Google revocation fails, the encrypted credential stays in a private retry queue until revocation succeeds. Events already in Google Calendar remain until you delete them there.
Task promises and rewards
- A task-promise label stays in account-scoped storage in the browser where you arm it.
- The application does not send task-promise labels to the server, OpenAI, Resend, diagnostics, rewards, or billing records.
- The database stores an opaque request identifier, deadline, cancellation lock, shadow stake, state, fixed proof kind, and timestamps.
- A task promise stores its deadline, selected stake, completion declaration, state and content-free records needed for its waiver and any payment. The task label stays in this browser and is not sent to our servers. Optional photo or screenshot proof is planned and is not available yet; no image is collected now. If uploads become available, you may choose to upload one photo or screenshot for a task before its deadline. We will ask for your separate, optional consent at your first upload, after showing you the image-processing details; accepting this policy does not opt you in. You and Alex may see the live image; Alex is the only reviewer and may mark it seen or ask for a clearer image. Images can reveal health information or information about other people. Live access ends seven days after the task deadline. Your own completion declaration decides whether the task is done. Uploading an image, choosing not to upload, and Alex’s review have no effect on a charge. We will not send proof images to AI services, Realtime voice, diagnostics, logs, email or payment providers. We will explain the final storage, deletion and backup terms before upload opens.
- A missed task can create a shadow penalty. If live stakes are enabled for your account, separate accepted stake terms can instead create a card charge after the waiver period, but only when you armed that task after accepting the mandate.
- The live-stake record stores the selected amount, member-local monthly cap, time zone, mandate version, payment state, and content-free provider identifiers. It never stores the task label.
- Task notice records contain the penalty identifier, notice kind, delivery state, attempt count, and timestamps. They contain no task label.
- Timely task completion can award stubs. Stub awards and Buddy purchases use content-free identifiers and amounts.
Membership and payment data
- The application sends your account email, monthly membership plan, currency, selected price, and fixed purchase-acceptance version to Stripe Checkout. A combined Checkout also sends your chosen stake, monthly cap, and separate automatic-collection consent version.
- Stripe processes your billing address, payment method, transaction details, and fraud-prevention data. The application does not receive or store your full card number.
- The application database stores pseudonymous Stripe customer, Checkout, price, subscription, and event identifiers with plan, status, acceptance, and timestamp evidence.
- A complimentary or externally paid service account can use Stripe Checkout in setup mode to save a payment method without buying a subscription. The proposed public combined Checkout uses one setup session before an owned trial subscription is created.
- Live accountability stakes require separate fixed-version terms and payment authority. The database stores the acceptance time and content-free Stripe Checkout, SetupIntent, PaymentMethod, invoice, payment, and event identifiers.
- A missed task fine waits at least 24 hours after the task deadline and can be waived during that period. Weekly promises are record-only under every stake mandate and never lead to a charge. Booking misses follow separate make-up and clearance rules. A member-local monthly cap limits live stakes.
Live call and consent data
- Your microphone audio and live conversation go directly from your browser to OpenAI Realtime.
- Before each voice call, you must give separate explicit consent for special-category data that you choose to share.
- This consent covers special-category data that you choose to share during the current call; that call’s task, plan, progress, summary, carry-over, feedback, and transcript saved in this browser; and OpenAI abuse monitoring.
- The possible categories are racial or ethnic origin, genetic data, political opinions, religious or philosophical beliefs, trade-union membership, health, sex life, and sexual orientation.
- The service does not ask for, infer, profile, or require special-category data.
- The service does not use your voice or other biometric data to identify you.
- The database consent evidence contains account and session identifiers, the fixed Article 9 statement version, an affirmative value, and server timestamps. It contains no call content.
- Normal call completion ends the live-call purpose. It does not withdraw consent for saved browser content or change OpenAI’s up-to-30-day abuse-monitoring period.
- You can withdraw consent at any time. During a call, select "Withdraw consent and end call". After a call, select "Delete this call and withdraw local consent".
- OpenAI content that was already received can remain under its abuse-monitoring rules for up to 30 days.
Call content
- OpenAI returns assistant audio and recognised speech. The application does not send saved call sheets back to OpenAI.
- The browser stores local tasks, plans, progress, summaries, feedback, and recognised call transcripts.
- During a generic call, OpenAI processes the selected task, cadence, live turns, and current tool values.
- A generic reconnect can send the saved plan and progress. The known message flow can send only the safe first name, cadence, and setup stage.
- Optional camera video stays in the local video element. It does not go to OpenAI, Vercel, Supabase, or Resend.
- After a terminal call, you can separately choose to share one bounded transcript with authorised Ughbusting AI administrators for product improvement. The live-call consent does not authorise this optional sharing.
- A shared copy contains the selected task, recognised speech, typed turns, assistant audio transcripts, clipped and interrupted markers, terminal outcome, and optional feedback. It excludes raw audio, camera data, tokens, SDP, device data, IP addresses, cookies, provider responses, and browser or provider identifiers.
- Authorised administrators can review a shared copy for up to seven days. You can delete it sooner. The hourly job deletes it from live storage within one hour after expiry; backups can retain a deleted copy for up to seven more days and are not used for product review.
- An early deletion creates a signed content-free marker in a separate private Vercel store before Supabase removes the live copy. The marker contains opaque identifiers, the deletion actor, and timestamps. It contains no transcript content.
Admission and technical data
- The application database stores opaque reservation identifiers, duration, timestamps, state values, allowances, and secret-request results.
- After the browser has persisted a started first call, the database records its opaque reservation identifier and a server timestamp. This blocks later schedule changes. It is operational metadata, not attendance or completion evidence.
- Voice calls send bounded content-free operations events and cumulative numeric usage through Vercel to Supabase.
- The service records content-free 20-hour and 30-hour membership usage alerts for internal capacity review. These alerts never block a call.
- Supabase calculates estimated cost from an immutable price table. The browser does not send a cost value.
- Operations events exclude tasks, transcripts, summaries, audio, camera data, raw errors, provider text, credentials, tokens, SDP, devices, user agents, cookies, and raw IP addresses.
- A keyed digest of your IP address limits sign-in, token, and terminal-fault requests. These controls do not store the raw IP address.
- Vercel still processes request IP addresses and request metadata as the hosting provider.
- One terminal voice fault can send fixed technical values and a random request identifier to Vercel logs.
Optional product analytics
- Product analytics is optional and off by default. It starts only after you choose "Yes, share usage data" while signed in. It never runs for a visitor who is not signed in. It runs only on the call and dashboard pages of the application, never on public pages, this privacy notice, or the administrator, invitation, call-link, or privacy-request pages.
- If you opt in, PostHog receives the address of each page you visit and of the page that linked to it, without any query string or fragment. It also receives clicks on application controls with the control text and attributes masked, your browser and operating system and their versions, the browser user-agent text, your device type, your screen and window size, your browser language, and your time zone.
- If you opt in, PostHog also records session replays. A replay masks all text and all typed input. The live call view, transcripts, task and promise text, onboarding answers, and the weekly planner are blocked from replays entirely. A replay records no network requests, console output, or canvas content.
- PostHog links these records to your internal account identifier only. The application sends it no email address, name, or other profile detail.
- Product analytics never collects tasks, promises, transcripts, call audio, camera data, onboarding answers, your email address, your name, or payment details. PostHog does not receive your IP address, because requests reach it from our server, not your browser. PostHog records no location.
- A consent record stores the fixed policy version, your acceptance time, and any withdrawal time. It contains no analytics content.
Why the service uses data
- Create and authenticate registered accounts, then send private sign-in links.
- Run a requested Realtime accountability call and return recognised speech and assistant audio.
- Control call admission, reconnects, allowances, security limits, and the application budget.
- Protect the service and diagnose terminal voice faults without sending call content to the server log.
- Give the account holder local call history, feedback exports, preferences, and deletion controls.
- Record content-free task promises, self-declared outcomes, stakes, waivers, payment evidence, and Buddy stub rewards.
- If you opt in, understand how members use the application and fix confusing parts of it, using masked product analytics and session replays.
- Show anonymous Google Calendar conflicts across every calendar you own or have chosen to show, not just your primary calendar, and create or update requested Ughbusting call events.
- Contract supports membership signup, payment, renewal, cancellation, access, and service-confirmation processing.
- Legitimate interests supports the requested beta service and account administration.
- Legitimate interests supports authentication, security, admission, fixed diagnostics, and content-free operations measurement.
- Legitimate interests supports requested task promises, shadow accountability records, and content-free Buddy rewards.
- Contract supports separately accepted live-stake terms, the payment mandate, the displayed cap, waivers, and collection through Stripe.
- Legal obligation supports six-year pseudonymous stake mandate, invoice, payment, refund, and dispute evidence.
- Legal obligation supports rights handling and the minimum compliance records.
- Explicit consent is the Article 9 condition for special-category data that a user chooses to share during a live call.
- Consent is the Article 6 lawful basis for optional seven-day shared transcripts used for product improvement.
- Consent supports the optional Google Calendar connection. You can withdraw it with the disconnect control.
- Separate explicit consent is the Article 9 condition for optional seven-day shared transcripts used for product improvement.
- This release processes no marketing data.
- Consent is the Article 6(1)(a) lawful basis for optional product analytics and masked session replays. It is off by default. You can withdraw it at any time in Account, under "Privacy and account data". Withdrawing does not affect your membership or any other feature.
- For members in Canada, your opt-in is your express consent to optional product analytics. You can withdraw it at any time in the same way.
Service providers and international processing
Your information may be processed outside the country where you live, including in the UK, Ireland, Germany and the US. While it is in another country, that country's courts, law enforcement or national security authorities may be able to access it under local law.
OpenAI
Realtime speech, recognised speech, assistant audio, and API security monitoring.
The project is in the Global region. Training sharing is disabled. API logging is enabled per call. No Zero Data Retention approval is proved.
Read the official provider sourceVercel
Application hosting, request processing, the fixed server diagnostic log, and the private transcript-deletion replay store.
The team uses Pro. Web Analytics Plus is available, but this application does not integrate Vercel Analytics. The private store ughbusting-deletion-ledger was provisioned in London region lhr1 on 26 August 2026 and connected to Production. Its live content-free canary and non-empty isolated restoration drill passed. Vercel documents AES-256 storage encryption and customer-data backups every two hours with 30-day retention. Runtime-log retention is one day. Vercel also handles requests to our /ingest route, which passes analytics data to PostHog only for members who opted in.
Read the official provider sourceSupabase
Managed authentication, private Postgres control metadata, and optional shared transcripts.
The project uses Pro in London. Daily physical backups run. Point-in-Time Recovery is off.
Read the official provider sourceOptional social sign-in, anonymous Calendar availability checks, and creation or update of Ughbusting call events.
Sign-in and Calendar use separate OAuth clients and grants. Calendar refresh credentials are encrypted, access tokens stay in memory, and busy intervals are not stored.
Read the official provider sourceResend
Delivery of account-creation, invitation, sign-in, promise, requested visit and membership reminders, task notices, membership-confirmation, and content-free shared-transcript review emails. Member emails are escaped, image-free HTML from a plain Ughbusting identity; no email renders Buddy artwork.
The workspace uses Free. Email is sent through Ireland, but Resend stores message content, delivery logs, webhook payloads, and account records in the United States. Free email and log data is retained for 30 days while the account is active; backups persist for seven days, and remaining customer data is deleted within 90 days after account termination. The DPA includes EU Standard Contractual Clauses and the UK Addendum for transfers. Open and click tracking are off.
Read the official provider sourceStripe
Hosted Checkout, saved payment methods, recurring membership payments, standalone stake invoices, receipts, retries, refunds, fraud prevention, and the account billing portal.
Stripe receives the account email and handles billing and card details. The application stores provider identifiers, fixed mandate and contract versions, amounts, states, and timestamps. It never stores a full card number or task label.
Read the official provider sourcePostHog
Optional product analytics and masked session replays, only after you opt in.
PostHog, Inc., of San Francisco, United States, provides the service from its EU Cloud, hosted on Amazon Web Services in Frankfurt, Germany. It acts as a processor under its data processing agreement. Data in transit can pass through Cloudflare’s global network. PostHog is a US company. For any transfer to the United States, its agreement relies on the EU-US Data Privacy Framework with its UK Extension, and on the EU Standard Contractual Clauses with the UK transfer addendum. Requests go through our own /ingest route on Vercel, which forwards no cookie, authorisation, or client IP header to PostHog. The project is set to discard client IP addresses and has location lookup turned off. The free plan is used.
Read the official provider sourceSome provider account and subprocessor-notice evidence remains a release gate.
Retention and deletion
- Account-local browser content
- 180 days after the last meaningful use, or earlier deletion by the user.
- Browser call sheets
- The newest 20 sessions, with a 180-day maximum age.
- Browser diagnostics
- The newest 250 fixed technical events, with a 30-day maximum age.
- Active account identity
- While the account stays active.
- Onboarding profile
- The username, first-call start boundary, and first-call completion record remain while the account stays active, or until account deletion. An account created before 17 September 2026 can also retain the older shadow-stake and membership-interest fields, which the current onboarding no longer sets.
- Ugh Buddy profile, rewards, and unlocks
- The selected appearance, room, items, content-free progress, stub ledger, purchases, and unlock evidence remain while the account stays active, or until account deletion.
- Browser task-promise labels
- The newest 50 labels remain in the account-scoped browser store until local or account deletion.
- Task promises
- Opaque task settings and states remain while the account stays active, or until account deletion.
- Requested visits and reminder delivery records
- 30 days after completion, cancellation, suppression, or expiry. Earlier account deletion removes these records.
- Optional reminder preferences
- While the account stays active, or until account deletion. Withdrawal stops future requested reminders.
- Task notice delivery records
- 90 days after the latest creation, claim, failed delivery, accepted delivery, or notice expiry. Earlier account deletion removes these records.
- Task shadow-penalty evidence
- Content-free amount, state, waiver, and timestamp evidence remains while the account stays active, or until account deletion. It contains no task label.
- Live-stake mandates and financial evidence
- Completed mandate, invoice, payment, refund, and dispute evidence remains pseudonymous for six years. Pending or processing stakes are voided on account deletion. The record contains no task label.
- Booking penalty evidence (a missed booked call or an unbooked week)
- A non-stake booking penalty remains 90 days after it occurred. A settled penalty with live-stake authority remains pseudonymous for six years, the same as other financial evidence. A pending, processing, failed, or held penalty keeps its slot and plan link while it stays open.
- First-call schedule
- Until the user cancels it, its call timer starts, the first call completes, or the user deletes the account.
- Weekly call plans and usage alerts
- 90 days after the planned week or alert time, or earlier account deletion for identifiable plans.
- Google Calendar connection and event references
- While connected, or until disconnect or account deletion. Access tokens and busy intervals are not stored. Created Google events remain in the member’s calendar.
- Google Calendar revocation debt and evidence
- A failed revocation keeps the encrypted credential in the private retry queue until Google revocation succeeds. Success clears the credential. The remaining content-free evidence stays for three years.
- Disabled or revoked accounts and failed or expired registration links
- 30 days before deletion eligibility.
- Identifiable admission and operations rows
- 90 days. The paid-beta release activates daily deletion only after the approved retention sequence. Before activation, no automatic schedule applies.
- Public lifecycle notice outbox rows
- 90 days after the row’s own due time. The record contains amount, currency, cap, and date evidence, never free text.
- Automatic-collection consent record
- While the account stays active, or until account deletion. Withdrawal stops future automatic attempts and is itself recorded as a separate timestamped event.
- Operational live-call consent and withdrawal state
- Until its pending or bound call expiry. The paid-beta release activates daily deletion only after the approved retention sequence. Before activation, no automatic schedule applies.
- HMAC IP-limit rows
- Rows expire after their limit window. The paid-beta release activates five-minute cleanup only after the approved retention sequence. Before activation, no automatic cleanup schedule applies.
- Minimal invitation, consent, rights-request, and deletion evidence
- Three years. These records contain no call content.
- Optional shared transcript
- The live copy lasts up to seven days after completion or sharing, whichever is earlier. The hourly job removes it within one hour after expiry; backup residue can remain for up to seven more days.
- Shared-transcript administrator access events
- 90 days. Events contain fixed values and no transcript content.
- Shared-transcript deletion outbox and signed markers
- Completed Supabase outbox rows and private Vercel Blob markers remain for three years. Pending outbox rows remain until deletion completes. These content-free records contain opaque identifiers, the deletion actor, and timestamps. Vercel can retain deleted Blob-marker residue in its backups for 30 additional days.
- Ordinary support records
- 12 months.
- Membership, refund, and contract evidence
- Pseudonymous plan, price, acceptance, payment, and subscription records remain for six years. A refund case remains actionable until its final resolution, then remains for six years.
- Stripe payment records
- Stripe applies its own legal, fraud-prevention, and account-retention periods.
- Application session cookie
- Eight hours, or earlier sign-out or revocation.
- OpenAI Realtime content
- Default abuse-monitoring content can remain for up to 30 days.
- Supabase database backups
- The current Pro plan provides daily backups with seven days of access.
- PostHog identifier cookie and browser storage
- Set only after you opt in. The cookie ph_ followed by our project key, and matching browser storage, hold a random identifier and session details. They last up to one year after your last use, or until you withdraw consent, when the application removes them from this browser.
- PostHog analytics events
- PostHog keeps events for one year on the free plan. PostHog does not state when it deletes older events, so they can remain after that year until you withdraw consent or delete your account.
- PostHog session replays
- 30 days after recording, unless you withdraw consent or delete your account first.
- PostHog data after withdrawal or account deletion
- Within 30 days after you withdraw consent or delete your account, we ask PostHog to delete your analytics events and replays. During the beta, an operator does this by hand. PostHog destroys replays when it receives the request and deletes events later in a background job.
- Product analytics consent record
- While the account stays active, or until account deletion. Withdrawal stops future capture and is itself recorded with its own timestamp.
This deployment runs the configured five-minute HMAC cleanup and daily general-retention schedules. Their activation required a preview, a separately approved manual prune, and a zero re-preview.
The separately configured hourly transcript-share expiry job removes only expired shared transcripts and their linked content-free records.
Your information rights and support
Open Account to delete this browser's local data. In History, Saved conversations can delete one saved conversation or all saved conversations. Diagnostics can delete all local diagnostics.
The internal response target is 28 days. The legal deadline can change for a complex request.
Use the privacy email for access, correction, deletion, restriction, objection, portability, complaints, or support.
The applicable rights depend on the approved lawful bases and the circumstances of each request.
Read the request routes and current release blockerYour right to object
You have the right to object to processing based on legitimate interests.
This covers the beta service, account administration, authentication, security, admission, fixed diagnostics, and content-free operations measurement.
Email the privacy contact or use the privacy-request route. The controller will stop the processing unless a lawful exception applies.
Product analytics is based on consent, not legitimate interests. You can withdraw it at any time in Account, under "Privacy and account data", or by emailing the privacy contact. Withdrawal stops new capture straight away and does not affect your membership.
Object to legitimate-interests processingRelease gates
- Complete the ICO data-protection fee self-assessment.
- Record each provider agreement, international-transfer safeguard, account identity, support-access rule, retention fact, and subprocessor-notice owner.
- Run one existing-account live-call consent journey before external self-registration.
- Complete one controlled live charged-and-waived cycle on the controller’s own card before an external live stake.
Artwork credits
The 3D room includes "Bonsai" and "Gramophone" by Don Carson (CC BY 3.0), via Poly Pizza. Other 3D models are CC0 (no attribution required) from creators including Quaternius, CreativeTrio and Isa Lousberg. Bonsai source Gramophone source
Complaints
Contact the controller first if you can. You can also complain to the Information Commissioner's Office.
Information Commissioner's Office complaint guidance