Privacy policy

Last updated

The short version

  • The website sets no cookies and runs no analytics or ad trackers. The one exception is the Talk page, where Google's booking calendar sets its own cookies.
  • When you use the demo app, the words you type or say (as text) go to an outside AI company to get an answer. We do not keep those words. We do not control what that company keeps.
  • If you use your voice in Chrome, Chrome sends your audio to Google to turn it into text. We never receive the audio.
  • If you join the waitlist, we keep your name, email, restaurant name and a few details, and we use them only to email you about the Heard beta. Email us any time to be removed.
  • We do not sell your information. We do not show you targeted ads. Heard is not for anyone under 13.

Heard is made by Buzzy Automation LLC, a two-person company in Dallas-Fort Worth, Texas.

This policy covers the Heard website and any address where we show the Heard demo or app. It also covers the Heard beta waitlist. It does not cover the Heard beta for real restaurants. That will have its own agreement (see section 11).

The addresses it covers today:

  • heardbybuzzy.com (the website)
  • app.heardbybuzzy.com and demo.heardbybuzzy.com (the demo app)
  • lineboard.buzzyautomation.com (the same demo app)

The same demo app also runs at a few other web addresses we use for our own outreach. This policy covers all of them.

1. Who we are and how to reach us

Buzzy Automation LLC, a Texas limited liability company run by Sheraz Gandhi and Manha Khan.

Use that one email address for any question or request in this policy.

2. The website (heardbybuzzy.com)

No cookies, no trackers

The website sets no cookies. It does not use analytics, pixels, tag managers, session recording or ad tags. The site itself stores nothing in your browser. Fonts and images come from our own server, not a third party.

The one exception is the Talk page, where Google's booking calendar runs inside a frame and sets Google's own cookies. See "The Talk page" below.

If any of this changes, we will update this page first.

Do Not Track and other parties

We do not track you across other websites, so we do not change anything in response to a Do Not Track or Global Privacy Control signal. The site works the same for everyone.

The only other party that collects data when you use this website is Google, and only on the Talk page (see below). No other company collects data about you on this site.

Connection records

Like any website, ours runs on a server. When your browser asks for a page, the server sees your IP address, browser type, the page you asked for and the site that sent you. The server writes this to a log. The log has no fixed deletion date: it is cleared each time we update the app, which usually happens within days or weeks.

The pretend phones on the site

Several pages (the home page, the demo page and the feature pages) show a pretend phone where you can type a line or tap a chip. Nothing you type there leaves your browser. The replies are canned. The microphone is switched off on every website page.

The demo video

The "Watch the demo" scene on the demo page is an animation with a sound file served from our own server. It starts only when you click it. Nothing is sent anywhere.

The Talk page (booking a call)

The Talk page shows Google's appointment booking page inside a frame. When that frame loads, your browser connects to several Google servers. Google receives your IP address and browser details, reads any Google cookies your browser already holds, and sets at least one new Google cookie. Google may run its reCAPTCHA check inside the frame. The page also makes one small request to calendar.google.com to check that the frame can load.

Anything you book (your name, email, the time you choose, and your answers) goes to Google Calendar and lands on Sheraz's calendar. Google's own privacy policy covers what Google does with it. We do not know how long Google keeps it.

The Google servers the Talk page connects to today:

  • calendar.google.com
  • www.google.com (reCAPTCHA)
  • gstatic.com
  • googleusercontent.com
  • play.google.com
  • calendar-pa.clients6.google.com

Some links take you to other sites, mainly our company site and Google's booking page. Those sites have their own policies and their own trackers. Our company site uses analytics and session recording tools that this site does not.

Links from this site to the demo app and to our company site carry a short tag that says you came from this site. Your browser also tells the site you land on where you came from. Our company site keeps that tag in your browser for up to 90 days under its own policy.

The sites we link to:

  • buzzyautomation.com (our company site)
  • app.heardbybuzzy.com (the demo app)
  • calendar.google.com (booking, on the Talk page)

3. The demo app

The demo app is a pretend kitchen called Juniper Kitchen. Its people, menu and numbers are made up. Nothing in it is real restaurant data.

What leaves your browser

Some replies come from the app itself, inside your browser. Others come from an outside AI model. The "Plain talk" setting controls this, and it is on by default. When it is on, the app sends these things to our server:

  1. The text of what you said or typed. Up to 500 characters per turn.
  2. Your last 3 commands and the app's last 3 replies, if they happened in the past 2 minutes. This gives the model the thread of the conversation. The app forgets them after 2 minutes, or when you switch which sample person you are viewing as.
  3. A small snapshot of the pretend kitchen. Up to 6 KB.

The snapshot holds:

  • which sample person you are viewing as
  • the sample staff and the restaurant name
  • the date, time and covers forecast
  • items that are low or out
  • open requests and the prep count
  • expected deliveries and suppliers

If you paste a recipe card into "Add a recipe", the app sends the card text (up to 6 KB). It also sends the sample stock list: ingredient names, units and pack sizes. No counts and no prices.

Where it goes

Our server passes that text to OpenRouter, a service that forwards requests to AI model companies. Today the default model is DeepSeek V4 Flash, and we may switch to another model we choose. OpenRouter decides which company's computers answer each request, and that can change from one request to the next. We do not know which country those computers are in.

We do not keep your text. Our server writes one log line per request with the status, the model, which company answered, the time it took, how many turns, token counts and the cost. It does not write your words, the snapshot or your IP address.

Since October 11, 2026, every request asks OpenRouter to send it only to model providers that, according to OpenRouter, neither keep your text nor use it for training. We rely on OpenRouter's routing and on those providers' own terms. We cannot check what they do ourselves.

Please do not type real people's names, real customer details or payment details into the demo. It is a pretend kitchen, and the text goes to outside companies.

Your voice

If you use the microphone, your browser turns your speech into text. Our code never receives the audio.

  • In Chrome, Chrome sends your audio to Google's speech service.
  • In Safari, Apple handles it.
  • In other browsers, that browser's maker handles it.

Each browser's own privacy policy covers that audio. We do not know how long they keep it. The only thing that reaches us is the text, as described above.

The app also shows a small level meter while you talk. That meter reads your microphone inside your browser only. Nothing is recorded and nothing is sent.

Spoken replies

"Read replies out loud" is on by default. You can turn it off in settings. When it is on, your browser or device reads the text with its own voices. Some voices (often labelled "Online" or "Natural") are run by the browser maker's servers. That is a browser setting, not ours.

Usage counts

The app sends us a tiny signal at a few moments: when you start a guided mission, finish a step, or click "Book a call". The signal holds the event name, the mission and the step. The first signal is sent as soon as you open the app for the first time, with no click, because the app starts the first guided mission for you.

The signal is a normal web request, so it reaches our server with your IP address, like any page load. The app uses the IP only to limit how many signals one address can send per minute (see "Limits on requests"). The count it stores has no IP address, no cookie and no id in it. Whether the server's own logs record the request is not yet confirmed (see "Connection records" and "Log retention").

Each day's totals are also written once to our server log, which is cleared each time we update the app. The totals file is kept for 400 days.

Limits on requests

The app keeps your address in the server's memory to count requests. It is cleared when the app restarts or when the list gets long. We do not save it in a database. There is also a cap on the total number of AI requests the app will make in a day.

Log retention

Our server log has no fixed deletion date. It is cleared each time we update the app, which usually happens within days or weeks.

What your browser keeps

The app saves your demo progress in your own browser (which sample person you chose, your layout, your settings and the state of the pretend kitchen). It sets no cookies. "Reset demo" in settings clears the pretend kitchen. Clearing your browser's site data clears the rest.

The app's "Book a call" link takes you to the Talk page on this website, with a tag that says you came from the app.

No outside scripts

The app loads nothing from third-party servers. No analytics, no ad tags.

4. The waitlist

Here is how the waitlist works.

What we ask for

  • Restaurant name
  • Your name
  • Email
  • Which point-of-sale you use (Square, Toast, Clover, other, or none)
  • City (optional)
  • A note (optional)
  • A checkbox saying yes to emails about the Heard beta

Where it goes

Your browser sends the form straight to Supabase, the company that hosts our waitlist table. Supabase's servers are in the US (Oregon). Supabase also sees your IP address and browser details as part of that request, as any web host does. We record the date and time and that the sign-up came from the waitlist page.

Who sees it

Only Sheraz and Manha at Buzzy Automation. We also use an AI assistant, Claude (made by Anthropic), to help us read and answer email and keep the list in order. It works inside our own accounts.

What we use it for

Only to email you about Heard and the Heard beta: when it opens, whether there is a place for you, and what to expect. We will not sell your details or give them to another company.

How long we keep it

We keep your waitlist entry until the beta opens or for 12 months, whichever comes first. After that we either delete it or email you once to ask if you still want to hear from us.

If you sign up more than once, we may hold more than one entry for you. When you ask to be removed, we remove them all.

Supabase keeps daily backup copies for 7 days, so a deleted entry can stay in a backup for up to 7 days before it is gone.

How to get off the list

Email sheraz@buzzyautomation.com, or use the unsubscribe link in any email we send you. We will stop emailing you within 10 business days and delete your entry within 30 days. We will confirm by reply.

5. Where your data is kept

WhatWho holds itWhere
The website and the demo appHetzner, on a server we rentA server in Nuremberg, Germany
Usage counts and server logsSame Hetzner serverSame
Waitlist entriesSupabaseUnited States (Oregon)
Text you send the demo appOpenRouter and the AI model company it picksUnknown to us
Your voice, if you use itYour browser's maker (Google in Chrome, Apple in Safari)Their servers
Call bookingsGoogle CalendarGoogle's servers
Emails you send usGoogle Workspace (Gmail), our email providerGoogle's data centers

6. Who else gets your data

We share data only with the companies that do a job for us, listed here. We do not sell it and we do not trade it.

  • Hetzner: hosts the website, the demo app and the usage counts.
  • Supabase: holds the waitlist table.
  • OpenRouter and the AI model company it routes to: receive the text you send the demo app.
  • Google: receives your voice audio in Chrome, and runs the booking page on the Talk page.
  • Apple: receives your voice audio in Safari.
  • Your browser's maker, if you use another browser's voice or read-aloud feature.
  • Google Workspace (Gmail): holds the emails you send us.
  • GitHub: holds our source code. No visitor data is in the code.
  • Anthropic (Claude): the AI assistant that helps us read and answer email and keep the waitlist in order.

If we add a company to this list, we will update this page.

7. How long we keep things

WhatHow long
Text you send the demo appWe do not keep it. Outside companies: not in our control
Voice audioWe never receive it
Usage count totals400 days
Server log linesNo fixed date; cleared each time we update the app
Waitlist entriesUntil the beta opens or 12 months, whichever comes first
Call bookingsIn Google Calendar until we delete them
Emails you send usIn our mailbox until we delete them; no set date

8. Your choices and rights

Wherever you live, you can ask us:

  • what information we have about you,
  • to correct it, or
  • to delete it.

Email sheraz@buzzyautomation.com. We will reply within 45 days. We may ask you to confirm your email address so we know it is you. We will not treat you differently for asking. If we say no to a request, we will tell you why, and you can ask us to look at it again.

We do not sell your personal information. We do not share it for targeted advertising. We do not use it to build a profile of you.

Where your data is processed. The site and the demo app run on a server in Germany. The waitlist is kept in the United States (Oregon). Text sent to the AI helper, voice transcription and the Google calendar are handled by those companies wherever they run, which we do not control (see the table in section 5). So if you are in the United States, parts of your data are handled outside the US.

If you live in Texas. Texas law may give you the rights above, and the right to get a copy of your data in a usable form.

If you live in California. California law may give you the rights above, plus the right to know what categories of information we collect and why. We do not sell or share personal information as California defines those words.

If you live outside the United States. If your country's law gives you more rights, email us and we will do our best to honor them.

9. Children

Heard is for people who run and work in restaurant kitchens. It is not for anyone under 13, and it is not aimed at children. We do not knowingly collect information from children under 13. If you believe a child has given us information, email us and we will delete it.

10. Emails from us

We email waitlist members only about Heard and the Heard beta. Every email we send will have an unsubscribe link and our mailing address, and you can also just reply and say stop. We do not send text messages and we do not ask for your phone number on the waitlist.

11. The beta for real restaurants

If you join the Heard beta as a founding restaurant, Heard will hold more than this page covers. That means staff names and work emails, recipes, costs, stock counts, suppliers, prep lists, and the items on each sale if you connect your point-of-sale system.

A separate Beta Agreement will cover all of that. It will have its own section on data. It will be in place before any real restaurant data goes in.

When the point-of-sale link is built, it will be built to drop your customers' names, card numbers, payment details and tips before anything is saved. Heard will not store them.

12. A plain note on security

This page describes what happens to your data. It does not make security promises. We hold no security certifications, and we would rather tell you what we do than use a label.

What we can say today, as facts about how the demo app works:

  • It limits how many requests one address can send, and it caps the total number of AI requests per day.
  • It checks where a request comes from. That check blocks other websites' pages from calling it. It does not block a script that fakes the check.
  • Our server does not write your words to its logs.

If you find a security problem on the site, please email sheraz@buzzyautomation.com and tell us what you found, instead of testing it further.

If we ever learn that your data was exposed, we will tell you by email.

13. Changes to this policy

If we change this page, we will change the date at the top. If the change matters to waitlist members (for example, a new company that gets their data), we will email them before it takes effect.

14. Contact

Buzzy Automation LLC 18484 Preston Rd, Ste 102 #635, Dallas, TX 75252 sheraz@buzzyautomation.com 972-885-3979