Privacy Policy
1. Who we are
Maddy ("we," "us," or "our") is an AI-powered marketing assistant for restaurants, operated by V, based in San Jose, CA. Questions? Email us at v@getmaddy.com.
2. Information we collect
From restaurant owners (you):
- Name and restaurant name — provided at signup
- Phone number — used to send and receive SMS messages via Maddy
- Menu photos and text — sent via MMS or typed in conversation; used to build your knowledge base
- Brand preferences — autonomy level, brand voice, posting schedule; stored to personalize Maddy's behavior
From connected accounts (via OAuth):
- Instagram Business Account — access tokens stored encrypted; used to post content, read and reply to comments and DMs on your behalf
- Google Business Profile — access tokens stored encrypted; used to read and reply to Google reviews on your behalf
- We never store your Instagram or Google password
From your customers (indirectly):
- Instagram comments and DMs directed at your account — read to generate replies; not stored beyond what's necessary to craft the response
- Google reviews on your listing — read to generate replies; not stored beyond the response workflow
Automatically:
- Usage metrics — posts published, comments replied to, engagement counts; stored per day for your daily summary
- Standard server logs — IP addresses, request timestamps; retained for 30 days for security and debugging
3. How we use your information
- To operate the Maddy service — posting to Instagram, replying to comments and reviews, sending you summaries and alerts
- To personalize content — using your menu, brand voice, and schedule preferences
- To send SMS notifications — post drafts, approval requests, review alerts, daily summaries
- To process payments — your billing information is handled by Stripe; we never see or store your card number
- To improve the service — aggregated, anonymized usage patterns only
We do not use your data to train AI models, and we do not sell your data to any third party.
4. Third-party services
Maddy relies on the following services to operate. Each has its own privacy policy.
- Twilio — SMS/MMS delivery (privacy policy)
- Meta / Instagram — Instagram and Facebook API access (privacy policy)
- Google — Google Business Profile API (privacy policy)
- OpenAI — GPT-4o vision for photo analysis and text embeddings (privacy policy)
- Anthropic — Claude for caption and reply generation (privacy policy)
- Stripe — subscription billing (privacy policy)
- Google Cloud Platform — infrastructure, storage, and databases (privacy policy)
- Vercel — landing page hosting (privacy policy)
5. Data storage and security
- All data is stored on Google Cloud Platform infrastructure in the United States (us-central1)
- OAuth tokens (Instagram, Google) are stored in Google Secret Manager — encrypted at rest, never in plain text
- Media files (your photos) are stored in Google Cloud Storage with access controls
- All data in transit uses TLS encryption
- We apply the principle of least privilege: each service only accesses the data it needs
6. Data retention
- While your subscription is active, we retain your tenant data, menu knowledge base, and analytics
- On subscription cancellation, we begin a 30-day grace period; after 30 days all your data is permanently deleted — including your Weaviate knowledge base, GCS media files, Firestore records, and Secret Manager tokens
- Your Twilio number is released and reassigned after deletion
- Server logs are deleted after 30 days
7. Your rights (CCPA and general)
You have the right to:
- Access — request a copy of the data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — request permanent deletion of all your data at any time, including before your subscription ends
- Portability — request your data in a machine-readable format
- Opt out of SMS — reply STOP to any Maddy text message at any time
To exercise any of these rights, email v@getmaddy.com. We respond within 10 business days.
8. SMS messaging
By signing up for Maddy AI, you consent to receive SMS messages from your dedicated Maddy AI number. Message frequency varies based on your activity. Message and data rates may apply. Reply STOP to unsubscribe at any time. Reply HELP for help.
9. Children's privacy
Maddy is a business tool for restaurant owners and is not directed at anyone under 18. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy as the service evolves. We'll notify active users via SMS before material changes take effect. The "last updated" date at the top of this page always reflects the current version.
11. Contact
Questions, data requests, or concerns:
v@getmaddy.com
San Jose, CA, United States