Privacy Policy

Last updated: November 4, 2025

Your Privacy Matters

At BA Assistant, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1.Information We Collect

Account Information

When you create an account, we collect:

  • Email address (via Google OAuth)
  • Name and profile information from Google
  • Subscription tier and payment status
  • Optional profile details (first name, last name, position, country)

Usage Data

We automatically collect information about your use of the Service:

  • Generated documents (Use Cases, User Stories, Acceptance Criteria)
  • Document types, languages, and generation timestamps
  • Generation counts (daily and monthly)
  • Feature usage and interaction patterns
  • Browser type, device information, IP address
  • Access times and referring URLs

Payment Information

Payment processing is handled by Stripe. We do not store your credit card information. Stripe collects and processes payment data according to their Privacy Policy.

2.How We Use Your Information

We use the information we collect to:

  • Provide the Service: Generate documentation, manage your account, process subscriptions
  • Improve the Service: Analyze usage patterns, identify bugs, enhance features
  • Communicate with you: Send important updates, respond to support requests, notify about changes
  • Ensure security: Detect fraud, prevent abuse, enforce our Terms & Conditions
  • Comply with legal obligations: Respond to legal requests, protect our rights
  • Marketing (with consent): Send newsletters, product updates, promotional offers

3.Data Sharing & Disclosure

We do not sell your personal information. We may share your data with:

  • Service Providers: OpenAI (for AI generation), Stripe (for payments), Supabase (for data storage), Vercel (for hosting)
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In case of merger, acquisition, or asset sale
  • With Your Consent: When you explicitly authorize us to share your data

We never share your generated documentation content with third parties except as necessary to provide the Service (e.g., OpenAI for generation).

4.Data Storage & Security

We implement industry-standard security measures to protect your data:

  • Encryption: All data transmitted over HTTPS/TLS
  • Database Security: Hosted on Supabase with row-level security policies
  • Authentication: Google OAuth 2.0 with secure session management
  • Access Control: Restricted access to personal data by authorized personnel only
  • Regular Backups: Automated backups to prevent data loss

Data Location: Your data is stored on servers in the United States (Supabase/AWS).

Retention: We retain your data as long as your account is active. After account deletion, data is retained for 90 days for recovery purposes, then permanently deleted.

5.Your Privacy Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information (via Settings page)
  • Deletion: Request deletion of your account and data
  • Export: Download your generated documentation
  • Opt-out: Unsubscribe from marketing emails (link in every email)
  • Object: Object to processing of your data for certain purposes
  • Withdraw Consent: Withdraw consent for data processing (may affect Service access)

To exercise these rights, contact us at privacy@ba-assistant.com

6.Cookies & Tracking Technologies

We use cookies and similar technologies to:

  • Essential Cookies: Required for authentication and session management
  • Analytics Cookies: Track usage patterns to improve the Service (optional)
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling essential cookies may affect Service functionality.

7.Third-Party Services

Our Service integrates with third-party providers. Please review their privacy policies:

8.Children's Privacy

BA Assistant is not intended for users under 18 years old. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

9.International Data Transfers

If you access BA Assistant from outside the United States, your data may be transferred to and processed in the US. By using the Service, you consent to such transfers.

GDPR Compliance (EU Users): We comply with EU data protection laws. You have additional rights under GDPR, including data portability and the right to lodge a complaint with a supervisory authority.

10.Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be notified via email or in-app notification at least 30 days in advance.

The "Last updated" date at the top indicates when changes were last made. Continued use of the Service after changes constitutes acceptance of the updated policy.

11.Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

BA Assistant Privacy Team

Email: privacy@ba-assistant.com

General Support: support@ba-assistant.com

Company: StViga's Company

Our Commitment to Your Privacy

We are committed to protecting your privacy and ensuring transparency in how we handle your data. Your trust is paramount, and we continuously work to maintain the highest standards of data protection.