BuyerEngineAI Terms of Service · Privacy Policy · Sign in

Privacy Policy

Last updated: 16 September 2026

This policy explains what personal data BuyerEngineAI collects, where it comes from, why we use it, who sees it, how long we keep it, and what you can do about it. It is written for our customers, for the Reddit users our customers find and contact through the software, and for anyone who visits https://buyerengine.hustlegrow.com. If anything is unclear, email support@hustlegrow.com.

Contents

  • 1. Who we are
  • 2. What this policy covers
  • 3. Who we hold data about
  • 4. Account holders
  • 5. Buyers through JVZoo and WarriorPlus
  • 6. Agency client sub-accounts and partner-branded copies
  • 7. Reddit users whose public posts we collect
  • 8. People who exchange Reddit private messages with our customers
  • 9. Site visitors
  • 10. Cookies and browser storage
  • 11. Who receives your data
  • 12. Transfers outside the EU and EEA
  • 13. How long we keep data
  • 14. Automated processing and AI
  • 15. The Trusted Accounts pool
  • 16. Telegram notifications
  • 17. Admin access
  • 18. Security
  • 19. Your rights
  • 20. Rights of Reddit users who are not our customers
  • 21. Children
  • 22. Changes to this policy
  • 23. Contact

1. Who we are

BuyerEngineAI is made and run by HustleGrow AB, Hälsjögatan 11, 217 66 Malmö, Sweden. Organisation number 559504-9494. VAT number SE559504949401. Email: info@hustlegrow.com. Support: support@hustlegrow.com. We have not appointed a data protection officer. Send privacy requests to info@hustlegrow.com.

We are a Swedish company, so the EU General Data Protection Regulation (GDPR) and Swedish data protection law apply to everything in this policy.

We are the controller for account, purchase and platform data. For the Reddit users our customers find and contact, we and the customer (for Agency licences, the agency owner) are joint controllers (GDPR Article 26). In short: the customer decides whom to search for and whether to reply or message, and answers for that contact being lawful. We decide how the software collects, scores, stores and secures the data, and answer for that. You can use your rights against either of us. We handle requests for both (section 20). For the data inside an agency client sub-account, the agency owner is the controller and we are its processor (section 6). For security records, AI usage records and AI Learning statistics we act as controller for all accounts, on the basis of our legitimate interest.

2. What this policy covers

This policy covers:

  • the web application at https://buyerengine.hustlegrow.com, including sign-up, login, the dashboard, every tool inside it, and our admin area;
  • the service emails we send (password resets, welcome emails, purchase confirmations, replies to feedback);
  • our Telegram bot, if you choose to connect it;
  • public lead report pages (created with the Export to Web Page button in the Lead Monitor; the page itself is titled Reddit Lead Generation Report) that customers can publish from the software;
  • partner-branded copies of the software that run on our platform under another name or domain.

It does not cover what Reddit, JVZoo, WarriorPlus, Telegram or Google do with data you give them directly through their own services; each has its own privacy policy. Companies that process data on our behalf, such as OpenAI, MailerSend, Hostinger and DataForSEO, are covered by this policy and listed in section 11; we remain responsible for their processing. We are not affiliated with or endorsed by Reddit.

The software is for business use by people aged 18 or over. Our Terms of Service govern your contract with us. This policy explains the personal data side of that contract.

3. Who we hold data about

  • Account holders. People who sign up or are given a login.
  • Buyers. People who buy through JVZoo or WarriorPlus. Usually the same people as account holders.
  • Agency client sub-accounts. People for whom an Agency customer has created a login.
  • Reddit users whose public posts we collect. People who post or comment on Reddit and whose public content matches a customer's search. These people have not signed up with us.
  • People who exchange Reddit private messages with our customers. Reddit users who receive a message from a customer through the software and may reply. They have not signed up with us either.
  • Site visitors. Anyone who loads a page at https://buyerengine.hustlegrow.com, including public lead report pages, or who messages our Telegram bot without linking an account.
  • Our own Trusted Account holders. The Reddit accounts in the shared pool are operated by us. Where a pool account was originally registered by an individual, we hold that person's Reddit username, karma figures, account age, tokens (which our daily keep-alive job refreshes even when the account is idle), status, our internal notes, and a health record (failed writes, the subreddits they failed in, the last Reddit error text, action counts) from which we derive whether the account looks restricted. We hold these as controller, on the basis of our agreement with them (Article 6(1)(b)), and delete the tokens and profile record when the account leaves the pool. Usage records refer to a pool account by an internal number that our staff can link to the account. We do not revoke the app on the owner's Reddit account for them; they should do that at reddit.com/prefs/apps.

4. Account holders

The table below lists what we hold about you as an account holder. "Contract" means we need the data to provide the service you signed up for (GDPR Article 6(1)(b)). "Legitimate interest" means we have weighed our interest against yours and named the interest (Article 6(1)(f)). You can object to any legitimate-interest processing (section 19).

To open an account we need a name, an email address and a password; without them we cannot create an account. Everything else in the table is optional and depends on the features you use. If an agency owner created your login, section 6 applies instead: your agency owner is the controller and decides the legal basis, and we hold the data as their processor.

What we holdWhere it comes fromWhy we use itLegal basis
Your name and email address You type them at sign-up. If you bought through JVZoo or WarriorPlus, the payment platform sends them to us and we create the account for you. If an agency created your login, the agency owner typed them. To identify your account, log you in, send password resets and service emails, and reply to your feedback. We do not verify your email address at sign-up. Contract
Your password You choose it, or we generate a starting password when the payment platform creates your account and email it to you. To log you in. We store only a bcrypt hash, never the password itself. Contract
Account activity: creation date, last login, number of logins, plan tier, credit balance, purchase transaction ids, account status Generated by the software, or sent by the payment platform To run your account, apply credit limits and tier features, handle refunds, and support you Contract
Failed login attempts: the email address typed, the IP address, the time Your browser To block brute-force attacks. We block after 8 failed logins, or 8 password-reset requests, for one email address, or 30 from one IP address, within 15 minutes. Legitimate interest: keeping accounts secure
Password reset records: a hash of the reset token, when it expires, when it was used, and the IP address that asked for it Generated when you, or anyone else, asks for a password reset for your email address To make each reset link single-use and valid for one hour, and to investigate abuse Legitimate interest: keeping accounts secure
Session identifier Set by the software when you log in (see section 10) To keep you logged in between page loads Contract
Your Reddit connection: your Reddit username, the OAuth access token and refresh token Reddit issues to us, when they expire, when you connected, and whether you have chosen to act as your own account or through the Trusted Accounts pool Reddit, when you authorise the app on Reddit's consent screen. The sign-in is completed on our main domain and the tokens are passed to the software through our own database. Completed handoffs are removed from that database when the software collects them; abandoned handoffs are not removed automatically today and are cleared by hand. To search Reddit, post comments, send and read private messages, and check your account health on your behalf. The app asks Reddit for these permissions, without expiry: identity, read, submit, private messages, flair, edit, history, my subreddits, save, subscribe, vote. It uses identity, read, submit and private messages. One legacy endpoint can also read a subreddit's flair list (flair). The other six (edit, history, my subreddits, save, subscribe, vote) are requested but not used. We intend to drop them. While you have open message threads the software reads the 50 newest items in your Reddit inbox every few minutes, including messages unrelated to the software, and keeps only replies to threads it opened. Contract
Your products and offers: name, website URL, description, price, business type, industry, target and excluded subreddits and keywords, auto-scan and auto-reply settings, custom comments; the keywords, intent phrases and subreddits the AI suggests; up to 2,500 characters of text our server fetches from your website URL; a numeric "embedding" of your product description You type them in. The AI expands them. Our server fetches your web page. To build Reddit searches, judge which posts match your product, and draft replies Contract
Scan, campaign and outreach settings: scan job parameters and progress, Done For You campaign settings and plans, follow-up rules, copilot or autopilot mode, pitch settings, message templates, tracked brand and competitor terms, keywords you type for Google rank checks You To run the features you switch on Contract
Agency sales page: page title, slug, product name and details, cart and button code, and footer HTML, all stored as you typed them (the hero image upload on that page does not store an image today) You To build the sales page offered in the Agency dashboard Contract
Notes, tags and pipeline status you add about leads and conversations You To give you a simple CRM over your prospects Contract
AI usage records: which feature called the AI, the model, token counts, whether the call succeeded, the time Generated on every AI call To attribute cost and flag unusually heavy use for a human to look at. Our admin sees this per user. Legitimate interest: controlling cost and preventing abuse
AI Learning outcome records: for each comment you post through the software, the Reddit comment id, post id, link, subreddit, time, which feature posted it, whether it carried your offer link, a hash of the comment text, which account posted it, and whether Reddit later kept or removed it Generated when you post, then re-read from Reddit by our software To learn which subreddits remove comments or links, and to steer future scans and replies. Statistics are pooled across all customers. AI Learning is on by default and you can switch it off (section 19). Legitimate interest: improving the service
Trusted Accounts usage: which pool account acted for you, the action type, the subreddit, the time Generated when you post or message through the pool To apply daily caps, rotate accounts, and let our admin see who is using which account (section 15) Contract, and legitimate interest: protecting the pool accounts
Telegram link: your Telegram chat id, Telegram username, notification level, link time Telegram, when you tap the link we generate To send you notifications and answer bot commands (section 16) Contract, at your request
Feedback: your name, email, feedback type, message, time You, through the feedback box To read, answer and act on your feedback. Feedback is also emailed to our support inbox, with your name and address as the sender so we can reply to you. Contract
Terms acceptance: the date and time you ticked the sign-up box and the version of the Terms shown Generated when you sign up To show that you accepted the Terms, and which version Legitimate interest: proving the contract; legal obligation where the law requires it
Your preferences: AI Learning on or off, which Reddit identity you post as, Telegram notification level You To honour your choices Contract

Things worth knowing

  • Your website is fetched by our server. When you save a product or offer with a URL, our server loads that page and sends up to 2,500 characters of its text, together with the name, price and description you typed, to OpenAI to extract keywords and a buyer profile.
  • Keyword lookups are shared. When you check a Google ranking, we look up the keyword's monthly search volume once and cache the result for 30 days without your identity. Other customers who check the same keyword reuse that cached number.
  • Some records are written to server logs. The software writes email addresses of people we send email to, Reddit usernames, generated reply text, payment notifications and error responses to server log files for troubleshooting. Log files under our web root are blocked from being read over the web (section 18). See section 13 for how long they exist.
  • No marketing list today. The software can pass your name and email to an email marketing provider when you sign up or buy. At the date of this policy the connection is switched off and no marketing emails are sent. The software still passes your name and email to a relay script on our own server, which currently forwards nothing; for purchases, that attempt is also written to a log line on our server. If we connect a provider, we will name it here and update this policy before any marketing email is sent.

5. Buyers through JVZoo and WarriorPlus

We sell through JVZoo and WarriorPlus. They take your payment. We never see your card number or bank details. We do not currently sell credit packs; the second row below applies only if we do.

What we holdWhere it comes fromWhy we use itLegal basis
Your name, email address, transaction or receipt id, product bought, and event type (sale, refund, chargeback) A payment notification the platform sends to our server when you buy, are refunded, or a chargeback happens To create or upgrade your account, match refunds to the right account, and keep our sales ledger Contract, and legal obligation: Swedish accounting law requires us to keep sales records
Credit packs only (not sold today): sale amount, currency, your IP address, and the full payment notification, which we write to a log file Same notification Adding credits and troubleshooting failed purchases. We would use the IP address only to investigate fraud and chargebacks. On request we clear the IP address from the sales record and keep the rest of the record, which is part of our accounts. Contract, and legitimate interest: making sure you get what you paid for and preventing fraud

When your first purchase comes in, we create your account and email you a login link and a starting password. That email contains the password in readable form. Change it after your first login.

If your purchase is refunded or charged back, your account or upgrade is switched off. The account stays until you ask us to delete it. Sales records stay for as long as accounting law requires (section 13). Refunds are handled according to the refund terms shown on the sales page at the time of purchase. Send refund requests to support@hustlegrow.com.

6. Agency client sub-accounts and partner-branded copies

Agency sub-accounts

Agency customers can create logins for their own clients. If you are an agency client, you should know:

  • Your agency owner typed your name, email address and password. We do not email you when the account is created and we do not verify your email address.
  • Your agency owner can suspend or reactivate your login, reset your password, delete your account, and log in as you. When they log in as you they can see and do everything in your account, including connecting a Reddit account to it and posting from it. The software keeps no record of when this happens and does not notify you.
  • If the agency owner's purchase is refunded, your account is switched off and detached from the agency, but not deleted.

For the data inside a client sub-account, the agency owner is the data controller and we are its processor under our Terms of Service. The agency owner decides why the account exists, must have a lawful basis for it, and must tell the client about it. For security records, AI usage records and AI Learning statistics we act as controller on the basis of our legitimate interest, for all accounts (section 1). If you are an agency client with a question about your data, contact your agency owner first. If that fails, contact us and we will help.

Deleting a client from the agency dashboard removes the client's account, products, leads, scan jobs, lead report pages, scraped posts, conversations, Trusted Accounts usage, upgrade records and the stored Reddit tokens. (Clients do not buy from us, so a client account holds no sales records and the accounting retention in section 13 does not arise.) The app's authorisation on the client's Reddit account is not revoked at Reddit; the client should remove it at reddit.com/prefs/apps. It does not remove the client's offers, Done For You campaigns, templates, follow-up rules, brand mentions and tracked terms, DM settings, AI Learning records, embedding vectors, queued pool actions, Telegram link, feedback, password reset records or AI usage records. Email us and we remove those too.

Partner-branded copies (whitelabel)

Some partners run the software under their own brand and domain. Accounts created there live in the same database as everyone else's and this policy applies to them. The partner is an independent controller for your purchase and support relationship. For that purpose the partner receives from us your name, email, creation date, login count, status, credits, upgrade status and lead count, can see which access code you redeemed, and can suspend your account. HustleGrow AB remains the controller for the platform. If you bought from a partner, their purchase notification may create your account and email you a starting password in the same way as section 5.

If you are a partner: when we create your branded copy we use your account email as its public support address and the first part of your email in its subdomain until you change them in the whitelabel settings. We also keep a change log for your branded copy (your custom domain, the addresses it resolved to when you verified DNS, licence transaction ids, and our admin actions on it); it is not pruned. Verifying DNS sends your custom domain to our server's DNS resolver. You can see which customer email redeemed each access code you issue.

7. Reddit users whose public posts we collect

This section is our notice under GDPR Article 14 to people who have not signed up with us. We publish it here instead of messaging each Reddit user: sending a private message to every author whose post we collect would itself be unwanted contact and out of proportion to the collection of content you already made public (Article 14(5)(b)). We delete on request (section 20). For public comments, where we do not message you, this public notice is the only one you receive. Private messages sent through the software do not yet carry a link to this section; until they do, this notice is the only one you receive for those too.

What we collect about you

  • Your Reddit username.
  • Your post: its Reddit id, title, full text, link, subreddit, score, comment count, posting time, and which of our customer's keywords matched it.
  • For brand and competitor monitoring: your post or comment that mentions a term a customer tracks, including up to 1,500 characters of its text, plus an AI sentiment label (positive, neutral, negative) and a short AI note about your attitude toward the brand.
  • An AI-generated score from 0 to 100 estimating whether your post shows buying intent for the customer's product, a short AI-written reason (up to 280 characters), and a lead type (asking for help, or showing off).
  • Where a customer checks it: the Google ranking of your thread for a keyword.
  • Anything the customer adds about you: private notes, tags, and a pipeline status such as "contacted" or "converted".
  • A reply the AI drafts to your post, and if the customer posts it, the link to that comment.
  • For Done For You campaigns: the same fields, plus the comment or message drafted to you, when it is scheduled, and which account sent it.

Where it comes from

Reddit's public API. Our software searches Reddit, and reads the live comment stream of subreddits a customer targets, using either the customer's own connected Reddit account or one of our Trusted Accounts. We only store content you posted publicly on Reddit. We do not store your private Reddit data unless you have an open message thread with one of our customers. Anything you send to a connected Reddit account is downloaded transiently with the rest of that inbox and discarded at once if it does not belong to such a thread (section 8).

Why

Our customers use the software to find public posts where someone seems to be looking for a product or service like theirs, to reply publicly, to send a private message, and to see what people are saying about their brand.

Legal basis

Legitimate interest (GDPR Article 6(1)(f)): our customers' interest in finding and joining public conversations that are relevant to their business, and our interest in providing that service. We rely on this because the content is already public, we collect a limited set of fields, the AI score has no legal or similar effect on you, and you can object at any time (section 20). A customer either reviews each reply before it goes out, or switches on an unattended mode. In unattended modes (auto-reply, autopilot follow-ups, automatic Done For You campaigns; see section 14) the software posts a comment or sends a message without a person reading it first. Those modes are capped per day, auto-reply only acts on posts scoring at least 65, and the customer remains responsible for every message. The collection and scoring of your posts is profiling used for direct marketing; your objection to it is absolute (section 20).

Who receives it

  • OpenAI (United States) receives:
    • your post title, subreddit and the first 500 characters of your post, to score it;
    • up to 1,500 characters when a scan has many candidates;
    • the full post text when a reply is drafted, whether by the customer or by auto-reply, autopilot or a Done For You campaign;
    • up to 500 characters of a brand mention, for sentiment;
    • your username when a private message opener or follow-up is drafted.
  • The customer who ran the scan sees your username, post and the AI score and reason in their dashboard and can download a spreadsheet of leads.
  • Anyone with the link, if the customer publishes a public lead report page with the Export to Web Page button. That page shows your username, your post title and text, the subreddit, score, comment count and the AI match percentage. It needs no login and has no expiry. It carries a no-index instruction so search engines should not list it, and its address contains a long random code so it cannot be guessed, but anyone who has the link can open it. For a lead report page, we and the customer are joint controllers: the customer decides to publish it and must have a lawful basis for showing your username, post and score to the public; we host it, decide its format, and remove it. There is no unpublish button; we will take a page down on request from you or the customer.
  • Telegram, if the customer connected it: post titles, subreddits, scores and links.
  • Reddit, when the customer posts a reply or sends you a message.

How long

Lead and scraped-post records stay until the customer clicks Delete all leads for that product, clears their scraped posts, or deletes the Done For You campaign. There is no way to delete a product itself; a product and its leads are only removed when we close the account (section 13) or when an agency owner deletes a client sub-account (section 6). There is no automatic time limit. Scraped posts older than 30 days disappear from the customer's dashboard but stay in the database until cleared. Deleting leads does not stop the same post being collected again on the next scan. Brand mention records are not removed by anything you or the customer can do in the dashboard. Public lead report pages are not removed by any action of the customer who published them; the only exception is an agency owner deleting a whole client account, which removes that client's pages. Otherwise we remove both when you or the customer ask. See section 20 for how to ask.

8. People who exchange Reddit private messages with our customers

This section is also an Article 14 notice. It applies if a customer sends you a private message through the software and to anything you write back.

What we collect

  • Your Reddit username, and the post of yours the customer was replying to (id, title, link, subreddit).
  • Every message in the thread, in full: what the customer sent you and what you sent back, with Reddit message ids and times.
  • Whether you replied, and when.
  • The customer's private notes, tags and status about you.

Where it comes from

The sending Reddit account's inbox. Every few minutes the software reads the 50 newest items in the inbox of each Reddit account with open threads from the last 45 days. It keeps only messages from people who have an open thread and discards everything else immediately. If the message was sent from one of our Trusted Accounts, the inbox being read is ours, and one read serves every customer sharing that account.

Why

To show the customer the conversation, stop follow-ups when you reply, draft the customer's next reply, and notify them.

Legal basis

Legitimate interest (Article 6(1)(f)): the customer's interest in holding a conversation you took part in, and our interest in providing that. You can object (section 20).

Who receives it

  • OpenAI receives the whole thread, including everything you wrote, each time the customer asks for a drafted reply or the scheduled follow-up job drafts one, together with your Reddit username, your post title and subreddit. Your latest message (up to 400 characters) and your original post are also sent to a smaller model that answers yes or no to whether the customer's offer fits your situation.
  • Telegram, if the customer connected it: your username and the first 200 characters of each new message you send.
  • The customer, in their inbox and in a spreadsheet export.
  • We, if the message came from a Trusted Account, because we hold that Reddit account and can see the thread on Reddit.

How long

Until the customer deletes the thread. Disconnecting their Reddit account does not delete the thread. There is no automatic purge.

Follow-ups

Customers can set follow-up rules. In copilot mode a human approves each follow-up. In autopilot mode the software sends AI-written follow-ups without a human reading them first. If you reply saying you are not interested or asking the customer to stop, the software closes the thread and sends no further follow-ups from it. If a customer contacts you again after that, email us (section 20) and we will delete your data.

9. Site visitors

  • Content delivery networks and fonts. Every page, including the login page, sign-up page and public lead report pages, loads scripts, styles and fonts from third-party servers. Your browser sends your IP address, browser type and the page address to those servers. They are listed in section 10. They send us nothing about you. Legal basis: our legitimate interest in delivering pages quickly and reliably (Article 6(1)(f)).
  • Server access logs and application logs. Our web server records the IP address, page requested, referrer, browser type and time of every request, and the software writes email addresses of people we email, Reddit usernames, generated reply text, payment notifications and error responses to log files. Purpose: detecting attacks, diagnosing faults and investigating abuse. Legal basis: our legitimate interest in keeping the service secure and working (Article 6(1)(f)). Our hosting provider keeps the access logs under its standard rotation; we will tell you the current period on request. Application and job log files are not deleted automatically; we clear them by hand (section 13).
  • Failed logins and reset requests. If you try to log in and fail, or ask for a password reset, we record the email address you typed, your IP address and the time, whether or not the address belongs to an account (section 4).
  • Public lead report pages. We count views and record the last view time. We do not record who viewed.
  • Telegram bot. If you message our bot without a valid link, we read your chat id, username and message to send a canned reply and do not store them.

We do not run analytics, tag managers, advertising pixels, heat maps or session recording anywhere on the site.

10. Cookies and browser storage

Our cookie

NamePurposeLifetimeSettings
REDAISESSID Keeps you logged in. Contains a random session id only. 7 days, or until you log out. The server-side session may end sooner after inactivity, in which case you log in again. HttpOnly, SameSite=Lax, Secure on HTTPS. The id is regenerated when you log in and when you reset your password.

Our own cookie is strictly necessary to provide the service, so we show no banner for it. We set no other cookies ourselves. Of the third-party servers listed below, only Wistia sets cookies, on the reseller page only.

Browser storage

The dashboard stores one entry in your browser's localStorage to remember whether you collapsed the tips panel, and one sessionStorage flag so a one-time notice is not shown twice. Neither leaves your browser.

Third-party servers your browser contacts

  • cdnjs.cloudflare.com (Cloudflare, United States): jQuery, Bootstrap, DataTables, TinyMCE and Font Awesome, on nearly every page.
  • fonts.googleapis.com and fonts.gstatic.com (Google, United States): the Nunito web font, on most pages.
  • code.jquery.com: jQuery on the agency client and reseller pages and on two admin pages.
  • cdn.jsdelivr.net: Bootstrap on the agency client and reseller pages.
  • stackpath.bootstrapcdn.com: Bootstrap on two admin pages.
  • fast.wistia.net (Wistia, United States): the training video on the reseller page. Wistia sets its own player cookies and records playback.

Each of these sees your IP address, browser type and the page you are on, under its own privacy policy. We chose them for speed and reliability. These libraries are required for the dashboard to work; a browser content blocker that stops them will break most pages. The video on the reseller page is the only optional load.

11. Who receives your data

We do not sell personal data. The companies below process data for us (processors) or receive data because you use their service or bought through them (independent controllers).

WhoWhat they receiveRole and location
OpenAI Reddit posts, comments and private messages as described in sections 7 and 8; your product name, URL, price, description, fetched web page text, keyword lists, campaign details and message templates. We never send your account name, email address or account id as identifiers, but anything you type into a description, template or campaign, and the text of your own web page, is sent as written and may contain your name or contact details. Reddit usernames are sent only as described in sections 7 and 8. Processor. United States. Used under OpenAI's API business terms, under which OpenAI does not use the data to train its models. OpenAI keeps API inputs and outputs for up to 30 days to monitor abuse, then deletes them.
MailerSend Email address, name, subject and body of every service email: reset links, welcome emails with starting password, purchase confirmations with transaction id, and your feedback sent to our support inbox Processor. Lithuanian company, EU.
Hostinger International Ltd Web and database hosting, the server log files described in this policy, and the same emails as fallback delivery if MailerSend fails Processor. Cyprus company, EU. We will confirm the data centre location on request.
Google Custom Search API The keyword you type for a rank check. Not the Reddit link, which is compared on our server. Independent controller, under Google's API terms. United States. We send only the keyword.
DataForSEO The same keyword, lower-cased, with a country and language code Processor. United States.
Cloudflare (cdnjs), Google Fonts, jQuery CDN, jsDelivr, StackPath, Wistia Your IP address, browser type and page address when your browser loads their files (section 10) Independent controllers. United States or global networks; jsDelivr is operated from Poland over a global network.
Reddit Your OAuth tokens, the searches the software runs for you, the comments and messages you send, and the usernames you message. Everything you do through the software on Reddit is subject to Reddit's own policies. Independent controller. United States.
JVZoo, WarriorPlus They send us your purchase data. We send back a confirmation that we received it and, if processing fails, a technical error message. Independent controllers. United States.
Telegram Messages we send to your chat (section 16), including your email address when you first link, Reddit usernames and message snippets from your conversations Independent controller. May store data outside the EU and EEA. Only if you connect it.
Your agency owner Everything in your account, if you are an agency client (section 6) Controller. Wherever they are.
Your partner (branded copies) Your name, email, creation date, login count, status, credits and lead count, if you signed up under a partner's brand (section 6) Independent controller for the sale and support relationship. Wherever they are.
eslcore.com Our software version and licence key when staff open the admin user list. No personal data. Legacy licence check by the framework vendor. Location not known to us.
Anyone with the link Lead report pages a customer chooses to publish (section 7) Public.
Authorities Data we are legally required to hand over Only when the law requires it.

12. Transfers outside the EU and EEA

OpenAI, Google, DataForSEO, Cloudflare, Wistia and the other content delivery networks listed in section 10 are in the United States or run global networks. For each provider outside the EU and EEA that processes data for us, we rely on the European Commission's standard contractual clauses included in that provider's data processing terms, or on the EU-US Data Privacy Framework where the provider is certified under it. You can ask us for a copy of the relevant clauses. The content delivery networks and font servers are contacted by your browser directly and we have no contract with them. Cloudflare, Inc. and Google LLC are certified under the EU-US Data Privacy Framework, which covers the transfer of your IP address; jsDelivr is operated from Poland. For code.jquery.com, StackPath and Wistia we know of no such certification.

Reddit, JVZoo, WarriorPlus and Google Custom Search are independent controllers. Data reaches them because you use Reddit through the software, bought through them, or asked for a rank check. Their own privacy policies govern what they do with it.

Telegram (based in Dubai) may store messages on servers outside the EU and EEA, and no adequacy decision covers it. We send your own account data there only because you connected it and asked for notifications (GDPR Article 49(1)(b)); disconnecting stops it. Reply alerts also carry the sender's Reddit username and the first 200 characters of their message (section 16); there is no separate transfer safeguard for that data. If you do not want data sent there, do not connect Telegram, or set notifications to off and disconnect.

13. How long we keep data

This table says what happens in the software today and what we do by hand.

DataHow long
Your account and everything linked to it: name, email, password hash, settings, products, leads, conversations, campaigns, templates, rules, brand mentions, feedback, usage records For as long as you have an account. The software has no self-service delete button and no automatic clean-up, and the admin tool only removes the account row. Email info@hustlegrow.com to close your account. Within 30 days we then remove, by direct database work, every record keyed to your user id in the tables listed in this policy, revoke your Reddit token at Reddit, and delete your product and offer embedding vectors. Lines in server log files are not removed. If your purchase is refunded, your account is switched off but stays until you ask. If we close your account under the Terms, we delete your data the same way, within 30 days of closure, except sales records.
Offers "Delete" in the app only deactivates an offer. Its details, the AI analysis of your web page and its embedding vector stay until we close your account.
Agency sales page content Kept until we close your account; there is no delete button.
Sales and payment records Until the end of the seventh year after the calendar year in which the financial year of the sale ended, as Swedish accounting law requires. These survive account deletion. The buyer IP address on a credit-pack sale is cleared from the record on request; the rest of the record stays.
Failed login attempts and reset requests Rows older than one day are swept roughly once in every fifty recorded failures, so on a quiet site they can stay for days or weeks. Rows for an email address are deleted as soon as that address logs in successfully.
Password reset records The link stops working after one hour or once used. The record stays until we close your account or you ask us to remove it.
Session Cookie: 7 days. Logging out ends it at once. The server-side session may end sooner after inactivity.
Reddit tokens Until you click Disconnect, which revokes them at Reddit and deletes them. If your account is closed without disconnecting first, we delete the stored tokens and revoke them at Reddit by hand. If an agency owner deletes your account, the stored tokens are deleted but the authorisation stays on your Reddit account until you remove it yourself at reddit.com/prefs/apps.
Reddit sign-in handoff records on our main-domain database Removed as soon as the software collects them. Abandoned handoffs are not removed automatically today and are cleared by hand.
Telegram link Until you disconnect or link from another chat. One-time link tokens expire after 15 minutes.
Reddit users' public posts, AI scores and campaign targets Until the customer clicks Delete all leads for the product, clears scraped posts, or deletes the campaign. There is no way to delete a product itself; a product and its leads go only when we close the account or an agency owner deletes a client sub-account. No time limit.
Brand mention records No customer delete exists. Kept until we remove them on request.
Public lead report pages No unpublish button exists. Deleting leads does not update or remove the page. Also removed when an agency owner deletes the client account that published it. Otherwise kept until we remove them on request.
Private message threads Until the customer deletes the thread. Disconnecting Reddit does not delete them.
Queued pool actions The recipient, the text and the target link stay until we remove them on request. No customer delete exists.
AI Learning outcome records Kept without time limit and pooled into statistics. Switching AI Learning off stops new records; existing records stay until we delete them on request.
AI usage records, Trusted Accounts usage records, product embedding vectors Kept without time limit. Deleted by hand when we close your account on request.
Keyword search volume cache Refreshed after 30 days, never deleted. Holds no identity.
Server and job log files Not deleted automatically by the software. We clear them manually. They can contain email addresses, Reddit usernames, message text and payment notifications.

14. Automated processing and AI

The software uses OpenAI models to:

  • score each collected Reddit post from 0 to 100 for buying intent and write a one-line reason;
  • rank large batches of posts by similarity to your product before scoring;
  • draft public comments, private message openers, replies and follow-ups;
  • decide yes or no whether your offer fits a conversation before it is mentioned;
  • label brand mentions as positive, neutral or negative;
  • suggest keywords and subreddits, and classify whether a subreddit allows promotion;
  • extract a buyer profile from your product page.

Scores and drafts can be wrong. You must review what the AI produces. You are responsible for anything you post or send. If the AI service is unavailable, every candidate post is kept with a default score of 60 and the note "not scored", so more posts are kept, not fewer, when scoring fails. The buying-intent score is profiling in the GDPR sense.

Some features act without a human reviewing each step, but only if you switch them on: auto-reply posts AI comments to leads scoring 65 or higher; autopilot sends AI follow-ups; Done For You campaigns in automatic mode post comments and messages on a schedule. In every case you chose the feature and can stop it; the software applies fixed daily caps (today 10 auto-replies per product per day, and 10 pool actions per day on the Front End tier). Where a subreddit's rules allow promotion, auto-reply decides at random whether a comment includes your offer link.

None of this produces a decision with legal or similarly significant effect on anyone. For a Reddit user, the result is at most a public comment or a few private messages. They come from the customer's own Reddit account or from one of our Trusted Accounts, on the customer's instruction. The Reddit user can ignore them. For you, we make no automated decisions about your account. We do flag unusually heavy AI use for a human to look at.

15. The Trusted Accounts pool

Instead of your own Reddit account, you can post comments and send messages through a pool of aged Reddit accounts that we operate. Posts made through the pool are made on your instruction and you are responsible for their content. We may refuse, hold, cap, delay or remove any action, and may withdraw pool access at any time.

When you use the pool:

  • We record, for every action, which pool account was used, your user id, the action type (comment, message, follow-up, reply), the subreddit and the time. This applies daily caps per user and per account, spaces actions out, and lets our admin see which customer is using which account and how often. Front End accounts currently get 10 pool actions per day. Limits may change, as the Terms explain.
  • The dashboard shows the pool identity only as "BuyerEngineAI Trusted Account".
  • Searches you run while the pool is selected are performed under our account, not yours. The software also uses pool accounts to re-read comments posted by any customer, to check whether Reddit kept them.
  • Replies to pool-sent messages arrive in our account's inbox. The software matches them to the right customer by sender. If two customers have open threads with the same person through the same pool account, the reply is held and shown to both as needing attention, without its content. It is never attributed automatically; each customer is told to read it on Reddit. A marker with the message id and the sender's username stays on each affected thread.
  • Because we hold the pool accounts, we can read on Reddit any conversation held through them. Content sent through the pool may be held in a queue for our review before it goes out.
  • Reddit sees our account acting, not yours.

We give no guarantee that a pool account, or your own account, will not be restricted by Reddit, and no guarantee of results, traffic, rankings, leads or income.

16. Telegram notifications

You can connect a Telegram chat from your settings page. We generate a one-time link that expires after 15 minutes. When you tap it, Telegram tells us your chat id and username and we store them.

After that, we send to Telegram:

  • when you link: a confirmation containing your account email address;
  • on request (/status): your credit balance, your connected Reddit username, and your lead and message counts;
  • when a scan finishes: the number of new leads;
  • when a prospect replies: their Reddit username and the first 200 characters of their message;
  • on request (/leads and /inbox): recent lead titles, subreddits, scores and links, and up to 10 recent conversation partners with short snippets.

Everything sent to Telegram stays in your Telegram chat history under Telegram's control. Telegram's servers may be outside the EU and EEA (section 12). You can set notifications to off, milestones or all. "Off" stops pushes; commands you type still get answers. Disconnecting deletes the link from our database.

17. Admin access

Our staff use an admin area to run the service. Through it they can see:

  • every account's name, email, creation date, login count, product count, credits and status;
  • every credit-pack sale (none today), including the buyer IP address reported by the payment platform;
  • every purchase and upgrade with its transaction id;
  • each user's AI usage;
  • each user's Trusted Accounts usage next to the real pool account name;
  • queued pool actions, and replies from your own Reddit account held for carrying a link, with their content and the author's email;
  • the owners of partner-branded copies.

Staff can ban or unban an account, delete it (the admin tool removes only the account row; the rest is removed by hand, section 13), set a new password for it, change its credits, and grant or revoke tiers. Staff can also create an account for you with a name, email address and starting password they choose; we do not email you when this happens. Feedback you submit lands in our support inbox. Server logs are readable by staff.

We use this access only to provide support, handle billing and refunds, investigate abuse, and keep the service secure.

18. Security

What is in place today:

  • Account passwords are stored as bcrypt hashes; we cannot read them. Reddit tokens and partners' payment-platform secrets are stored in our database without additional encryption; the database is reachable only by our staff and our hosting provider.
  • The session cookie is HttpOnly and SameSite=Lax, is marked Secure over HTTPS, and its id is regenerated on login and on password reset.
  • Login and password reset requests are throttled: 8 failed logins, or 8 password-reset requests, for one email address, or 30 from one IP address, within 15 minutes triggers a block.
  • Password reset links are single-use, stored only as a hash, and expire after one hour.
  • Traffic to https://buyerengine.hustlegrow.com runs over HTTPS.
  • Log files under our web root are blocked from being read over the web.
  • Disconnecting Reddit revokes the tokens at Reddit as well as deleting them from our database.
  • The admin area requires a staff login.

No system is perfectly secure. If a breach affects your data in a way that puts you at high risk, we will tell you as the GDPR requires.

19. Your rights

Your right to object

If you are a Reddit user who has not signed up with us, the collection and scoring of your posts is profiling used for direct marketing. You may object at any time and we will delete your records and stop; we do not weigh any other interest against yours. Section 20 explains how to object and the limits of what the software can do today. If you are an account holder, you may object to our legitimate-interest processing (login security records, AI usage records, AI Learning). We then stop unless we can show compelling legitimate grounds.

All your rights

Under the GDPR you can ask us to:

  • Access the personal data we hold about you and get a copy.
  • Correct it. You cannot change your name or email address inside the app. Email us and we change it.
  • Erase it. There is no delete button in the app. Email us and we close your account and delete your data by hand within 30 days (section 13). We keep sales records for as long as accounting law requires.
  • Restrict processing while a dispute is sorted out.
  • Port your data. There is no export button for your account data. Email us and we send you a machine-readable copy within 30 days. Leads can be downloaded as a spreadsheet from the dashboard at any time.
  • Object to processing based on legitimate interest, including AI Learning. You can also switch AI Learning off in the Lead Monitor; that stops new records but does not delete old ones, so email us if you want them gone.
  • Withdraw consent where we rely on it. Today we do not rely on consent for any processing in this policy. Disconnecting Reddit or Telegram, or turning off auto-reply, autopilot or campaigns, stops those features; they rest on your contract and your request, not consent. Stopping does not affect what happened before.
  • Complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), at www.imy.se, or to the data protection authority where you live.

To use any of these rights, email info@hustlegrow.com from the email address on your account. If you write from another address, we will ask you to confirm from the account address before we act. We answer within 30 days. There is no charge unless a request is clearly unfounded or repetitive.

If someone has created an account with your email address without your permission, email us and we will delete it.

20. Rights of Reddit users who are not our customers

This section is for Reddit users who have not signed up with us. If you believe a customer has collected your post, scored it, messaged you, or published a lead report page that includes you, you have the same rights as in section 19. That means access, correction, erasure, restriction and objection, and the right to complain to IMY or your local authority.

To use them, email info@hustlegrow.com with your Reddit username and, if you have them, the link to your post and the Reddit username that contacted you. For erasure and objection requests we ask you to confirm from the Reddit account, for example by replying from it to a short Reddit message we send you; we do this only to make sure nobody deletes records about you without your knowledge. If you cannot do that, tell us why and we will look for another way to confirm. For access or a copy of your data we will ask you to confirm the request from that Reddit account in the same way before we release anything. We will search our leads, scraped posts, brand mentions, message threads, campaign targets, queued pool actions and lead report pages for your username, and AI Learning records for the id or link of your post, and delete the matching records within 30 days. Server log files are not searched; we clear them periodically. We will confirm by email when it is done.

Two honest limits. First, the software has no block list, so a later scan could collect the same post or a new post of yours again; if that happens, email us again and we will delete again. Second, comments and messages a customer already posted on Reddit live on Reddit, not with us; contact the customer or Reddit to remove them, and tell us if you would like us to ask the customer on your behalf.

21. Children

BuyerEngineAI is for business use by people aged 18 or over. We do not knowingly hold accounts for anyone under 18. If we learn that we do, we delete the account. If you think a minor has an account, email us.

22. Changes to this policy

When we change this policy we update the date at the top. For significant changes, such as a new processor or a new purpose, we will tell you inside the app or by email before the change applies. Earlier versions are available on request.

23. Contact

HustleGrow AB
Hälsjögatan 11
217 66 Malmö
Sweden
Organisation number 559504-9494
VAT number SE559504949401
General: info@hustlegrow.com
Product support: support@hustlegrow.com
Privacy requests and account closure: info@hustlegrow.com

Swedish law governs this policy and our processing.

(C)2026 BuyerEngineAI
Support Email : support@hustlegrow.com