Privacy Policy
Last updated 24 August 2026
The short version
We collect what is needed to run your assistant and bill you for it. We do not sell anything about you, and we do not use your documents or your visitors’ conversations to train models.
Two kinds of people
You, the customer. You signed up, you upload the material, you pay. This policy describes what we do with your information directly.
Your visitors. They talk to an assistant on your website. For their data you are the controller and we are your processor: we handle it on your instructions, and your own privacy policy is what governs it. You are responsible for telling your visitors that an assistant is available and that their messages are processed.
What we collect from you
Your name, email address, and workspace name, so you can sign in and we know what to call you. A hashed password, which we cannot reverse.
The documents and pages you add, and the index we build from them so questions can be matched against them.
Usage counts such as replies used in the current period, so plan limits can be enforced and shown to you.
We do not receive or store your card number. Payment is handled by our payment provider, who tells us only that a subscription started, renewed, or ended.
What we collect from your visitors
The messages they send to your assistant and the answers it gave, so you can read them in your dashboard and see what people are asking. These are kept until you delete the conversation or the workspace.
The website address the assistant was opened from, which is what allows us to refuse to load it on sites you have not authorised.
The assistant does not read the page it sits on. It runs in an isolated frame and cannot see your visitors’ other browsing, form fields, or cookies. Ask your visitors not to type sensitive personal information into it, and do not configure it to request any.
Who else sees it
To produce an answer, the relevant excerpts of your material and the visitor’s question are sent to a third-party provider of language and embedding models. They process it to return an answer and do not use it to train their models under our agreement with them.
We also use infrastructure providers for hosting, databases, and email, and a payment provider that acts as merchant of record. Each of them handles only what their function requires.
A current list of these subprocessors is available on request, and we will give notice before adding one that materially changes how your data is handled.
We do not sell personal data, and we do not share it for advertising.
Where it is processed
The service runs on infrastructure outside India, and our model and infrastructure providers may process data in other countries, including the United States. Where required, transfers rely on the standard contractual protections offered by those providers.
How long we keep it
Your documents and their index stay until you delete the source or the workspace. Conversations stay until you delete them or the workspace. Account and billing records are kept while your account exists, and afterwards only as long as tax and accounting rules require.
Deleting a workspace removes its content and cannot be undone.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Most of this you can do yourself from the dashboard; for the rest, email us and we will respond within thirty days.
If a visitor asks you to delete their conversation, you can do that from the dashboard without involving us.
Security
Traffic between your browser, your visitors’ browsers and this service is encrypted with HTTPS, and the database connection uses TLS. Internal traffic between our own components stays on a private network and does not cross the public internet. Passwords are hashed with a slow algorithm and cannot be reversed.
Each assistant will only load on the website addresses you list, so a key copied off your page cannot be used on another site.
Your documents and conversations are stored so the service can search them and show them back to you, which means they are readable by the service rather than encrypted only to you. See our terms for what we do and do not do with them.
No service is immune to breach. If one occurs and affects your data, we will tell you promptly and describe what happened.
Cookies
The dashboard sets one cookie to keep you signed in. Our own marketing pages also carry an advertising measurement tag, which sets cookies to record whether a visit followed one of our adverts; it runs on this website only. The assistant we host on your site sets no cookie on your visitors’ browsers, and carries no tracking of any kind.
Children
The service is not intended for children, and you should not configure an assistant aimed at them without meeting the consent rules that apply where your visitors live.
Changes and contact
If this policy changes materially we will give notice by email or in the dashboard. Questions, requests, or complaints: johinjohny144@gmail.com.