Privacy Policy
Last updated 21 September 2026
The short version
We collect what is needed to run your assistant and bill you for it. We do not sell anything about you, and we do not use your documents or your visitors’ conversations to train models.
Two kinds of people
You, the customer. You signed up, you upload the material, you pay. This policy describes what we do with your information directly.
Your visitors. They talk to an assistant on your website. For their data you are the controller and we are your processor: we handle it on your instructions, and your own privacy policy is what governs it. You are responsible for telling your visitors that an assistant is available and that their messages are processed.
What we collect from you
Your name, email address, and workspace name, so you can sign in and we know what to call you. A hashed password, which we cannot reverse.
The documents and pages you add, and the index we build from them so questions can be matched against them.
Usage counts such as replies used in the current period, so plan limits can be enforced and shown to you.
We do not receive or store your card number. Payment is handled by our payment provider, who tells us only that a subscription started, renewed, or ended.
What we collect from your visitors
The messages they send to your assistant and the answers it gave, so you can read them in your dashboard and see what people are asking. These are kept until you delete the conversation or the workspace.
The website address the assistant was opened from, which is what allows us to refuse to load it on sites you have not authorised. With each conversation we also record the page it started on, the referring page, the browser’s user agent, the visitor’s country where our network reports it, a random visitor identifier (see Cookies below), and any details your own site passes to the assistant or the visitor types into a contact form.
The assistant does not read the page it sits on. The conversation runs in a separate frame that has no access to your page, and the small script that loads it collects nothing from the page: not its text, not your form fields, and not your cookies. It is an ordinary script tag on your site, so treat that as a statement of what it does rather than of what the browser prevents. It has no access to your visitors’ browsing on other sites. Ask your visitors not to type sensitive personal information into it, and do not configure it to request any.
Who else sees it
To produce an answer, the relevant excerpts of your material and the visitor’s question are sent to a language model provider, and your material is sent to an embedding provider when it is indexed. OpenAI’s API terms say data sent through its API is not used to train its models unless the customer opts in. Google’s Gemini API terms say Google does not use prompts or responses to improve its products when the API is used as a paid service, and may when it is used unpaid.
These are the subprocessors we use today:
- Oracle Cloud: hosting of the service, its database and stored files, and encrypted backups. India (Mumbai region).
- OpenAI: generating answers and building the search index from your material. United States and other countries where it operates.
- Google: the Gemini model, used only when the primary model is unavailable, and, if you accept measurement cookies, the advertising tag on our marketing pages. Any country where Google or its agents have facilities.
- Resend: sending account and notification email. United States.
- Dodo Payments: checkout and billing, as merchant of record. It may process data in other countries under its own privacy policy.
- Cloudflare: DNS for our domains. It answers lookups for our addresses and does not carry your content. Global network.
If you add your own model provider key, requests on that key go to the provider you chose under your own agreement with it, not ours. If you connect a source such as Notion, Google Drive, OneDrive, Slack or a database, we read from it with the access you grant, and that service is your provider rather than ours. We will give notice before adding a subprocessor that materially changes how your data is handled.
We do not sell personal data, and we do not share it for advertising.
Where it is processed
The service, its database and your stored files run on servers in Mumbai, India. Our model, email and payment providers process data in other countries, including the United States, as listed above. Where required, transfers rely on the standard contractual protections offered by those providers.
How long we keep it
Your documents and their index stay until you delete the source or the workspace. Conversations stay until you delete them or the workspace. Account and billing records are kept while your account exists, and afterwards only as long as tax and accounting rules require.
Deleting a workspace removes its content and cannot be undone.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Most of this you can do yourself from the dashboard; for the rest, email us and we will respond within thirty days.
If a visitor asks you to delete their conversation, you can do that from the dashboard without involving us.
Security
Traffic between your browser, your visitors’ browsers and this service is encrypted with HTTPS. The database runs on the same server as the service and is reached over a private network inside that server, not over the public internet, and that internal connection is not separately encrypted. Passwords are hashed with a slow algorithm and cannot be reversed.
Each assistant will only load on the website addresses you list, so a key copied off your page cannot be used on another site.
Rows copied from a connected database are private unless you mark them public. A private row is only used to answer a visitor who has typed details matching that row, such as an order number and email address, in the same conversation. Those details are kept only as salted hashes, answers built from private rows are never cached or shown to other visitors, and repeated failed attempts are limited per visitor and per IP address. This is a check on details the visitor already knows, not a sign-in.
Your documents and conversations are stored so the service can search them and show them back to you, which means they are readable by the service rather than encrypted only to you. See our terms for what we do and do not do with them.
No service is immune to breach. If one occurs and affects your data, we will tell you promptly and describe what happened.
Cookies
The dashboard sets one cookie to keep you signed in. That one is not optional: without it there is no way to stay signed in, so it is part of the product rather than something to agree to.
Separately, our own marketing pages can carry three measurement tags: one that records whether a visit followed one of our adverts, one that counts page views, and one that records how a visit moves through the page. All three set cookies, and none loads until you have said yes. Decline and they are never requested at all, rather than loaded and asked to behave. They run on this website only.
The third is the one worth spelling out. On our marketing pages and the sign-in and sign-up forms it records where a pointer is clicked, how far a page is scrolled, and a reconstruction of the page as it was drawn, so that we can see where our own explanations fail. Text you type is masked before it leaves the browser, so a recording shows that a field was filled and not what was put in it. Nothing inside the dashboard is recorded: your documents, your assistants, your visitors’ conversations, your invoices and your provider keys are all on the other side of the sign-in, and the tag is not loaded there. Recordings are kept on infrastructure we run, are not sold, and are not shared with an advertising network. Change your mind at any time below, and write to us if you would like a recording already taken deleted.
The assistant we host on your site sets no cookie on your visitors’ browsers and loads no advertising or analytics tags. It does keep one random identifier in the browser’s local storage, so a returning visitor’s conversations are grouped together, and it records the page, browser and country described above. It does not follow visitors to other sites.
Children
The service is not intended for children, and you should not configure an assistant aimed at them without meeting the consent rules that apply where your visitors live.
Changes and contact
If this policy changes materially we will give notice by email or in the dashboard. Questions, requests, or complaints: johinjohny144@gmail.com.