Legal
Privacy Policy
Placeholder — not a real privacy policy
This is placeholder text. Replace with reviewed legal content before accepting real customers.
This page will explain what personal data we process, why, and what rights people have. The structure below shows what the final policy needs to cover.
1. Who we are
[Placeholder: legal company name, registration number, address, and who to contact about privacy.]
2. What information we collect
[Placeholder: the categories of personal data collected, for business customers and for their website visitors.]
Drafting notes — facts about the product, not policy text
- Account: email address and password (handled by Supabase Auth).
- Business profile: company name, business/tax ID, address, website, industry and logo (all optional except the name).
- Agent content: descriptions, generated system prompts, uploaded documents and their extracted text, clarifying questions and answers, test messages and reviews.
- Website visitors using the chat widget: their messages and the agent's replies; if they ask for a person, the name, email and message they choose to enter.
- Visitor IP addresses are not stored; a salted one-way hash is kept for rate limiting. The widget keeps the visitor's conversation in their own browser's local storage.
3. How we use it
[Placeholder: the purposes of processing and the legal basis for each.]
4. Service providers that process data for us
[Placeholder: the list of sub-processors, what each one receives, and where they process it.]
Drafting notes — facts about the product, not policy text
- Supabase: database (including the extracted text of uploaded documents; the original files are not kept), authentication, and file storage (company logos).
- AI model provider: generating agents, clarifying questions and replies. Receives agent prompts, conversation messages and relevant document excerpts.
- Document search provider: turns document text and visitor messages into embeddings for document search.
- Error-tracking service: receives technical details when something fails (error messages, stack traces, page addresses, internal ids). Message contents, email addresses, file names, cookies and IP addresses are not sent.
- Uptime-monitoring service: regularly checks that the website and a health endpoint respond; it receives no personal data.
- Hosting provider: to be added when the app is deployed.
5. Businesses and their website visitors
[Placeholder: how responsibilities are split between us and the businesses that put the widget on their websites, for their visitors' data — to be defined with a lawyer.]
6. How long we keep data
[Placeholder: retention periods for each category of data.]
Drafting notes — facts about the product, not policy text
- There is no automatic deletion yet; data is kept until the account owner deletes it.
7. Your rights
[Placeholder: the rights people have over their data and how to exercise them.]
Drafting notes — facts about the product, not policy text
- Account owners can permanently delete their account and all its data themselves: Settings → Profile → Delete account. This removes the login, business profile and logo, agents, documents, questions, conversations and follow-ups (including visitors' contact details) straight away; nothing is kept.
8. Contact
[Placeholder: how to reach us about privacy (currently support@example.com, also a placeholder).]