Privacy policy

Draft for legal review. Not a final document.

Last updated: 1 September 2026.Download as text

Who processes what

The organization that contracts the service is the controller of their end users data. We are the processor: we process that data on their behalf and following their instructions.

For the data of that organization team members —who signs in, with which email— we are the controller.

What we store

Conversations and their messages, the contact details of end users that the organization loads or that they provide themselves, attachments, and the knowledge base material.

For each AI answer we store the model, the tokens and the cost, to be able to bill and so the organization knows what it is spending.

What we do not store

Card data: the payment gateway handles it and it never passes through our systems.

Technical logs contain neither credentials nor personal data: they are redacted before being written, by field name and by value shape.

Rights

Any end user can ask the organization serving them for a copy of their data or its deletion. The organization resolves it from their panel, and the export is a file readable without us.

Deletion removes what identifies the person and their files, and anonymises their messages: the conversation is also the organization support history.

Retention

Each organization configures how long they keep things. Unconfigured, nothing is deleted. On cancellation, everything of theirs is deleted.