Privacy Policy
1. Data we process
We process the following data to operate the Service:
- Account data — name, email, hashed password (or Google sign-in identifier), company name.
- Uploaded documents — the manuals, catalogs, and internal docs you add to your knowledge base, plus derived embeddings and search indexes.
- Query & chat history — questions you ask and the answers returned, so you can revisit past conversations.
- API keys — stored encrypted at rest, never in plain text.
- Usage data — basic product analytics (pages visited, feature usage) to improve the Service.
Uploaded documents are processed only to answer your own team's queries. They are never added to a shared or public training set, and never exposed to another customer.
2. Data isolation
Each customer (tenant) has an isolated document store, vector index, and chat history. There is no cross-tenant search — your documents are only ever retrieved to answer questions from your own account.
3. Sub-processors
We use the following categories of sub-processors to run the Service. We do not sell your data to any of them, and each is bound by its own data processing terms:
- LLM / embedding providers (e.g. OpenAI, DeepSeek) — process query text and document excerpts to generate answers and embeddings. Not used by these providers to train their own public models under our current agreements.
- Infrastructure & hosting — servers and databases (PostgreSQL, Redis, Qdrant) that store your account data, documents, and indexes.
- Cloudflare — network/CDN, DNS, and tunnel infrastructure used to serve the Service securely.
- Payment processor — handles billing and payment details for paid plans; we do not store your card details ourselves.
[DRAFT — confirm final sub-processor list and DPAs with counsel before publishing.]
4. Data retention & deletion
We retain your account data and documents for as long as your account is active. You can delete individual documents or your entire account at any time from account settings; deleted data is removed from active systems and purged from backups within [DRAFT — confirm backup retention window] days.
5. International data transfers
As our customers and infrastructure span the EU and US, data may be processed outside your home country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers. Enterprise customers may request an on-premise or private-cloud deployment to keep data within a specific region.
6. Your rights (GDPR & similar laws)
Depending on where you are located, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email [email protected] — we will respond within the timeframe required by applicable law.
7. Security
API keys and credentials are encrypted at rest. Access to customer data is scoped to your tenant and restricted to personnel who need it to operate or support the Service.
8. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or an in-app notice before they take effect.
10. Contact
Questions about this policy or your data? Email [email protected].