Account data
We collect the information needed to create and secure your workspace: name, email, company, password metadata, billing state, settings, team membership, and security preferences.
Customer conversations
When SuperBot is installed on a website, the platform may process visitor messages, chat transcripts, lead details, routing decisions, widget events, and support handoff context configured by the workspace owner.
Training sources
Workspace users can provide public website URLs, pasted text, policies, FAQs, product details, service rules, and published help articles. SuperBot uses those sources to produce grounded answers for that workspace only.
Usage data
We collect operational telemetry — page paths, device metadata, timestamps, feature usage, error logs, and security events — to keep the service reliable, prevent abuse, and improve product performance.
Billing data
Payment details are handled by our payment processors (Lemon Squeezy and PartnerStack). We store subscription identifiers, billing status, plan information, and transaction metadata needed to manage free and paid access.
How we use data
We use data to run the product, authenticate users, deliver AI support workflows, route conversations, provide analytics, respond to support requests, improve reliability, and protect the service from abuse.
AI processing
SuperBot uses configured knowledge and conversation context to generate answers for the customer workspace. Customer workspace content is not sold and is not used to train public foundation models.
Sharing and vendors
We do not sell personal data. We share data only with infrastructure, analytics, security, billing, email, support, and AI subprocessors needed to operate the service — under contractual safeguards.
- Cloud infrastructure for hosting and storage
- AI inference providers under data-processing agreements
- Email and notification senders for transactional messages
- Analytics for product improvement (no third-party ad networks)
Retention
We keep account, conversation, analytics, and billing records as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and support customer operations.
Deletion requests
Customers can request deletion of account-level data, subject to security, fraud-prevention, legal, billing, backup, and contractual retention requirements. Email [email protected].
Security controls
We use HTTPS/TLS, encrypted stored integration credentials, scoped workspace queries, secure cookies, rate limits, operational monitoring, and role-based access controls to reduce risk. Workspaces are isolated at the application and data-query layers.
Your choices
You can update account details, manage workspace settings, configure notification preferences, remove training sources, export relevant records, and request support for any privacy question.
