SuperBot
Start free
Legal · Privacy

Privacy Policy

How SuperBot handles website, workspace, conversation, training, billing, and support data — written as a practical product policy, not legal jargon.

Last updated · Questions? Contact us
§ 01

Account data

We collect the information needed to create and secure your workspace: name, email, company, password metadata, billing state, settings, team membership, and security preferences.

§ 02

Customer conversations

When SuperBot is installed on a website, the platform may process visitor messages, chat transcripts, lead details, routing decisions, widget events, and support handoff context configured by the workspace owner.

§ 03

Training sources

Workspace users can provide public website URLs, pasted text, policies, FAQs, product details, service rules, and published help articles. SuperBot uses those sources to produce grounded answers for that workspace only.

§ 04

Usage data

We collect operational telemetry — page paths, device metadata, timestamps, feature usage, error logs, and security events — to keep the service reliable, prevent abuse, and improve product performance.

§ 05

Billing data

Payment details are handled by our payment processors (Lemon Squeezy and PartnerStack). We store subscription identifiers, billing status, plan information, and transaction metadata needed to manage free and paid access.

§ 06

How we use data

We use data to run the product, authenticate users, deliver AI support workflows, route conversations, provide analytics, respond to support requests, improve reliability, and protect the service from abuse.

§ 07

AI processing

SuperBot uses configured knowledge and conversation context to generate answers for the customer workspace. Customer workspace content is not sold and is not used to train public foundation models.

§ 08

Sharing and vendors

We do not sell personal data. We share data only with infrastructure, analytics, security, billing, email, support, and AI subprocessors needed to operate the service — under contractual safeguards.

  • Cloud infrastructure for hosting and storage
  • AI inference providers under data-processing agreements
  • Email and notification senders for transactional messages
  • Analytics for product improvement (no third-party ad networks)
§ 09

Retention

We keep account, conversation, analytics, and billing records as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and support customer operations.

§ 10

Deletion requests

Customers can request deletion of account-level data, subject to security, fraud-prevention, legal, billing, backup, and contractual retention requirements. Email [email protected].

§ 11

Security controls

We use HTTPS/TLS, encrypted stored integration credentials, scoped workspace queries, secure cookies, rate limits, operational monitoring, and role-based access controls to reduce risk. Workspaces are isolated at the application and data-query layers.

§ 12

Your choices

You can update account details, manage workspace settings, configure notification preferences, remove training sources, export relevant records, and request support for any privacy question.

Need a deeper review?

We can provide a Data Processing Agreement, subprocessor list, or enterprise security review on request. Email [email protected] and we'll get back the same business day.