Skip to main content
SuperBot
Start free
Legal · Privacy

Privacy Policy

How SuperBot handles website, workspace, conversation, training, billing, and support data — written as a practical product policy, not legal jargon.

Last updated Questions? Contact us
§ 01

Account data

We collect the information needed to create and secure your workspace: name, email, company, password metadata, billing state, settings, team membership, and security preferences.

§ 02

Customer conversations

When SuperBot is installed on a website, the platform may process visitor messages, chat transcripts, lead details, routing decisions, widget events, and support handoff context configured by the workspace owner.

§ 03

Training sources

Workspace users can provide public website URLs, pasted text, policies, FAQs, product details, service rules, and published help articles. SuperBot uses those sources to produce grounded answers for that workspace only.

§ 04

Usage data

We collect operational telemetry — page paths, device metadata, timestamps, feature usage, error logs, and security events — to keep the service reliable, prevent abuse, and improve product performance.

§ 05

Billing data

Payment details are handled by our payment processors (Lemon Squeezy and PartnerStack). We store subscription identifiers, billing status, plan information, and transaction metadata needed to manage free and paid access.

§ 06

How we use data

We use data to run the product, authenticate users, deliver AI support workflows, route conversations, provide analytics, respond to support requests, improve reliability, and protect the service from abuse.

§ 07

AI processing

SuperBot uses configured knowledge and conversation context to generate answers for the customer workspace. Customer workspace content is not sold and is not used to train public foundation models.

§ 08

Sharing and vendors

We do not sell personal data. We share data only with infrastructure, analytics, security, billing, email, support, and AI subprocessors needed to operate the service — under contractual safeguards.

  • Cloud infrastructure for hosting and storage
  • AI inference providers under data-processing agreements
  • Email and notification senders for transactional messages
  • Analytics for product improvement (no third-party ad networks)
§ 09

Retention

We keep account, conversation, analytics, and billing records as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and support customer operations.

§ 10

Deletion requests

Customers can request deletion of account-level data, subject to security, fraud-prevention, legal, billing, backup, and contractual retention requirements. Email [email protected].

§ 11

Security controls

We use HTTPS/TLS, encrypted stored integration credentials, scoped workspace queries, secure cookies, rate limits, operational monitoring, and role-based access controls to reduce risk. Workspaces are isolated at the application and data-query layers.

§ 12

Webflow App data

The SuperBot Webflow App is a Data Client App. It requests four scopes and uses each one for a single purpose: sites:read to identify the site you authorize, custom_code:read and custom_code:write to install and maintain the chat widget's script, and authorized_user:read to read the installing user's email so your SuperBot workspace can be created or matched. Installing the App creates a SuperBot workspace for that email if one does not already exist; if it does, the Webflow site is linked to it.

  • Stored per install: the Webflow site id, site name, workspace id, published domain, the OAuth access token, the scopes granted, the installing user's email, and the id, version and status of the script we injected
  • Never accessed or stored: your site's page content, CMS collections, form submissions, ecommerce orders, or any other Webflow data — the scopes above do not grant access to them, and the App requests nothing more
  • The injected script is a small inline bootstrap that loads the SuperBot widget; visitor conversations it produces are covered by the customer-conversations and AI-processing sections above
  • Disconnecting in the App dashboard removes the injected code and revokes the access token with Webflow. Removing the App in Webflow alone sends us no notification — Webflow provides no uninstall webhook — so we detect it when the stored token stops being accepted, and then mark the install inactive
§ 13

Your choices

You can update account details, manage workspace settings, configure notification preferences, remove training sources, export relevant records, and request support for any privacy question.

Need a deeper review?

We can provide a Data Processing Agreement, subprocessor list, or security review on request. Email [email protected] with what your team needs.