← Back to SupportGPT

Privacy Policy for SupportGPT

Effective July 21, 2026

This policy explains how SupportGPT processes information when account holders, workspace members, and visitors use supportgpt.app, its embedded chat agents, and related services.

Information we process

Account and workspace data, including names, email addresses, profile information, workspace memberships, subscription status, and support requests.

Customer content, including knowledge sources, files, URLs, integration content, agent instructions, chat conversations, feedback, contact details, and metadata a customer or visitor submits to an agent.

Technical and usage data, including IP-derived location, browser and device details, timestamps, cookies or local storage identifiers, request logs, rate-limit signals, and product analytics.

Payment and transaction records. Our payment provider processes payment credentials; we receive transaction, customer, subscription, and entitlement information needed to provide paid plans.

How we use information

We use information to provide and secure the service, authenticate users, answer visitor questions, retrieve customer-provided knowledge, generate AI responses, operate human handoff, process subscriptions, enforce usage limits, prevent abuse, troubleshoot incidents, communicate service updates, and improve product reliability.

Workspace customers decide what content they submit and how their agents collect visitor information. Those customers are responsible for providing any additional notices and obtaining any consent required for their use case.

Service providers and integrations

We do not sell personal information. We disclose information as needed to service providers that host or operate SupportGPT, including Supabase for authentication, database, and realtime infrastructure; Amazon Web Services for object storage and content delivery; Google, OpenAI, or Anthropic when the selected AI model processes a prompt; Creem for billing; Upstash when distributed abuse prevention is enabled; Resend for transactional email; and our configured product-analytics provider.

If a workspace connects an optional integration, relevant data and credentials are exchanged with that provider at the workspace's direction. Supported integrations may include Notion, Slack, Discord, Zendesk, Telegram, Calendly, WhatsApp, and Stripe. Those providers process information under their own terms and privacy notices.

We may also disclose information when required by law, to protect users or the service, or in connection with a corporate transaction. Providers may process data in countries other than the user's country.

Retention and security

We retain account and customer content while needed to provide the service and for legitimate security, backup, dispute, tax, and legal purposes. Retention can vary by data category and connected provider. Deleting a workspace or requesting account deletion starts deletion from active systems; limited copies may remain in backups or records that law requires us to keep until their retention period expires.

We use access controls, tenant authorization, encryption in transit, restricted object storage, secret protection, request limits, and monitoring-oriented controls. No online service can guarantee absolute security, so customers should avoid submitting data they do not need the service to process.

Your choices and rights

Depending on applicable law, you may request access, correction, export, restriction, objection, or deletion of personal information. Workspace owners can remove many records in the product. For account-level requests, email us from the address associated with the account. We may verify identity and may need to preserve information where legally required.

You can control browser cookies and local storage through browser settings, although clearing them may reset anonymous chat history or sign-in state. You can disconnect optional integrations from the workspace settings.

Children

SupportGPT is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information to the service.

Changes and contact

We may update this policy as the product or law changes. We will post the revised policy with a new effective date and provide additional notice when required. Questions and privacy requests can be sent to support@supportgpt.app.

This public policy should be reviewed for the jurisdictions and deployment configuration used by each production operator.