Privacy Policy

We take your privacy seriously. Learn how we collect, use, and protect your data.

Last updated: March 26, 2026

Information We Collect

We collect information you provide directly to us and information we collect automatically when you use our services:

  • Account information (name, email, company)
  • Knowledge base data (documents, PDFs, FAQs you upload)
  • Chat interaction data (conversations between your chatbot and your customers)
  • Technical information (IP address, browser type, device information)
  • Usage data (feature usage, analytics, performance metrics)
  • Communications (support requests, feedback)

How We Use Your Data

We use the information we collect for the following purposes:

  • Provide and maintain our AI chatbot services (legal basis: contract)
  • Index your uploaded knowledge base so your chatbot can answer from it (contract)
  • Process customer chat interactions through your widget (contract)
  • Manage your account and subscription (contract)
  • Provide customer support and respond to inquiries (legitimate interest)
  • Generate aggregated, non-personal analytics about service usage (legitimate interest)
  • Comply with legal obligations and prevent abuse (legal obligation)

How We Protect Your Data

We implement industry-standard security measures to protect your personal information:

Encryption in Transit & at Rest

All traffic uses TLS 1.2+; stored data is encrypted at rest by our infrastructure providers (Supabase / AWS).

Access Controls

Strict access controls and authentication for all system access.

Regular Backups

Automated daily backups with geographic redundancy.

24/7 Monitoring

Continuous monitoring for security threats and anomalies.

Data Sharing and Disclosure

We never sell your personal data to third parties.

We may share your information only in the following limited circumstances:

  • Sub-processors: Trusted third-party providers listed below help us operate the service.
  • Legal requirements: When required by law or to protect our legal rights.
  • Business transfers: In connection with a merger, acquisition, or sale of business assets.

Sub-processors

We use the following sub-processors to deliver the service. Each is contractually bound to handle data in line with applicable data protection law.

ProviderPurposeLocation
SupabaseAuthentication, database, file storageEU / US
OpenAIAI model that generates chatbot responses (zero data retention configured)US
QdrantVector storage for knowledge-base embeddingsEU
Lemon SqueezyPayment processing, merchant of record, tax complianceUS
Google (Sign-In)Optional OAuth loginGlobal

We will notify customers in advance before adding or replacing a sub-processor that materially affects how their data is processed.

We Do Not Train AI Models on Your Data

Your uploaded content, chat transcripts, and customer data are never used to train PaperBrainz machine-learning models or any general-purpose foundation model.

Chat content is sent to OpenAI only to generate the response shown to your visitor. We use OpenAI's API with zero-retention / no-training terms in effect, meaning OpenAI does not retain content beyond what is needed to return the response and does not use it to train their models.

Your knowledge-base content stays in your dedicated workspace and is only used to answer questions for your chatbot.

Your Rights and Choices

You have the following rights regarding your personal data:

Access

Request access to your personal data

Correction

Update or correct your information

Deletion

Request deletion of your account and data

Portability

Export your data in a portable format

Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, we securely delete personal data within 30 days, except where required by law.

  • Account data: Retained while your account is active
  • Knowledge base: Deleted upon account closure or at your request
  • Chat transcripts: Retained per your plan settings (exportable)
  • Billing records: Retained as required by tax and accounting regulations

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including compliance with GDPR requirements for transfers outside the EEA.

Privacy at a Glance

  • We never sell your personal data
  • We never train AI models on your content
  • Encryption in transit (TLS 1.2+) and at rest
  • We collect only what we need
  • You control your data — export or delete anytime
  • GDPR-aligned data handling

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through our service. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact Us About Privacy

If you have questions about this privacy policy or our data practices, please contact us:

Response Time

We respond to privacy inquiries within 30 days