Privacy
A privacy foundation built around purpose and control.
This page outlines the intended direction for handling business and customer data. It is not a final privacy notice.
This preliminary content is provided for product development and must be reviewed before public launch. Legal, privacy, security, tax, and regulatory requirements vary by jurisdiction.
Information categories
When the production service is configured, it may process account details, organisation configuration, approved knowledge, customer conversations, leads, and activity records. The exact categories and lawful bases depend on the service, customer instructions, and applicable jurisdiction.
Intended safeguards
- Organisation-level data separation and least-privilege access.
- Server-side handling of credentials and protected actions.
- Data minimisation, retention controls, and auditable activity.
- Controlled processors and regional arrangements where required.
Current foundation
Account authentication, tenant-scoped workspace configuration, grounded customer chat, conversations and leads can be stored in Supabase after the checked-in migrations and server environment are configured. The public demo remains fictional and separate. File ingestion, payments, business actions and third-party integrations are not connected.