Legal
Privacy policy
Last updated 31 August 2026
This page is a starting point covering how the service actually works. Have a lawyer review it before you take real payments.
The short version
The conversations you analyse never reach us. The engine runs entirely inside your own deployment. We hold only what we need to sell you a licence and let you retrieve it.
What we hold
- Your email address — to identify your account and send sign-in links.
- Your licence records — plan, seat count, expiry, status, and the signed key itself, so you can retrieve it from the dashboard.
- A Stripe customer reference — so renewals and cancellations map to the right licence. Card details are handled by Stripe and never touch our servers.
- Ordinary server logs — request metadata, kept for operational purposes.
What we never hold
- Conversation text, transcripts, or any input you give the application.
- The personality profiles it produces.
- Your end users' identities or any data about them.
The revocation check
Your deployment periodically asks our validation endpoint whether a licence has been revoked. The request carries one opaque licence id and nothing else; the reply is a yes or no. It carries no conversation data, no user data, and no information about how the software is being used.
Sub-processors
- Stripe — payments and billing.
- Google Cloud — hosting for this site and the validation endpoint.
- Our transactional email provider — delivering sign-in links.
Retention and your rights
We keep account and licence records while your subscription is active and for as long afterwards as tax and accounting rules require. You can ask us for a copy of what we hold about you, or ask us to delete it, by emailing the address in the footer. Deleting your account revokes any active licence.
Cookies
One cookie, holding your signed-in session. No analytics or advertising cookies.