Privacy Policy
Last updated 7 October 2026
In short: we collect what is needed to run an AI assistant on your website and nothing for advertising. Your documents and conversations belong to your account. We do not sell personal data or use it to train AI models. You can delete your account, and everything in it, from the dashboard.
Who this covers
ConvoSpire provides an AI assistant that businesses (our customers) add to their websites. This policy covers:
- Customers, who sign up at app.convospire.com and manage an assistant;
- Visitors, who talk to a customer's assistant on the customer's website;
- anyone browsing convospire.com.
For visitor conversations, the customer whose website you were on decides what the assistant is for and what happens to the conversation. We process that data on the customer's behalf. If you were a visitor, the quickest route for a request about your data is the business you were talking to. You can also contact us and we will pass it to them.
What we collect
From customers
- Account details: name, email address, business name, and password. Passwords are stored only as a one-way hash (bcrypt), never in readable form.
- What you give the assistant: documents, web pages and text you add to its knowledge base, its instructions, and its settings.
- Usage records: message and voice-minute counts for your plan, and a log of important account actions, such as sign-ins and deletions, with the IP address they came from.
From visitors to a customer's website
- The conversation: what the visitor types or says and what the assistant answers. Voice calls are kept as text transcripts, not as audio recordings.
- Contact details the visitor chooses to give, such as name, email, phone and company, and a short AI-written summary of what they asked about.
- Short facts a returning visitor has shared, such as their company or what they are looking for, so the assistant does not have to ask again. These deliberately exclude health, financial and identity details and other sensitive categories.
- Technical details recorded when a conversation starts: IP address, browser type, the website it happened on, and the referring page. The widget stores a random visitor identifier in the visitor's browser (local storage) so a returning visitor's conversation can continue. It does not set cookies.
- Files a visitor attaches, such as an image or PDF, are sent to the AI model to answer the question. We record that a file of that type was attached, but we do not keep the file.
From convospire.com
convospire.com sets no cookies. Visits may be counted with Cloudflare Web Analytics, which does not use cookies and does not track you across websites.
Why we use it
- To run the service: answering visitors, delivering leads and alerts to the customer, and showing transcripts in the dashboard.
- To keep accounts secure, prevent abuse and enforce plan limits. For example, IP addresses are used briefly for rate limiting.
- To send service emails: account, trial, lead and handoff alerts. We do not send marketing email.
- To fix problems and improve reliability.
We do not sell personal data or use it for advertising. ConvoSpire does not train AI models on customers' documents or conversations.
Who processes it for us
We use these providers to run ConvoSpire. Each receives only what its part of the service needs.
| Provider | What for |
|---|---|
| Google (Gemini API) | The AI model that writes answers, reads attachments, and runs voice calls. In a voice call the visitor's browser connects to Google directly, so the audio does not pass through ConvoSpire. Google processes this content under its Gemini API terms. |
| Supabase | Database: accounts, knowledge bases, conversations and leads. |
| Railway | Hosts our API servers and their short-lived cache. |
| Resend | Sends service emails. |
| Cloudflare | Hosts the dashboards, and counts website visits without cookies. |
| GitLab | Hosts convospire.com. |
These providers may process data in countries other than yours. We may also disclose data where the law requires it.
How long we keep it
We keep a customer's data, including their visitors' conversations and leads, for as long as the account exists, so the customer can read their history. When a customer deletes their account from the dashboard, the account and everything in it are permanently erased. Short-lived records, such as rate-limit counters, expire on their own within hours.
Your choices and rights
- Customers can see and change their account and content in the dashboard at any time, and delete the account entirely. On the Pro plan, leads and transcripts can be exported as CSV. For a copy of your data in any other form, email us.
- Visitors: a customer can erase what their assistant remembers about you from the dashboard. To have your conversations or contact details deleted, ask the business, or email us and we will arrange it with them.
- Depending on where you live, you may have rights to access, correct, delete, restrict or object to the use of your personal data, and to complain to a data protection authority. Email us to use any of them. We will reply within 30 days.
Security
All traffic is encrypted in transit (HTTPS). Each customer's data is kept separate from every other customer's. A widget only runs on the domains its owner lists. Passwords are hashed, and access to production systems is restricted. No system is perfectly secure. If we learn of a breach affecting your data, we will tell you without undue delay.
Children
ConvoSpire is a business service and is not directed at children under 16. Customers should not use it to collect data from children.
Changes
If we change this policy, we will update the date at the top. If the change is significant, we will email customers before it takes effect.
Contact
Questions or requests: support@convospire.com.