Privacy and data use
This notice describes the current AddMyBot MVP. A business using the widget decides what it publishes and how it handles its customers. Public launch requires operator identity, verified contact details and review of this notice.
Account and knowledge
Supabase Auth handles account email, password authentication and confirmation/reset flows. AddMyBot stores one business and agent per owner, configuration, private knowledge, indexes, hashed API keys and usage reservations. Documents, manual text and selected text from one public webpage are stored privately. Relevant text and questions are sent to configured Google AI models for embeddings and grounded generation. Bounded completed-turn context can be included. Contact form fields are excluded from AI history and retrieval. Google’s unpaid Gemini services may use submitted content and responses to improve products, with human review. Do not submit sensitive, confidential or personal information to AI chat or knowledge. Provider policies vary by region; review Google’s current terms before use. Consented follow-up contact fields are stored for the business and are not sent to the AI provider. Supabase storage, authentication and backups have separate provider policies.
Website messages and consented follow-up
Website questions, answers, citations and statuses are available for business review for 30 days, within record limits. When knowledge is insufficient, visitors can explicitly consent to providing an email and optional name/phone for that business to follow up. No email or CRM workflow is sent automatically. The business can change follow-up status or delete records. A response is not guaranteed.
Private tests and API access
Playground review history stays in tab memory. A private server context and retry cache hold questions and answers for up to 15 minutes; interpretation uses at most four completed turns within 2,000 bytes. New chat replaces the context. Tests do not create customer conversation or lead records. API chat uses approved sources and a 15-minute retry cache, without customer records. Keys are shown once and stored as hashes. Operational request hashes, counters and reservations are separate from review history.
Subscription billing
When you explicitly open Test Mode checkout, the official Razorpay checkout handles synthetic payment/contact details. AddMyBot does not store card numbers, bank credentials or OTPs. It stores owner-bound subscription identifiers, verified payment/invoice identifiers, plan, INR amount, coverage dates and processing metadata. These billing records are separate from the 30-day customer-review cleanup and are not sent to the AI provider. The checkout script loads only when requested. Billing metadata retention, merchant identity, tax treatment and refund decisions require owner/legal review before real sales. Never enter real payment instruments into this development workflow.
Browsers and network metadata
Authentication uses session cookies. Test history and widget visitor tokens stay in page memory, not persistent browser storage. Signed visitor sessions and exact origins constrain widget access. Keyed network pseudonyms support abuse controls where a trusted proxy is configured; a shared unknown-address bucket is used otherwise. Appearance and sidebar preferences are stored locally in your browser, without account or conversation data. Widget appearance preferences are separate. This MVP adds no advertising analytics. A webpage import contacts the specified public website from the application server and fetches HTML only.
Expiry, deletion and requests
Access expiry is enforced. Expired metadata/records are cleaned during relevant activity, within capacity limits; expiry does not promise an exact physical purge time. Backups may have separate retention. Owner deletion prevents customer record recovery and removes related data through the workflow. Knowledge deletion removes its source/index and private file; failed cleanup is reported and can be retried. New chat, deletion and revocation do not refund usage. Revocation blocks later key use and reply recovery.
For a business’s widget messages or consented contact request, contact that business through its published details. For account/platform privacy requests, contact the AddMyBot Support Team. A verified operator contact address must be configured before public launch.