Skip to content

Legal

Privacy Policy

Effective August 12, 2026

This policy covers the answerLoops hosted service (“answerLoops”, “we”, “us”). For your account, billing, and team information, answerLoops is the data controller. For the questions, replies, and other content your organization ingests through a connected channel, answerLoops acts as a data processor on your organization's behalf — your organization determines what gets connected and controls that content. If you run the open-source, self-hosted edition instead, you are the data controller for your own deployment and this policy doesn't apply to that instance — your own privacy policy governs it.

What we collect

Account & auth — name, email, and profile image from Google Sign-In, plus your organization name and team member roles.

Connected channel content — each channel only grants the access needed to answer support questions in it, and content read from a channel is used solely to create tickets and generate answers, never for anything else:

  • Discord — our bot reads messages in the channels and threads it's added to, to detect questions and post answers.
  • Slack — an installed org authorizes specific OAuth scopes for reading and posting messages in the channels it connects.
  • Google Chat — a paired space sends us the messages posted in it; we do not use this data to develop, improve, or train any general-purpose or non-personalized AI/ML model, consistent with Google's API Services User Data Policy.
  • Discourse and Circle — posts and comments from the categories or spaces your organization connects.
  • GitHub — a GitHub App installation reads Issues and Discussions and writes comments, scoped to the repositories you select.
  • Telegram — our bot reads messages sent to it directly or in groups it's added to.
  • Email — inbound messages forwarded to your connected address, or sent via a Gmail/Outlook mailbox you connect with send-only OAuth scopes (we never read that mailbox's inbox).
  • Website widget — visitor messages and, if a visitor provides one, their email address.

Knowledge sources — files, documentation URLs, repository content, and Notion pages your organization imports into its knowledge base.

Integration credentials — OAuth tokens, bot tokens, and webhook secrets for each channel you connect. These are encrypted at rest and used only to send/receive messages on your behalf.

AI provider keys — if you configure your own OpenAI, Anthropic, Google, Groq, Mistral, or other provider key, it's encrypted at rest and used only to call that provider on your organization's behalf. Saved keys are not displayed again in Settings.

Billing — handled by Stripe. We store your Stripe customer, subscription, and price identifiers; we never store card numbers ourselves.

Usage & product data — tickets, KB articles and embeddings, SLA and CSAT records, analytics events, feature-flag assignments, and API usage tied to your organization.

How we use it

To operate the product: route incoming questions, generate and grade AI answers, maintain your knowledge base, enforce SLAs, and show your dashboard/analytics.

To bill your subscription and enforce plan limits.

To send transactional email (ticket notifications, billing receipts, team invites) and, if you opt in, product updates.

We do not sell personal data, and we do not use it for behavioral advertising.

AI processing

answerLoops uses model services to draft and review replies and to create embeddings for knowledge search. Your organization configures its chat and embedding providers. These may be different services.

New hosted workspaces receive a one-time allowance of five AI-processed tickets using answerLoops-provided model access. After that allowance, your organization must configure its own provider credentials to continue AI processing.

Processing can include the question, relevant knowledge, recent conversation context, and source content used for indexing. The model provider processes this content under its own terms. Review the policies of each configured provider, including the embedding provider.

We do not use ticket, message, or knowledge-base content to train models we operate.

Who we share it with

Sub-processors that support running the service: Stripe (payments), Resend (transactional email), and our cloud hosting and database providers (storage and infrastructure). Each processes data only as needed to provide their service to us.

Discord, Slack, Discourse, Circle, Google, GitHub, and Telegram each receive the messages your organization sends back through their platform — governed by their own privacy terms as well as ours.

We disclose data if legally required to, or to protect the security or rights of answerLoops or our users. We otherwise do not share personal data with third parties.

Data retention & deletion

Deleting your organization starts a 30-day grace period during which an owner can restore it. After 30 days, the organization and its data (tickets, KB content, integrations, credentials) are permanently purged.

Disconnecting a single channel immediately deletes that channel's stored credentials (tokens, bot secrets) and stops new content from being ingested; content already ingested before disconnecting remains part of your organization's ticket and KB history until your organization is deleted.

Each connected platform (Discord, Slack, Google Chat, GitHub, Telegram) has its own data retention and deletion policy governing content on its side. Where a platform's own policy requires deleting data sooner than the timeline above, we defer to that shorter timeline for the data originating from that platform.

Widget leads and email addresses collected through connected channels are retained as part of your organization's data and deleted on the same schedule.

You can also ask us to delete specific data outside the normal account-deletion flow by emailing us at the address below; we'll act on that request within 30 days.

Security

Integration tokens and AI provider keys are encrypted at rest. Access to your organization's data is scoped to your team members and enforced at the database query layer. We run automated dependency, secret, and static-analysis scans on every change to this codebase.

If we become aware of a security incident affecting your data, we'll notify affected organizations without undue delay.

Your rights

Depending on where you live, you may have some or all of the following rights over your personal data: to access a copy of it, to correct it, to request its deletion, to receive it in a portable format, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority. You can exercise most of these from Settings, or by emailing us at the address below.

International data transfers

Our systems are hosted in the United States. If you or your organization access answerLoops from outside the United States, your data will be transferred to and processed in the United States.

Children's privacy

answerLoops is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We'll update the effective date above when this policy changes, and post material changes on this page before they take effect.

Contact

Questions about this policy or a data request: [email protected].