Legal
Privacy Policy
Effective August 12, 2026
This policy covers the answerLoops hosted service (“answerLoops”, “we”, “us”). For your account, billing, and team information, answerLoops is the data controller. For the questions, replies, and other content your organization ingests through a connected channel, answerLoops acts as a data processor on your organization's behalf — your organization determines what gets connected and controls that content. If you run the open-source, self-hosted edition instead, you are the data controller for your own deployment and this policy doesn't apply to that instance — your own privacy policy governs it.
What we collect
Account & auth — name, email, and profile image from Google Sign-In, plus your organization name and team member roles.
Connected channel content — each channel only grants the access needed to answer support questions in it, and content read from a channel is used solely to create tickets and generate answers, never for anything else:
- Discord — our bot reads messages in the channels and threads it's added to, to detect questions and post answers.
- Slack — an installed org authorizes specific OAuth scopes for reading and posting messages in the channels it connects.
- Google Chat — a paired space sends us the messages posted in it; we do not use this data to develop, improve, or train any general-purpose or non-personalized AI/ML model, consistent with Google's API Services User Data Policy.
- Discourse and Circle — posts and comments from the categories or spaces your organization connects.
- GitHub — a GitHub App installation reads Issues and Discussions and writes comments, scoped to the repositories you select.
- Telegram — our bot reads messages sent to it directly or in groups it's added to.
- Email — inbound messages forwarded to your connected address, or sent via a Gmail/Outlook mailbox you connect with send-only OAuth scopes (we never read that mailbox's inbox).
- Website widget — visitor messages and, if a visitor provides one, their email address.
Knowledge sources — files, documentation URLs, repository content, and Notion pages your organization imports into its knowledge base.
Integration credentials — OAuth tokens, bot tokens, and webhook secrets for each channel you connect. These are encrypted at rest and used only to send/receive messages on your behalf.
AI provider keys — if you configure your own OpenAI, Anthropic, Google, Groq, Mistral, or other provider key, it's encrypted at rest and used only to call that provider on your organization's behalf. Saved keys are not displayed again in Settings.
Billing — handled by Stripe. We store your Stripe customer, subscription, and price identifiers; we never store card numbers ourselves.
Usage & product data — tickets, KB articles and embeddings, SLA and CSAT records, analytics events, feature-flag assignments, and API usage tied to your organization.
How we use it
To operate the product: route incoming questions, generate and grade AI answers, maintain your knowledge base, enforce SLAs, and show your dashboard/analytics.
To bill your subscription and enforce plan limits.
To send transactional email (ticket notifications, billing receipts, team invites) and, if you opt in, product updates.
We do not sell personal data, and we do not use it for behavioral advertising.
AI processing
answerLoops uses model services to draft and review replies and to create embeddings for knowledge search. Your organization configures its chat and embedding providers. These may be different services.
New hosted workspaces receive a one-time allowance of five AI-processed tickets using answerLoops-provided model access. After that allowance, your organization must configure its own provider credentials to continue AI processing.
Processing can include the question, relevant knowledge, recent conversation context, and source content used for indexing. The model provider processes this content under its own terms. Review the policies of each configured provider, including the embedding provider.
We do not use ticket, message, or knowledge-base content to train models we operate.
Data retention & deletion
Deleting your organization starts a 30-day grace period during which an owner can restore it. After 30 days, the organization and its data (tickets, KB content, integrations, credentials) are permanently purged.
Disconnecting a single channel immediately deletes that channel's stored credentials (tokens, bot secrets) and stops new content from being ingested; content already ingested before disconnecting remains part of your organization's ticket and KB history until your organization is deleted.
Each connected platform (Discord, Slack, Google Chat, GitHub, Telegram) has its own data retention and deletion policy governing content on its side. Where a platform's own policy requires deleting data sooner than the timeline above, we defer to that shorter timeline for the data originating from that platform.
Widget leads and email addresses collected through connected channels are retained as part of your organization's data and deleted on the same schedule.
You can also ask us to delete specific data outside the normal account-deletion flow by emailing us at the address below; we'll act on that request within 30 days.
Security
Integration tokens and AI provider keys are encrypted at rest. Access to your organization's data is scoped to your team members and enforced at the database query layer. We run automated dependency, secret, and static-analysis scans on every change to this codebase.
If we become aware of a security incident affecting your data, we'll notify affected organizations without undue delay.
Your rights
Depending on where you live, you may have some or all of the following rights over your personal data: to access a copy of it, to correct it, to request its deletion, to receive it in a portable format, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority. You can exercise most of these from Settings, or by emailing us at the address below.
International data transfers
Our systems are hosted in the United States. If you or your organization access answerLoops from outside the United States, your data will be transferred to and processed in the United States.
Children's privacy
answerLoops is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We'll update the effective date above when this policy changes, and post material changes on this page before they take effect.
Contact
Questions about this policy or a data request: [email protected].