AnswerLoop Privacy Policy (Draft — counsel review pending)
Last updated: [DATE]
This page is scaffolded from counsel's working draft and is not final. Bracketed placeholders (e.g. [DATE], [LEGAL ENTITY NAME], [DOMAIN]) are counsel's to fill before this policy is published. Final, counsel-approved text replaces this draft before the launch-day merge.
To counsel: placeholders in [BRACKETS]. Product facts (data flows, subprocessors, retention numbers) are verified against the codebase as of 2026-07-02 and are enforced in software (retention cron, churned-account purge). Please review role framing (processor vs. controller), state-law scope (US-only service; TX/CA emphasis for home-services customers), and the children's/ sensitive-data sections.
Who we are: AnswerLoop ("we," "us"), a product of [LEGAL ENTITY NAME, e.g., Revity Digital LLC], [ADDRESS]. Contact: privacy@[DOMAIN].
AnswerLoop provides AI-powered site search and chat widgets that businesses ("Customers") install on their own websites to answer their visitors' ("Visitors") questions from the business's own website content and to capture service requests.
1. The two roles we play
For Customer account data, we are the controller. This covers information Customers give us to run their account.
For Visitor data collected through a Customer's widget, we are a service provider/processor acting on the Customer's instructions. The Customer is the controller of its Visitors' data. Visitors with questions about a business's data practices should contact that business; we assist Customers in honoring such requests.
2. What we collect
A. Customer account data (we are controller): name, email, and login credentials (managed by our authentication provider, Clerk); billing details (processed by Stripe — we never store card numbers); website domain and site content you ask us to index; settings, notification email/phone; support communications.
B. Visitor data via the widget (we are processor):
Conversations and search queries — the questions Visitors type, and the answers given, recorded so the widget can respond, so the Customer can review conversations, and so unanswered questions can be surfaced to the Customer.
Lead details Visitors choose to submit — name, email and/or phone, and their message, collected only when a Visitor submits them to request contact or a quote.
Technical/usage data — an opaque per-visitor identifier, page URL, timestamps, and approximate request metadata used for security, rate-limiting, and conversation grouping. We do not build cross-site advertising profiles and we do not sell or share personal information for cross-context behavioral advertising.
C. Public business data (prospecting): we may collect publicly available business contact information (e.g., a business's published email address) to contact businesses about our services. Recipients can opt out via the unsubscribe mechanism in any such email, and we honor suppression permanently.
D. Anonymous website preview: when someone tries our live preview on a domain, we crawl up to 10 public pages of that domain and retain that temporary index for 24 hours, after which it is automatically deleted.
3. How we use information
To provide the service (answer Visitor questions only from the Customer's own site content), deliver leads to the Customer (email, SMS, and — if the Customer connects it — their CRM such as Jobber), show Customers their conversations/leads/search analytics, secure and rate-limit the service, bill Customers, improve reliability, and send Customers service communications.
AI processing — no model training. Visitor messages and site content are processed by our AI subprocessors (Anthropic for responses; Voyage AI for search relevance) under commercial API terms; inputs are not used to train their models. Answers are generated only from the Customer's own indexed website content.
4. Subprocessors
| Provider | Purpose |
|---|---|
| Supabase | Database & storage (encrypted at rest) |
| Vercel | Application hosting |
| Clerk | Customer authentication |
| Stripe | Payments |
| Anthropic | AI response generation |
| Voyage AI | Search relevance (embeddings) |
| Resend | Transactional email (lead alerts, digests) |
| Twilio | SMS lead alerts (when enabled by Customer) |
| Upstash | Rate-limiting & caching |
| ScrapingBee | Website crawling for indexing |
| Jobber | CRM lead delivery (only when the Customer connects their own Jobber account) |
We update this list here; material changes are notified to Customers.
5. Retention (enforced in software)
| Data | Retention |
|---|---|
| Visitor conversations & search queries | 24 months, then automatically deleted |
| Visitor lead details | Until the Customer deletes them or the Customer's account closes |
| Anonymous preview index | 24 hours |
| Customer account data | Life of the account |
| Closed accounts | All Customer and Visitor data (site index, conversations, leads, integrations) hard-deleted 30 days after account closure |
| Billing records | As required by law |
| Suppression/opt-out records | Kept indefinitely (so opt-outs stick) |
Customers can delete individual leads and conversations from their dashboard at any time.
6. Your rights
Visitors: contact the business whose website you used; we support their fulfillment. You may also email privacy@[DOMAIN] and we will route or act as the law requires.
Customers and prospects: email privacy@[DOMAIN] to access, correct, delete, or export your personal information, or to opt out of marketing. We respond within 30 days. We do not discriminate for exercising rights. [COUNSEL: confirm CCPA/CPRA, Texas TDPSA, Virginia VCDPA phrasing appropriate to current thresholds.]
7. Security
Encryption in transit (TLS) and at rest; tenant data isolation enforced server-side; OAuth tokens for connected integrations encrypted with AES-256-GCM; access limited to authorized personnel; payment data handled solely by Stripe. No method is 100% secure; we will notify affected Customers of a breach as required by law.
8. Scope, children, changes
The service is offered to U.S. businesses and is not directed to children under 13; we do not knowingly collect children's data (Visitor-typed content is controlled by the Customer's audience). We are not directed at the EU/UK. Material changes to this policy will be posted here with a new "Last updated" date and notified to Customers.
Contact: privacy@[DOMAIN] · [LEGAL ENTITY, ADDRESS]