QuelpAI

Privacy Policy

What data QuelpAI collects, why, who it’s shared with, and the choices you have.

Last updated: August 24, 2026

This policy is a starting template based on how QuelpAI actually works today. It is not legal advice — have it reviewed by a qualified privacy lawyer, keep the sub-processor list current, and replace the bracketed placeholders ([Legal entity], [Jurisdiction], [Company address]) with your real details before launch.

1. Scope & our two roles

This policy covers [Legal entity] operating as QuelpAI (“QuelpAI”, “we”). QuelpAI is an AI sales agent that businesses embed on their websites to answer questions, qualify visitors, capture leads, and book meetings. We handle personal data in two different roles:

  • As a controller — for our own customers’ account, billing, and usage data, and for our website visitors. We decide how that data is used.
  • As a processor — for data our customers collect from their own website visitors through the QuelpAI widget (conversations, leads, bookings). Here the customer is the controller; we process it on their behalf and under their instructions.

If you chatted with a QuelpAI agent on someone else’s website, that business is responsible for your data — see “Website visitors” below.

2. Information we collect

  • Account data — your name, email, hashed password (or Google profile basics if you sign in with Google, such as name, email, and avatar), and workspace settings.
  • Billing data — plan and subscription status. Payments are processed by Stripe; we receive limited details (e.g. status, last-four, billing metadata) but do not store full card numbers.
  • Website & knowledge content — pages we crawl at your direction, plus facts, brand assets, and configuration you add so the agent can answer accurately.
  • Conversation & lead data — messages exchanged with the agent, and details visitors provide (name, email, company, phone, enquiry), meeting bookings, and intent/lead scores.
  • Visitor & usage data — page URLs and on-site events used to detect intent, plus technical logs such as IP address, browser/device type, timestamps, and error data.

3. How we use information

  • provide and operate the Service — run the agent, generate answers, score and route leads, book meetings, and send notifications;
  • authenticate you and secure accounts (including Google sign-in);
  • process payments and manage subscriptions;
  • send transactional messages — owner alerts, booking confirmations, and AI-drafted follow-ups you enable;
  • maintain, debug, and improve the Service and its safety;
  • comply with law and enforce our Terms.

4. AI processing & sub-processors

To generate replies and other AI features, conversation content and relevant context are sent to large-language-model providers. We rely on the following sub-processors to run the Service. This list may change as the Service evolves — we’ll keep it current.

  • Neon — managed PostgreSQL database hosting (primary data store).
  • LLM providers (Google Gemini, Groq, OpenRouter) — generate agent responses and drafts from conversation content.
  • Google — sign-in (OAuth), the optional Google Sheets integration, and website performance checks (PageSpeed).
  • Stripe — payment processing and subscription billing.
  • Resend — transactional and follow-up email delivery.
  • ImgBB — hosting of brand logos and uploaded images.

5. Cookies & local storage

We keep this minimal and do not use third-party advertising trackers. We use:

  • Essential storage — the dashboard stores your login tokens and active workspace in your browser’s local storage so you stay signed in.
  • Widget storage — the chat widget may store a small identifier to keep a conversation continuous for a returning visitor.

Where a customer deploys the widget in a region requiring consent, the customer is responsible for obtaining it on their site.

6. How we share information

  • Sub-processors — as listed above, to run the Service.
  • Integrations you connect — when a customer connects Slack, Zapier, HubSpot, Google Sheets, Zoho CRM, or a webhook, we send the relevant lead and event data to that destination at the customer’s instruction.
  • Legal & safety — where required by law, or to protect our rights, users, and the Service.
  • Business transfers — as part of a merger, acquisition, or asset sale, subject to this policy.

We do not sell your personal data.

7. Data retention

We keep personal data for as long as your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer period is required by law (for example, tax and accounting records). Customers can delete leads, conversations, and their account from the dashboard; deleting your account removes your workspace data, subject to backups that expire on a rolling basis.

8. Security

We take reasonable technical and organizational measures to protect data — including encryption in transit (HTTPS), hashed passwords (bcrypt), scoped API keys, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your data, we will notify you as required by law.

9. International transfers

QuelpAI is operated with infrastructure that may store and process data outside your country (our primary database is hosted in Singapore, and sub-processors operate globally). Where required, we rely on appropriate safeguards for cross-border transfers.

10. Your rights & choices

Depending on where you live (e.g. under GDPR or CCPA), you may have rights to access, correct, delete, port, or object to the processing of your personal data, and to withdraw consent. Account holders can manage much of this directly in the dashboard. To make a request, email hello@quelpai.com. We will respond within the timeframe required by applicable law.

11. If you chatted with an agent on another website

When you use a QuelpAI-powered chat on a business’s website, that business decides what data is collected and why — they are the controller. We process it on their behalf. To access or delete that data, please contact the business that operates the website. We will support them in honouring your request.

12. Children

The Service is not directed to children and is not intended for anyone under 16 (or the age set by local law). We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the Service changes. Material changes will be signposted (for example by email or in the dashboard), and the “last updated” date above will change.

14. Contact us

For privacy questions or requests, email hello@quelpai.com. Data controller: [Legal entity], [Company address], [Jurisdiction].