Privacy Policy

Effective date: June 28, 2026

1. Information We Collect

We collect data necessary to provide the QwryAI platform, including:

  • Account and identity data (name, email, authentication metadata).
  • Workspace and configuration data (chatbot settings, integrations, prompts, and uploaded content).
  • Conversation and support data (messages, tickets, knowledge-base content, and optional attachments).
  • Connected channel account data when you enable integrations such as email, chat, social messaging, commerce, scheduling, or team notification channels, including OAuth profile details, channel identifiers, sender details, message metadata, support content, and attachments needed to operate those channels.
  • Billing and transaction data (plan, subscription status, payment records from payment processors).
  • Technical and usage data (IP address, device/browser data, logs, diagnostics, and product analytics events).

2. Data Sources

Data is collected directly from users and workspace admins, through connected services such as Google, Microsoft, Shopify, Meta, Slack, Calendly, and email providers, and automatically from platform usage.

3. How We Use Information

We process personal and customer data to operate and improve the service, including authentication, model-powered responses, support operations, billing, fraud prevention, security monitoring, and legal compliance.

When AI features are enabled, conversation content and related workspace context may be processed by configured AI model providers only to generate, classify, route, summarize, or improve support workflows for your workspace. We do not use customer content from connected channels or Google user data to train generalized AI or machine learning models.

4. Connected Channels and Messaging Data

If you connect a customer-support channel, QwryAI uses the authorization method for that channel, such as OAuth, API tokens, signed webhooks, IMAP/SMTP credentials, or platform app permissions. Connected channels may include website chat, Gmail, Outlook, custom email, WhatsApp, Instagram, Facebook, Telegram, TikTok, Slack, Calendly, Shopify, and other integrations you enable. We use this access to receive support messages, create or update conversations, display channel-specific sender and message details, send replies or notifications, and perform the specific support, scheduling, commerce, or routing actions you configure.

Channel data may include account or page identifiers, mailbox addresses, phone numbers, profile names, handles, sender and recipient details, subjects, message bodies, message identifiers, thread references, timestamps, delivery statuses, order or product context where commerce features are enabled, and attachment or media metadata and content where the channel provides it. Channel data is processed through webhooks, polling, queues, and delivery workers for connection verification, inbound message processing, duplicate detection, routing, retries, outbound delivery, and auditability. For email channels, QwryAI starts from the current mailbox cursor by default and does not import historical mailbox content unless configured to do so.

OAuth access tokens, refresh tokens, API keys, webhook secrets, IMAP/SMTP passwords, and comparable integration credentials are stored encrypted where QwryAI stores them. We use connected channel data only to provide, secure, monitor, and improve the channel functionality enabled for your workspace, and to comply with legal obligations.

For Google APIs, including Gmail, QwryAI does not sell Google user data, use it for advertising, or transfer it except as needed to provide and secure the functionality you enabled, comply with law, or use service providers acting on our behalf under confidentiality and security obligations. QwryAI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Third-Party Services

Depending on enabled features, we use third-party providers such as:

  • OpenAI and AI model providers for language and embedding features.
  • Stripe for billing, payment processing, and invoicing workflows.
  • Google, Microsoft, Meta, Slack, Calendly, Shopify, Telegram, TikTok, and other integration providers for channels you authorize.
  • Sentry and analytics providers for error monitoring and usage insights.
  • Cloud/infrastructure providers (including storage, queues, and caching such as AWS and Upstash where configured).
  • Communication and email providers for transactional notifications.

6. Data Sharing

We do not sell personal information. We disclose data only to subprocessors and service providers needed to deliver the platform, and to authorities when legally required.

7. Data Protection and Security

We use administrative, technical, and organizational safeguards to protect personal data and customer content. These safeguards include tenant-scoped access controls, authentication and role checks, transport encryption, encrypted storage for integration credentials such as OAuth access tokens, refresh tokens, API keys, IMAP/SMTP passwords, and webhook secrets, signed OAuth state values, webhook signature validation, credential redaction from API responses, rate limits, queue retry controls, monitoring, and restricted operational access.

No system can be guaranteed completely secure. If we identify a security incident affecting personal data, we will investigate, mitigate, and provide notices where required by law.

8. Data Retention and Deletion

We retain data for the duration of your account and for a limited period after termination for security, legal, and financial requirements. Typical retention targets:

  • Account and workspace records: while account is active.
  • Connected channel integration credentials: while the integration is connected, unless earlier revoked or deleted.
  • Support conversations created from email and other channels: while the workspace or chatbot record is active, unless deleted earlier through product controls or a verified deletion request.
  • Operational logs and security events: up to 12 months.
  • Billing and tax records: up to 7 years where legally required.

Disconnecting a channel integration deletes the stored integration credentials for that channel and disables its conversation mapping where applicable. Existing support conversation records remain subject to your workspace retention, deletion controls, verified privacy requests, and legal hold requirements.

9. Your Privacy Rights

Depending on jurisdiction (including GDPR/UK GDPR and CCPA/CPRA), you may have rights to access, correct, delete, export, or restrict processing of your data, and to appeal where applicable.

To exercise rights, contact support@qwryai.com. We verify requests before processing.

10. Cookies and Tracking

We use essential cookies (for authentication and session management) and may use analytics cookies where configured. See the Cookie Policy for details.

11. International Transfers

Your data may be processed in countries other than your own. Contractual and technical safeguards are used where required by law.

12. Contact

For privacy requests, contact us at support@qwryai.com.