Privacy Policy

Last updated: March 1, 2026

What we collect

When you sign up, we collect your name and email via our authentication provider (Clerk).

When you use your AI assistant, the following is stored in your dedicated instance:

  • Conversation history across all connected channels
  • Files uploaded to or generated by your assistant
  • Channel connection credentials (WhatsApp sessions, Telegram bot tokens, etc.)
  • Assistant memory and knowledge base content you provide
  • Usage logs (message counts, token usage — for billing and service management)

Where your data lives

  • Your assistant runs in a dedicated container on our infrastructure in the United States
  • Account data (email, username, billing) is stored in Supabase (cloud, US region)
  • Authentication is handled by Clerk (cloud provider)
  • The website is hosted on Vercel
  • Payments are processed by Stripe (we never see or store your card details)

AI processing and third-party providers

Your assistant's AI responses are generated by third-party model providers. When you send a message to your assistant, your prompt and relevant context are sent to these providers for processing.

Current AI providers include:

  • Mistral AI (via OpenRouter) — used for standard-tier AI processing
  • Anthropic — used for premium-tier AI processing

These providers process your data under their own privacy policies and terms. We select providers with strong privacy commitments and enterprise-grade data handling. We do not use providers that train on customer data by default, but we recommend reviewing their policies directly:

Who can access your data

  • You and your team — via your assistant and the data export feature
  • GetOnIt administrators — for operations, debugging, and support only
  • AI providers — receive your prompts and context for processing (see above)
  • Infrastructure providers — Supabase, Clerk, Vercel, Stripe (for their respective services)

We do not sell your data. We do not use your data to train AI models. We do not share your data with third parties for marketing purposes.

Data isolation

Each team's assistant runs in a dedicated container instance. Your conversations, files, and knowledge base are stored separately from other customers. Container isolation means your data is not accessible to other users of the service.

Data retention

  • Active account: Your data is retained while your account is active
  • Cancelled subscription: Data retained for 30 days after cancellation, then permanently deleted
  • Deleted account: All data is permanently purged within 30 days
  • Usage logs: Retained for 90 days for billing and service management

Your rights

  • Access: View all your data through your assistant and dashboard
  • Export: Download all your data from your dashboard settings
  • Delete: Permanently remove all data by deleting your account
  • Correct: Update your information through your dashboard

If you're in the EU or California, you have additional rights under GDPR and CCPA respectively. Contact us to exercise these rights and we'll respond within 30 days.

Cookies

We use essential cookies for authentication (Clerk) and session management. We use Vercel Analytics for basic traffic data (page views, no personal tracking). We do not use advertising cookies or third-party tracking pixels.

Changes

We'll email you about material changes to this policy with at least 30 days notice.

Contact

Questions about your data or this policy? Email [email protected] and we'll respond within 48 hours.