1. Information we collect
Account details. Your name and email address, and your profile picture if you sign in with Google.
Workspace content. The email and chat messages your workspace handles, the customer records they belong to, the files people attach, and the knowledge base articles you write. If your workspace connects its own customer context API, we also send that API a customer's email address and store the answer it returns.
Widget visitor data. When one of our customers puts the Poise chat widget on their site, we record from each visitor: the page URL and title, the referrer, the viewport size, the timezone, the browser language, the user agent and the browser, operating system and device read from it, the city and country derived from the IP address, and the IP address itself. If the visitor types a name and an email address, we keep those too.
Usage and diagnostic data. Ordinary server logs and error reports, which include IP addresses and request paths.
Waitlist signups. If you join the waitlist on poise.so, we keep the name and the email address you gave us.
2. Signing in with Google
When you choose Continue with Google, we ask Google only for your basic profile: your name, your email address, your profile picture, and the identifier Google uses for your account. We use them to create your Poise account and to sign you in.
We do not request access to Gmail, Drive, Calendar, or Contacts, and we cannot read them.
Google user data is never sold, never shared for advertising, and never used to train AI models. It is used only to run the sign-in described here. The sign-in itself is handled by Supabase Auth on our behalf.
You can disconnect Poise from your Google account at any time at myaccount.google.com/permissions.
3. How we use it
- To run the service and show your workspace its own data.
- To reply when you write to support.
- To keep the service secure: rate limits, abuse investigation, and fraud prevention.
- To run the AI features described in the next section.
- To tell you about changes that affect you.
We do not sell personal data, and we do not use it for advertising.
4. AI processing
Summaries, drafts, classifications, and widget answers are produced by OpenAI models, which we reach through the Vercel AI Gateway. The text needed for the task is sent there to be processed, and the answer comes back to us.
Images can go too. When a chat widget visitor attaches a picture and that widget's AI is on, we may read the file and send it with the request, so the model can see what the visitor is describing. Only the recent ones count, in common picture formats and under a size limit; the rest of a visitor's files stay with us, and other kinds of attachment are never sent.
We do not use your content to train AI models.
5. Service providers
We use these companies to run Poise. Each one sees only what its job needs.
- Vercel hosts the app, runs its background jobs, and passes our AI requests on to the models.
- Supabase holds the database, the sign-in, and the files people upload.
- Amazon Web Services sends and receives the email.
- Upstash runs the Redis behind our rate limits and short-lived keys.
- Cloudflare checks a widget's first message for bots, and keeps the DNS records for a workspace's own domain.
- OpenAI provides the models behind the AI features above.
- Loops holds the waitlist for poise.so. Your browser never talks to Loops directly; we pass the name and the address on from our own server.
- Visitors counts page views on poise.so.
Browser push notifications go through the push service your browser vendor runs. We hold the signing keys ourselves, and no other provider is involved.
6. How long we keep it
- Workspace content stays while the account is open. Write to support@poise.so to close the account, and we delete it.
- Widget visitor IP addresses are cleared 90 days after they are recorded. The city and country stay; the address itself does not.
- What a workspace's own customer context API returns is stored as a snapshot and deleted once it has gone 30 days without being read. A snapshot that keeps being read keeps being stored.
- Waitlist signups stay until you unsubscribe.
7. Your rights
Write to support@poise.so to see what we hold about you, correct it, export it, or have it deleted. We answer as quickly as we can, and within any deadline the law sets.
Depending on where you live, you may have rights under the GDPR or the CCPA, including access, correction, deletion, portability, and objecting to some processing. The same address is where to use them.
When a workspace uses Poise to handle its own customers' messages, that workspace decides what happens to those records. Requests about them go to the workspace, and we help it act on them.
8. Security
Traffic runs over TLS, and the providers that store your data encrypt it at rest. Access is enforced row by row in the database, so one workspace cannot read another's data. We do not claim any security certification.
9. Cookies
Poise sets the cookies its sign-in needs to keep you logged in. The chat widget keeps a session token in the visitor's browser so a conversation survives a page reload. We do not set advertising or cross-site tracking cookies.
10. International transfers
Our providers run in the United States and in the European Union, so your data may be processed in either, whichever your data reaches first. Where a transfer leaves the European Economic Area, it relies on the safeguards the provider has in place.
11. Children
Poise is a tool for businesses. It is not for people under 16, and we do not knowingly collect their data. If you think a child's data has reached us, write to support@poise.so and we will delete it.
12. Changes to this policy
We will update this page when what we do changes. The date at the top is the day the current version took effect.
13. Contact us
Questions about this policy, or about the data we hold, go to support@poise.so. The terms that cover using Poise are in our Terms of Service.