Privacy Policy

Last updated: December 2024

Your privacy is critically important to us. This policy explains how we collect, use, and protect your information.

Data Protection

Enterprise-grade security

Transparency

Clear data practices

Your Control

You own your data

Minimal Collection

Only what's necessary

1. Information We Collect

Personal Information

  • Account Information: Email address, full name, password (encrypted), subscription details
  • Profile Data: User preferences, plan type, verification status
  • Billing Information: Payment details processed securely through Stripe (we do not store credit card information)
  • Communication Data: Support tickets, email correspondence, feedback

Usage Data

  • Service Usage: Chat conversations, AI responses, knowledge base interactions
  • Analytics Data: Feature usage, response times, success rates, token consumption
  • Integration Data: Crisp chat sessions, calendar appointments, product interactions
  • API Usage: API calls, endpoints accessed, usage patterns

Technical Information

  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Server logs, error reports, performance metrics
  • Cookies: Session cookies, preference cookies, analytics cookies

Content Data

  • Knowledge Base: Documents, text content, files you upload
  • Product Catalog: Product information, descriptions, metadata
  • Calendar Data: Appointment details, scheduling preferences

2. How We Use Your Information

Service Provision

  • Provide and maintain the NarodGPT platform and services
  • Process AI chat requests and generate responses using your knowledge base
  • Manage user accounts, authentication, and access control
  • Handle billing, subscription management, and payment processing
  • Enable integrations with third-party services (Crisp, Google Calendar, etc.)

Communication and Support

  • Send important service updates, security alerts, and notifications
  • Respond to support requests, inquiries, and feedback
  • Provide customer support and technical assistance
  • Send verification emails and account-related communications

Service Improvement and Analytics

  • Analyze usage patterns to improve service performance and features
  • Monitor system performance and identify technical issues
  • Develop new features and enhance existing functionality
  • Conduct research and analytics to improve AI responses

Legal and Security

  • Ensure platform security and prevent abuse or fraud
  • Comply with legal obligations and regulatory requirements
  • Protect our rights and the rights of our users
  • Investigate and prevent violations of our Terms of Service

3. Information Sharing and Disclosure

Third-Party Service Providers

We work with trusted third-party providers to deliver our service. These providers have access to your information only to perform specific tasks on our behalf and are obligated not to disclose or use it for other purposes:

  • OpenAI: AI model processing for generating responses (subject to their privacy policy)
  • Stripe: Payment processing and billing management
  • Google: Calendar integration and OAuth authentication
  • Railway: Cloud hosting and infrastructure services
  • Email Service Providers: Transactional email delivery

Business Transfers

If NarodGPT is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).

We Never Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is only shared as necessary to provide our service or as required by law.

4. Data Security and Protection

Security Measures

  • Encryption: Data encrypted in transit using TLS/SSL and at rest using AES-256
  • Access Controls: Role-based access controls and multi-factor authentication
  • Infrastructure Security: Secure cloud infrastructure with regular security updates
  • Monitoring: 24/7 security monitoring and intrusion detection
  • Audits: Regular security audits and vulnerability assessments
  • Employee Training: Security awareness training for all team members

Data Retention

  • Account Data: Retained while your account is active and for 30 days after deletion
  • Chat Conversations: Retained for service improvement, anonymized after 90 days
  • Knowledge Base Content: Retained until you delete it or close your account
  • Billing Records: Retained for 7 years as required by law
  • Log Data: Retained for 12 months for security and debugging purposes

Data Breach Response

In the event of a data breach, we will notify affected users within 72 hours and provide details about the incident, potential impact, and steps being taken to address the issue.

5. Your Rights and Choices

Data Access and Control

  • Access: Request a copy of your personal data we hold
  • Correction: Update or correct inaccurate personal information
  • Deletion: Request deletion of your account and associated data
  • Portability: Export your data in a machine-readable format
  • Restriction: Request limitation of processing of your personal data
  • Objection: Object to processing of your personal data for certain purposes

Communication Preferences

  • Opt out of marketing communications (service communications will continue)
  • Control notification settings in your account dashboard
  • Manage email preferences and frequency

Account Deletion

You can delete your account at any time through your account settings or by contacting support. Upon deletion, we will remove your personal data within 30 days, except for data we are required to retain by law.

6. Cookies and Tracking Technologies

Types of Cookies We Use

  • Essential Cookies: Required for basic site functionality, authentication, and security
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Help us understand how you use our service to improve it
  • Security Cookies: Detect suspicious activity and prevent fraud

Managing Cookies

You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our service.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with this privacy policy and applicable data protection laws.

For transfers outside the European Economic Area (EEA), we use Standard Contractual Clauses approved by the European Commission or other appropriate safeguards.

8. Children's Privacy

Our service is not intended for children under 16 years of age (or 13 in the United States). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

9. Regional Privacy Rights

European Union (GDPR)

If you are located in the EU, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with a supervisory authority.

California (CCPA)

California residents have specific rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and the right to delete personal information.

Other Jurisdictions

We comply with applicable data protection laws in all jurisdictions where we operate.

10. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new privacy policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice via email or prominent notice on our service.

Your continued use of the service after any changes indicates your acceptance of the updated privacy policy.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Questions or Concerns?

We're committed to protecting your privacy. If you have any questions or concerns about how we handle your data, please don't hesitate to reach out to our team.