1. Overview & Scope
This Privacy Policy explains how Saanish ("Saanish", "we", "us", or "our") handles personal information across our website (saanish.com), our cloud application, developer APIs, and the embeddable customer support chat widget installed on our customers' websites.
In the context of data protection laws (such as the General Data Protection Regulation / GDPR):
- Saanish as Data Controller: We act as a Data Controller for our direct customers' account credentials, billing records, and direct communications with us.
- Saanish as Data Processor: When our customers install our chat widget or connect knowledge bases, we act as a Data Processor on behalf of our customer, who remains the Data Controller for conversations conducted with their visitors.
2. Information We Collect
A. Account & Administrative Data
When you create an account, we collect your name, email address, company name, and authentication tokens via our authentication provider (Clerk). If you subscribe to a paid plan, payment transactions are processed securely via Stripe. Saanish does not store complete credit card numbers or CVV codes.
B. Knowledge Base & Training Content
To enable your AI chatbot to answer customer questions, you may upload documents (PDF, DOCX, TXT), connect Notion pages, sync Google Docs, or input website URLs for automatic crawling. We parse, chunk, and create vector embeddings from this content to power semantic search.
C. Chatbot Visitor & Conversation Data
When an end-user interacts with a Saanish widget on a website, we collect:
- Messages, questions, feedback ratings, and attachments sent during the chat session.
- A pseudonymized visitor identifier stored in local storage to preserve conversation threads.
- Technical metadata: approximate location (country/city derived from IP), browser type, OS, and referring URL.
- Visitor session events and optional diagnostic replay recordings where enabled by the website owner.
D. Usage & Diagnostic Telemetry
We automatically log operational telemetry such as API response latencies, error logs, and aggregated feature usage via PostHog to detect software bugs and optimize system performance.
3. How We Use Your Information
We process personal information for the following legitimate business purposes:
- Delivering the Service: Operating AI chatbots, synthesizing answers from your knowledge bases, notifying your team of customer escalations, and executing automated workflows.
- Billing & Account Management: Invoicing subscription plans, monitoring usage tiers, and sending transactional notices (such as password resets or receipt confirmations).
- Customer Support: Investigating reported errors, answering support inquiries, and debugging widget embed issues.
- Security & Fraud Prevention: Detecting abusive crawling, preventing distributed denial-of-service (DDoS) attacks, and maintaining platform integrity.
4. AI & Large Language Model (LLM) Data Handling
Our Core AI Commitment:
Saanish does not sell your data. We do not use your private company documents, internal knowledge bases, or end-user support chats to train generalized, public foundational models (such as public models offered by third-party AI vendors) without explicit consent.
When a visitor poses a question in the chat widget, Saanish queries your vectorized knowledge base to retrieve the most relevant reference snippets. These snippets, along with the visitor query and conversation context, are passed via encrypted enterprise APIs to foundational model inference providers (such as Google Cloud Vertex AI, Anthropic, or OpenAI). These enterprise API integrations operate under strict commercial terms that prohibit the provider from using customer API inputs for model training.
6. International Data Transfers
Saanish operates globally. If you access the Service from the European Economic Area (EEA), the United Kingdom, or other regions with laws governing data collection and use, your data may be transferred to and processed in the United States. Where required, we utilize standard contractual clauses (SCCs) approved by the European Commission to ensure equivalent data protection.
7. Data Retention & Deletion
We retain your information for as long as your account is active or as needed to provide the Service. You maintain granular control over your data:
- Knowledge Base Articles: You can delete any uploaded file, crawled URL, or FAQ snippet at any time via your dashboard, which immediately removes its vector index.
- Conversations: You can delete conversation logs, tickets, and visitor records directly from the inbox.
- Account Deletion: You can request full account deletion through your account settings or by contacting [email protected]. Upon confirmation, all associated chatbots, knowledge bases, and user records are permanently deleted within 30 days.
8. Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on your location, you have certain legal rights regarding your personal information:
Right to Access & Portability
Request a copy of the personal information we maintain about you in a structured format.
Right to Erasure ("Forgotten")
Request permanent deletion of your personal data where no legal retention duty applies.
Right to Rectification
Correct incomplete, inaccurate, or outdated personal details in your account.
Right to Object & Restrict
Object to processing based on legitimate interests or request processing limits.
To exercise any of these rights, email us at [email protected]. We respond to all verified requests within thirty (30) days.
9. Data Security & Encryption
Saanish adheres to industry best practices to protect your data. All network communication between users, the embed widget, and our servers is encrypted in transit using Transport Layer Security (TLS 1.3). All database records, knowledge bases, and vector embeddings are encrypted at rest using AES-256.
We employ strict Row-Level Security (RLS) policies within our database to ensure tenant data is completely isolated and accessible only by authorized team members.
10. Children's Privacy
The Service is intended strictly for businesses and professionals and is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we take immediate steps to delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. We will notify you of any material changes by updating the "Last Updated" date at the top of this policy and, where feasible, displaying a prominent notice within your dashboard or sending an email notification.
12. Contact Our Privacy Team
If you have any questions, concerns, or inquiries regarding this Privacy Policy, please reach out to:
Saanish Privacy & Data Protection Office
Privacy Email: [email protected]
General Inquiries: [email protected]
Website: https://saanish.com