← Back to home

Privacy Policy

Last updated: April 2026

1. Data Controller

Grundlabs GmbH ("we", "us") is the data controller for the SupportAI service. Contact: info@grundlabs.com

2. What Data We Collect

Account data: Email address, company name, hashed password (Argon2id). We never store plaintext passwords.

Usage data: Message counts, feature usage, login timestamps. Used for billing enforcement and service improvement.

Payment data: Processed by Stripe. We store only the Stripe customer ID and subscription status, not card numbers.

3. What We Do NOT Collect

Your documents: All document processing (embedding, indexing, vector search) happens locally on your device. Your files never leave your machine.

Your full knowledge base: Only the specific text snippets relevant to your question (typically 3-5 short paragraphs) are sent to our inference API alongside your question.

4. How We Process Data

DataWhereRetention
Questions + context snippetsOur EU server (inference only)Not stored after response
Account infoOur EU databaseUntil account deletion
Usage metricsOur EU database12 months rolling
Documents, embeddingsYour device onlyYou control

5. Data Location

Our servers are located in the European Union (Netherlands). We do not transfer personal data outside the EU.

6. Third-Party Processors

Stripe: Payment processing. See Stripe's Privacy Policy.

We do not use analytics trackers, advertising networks, or third-party cookies.

7. Your Rights (GDPR)

Under the GDPR, you have the right to:

To exercise these rights, email info@grundlabs.com.

8. Cookies

We use only essential cookies for authentication (session tokens stored in localStorage). No tracking cookies.

9. Changes

We may update this policy. Significant changes will be communicated via email to registered users.

10. Contact

Grundlabs GmbH
Email: info@grundlabs.com