DRAFT — pending legal review. Not yet a binding document.
Privacy policy
Predvora ("we", operated by Predvora (company registration details pending)) turns business websites into AI representatives. This policy explains what we process, why, and your rights. Two roles matter: for data our customersgive us (their website content, their visitors' conversations) we act as a processoron the customer's behalf; for our own customer accounts and billing we are the controller.
What we process
- Account data (controller): name, email, password hash or Google sign-in identity, workspace membership, billing status. Legal basis: contract.
- Website content(processor): pages of the customer's public website, crawled with their instruction, cleaned and turned into structured business facts and searchable fragments so the representative can answer from verified knowledge.
- Visitor conversations (processor): messages exchanged with a representative, an AI-generated summary and intent, and contact details a visitor chooses to share (which become a lead for the business). Every widget shows a notice that conversations are AI-processed and shared with the business.
- Technical data: hashed IP addresses (spam and abuse control; the hash is deleted after {IP_HASH_RETENTION_DAYS, default 30} days), hashed user agents, and operational metadata (timestamps, token counts, latency). We never store raw IP addresses long-term and never log message content.
- Payments: processed by Stripe; we never see card numbers.
AI processing
Conversations and website content are processed by AI providers (Anthropic for responses and classification, OpenAI for text embeddings) under data processing agreements. We do not use customer or visitor data to train models, and our provider agreements exclude training on this data.
Subprocessors
Vercel (hosting), Neon (database), Trigger.dev (background jobs), Upstash (rate limiting), Anthropic and OpenAI (AI processing), Firecrawl (website crawling), Stripe (payments), Resend (email), Cloudflare Turnstile (bot protection), Sentry (error monitoring, content-scrubbed), Axiom (operational logs, never message bodies). A current list with regions is available on request.
Retention
- Conversation transcripts: 12 months, then deleted automatically.
- Leads and outcome records: kept while the customer's account exists (they belong to the business).
- Hashed IPs: deleted after the short-retention window (default 30 days).
- Account and billing records: for the life of the account plus statutory periods.
Your rights
Under the GDPR you can request access, correction, export, deletion, or restriction of your data. Website visitors should contact the business they talked to (the controller); we support the business in honoring the request. Customers can request export or deletion of their whole workspace at any time. Contact: notifications@predvora.com.
Cookies
We use only strictly necessary cookies (session sign-in, workspace preference). The embedded widget uses sessionStorage on the visitor's device to keep a conversation together; it sets no tracking cookies.
Changes
We will announce material changes to this policy by email and on this page.