Privacy Policy

Last updated: September 20, 2026

1. Introduction

SupportCoach AI ("we", "us", or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and protect information when you use our platform at supportcoach.io ("the Service").

2. Information We Collect

We collect the following types of information:

Account Information

When you create an account, we collect your email address, name, and organization name. This information is used for authentication and to associate your data with your organization.

Chat Transcript Data

When you upload chat transcripts for analysis, we store the transcript text, parsed messages, and AI-generated analysis results (coaching feedback, scores, topic classifications, and flags). This data is stored in our database and processed by our AI service to generate coaching insights.

Company Coaching Context

If you provide company-specific coaching context (product workflows, process knowledge, coaching standards), this is stored and used to improve the relevance of AI-generated coaching feedback for your organization.

Usage Data

We may collect basic usage information such as login times, pages visited, and features used. This data is used to improve the Service. It is processed on our behalf by our analytics provider, PostHog (see Section 6), and is not sold, rented, or shared with anyone else.

How You Found Us

When you visit our public website, we measure page visits on our own servers — no analytics script runs in your browser, no analytics cookie is set, and your IP address is not attached to these measurements. We record the page visited, standard campaign parameters if you arrived from a link that carries them (such as utm_source or an ad click identifier), and the domain of the referring site — never the full referring address. Your browser may also remember these campaign parameters locally for up to 90 days (in local storage, not a cookie) so that if you sign up, we can associate your account with the campaign or referral that brought you here. This information leaves your browser only if you sign up. (Added September 20, 2026.)

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Generate AI-powered coaching feedback and performance analytics
  • Authenticate your identity and manage your account
  • Process payments through our third-party payment provider
  • Communicate with you about your account or the Service
  • Comply with legal obligations

4. Data Isolation

SupportCoach AI is a multi-tenant platform. All data is isolated by organization. Your chat transcripts, analysis results, coaching context, and reports are only accessible to authenticated users within your organization. No other customer can access your data. Row-level security policies are enforced at the database level.

5. AI Processing

Chat transcripts are sent to OpenAI's API for analysis. OpenAI processes the transcript text to generate coaching feedback and returns the results to our platform. We use OpenAI's API in accordance with their data usage policies. As of the date of this policy, OpenAI does not use API inputs or outputs for model training. We recommend reviewing OpenAI's current data usage policy at openai.com/policies for the most current information.

6. Third-Party Services

We use the following third-party services to operate the platform:

  • Supabase — database hosting and authentication
  • OpenAI — AI analysis of chat transcripts
  • Vercel — application hosting
  • Railway — API hosting
  • Resend — transactional and weekly summary email
  • Paddle — payment processing
  • PostHog — product analytics on how the Service is used. Receives account and organisation identifiers, the organisation name, and usage events. Never receives chat transcripts, draft replies, names, or email addresses

We do not sell, rent, or share your personal information or chat data with any other third parties.

7. Data Storage and Security

Your data is stored in Supabase (PostgreSQL) with row-level security enabled. All communication between your browser and our servers is encrypted via HTTPS. We do not store payment card numbers, CVVs, or bank account details — all payment processing is handled by our payment provider. API keys and service credentials are stored securely as environment variables and are never exposed to client-side code.

8. Data Retention

Your data is retained for as long as your account is active. If you cancel your subscription, your data will be retained for 30 days to allow for reactivation. After 30 days, your data may be permanently deleted. You may request deletion of your data at any time by contacting us.

9. Chrome Extension (Live Agent Coach)

This section describes data practices specific to the Support Coach AI "Live Agent Coach" Chrome extension, which differs from the dashboard described above. The extension provides real-time coaching while a support agent composes a reply; it does not upload or store conversation transcripts.

If you are reviewing the extension for an IT or security team, our Security and IT Review page covers the permissions it requests, the exact payload it transmits, and how to deploy it across a managed Chrome fleet.

What the extension accesses

When an agent installs the extension and types a reply inside a supported help desk (Zendesk, Intercom, or Zoho SalesIQ), the extension reads the reply text the agent is composing in order to analyze it. The extension runs only on these supported help-desk domains. It reads only the agent's own draft reply — it does not read or transmit the customer's messages or the wider conversation.

What is transmitted, and to whom

The agent's draft reply text is sent over an encrypted (HTTPS) connection to our servers and to OpenAI's API, which analyzes the draft and returns coaching feedback and a suggested rewrite. OpenAI acts as a sub-processor; as of the date of this policy, OpenAI does not use API inputs or outputs for model training (see Section 5).

What we store — and do not store

The draft reply text is processed transiently and is not stored in our database. It may be held briefly in a short-lived in-memory cache (up to 60 seconds, keyed by a non-reversible hash) to avoid duplicate processing, after which it is discarded. In our own database we retain only aggregate coaching statistics — which coaching rule types were triggered and counts of suggestions shown, accepted, or dismissed. These statistics contain no message content, no customer data, and no draft text.

Separately, we record product analytics events in PostHog (Section 6) so we can see how the Service is used — for example that a check completed, that a suggestion was accepted, or that a check failed. Unlike the statistics above, these events are attributed to an organisation and an agent by internal identifier, so they are not aggregate. They carry counts, durations, rule-family names, the extension version and the organisation name. They never carry draft text, chat transcripts, customer data, names, or email addresses — those field names are refused outright, over-long values are dropped rather than shortened, and location is not derived from them.

Limited use

Our handling of data received from the Chrome extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. The draft text accessed by the extension is used solely to provide the real-time coaching feature. It is not sold or transferred to others except to the service providers needed to deliver the feature (such as OpenAI); it is not used or transferred for advertising, ad personalization, or to determine creditworthiness; and it is not used for any purpose unrelated to the coaching feature. We do not allow humans to read this data except (a) with your consent, (b) as necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to or restrict certain processing of your data

To exercise any of these rights, contact us at support@supportcoach.io.

11. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. This remains true with PostHog in place: our product analytics are sent from our own servers, not from your browser, so no analytics script or analytics cookie is loaded on this site, in the admin console, or in the Chrome extension.

12. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or through the Service. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

14. Contact

If you have questions about this Privacy Policy, please contact us at support@supportcoach.io.