CustomerGPT LogoCustomerGPTBack to Home
Legal

Privacy Policy

This policy describes how CustomerGPT collects, protects, and handles your product documentation and customer interactions.

Effective date: May 30, 2026

1. Information We Collect

We collect information necessary to train your customized AI assistants and optimize chatbot performance:

  • Documentation and Uploads: Any website links, FAQ copy-pastes, or PDF manuals you ingest into our training vectors.
  • Conversation History: Transcripts of interactions between website visitors and your custom chatbots (stored for analytical lead captures).
  • Developer Identifiers: Account emails, Google OAuth metadata, and usage tokens.

2. Encryption & Data Processing Standards

All trained training texts and database chunks are encrypted at rest using AES-256 and in transit using TLS 1.3. We leverage multi-tenant vector segmentation inside PostgreSQL database systems, ensuring that no tenant's data or vector weights are ever cross-shared or exposed to other chatbots.

3. Compliance Commitments (GDPR, SOC-2, HIPAA)

CustomerGPT is fully compliant with GDPR regulations. Customers can request full deletions of trained indexes or customer interaction logs at any time. We support standard Data Processing Agreements (DPA) and provide BAA contracts for HIPAA-eligible customers on our Enterprise packages.

4. Third-Party Embed Integrity

Our embed widget does not track visitor browsing habits, inject tracking cookies, or parse third-party session IDs. All dialogues are grounded solely in the scope of your custom vector database chunks, protecting your end-users from tracking.

5. Google API User Data & Limited Use Disclosure

When you choose to connect your Google account (such as Google Drive or YouTube integrations), CustomerGPT accesses specific user data to power your custom AI chatbot knowledge bases:

  • Google Drive File Access (https://www.googleapis.com/auth/drive.file): Allows reading contents of documents and files explicitly selected by you to construct your knowledge base.
  • YouTube Read Access (https://www.googleapis.com/auth/youtube.readonly): Allows retrieving video metadata, titles, descriptions, and transcripts for video knowledge indexing.

Google API Services User Data Policy (Limited Use Statement):

CustomerGPT's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI/ML Model Training Restriction: CustomerGPT does not use raw or derived Google user data to train, improve, or fine-tune generalized AI/ML models. Google data is strictly isolated to generate vector embeddings for your own specific chatbot queries and is never shared with third parties for marketing or training purposes.

6. Contact Privacy Officers

If you have any inquiries regarding data processing, indexing boundaries, or wish to execute a Right to Be Forgotten request, please email our privacy compliance team at support@customergpt.ai.