Privacy Policy

    Last updated: September 19, 2026

    1. Overview & Who We Are

    Impact AI Inc ("Impact AI," "we," "us," or "our") operates a platform that lets businesses build, train, customize, and embed conversational chatbots on their own websites. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

    This policy applies to two groups of people:

    • Customers — the businesses and individuals who create an Impact AI account and build chatbots.
    • Visitors — the people who interact with a customer's embedded chatbot. Visitors may never have heard of Impact AI; their information is handled on the customer's behalf as a data processor.

    If you have any questions about this policy or your data, contact us at privacy@impactaiinc.com.

    2. Information We Collect

    We collect only the information needed to run the service. We do not buy personal data from data brokers.

    Account data (customers)

    When you create an account we collect your name, email address, and a password. The password is hashed by our authentication provider and is never stored in readable form. If you sign in with Google or LinkedIn, we receive the profile information you authorize those providers to share (typically name, email, and a profile photo).

    Chatbot configuration & training data

    You enter the questions and answers, settings, branding, and configuration that define each chatbot. This content is stored so your chatbot can respond to visitors.

    Visitor / end-user data

    When someone interacts with a customer's chatbot, we store, on the customer's behalf:

    • Chat messages — the visitor's question and the bot's answer, linked to an anonymous session ID.
    • Contact details the visitor types into the bot (for example name, email, phone number, or custom fields a customer configures).
    • Questions the chatbot could not answer, logged so the customer can review and improve their bot.

    We do not collect visitor IP addresses for tracking purposes. Session IDs are generated client-side and are not tied to a person unless the visitor provides contact details.

    Usage & analytics

    We count monthly AI interactions per chatbot to enforce plan limits, and we record which A/B test variant a visitor was shown along with experiment events (view, click, sign-up). We also use platform-level analytics that report aggregate page views.

    Payment data

    When you purchase a paid plan, your billing email and subscription records are stored with us. Card numbers and other payment details are handled entirely by our payment processor, Stripe, and are never stored on our servers.

    Bring-your-own-AI provider keys (Enterprise)

    Enterprise customers may connect their own AI provider (OpenAI, Anthropic/Claude, Google Gemini, or any compatible service). The API key you supply is stored on our servers and used only to call your chosen provider. Only a non-sensitive key hint is ever displayed in the interface; the full key is never returned to the browser.

    3. How We Use Your Information

    We use the information we collect to:

    • Operate and maintain the service, including answering visitor questions via your chatbots.
    • Process payments and manage your subscription, plan limits, and billing.
    • Generate AI fallback answers when a deterministic match is not found (see Section 4).
    • Run A/B experiments that help us improve the service.
    • Detect, investigate, and prevent fraud, abuse, or security issues.
    • Communicate with you about your account, support requests, and material policy changes.
    • Comply with our legal obligations.

    We do not use visitor chat messages to train AI models, and we do not sell personal information.

    4. AI & Third-Party Processing

    Impact AI answers most questions deterministically — by retrieving the approved answer you configured. When no matching answer is found, the visitor's question may be sent to an AI model to generate a fallback response. This happens in two ways:

    • Lovable AI Gateway (default) — the question is sent to a hosted OpenAI model operated by our platform provider. The provider processes the prompt under its own terms to return an answer; the prompt is not used to train models.
    • Bring-your-own-AI (Enterprise) — the question is sent directly to the AI provider you configured (OpenAI, Claude, Gemini, or compatible service), under that provider's terms and your account.

    Out-of-scope questions are refused rather than answered, so most visitor messages never reach an AI model at all. Where a message is sent to a provider, only the visitor's question is transmitted, not the customer's full training data.

    5. Cookies & Local Storage

    We use a small set of cookies and browser storage:

    • Authentication cookie — keeps you signed in. Essential; the service does not work without it.
    • Experiment cookies (_ie_exp_*) — remember which A/B variant you were assigned, so you see a consistent experience. These last up to one year and use SameSite=Lax.
    • Local storage — the no-account demo at /try stores your sample questions and answers in your browser only. Nothing is uploaded unless you create an account.

    We do not use third-party advertising or cross-site tracking cookies. For more detail, see our Cookie Policy. You can clear cookies or local storage at any time through your browser settings; doing so will sign you out and reset the demo.

    6. Data Sharing & Sub-Processors

    We share personal information only with the sub-processors needed to run the service, and only to the extent required for them to perform their function:

    • Lovable Cloud — hosts the PostgreSQL database where account, chatbot, and conversation data is stored.
    • Stripe — processes payments. Stripe receives your payment details directly; we receive only a customer identifier and subscription status.
    • Lovable AI Gateway / your chosen AI provider — receives the visitor question needed to generate a fallback answer (see Section 4).
    • Google / LinkedIn — provide sign-in when you choose them; they share only the profile data you authorize.

    We may also disclose information when required by law, to protect our rights, or to respond to a valid legal request. We do not sell or rent personal information to anyone.

    7. Data Retention

    We keep personal information only as long as needed for the purposes described in this policy:

    • Account data is kept while your account is active and deleted shortly after you close it.
    • Chatbot configuration and training data is kept while the chatbot exists and removed when you delete it.
    • Visitor conversation and contact data is retained for the customer to review and improve their bot; it is deleted when the customer closes their account or deletes the chatbot.
    • Unanswered-question logs are kept for the customer to review and removed with the chatbot.
    • Experiment data is aggregated after an experiment concludes; individual variant assignments may persist until the experiment cookie expires.
    • Payment records are retained as required for accounting and tax compliance.

    This describes our retention intent. We are working toward automating deletion; until then, you may request deletion at any time by emailing privacy@impactaiinc.com.

    8. Security

    We take reasonable measures to protect your information:

    • Database access is scoped by Row Level Security so each customer can only reach their own data.
    • Passwords are hashed by the authentication provider and never stored in readable form.
    • Secrets such as API keys are stored on the server and never exposed to the browser.
    • Privileged ("service role") database access is limited to server functions and is not available to the client.
    • All traffic is served over HTTPS.

    No system is perfectly secure. If you believe a vulnerability affects your data, contact us at privacy@impactaiinc.com.

    9. Your Rights — GDPR (EU/UK)

    If you are in the European Union, the European Economic Area, or the United Kingdom, you have the following rights under the GDPR:

    • Access — request a copy of the personal data we hold about you.
    • Rectification — ask us to correct inaccurate or incomplete data.
    • Erasure — ask us to delete your personal data ("right to be forgotten").
    • Restriction — ask us to limit processing of your data in certain circumstances.
    • Portability — receive your data in a structured, machine-readable format.
    • Objection — object to processing based on our legitimate interests.
    • Withdrawal of consent — where we rely on consent, you may withdraw it at any time.

    Our lawful bases for processing are: contract (to provide the service you signed up for), legitimate interests (security, fraud prevention, and service improvement), and consent (for optional cookies and experiments).

    We do not use automated decision-making that produces legal or similarly significant effects on you. If you wish to exercise any right, email privacy@impactaiinc.com. You also have the right to lodge a complaint with your local data protection authority.

    10. Your Rights — CCPA/CPRA (California)

    If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:

    • Know — request the categories and specific pieces of personal data we collect about you.
    • Delete — request deletion of your personal data, subject to legal exceptions.
    • Opt out of "sale" — we do not sell personal information, so there is nothing to opt out of. You may still submit a request at any time.
    • Limit use of sensitive data — we limit use of sensitive personal information to the purposes needed to provide the service.
    • Non-discrimination — we will not discriminate against you for exercising your rights.

    To exercise these rights, email privacy@impactaiinc.com. Authorized agents may submit requests on behalf of a consumer with written permission.

    11. Children's Privacy

    The service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal data, please contact us at privacy@impactaiinc.com and we will delete it.

    12. International Data Transfers

    Our infrastructure and sub-processors may process data in the United States and other regions. When personal data is transferred outside the EU/UK, we rely on appropriate safeguards such as Standard Contractual Clauses, or transfer to a country covered by an adequacy decision, as applicable.

    If you have questions about international transfers, contact us at privacy@impactaiinc.com.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top of this page. For material changes, we will provide a prominent notice on our site or notify affected customers directly. We encourage you to review this page periodically.

    14. Contact Us

    If you have any questions, requests, or concerns about this Privacy Policy or your personal data, contact us at privacy@impactaiinc.com.