Overview
This Privacy Policy describes how Stopngage Solutions Pvt. Limited ("SuprAI," "we," "us"), the company behind the SuprAI platform (suprai.one), collects, uses, stores, shares, and protects information in connection with our platform, dashboard, APIs, connectors, and related services (the "Service").
SuprAI is the AI operating system for your company: one place where a Customer's apps, answers, and agents come together. We unify a Customer's Enterprise Context — data and knowledge from their connected business systems — into a single, permissioned layer, deliver role-aware answers, and let Customers build, run, and share AI-powered Workflows, Skills, and Agents across their organization, including through AI assistants the Customer already uses.
This Policy applies to:
- Authorized Users — individuals who access the Service under a Customer's account
- Customers — the organizations that hold a SuprAI account and connect their systems
- End Customers — individuals whose personal data is contained in a Customer's connected systems (e.g., a Customer's own customers, employees, or vendors)
- Visitors — individuals browsing our website
This document is a notice of our practices. Where consent is required by law, we obtain it separately (e.g., at account creation or connector authorization), not through your mere use of the Service.
Roles: Controller vs. Processor
This distinction governs how every clause below applies.
| Data | SuprAI's role | Who decides how it's used |
|---|---|---|
| Account data (name, email, login) of Authorized Users and Visitors | Controller (Data Fiduciary under India's DPDPA) | SuprAI |
| Usage, telemetry, and log data of the Service itself | Controller | SuprAI |
| Enterprise Context — data ingested from a Customer's connected systems, including any End Customer or employee personal data it contains | Processor (Data Processor under DPDPA) | Customer |
| Workflow, Skill, and Agent configurations and their run inputs/outputs | Processor | Customer |
Where SuprAI acts as Processor, we process data only on the Customer's documented instructions, only for the purposes the Customer has configured, and subject to the Data Processing Addendum ("DPA") available to Customers on request. We do not independently determine the purposes of that processing.
Data We Collect
2.1 Account data
Name, email address, profile photo, organization, and account identifiers, collected via Google Sign-In or other supported authentication when an account is created.
2.2 Enterprise Context (connector data)
When a Customer's administrator authorizes a connector, we ingest the data required to build that Customer's unified Enterprise Context. Depending on the connectors enabled, this may include:
| Connector category | Examples | Data accessed |
|---|---|---|
| Communication & collaboration | Slack, Google Workspace | Messages, documents, files, and directory data within authorized scopes |
| Commerce & operations | Shopify, GoKwik | Catalog, orders, customers, returns, store configuration |
| Payments & finance | Razorpay | Payment links, transactions, settlements |
| Knowledge & documents | Google Drive, Docs | Files and folders explicitly authorized |
| Other integrations the Customer authorizes | — | Scoped to what the Customer enables |
We request only the minimum scopes required for the features enabled. No connector is accessed without explicit administrator authorization, and connectors can be disconnected at any time.
2.3 Workflows, Skills & Agents
Configuration, logic, prompts, schedules, and metadata for the Workflows, Skills, and Agents a Customer builds or shares within its own organization, along with the inputs and outputs of their runs.
2.4 Connected AI Clients
Customers may connect the Service to third-party AI assistants and clients they already use (for example, via supported integration protocols). When a Customer does so, queries from those clients, and the responses the Service returns to them, pass through the Service. See Section 6.3 for how this data is shared.
2.5 Usage data
IP address, device and browser type, timestamps, pages and features used, API call logs, and diagnostic data.
2.6 Content
Prompts, queries, documents, files, and other input submitted to the Service by Authorized Users.
2.7 Cookies
We use strictly necessary cookies for authentication and session management, and analytics cookies to understand product usage. You can control cookies through your browser; disabling necessary cookies may break sign-in.
Google User Data & Limited Use
SuprAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- Use Google user data for advertising
- Use Google user data to train or improve AI/ML models, including third-party or foundation models — nor transfer it to any third-party AI tool for that purpose
- Sell or share Google user data with third parties, except as strictly necessary to provide core functionality you've requested
- Allow human access to Google user data except: (a) with your affirmative consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for internal operations where the data has been aggregated and anonymized
You may revoke SuprAI's Google access at any time at myaccount.google.com/permissions.
How We Use Data, and Our Legal Bases
| Purpose | Data used | Legal basis (where GDPR applies) |
|---|---|---|
| Authenticate accounts and operate the Service | Account data, usage data | Contract performance |
| Build Enterprise Context and power the Workflows, Skills, and Agents the Customer configures | Enterprise Context, Content, Workflow/Skill data | Contract performance (per Customer instructions) |
| Serve role-aware answers to Authorized Users and Connected AI Clients | Enterprise Context, Content | Contract performance |
| Maintain security: detect fraud, abuse, and unauthorized access | Usage data, account data | Legitimate interest |
| Improve reliability and performance of the Service | Usage data (aggregated where possible) | Legitimate interest |
| Communicate about the account, updates, or support | Account data | Contract performance / legitimate interest |
| Send marketing communications | Account data (business contact) | Consent / legitimate interest, with opt-out |
| Comply with legal obligations | As required | Legal obligation |
Marketing opt-out. You may opt out of marketing communications at any time via the unsubscribe link in any such email or by writing to privacy@suprai.one. Service and account notices are not marketing and will continue.
Aggregated data. We may generate aggregated, de-identified statistics (e.g., overall feature usage) that cannot reasonably identify any person or Customer, and use them to operate and improve the Service. We do not attempt to re-identify such data.
AI Processing, Model Training & Tenant Isolation
We hold ourselves to the same standard on this as the strictest enterprise AI vendors. Specifically:
- No model training. We do not use Customer Data, End Customer Data, Enterprise Context, Workflows, Skills, Agents, or Content to train, fine-tune, or otherwise improve any AI or ML model — ours or any third party's.
- No cross-tenant use. One Customer's Enterprise Context, Workflows, Skills, or Agents are never used to build, train, inform, or improve another Customer's Workflows, Skills, Agents, or AI outputs. Every tenant is isolated — there is no shared index or shared model state across Customers.
- Zero-retention inference. LLM inference is performed under Zero Data Retention (ZDR) agreements and Data Processing Agreements (DPAs) with our model providers. Prompts and outputs are not stored by those providers and are not used for their model training.
- Permission-aware retrieval. AI features — including answers served to Connected AI Clients — only surface content the requesting Authorized User is permitted to see under the access controls configured on the underlying connected systems and within the Service's role-based permissions. Retrieval respects permissions at query time, not just at ingestion.
- Customer control. Customer administrators control which data sources, Workflows, Skills, and Agents are exposed to AI features and to Connected AI Clients, via connector-level and role-based permissions, and may restrict or revoke access at any time.
Data Retention
| Data | Retention |
|---|---|
| Account data | Life of the account + up to 30 days after closure |
| Enterprise Context | Per Customer-configured retention; deleted or anonymized within 30 days of connector disconnection or account closure |
| Workflow/Skill/Agent configurations and run logs | Life of the account or per Customer-configured retention |
| Usage and security logs | Up to 12 months, unless needed longer for security investigation |
| Data subject to legal hold or legal retention duty | As required by law |
On verified deletion, data is removed from active systems within 30 days and from backups on the backup rotation cycle.
Security
We implement technical and organizational measures calibrated to the sensitivity of the data we process, including: encryption in transit (TLS) and at rest; role-based access controls and least-privilege access for our personnel; tenant isolation at the data layer; logging and monitoring of access to production systems; and secure development and credential-management practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach notification. If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data we process, we will notify affected Customers without undue delay and provide information reasonably required for the Customer to meet its own notification obligations, and will notify regulators and individuals where the law requires us to do so directly.
International Data Transfers
We are based in India, and the Service may process or store data in other countries through our sub-processors. Where personal data subject to GDPR or similar laws is transferred internationally, we rely on appropriate safeguards, such as Standard Contractual Clauses or an adequacy decision, as applicable.
Your Rights & Choices
Depending on your location and the applicable law, you may have the right to: access, correct, or delete your personal data; receive a copy in a portable format; object to or restrict certain processing; withdraw consent (without affecting prior processing); and complain to a supervisory authority.
- Authorized Users and Visitors (data for which SuprAI is controller): contact privacy@suprai.one. We will verify your identity and respond within the timeline the applicable law requires.
- End Customers (data we process for a Customer): contact the relevant organization directly; we will support their response as their processor.
- Customer administrators may disconnect any connector, adjust permissions, or revoke Google access at any time.
We will not discriminate against you for exercising any of these rights.
Grievance Redressal (India)
In accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, grievances may be addressed to our Grievance Officer:
We aim to acknowledge grievances within 72 hours and resolve them within the timelines prescribed by applicable law.
Children
The Service is designed for business use and is not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
Regulatory Frameworks
We process personal data consistent with, as applicable: India's Digital Personal Data Protection Act, 2023 (SuprAI acts as Data Fiduciary for Authorized User and Visitor account data, and as Data Processor for Customer-instructed processing of Enterprise Context); the EU/UK GDPR (with the legal bases stated in Section 4); and US state privacy laws (CCPA/CPRA and similar — we do not sell or share personal information for cross-context behavioral advertising, and California residents may exercise the rights in Section 10, including through an authorized agent with written permission).
Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date, and for material changes we will provide additional notice by email or in-product notification before the change takes effect.
Contact
See also our Terms of Service.