pAInpoint.solutions

Privacy Policy

Effective date: July 26, 2026

This policy explains what Painpoint Solutions, LLC ("Painpoint," "we," "us") collects, how we use it, and the choices you have. It covers our website, the free demo, the AI chat agent our customers install on their websites, and the customer dashboard.

Two kinds of people interact with our services, and we treat their data differently:

  • Customers: businesses that create accounts and subscribe (or try the demo).
  • Visitors: people who talk to an agent on a customer's website. If you are a visitor, the business whose website you used decides how the agent is deployed; we process your conversation on that business's behalf.

All privacy inquiries go through our contact page.

1. What we collect

Customer account data. Your name, email address, and login credentials (managed by our identity provider, Clerk), your business details and agent settings, and your communications with us.

Billing data. Payments are processed by Stripe. We receive billing name, email, and transaction records; full card numbers go to Stripe and are never stored on our systems.

Your website content. To build your agent, we read pages from the website you connect and store the extracted text. If you upload documents to your agent's knowledge base, we extract the text and then discard the uploaded file. We keep the extracted text, not the file.

Visitor conversation data. Messages visitors exchange with an agent, and any contact details a visitor chooses to share in a conversation (for example, to request a follow-up). Each customer's conversation data is stored in that customer's own dedicated database.

Demo data. Creating a demo requires a verified email address. Demo data (the sample of website content and any demo conversations) expires and is deleted automatically 7 days after the demo is created.

Technical data. Standard server logs (IP address, browser type, timestamps) used for security, rate limiting, and debugging, not for advertising.

2. How we use it

We use this data to provide and operate the services: building and running agents, answering visitor questions from the customer's content, delivering escalations and notifications, processing payments, providing support, securing the services, and sending customers service and (with unsubscribe available) marketing email. We do not sell personal data, and we do not use your data for third-party advertising.

3. AI processing

Agent responses are generated by AI models from Anthropic, and content retrieval uses embedding models from OpenAI. Conversation messages and relevant portions of the customer's content are sent to these providers to generate each response.

Your data is never used to train AI models, ours or anyone else's. Our agreements and settings with our AI providers exclude the use of your content and your visitors' conversations for model training.

4. Cookies

We use only essential cookies: the ones needed to keep you signed in and to keep the services secure. We do not use advertising or cross-site tracking cookies, which is why you won't see a cookie consent banner on our site.

5. When we share data

We share personal data only with: (a) the service providers listed in Section 6, to operate the services; (b) a customer, when a visitor's conversation happened on that customer's website (that is the point of the product); (c) authorities, when required by law; and (d) a successor entity if we are acquired or merge, in which case this policy continues to apply to data collected before the change.

6. Subprocessors

These providers process personal data on our behalf:

ProviderPurposeData involved
StripePayment processing and billingBilling name, email, payment details, transaction history
AnthropicAI response generationConversation messages, relevant customer content
OpenAIContent embedding and retrievalCustomer content text, visitor query text
ClerkIdentity and sign-inName, email, authentication data
NeonDatabase hostingAll service data at rest, in per-customer databases
ResendEmail deliveryRecipient email addresses, email content
Fly.ioApplication hostingService data in transit through our applications
UpstashRate limiting and session infrastructureTechnical identifiers
SentryError monitoringTechnical error reports, which may incidentally include personal data
FirecrawlWebsite readingPublic content of customer websites
BeehiivNewsletter deliverySubscriber email addresses
HumblyticsCookie-free marketing-site analyticsVisitor pageviews and clicks on our marketing pages only; no product or dashboard data, no cookies

We have executed data processing agreements with our data subprocessors. We will update this table when providers change; the current version is always at this page.

7. Retention

  • Customer account and agent data: kept while your account is active, deleted when your account is deleted (Section 8).
  • Visitor conversations: kept in the customer's database while that customer's account is active; deleted when the customer's account (or that data) is deleted.
  • Demo data: deleted automatically 7 days after demo creation.
  • Uploaded files: discarded after text extraction (only the extracted text is retained, under the rules above).
  • Payment records: after account deletion, de-identified transaction records are retained for approximately 7 years to meet tax and accounting obligations, then deleted. Stripe retains its own transaction records under its policies.
  • Server logs: retained briefly for security and debugging, then rotated out.

We may retain specific records beyond these periods where the law requires it or where they are needed to resolve disputes, enforce our agreements, or honor your choices. For example, we keep records of unsubscribe and opt-out requests (so we never contact you again after you ask us not to), records of your acceptance of our Terms, and data subject to a legal hold.

8. Deletion and your account's lifecycle

Deleting your account. You can delete your account from your account settings at any time. Deletion is real: we tear down your databases, remove your identity records, and scrub personal data from payment records (retaining only the de-identified transaction history described in Section 7). Before permanent deletion, we send an email notice and hold a 3-day grace period during which you can restore the account.

If you claim the money-back guarantee. A guarantee refund cancels your subscription and schedules your account for deletion on the same notice-and-grace terms. Re-subscribing during the grace period restores the account and cancels the deletion.

If you cancel and your paid period ends. The account enters the same deletion pipeline: email notice, 3-day grace, then permanent deletion.

9. Your rights and data export

You can access and correct your account data in your dashboard. You can request a copy of your data (including your agent's knowledge base and conversation history) through our contact page, and we will provide it in a portable format. You can delete your account yourself at any time (Section 8). If you are in a jurisdiction that grants additional privacy rights (such as the EU/EEA, UK, or California), we honor requests to access, correct, delete, or export your personal data, and you may also lodge a complaint with your local supervisory authority.

Visitors: if you spoke with an agent on a business's website, that business controls the deployment; direct requests to them, or contact us through our contact page and we will assist.

We do not discriminate against anyone for exercising privacy rights.

10. Security

Each customer's conversation and knowledge data lives in a dedicated, isolated database. Data is encrypted in transit and at rest, credentials are stored encrypted, and access to production systems is restricted. No system is perfectly secure, but isolation-per-customer is a structural protection most alternatives don't offer: your data is not commingled with other customers' data.

11. International transfers

We are a U.S. company and our services are hosted in the United States. If you use the services from outside the U.S., your data is processed in the U.S. Where required, transfers from jurisdictions with transfer restrictions rely on our subprocessors' standard contractual protections.

12. Children

The services are for businesses and are not directed to children. We do not knowingly collect personal data from anyone under 18 for account purposes. Customer websites are the customer's responsibility; if you believe a child's data has reached us, contact us through our contact page and we will delete it.

13. Changes to this policy

We may update this policy as the services evolve. Material changes will be announced to customers by email before they take effect. The current version, with its effective date, is always at this page.

14. Contact

All privacy inquiries (questions, rights requests, complaints) go through our contact page.