Privacy Policy
Last updated: 23 September 2026
Please read this first. This document is a template. It has not been reviewed by a lawyer. It is a starting point, not legal advice. Before BotClarify is sold to anyone, BotClarify Pte. Ltd. must have this policy checked by a qualified lawyer against the data protection laws that actually apply to it and to its customers. Do not rely on this text as it stands.
1. Who we are
BotClarify is operated by BotClarify Pte. Ltd., of 18 Marina Gardens Dr, Singapore 018953. You can reach us about anything in this policy at info@botclarify.com.
This policy covers the site at botclarify.com and the product at app.botclarify.com.
2. Two different roles, and why it matters
There are two kinds of personal data here, and we handle them differently.
- Account and billing data. Names, work email addresses, sign-in records, subscription details. For this we are the controller. We decide what we collect and why, and this policy explains it.
- The documents your organisation uploads, and the questions your people ask. For this we are a processor. Your organisation is the controller. It decides what goes in, and we act on its instructions. If you are an employee and you want to know why a particular document was uploaded, ask your organisation's administrator first.
3. What we collect
Account data
Your name, your work email address, your organisation's name, your role in it (administrator or member), your password in hashed form, and the invitations sent to and from your organisation.
Uploaded documents
The files an administrator uploads (PDF, DOCX, TXT, up to 25 MB each), the text we extract from them, and the numerical vector index we build from that text so the chatbot can search it. Whatever personal data those documents happen to contain is collected with them. What that is depends entirely on what your organisation chooses to upload.
Questions and answers
The questions people type into the chat, the answers returned, the source files cited, and the time of each exchange. Administrators can read the whole organisation's chat history. Members should know this.
Usage and technical logs
IP address, browser type, pages and actions in the app, timestamps, and error diagnostics. We use these to keep the service running, to find faults, and to spot abuse.
Payment data
Payments go through PayPal. PayPal handles the card or account details. We never see or store a full card number. We keep the subscription status, the plan, the amount, the date, and PayPal's transaction reference.
Messages you send us
If you email us or use the contact form, we keep what you wrote and our reply.
4. Why we use it, and the legal basis
Under the UK and EU GDPR, we rely on the following bases.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, host documents, answer questions | To provide the service you signed up for | Performance of a contract |
| Take payment, chase failed payments, keep invoices | To get paid and to meet accounting duties | Contract, and legal obligation |
| Keep logs, monitor for abuse, protect accounts | To keep the service secure and working | Legitimate interests |
| Support you when you write to us | To answer your question | Contract, and legitimate interests |
| Improve the product using aggregate, non-identifying usage numbers | To see what is slow or confusing | Legitimate interests |
| Send occasional service emails about your account | So you know about outages, changes and renewals | Contract, and legitimate interests |
| Send marketing email, where we do it at all | To tell you about the product | Consent, which you can withdraw at any time |
| Process your uploaded documents and questions | On your organisation's instructions | Your organisation's own basis; we act as processor |
Where we rely on legitimate interests, we have weighed our interest against your rights and think the processing is what you would reasonably expect. You can object, and we will look at it again. See section 9.
5. What we do not do
- We do not use your documents, your questions or the answers to train any model, ours or anyone else's.
- We do not share your documents with other customers. Each organisation's content is kept separate.
- We do not sell your personal data, and we do not share it with advertisers or data brokers.
- We do not run behavioural advertising or profiling on you.
6. The suppliers that process data for us
We do not run everything ourselves. These are the sub-processors we use. Each is bound by a contract to process data only on our instructions.
| Provider | Purpose | Where |
|---|---|---|
| Supabase | Database hosting. Your account records, the text extracted from your documents and the vector index all live here. | [[SUB-PROCESSOR REGION]] |
| Cloudflare R2 | Object storage. This is where the uploaded files themselves are kept. | [[SUB-PROCESSOR REGION]] |
| Voyage AI | Turns the text of your documents and your questions into vectors so they can be searched by meaning. | [[SUB-PROCESSOR REGION]] |
| DeepSeek | Generates the answers from the passages retrieved out of your documents. | [[SUB-PROCESSOR REGION]] |
| Google Gemini | Optical character recognition, used only to read scanned PDFs that have no text layer. | [[SUB-PROCESSOR REGION]] |
| Render | Application hosting. The BotClarify application runs here. | [[SUB-PROCESSOR REGION]] |
| PayPal | Takes payment and holds the card or account details we never see. | [[SUB-PROCESSOR REGION]] |
We may also disclose data to professional advisers, or to an authority where the law requires it, or to a buyer if our business is sold. If the list above changes we will update this page and tell administrators by email before the new supplier starts processing, so that they have a chance to object.
7. Our own staff
Our system administrators can technically read stored content, including uploaded documents and chat history. They do so to run and support the service: to fix a fault, restore data, investigate abuse, or answer a support request. Access is limited to the people who need it for those purposes. We would rather say this plainly than imply an isolation the architecture does not give.
8. International transfers
The suppliers listed above operate in more than one country, and some are outside the UK and the European Economic Area, including the United States. That means your data may be transferred outside your own country.
Where we make such a transfer, we rely on an adequacy decision where one covers the destination, and otherwise on the Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved. You can ask us at info@botclarify.com for details of the safeguards used for a particular supplier.
9. How long we keep things
- Free trial that is not upgraded. When the 3-day trial ends without an upgrade, we delete the uploaded documents, the search index built from them, and the chat history. That deletion is permanent. We keep the account, the organisation and the member list, so you can come back and subscribe without setting everything up again.
- Documents on a paid plan. Kept until an administrator deletes them, or until the account is closed.
- Chat history. Kept for the life of the organisation's account, unless it is deleted earlier.
- Account records. Kept while the account exists, and for up to 6 months after it is closed, then deleted.
- Billing and invoice records. Kept for as long as tax and accounting law requires, commonly 6 to 7 years.
- Technical logs. Kept for up to 12 months.
- Backups. Deleted content can persist in encrypted backups for up to 35 days before it is overwritten on the normal cycle.
BotClarify is not a backup service. Keep your own copies of anything you upload.
10. Your rights
If the UK or EU GDPR applies to you, you have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where consent is what we relied on. You can also object to processing based on legitimate interests.
How to use these rights depends on which data you mean.
- Your account data. Write to us at info@botclarify.com. We answer within one month.
- Data inside your organisation's documents or chat history. Your organisation controls that, so ask its administrator. If you come to us instead, we will pass the request to them and help them act on it.
We do not charge for this, and we will not treat you worse for asking. If you are unhappy with how we have handled a request, you can complain to your local data protection authority. In the UK that is the Information Commissioner's Office.
11. Cookies and browser storage
We do not use advertising cookies, and we do not run third-party tracking or profiling on the site.
The app keeps your sign-in session in your browser's local storage rather than in a cookie. It stays on your device until you sign out or clear your browser data, and it is there only to keep you signed in. We may also use a small number of strictly necessary cookies for security and load balancing. Blocking those would stop the app working.
If we ever add analytics or anything non-essential, we will ask for your consent first and update this page.
12. Children
BotClarify is a business tool and is not meant for children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, write to info@botclarify.com and we will delete it.
Note that a document your organisation uploads may itself mention a child. That is your organisation's responsibility to justify, not something we can judge from the outside.
13. How we protect data
- Traffic is encrypted in transit with TLS, and stored files and database contents are encrypted at rest by our hosting providers.
- Every organisation's data is separated, and folder permissions are checked before a search runs, so a private folder is never searched for someone who has no access to it.
- Passwords are stored hashed, never in readable form.
- Internal access is limited to staff who need it, and administrative actions are logged.
- We keep dependencies patched and review changes before they go live.
No service can promise perfect security. If a breach happens that puts your rights at risk, we will notify the relevant authority within 72 hours where the law requires it, and we will tell affected customers without undue delay. There is more detail on the Security page.
14. Changes to this policy
We may update this policy. The date at the top always shows the current version. If a change is material we will email the administrator on the account before it takes effect.
15. How to reach us
BotClarify Pte. Ltd.
18 Marina Gardens Dr, Singapore 018953
info@botclarify.com
Related pages: the Terms of Service set out the agreement between us, and the Security page explains how the service is protected.