Privacy policy
Effective 30 September 2026 · Version 2.8
01About this policy
This is the privacy policy of Supergence Technologies Inc. (Supergence, we, us). It says what personal information we collect, why, who handles it for us and in which country, how long we keep it, and the rights you have over it. It is written in plain language on purpose, and it is meant to be read without a lawyer.
Every sentence about what our service does describes what it does today. Where a feature is not yet switched on, the sentence says so, and the feature does not handle anyone's information until this policy has been updated to cover it.
Effective date: 30 September 2026. Version 2.8. This version replaces version 2.7 of 30 September 2026, which replaced version 2.6 of 29 September 2026, which replaced version 2.5 of 20 September 2026, which replaced version 2.4 of 19 September 2026, which replaced version 2.3 of 15 September 2026, which replaced version 2.2 of 13 September 2026, which replaced version 2.1 of 10 September 2026, which replaced version 2.0 of 8 September 2026, which replaced the draft that stood on this page before it. It applies alongside our Terms of service and, for clients, the written agreement between us.
Personal information means information about an identifiable individual. Business contact information used only to reach a person about their business, such as a work email address or a business telephone number, is treated as the law treats it: outside the definition in British Columbia, and outside most of the federal Act. We still handle it with care and we still honour every request to stop.
02Who we are, and the person in charge of your information
Supergence Technologies Inc. is a corporation incorporated under the Canada Business Corporations Act, based in Vancouver, British Columbia. We provide done-for-you operations to owner-operated Canadian businesses: a client workspace, an assistant that answers about the client's own account, an advert studio, an email desk and invoicing. A phone line is built and described in full in this policy, and is not in service for any account at its date; a website service is described conditionally, because it is not switched on for any account.
Our founder is our Privacy Officer and, for Québec, the person in charge of the protection of personal information (responsable de la protection des renseignements personnels). Title: Founder and Privacy Officer, Supergence Technologies Inc. The founder holds the highest authority in the business and has not delegated this role to anyone. The Privacy Officer is accountable for our compliance with privacy law and personally answers every question, access request, correction request, withdrawal of consent and complaint made under this policy.
How to reach the Privacy Officer: by email at hello@supergence.ai with the subject line Privacy, or by post to Supergence Technologies Inc., Attention: Privacy Officer, at the mailing address printed at the end of this policy. We acknowledge a privacy request within five business days and answer it within the time limits set out under Your rights.
03Which laws apply
Supergence Technologies Inc. carries on business from British Columbia. Where we are incorporated does not decide which privacy law applies to you; where we carry on business, and where you are, does. British Columbia's Personal Information Protection Act governs how we collect, use and disclose personal information. Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) governs the same information when it crosses a provincial or national border in the course of our business, which happens when we use a provider outside Canada and when we serve a client outside British Columbia.
If you live in Québec, the Act respecting the protection of personal information in the private sector (Québec) also applies to the personal information we hold about you, from the moment we carry on business in Québec. The Québec section of this policy says what that means for you and what we do before we serve a Québec client.
Where these laws differ, we follow the one that gives you more protection.
When we act for a client, for example by reading a mailbox the client connected or by sending an invoice to the client's customer, the client remains the organization responsible for that information under privacy law. We are its service provider and we handle the information only on its instructions and as this policy describes.
04Who this policy covers
Visitors: anyone who reads supergence.ai, tries the voice demonstration, or sends us a message through the site.
Enquirers: a person who fills in our contact form or writes to us about our services, whether or not they become a client.
Clients: a business that holds an account with us, and the person who signs in to its workspace.
The client's own customers and correspondents: the people whose information a client entrusts to us when it connects a mailbox, creates an invoice, writes to the assistant about them, uploads a picture, or, once the phone line is switched on, takes a call or a text message through us. These people have no relationship with Supergence. Their information reaches us only because a client is our client.
Businesses on public registers: our own outreach draws on municipal business licence registers. It draws on businesses, never people. Where a public register names a person, we drop that record before the list is built.
Our team: the founder and any team member on our access list, who see client accounts in order to run them.
05The short version
What we collect: your name, business name and contact details; what you write to us, to the assistant and in the studio; what you upload; the settings and instructions you give us; and the records your account creates, such as requests, invoices and drawn adverts. When you connect a mailbox or an advertising account, we also handle what is in it, on your instructions.
Who sees it: you; the founder and any team member on our access list, in order to run your account; and the providers named in this policy, in Canada and the United States, each of which receives only what its task needs. Nobody else, unless the law requires it.
Why: to answer you, to open and run your account, to sign you in, to do the work you ask for, to keep the service secure, and to keep the records the law requires. Nothing else.
The main risk: some processing happens in the United States. While your information is there it may be accessed by the courts, law enforcement and national security authorities of that country under United States law. The section Where your information is stored and processed says exactly what goes where.
What we never do: we do not sell or rent personal information. We do not share it with advertisers or data brokers. We do not use it to train any model, and our language model provider's terms prohibit it from doing so. We never move money, post anything public or widen what runs unattended without a yes from you, and a person at Supergence confirms every widening in writing.
Where we need your express consent, for example to use your microphone, to connect your mailbox or advertising accounts, or, when you connect a phone line, to transcribe its calls, we ask at that moment and you can say no.
06Visitors to our public site
Page counts. Our site uses Vercel Web Analytics and Vercel Speed Insights to count page views and measure how fast pages load. Web Analytics also counts a press on a link to our contact form, to book a call with us or to our switch page, and each enquiry our server accepted from the contact or switch form; each count is sent with the page it happened on, as a page view is, and adds only which link or form it was, where on the page the link sits and the page's language, all from a fixed list, and nothing you type. Presses are never counted in the client workspace, on the sign-in page or in our team console. Neither sets a cookie and neither identifies you across sites. We use no advertising cookies and no third-party trackers. These measurements are held by Vercel, whose analytics services are not pinned to a Canadian region, so we treat them as processed in the United States. They are loaded only on supergence.ai and its preview addresses, never on a page we host for a client.
What our site stores in your browser. The public site stores nothing of its own. The client workspace keeps your sign-in session and a few display preferences in your browser's local storage, on your device only. When a client starts connecting a mailbox or an advertising account, we set one short-lived cookie (named sg_mail_nonce or sg_oauth_nonce) that lives about ten minutes and ties that connection to the browser that started it, so nobody else can finish it. It is not used for anything else. Clearing your browser storage signs you out and forgets those preferences.
Your network address. When you send the contact form, ask for a sign-in code, use the studio or talk to the assistant, your network address (IP address) is counted for about ten minutes in the memory of the server that handled the request, to limit how many requests one address can make. It is not written to disk for those purposes. One exception is disclosed under Clients: each turn with the assistant writes your email address, your network address, the time and counts of what the turn used to a usage ledger.
The voice demonstration. Our public site, and one unlisted demonstration page, let you speak to a demonstration receptionist. Nothing is captured until you press the control that starts the call, and your browser asks for microphone permission first. From that moment your voice and anything you type are streamed from your browser directly to ElevenLabs in the United States, which produces the reply. Supergence's servers do not receive, store or listen to the audio. ElevenLabs handles it under its own terms, which may include keeping a recording or transcript for a period, so do not say anything in the demonstration you would not want a provider in the United States to hold. The demonstration is not linked to an account and does not identify you. End the call or leave the page and the stream stops. Deny the microphone permission and the demonstration simply does not run.
Server logs. Like every web service, ours writes error lines when something fails. Some of those lines can include the email address concerned, for example when a sign-in email cannot be delivered. They are held in Vercel's function logs, are read only by our team when something breaks, and are never used for anything else.
07Enquiries through our site
What we collect. When you send our contact form we collect your name, your email address, your business name, what you need, and anything you write in the message field. If you use our Switch page, we also record the name of the provider you are switching from, as a prefix on your message. With your enquiry we also keep which version of this policy the line under the form's button linked to, so we can show which one you were given.
Why. To reply to your enquiry, to prepare the preview you asked for, and, if you become a client, to open your account from what you told us. We do not add you to a marketing list and we do not sell or trade your details.
Where it goes. Your enquiry is stored in our database with Supabase in Montréal. A copy is sent as an email to our own inbox through Resend, in the United States, with your address as the reply address. If it is the only enquiry from your address in the previous 24 hours, and your address is not on our list of addresses that asked us to stop, we also send one automatic reply to it through Resend, in the form's language: it says your message reached us and a person will write back, offers a link to book a call with us, and carries nothing you typed. It is not sent when more enquiries than our daily ceiling arrived, or when we cannot check those conditions, and we keep no record of it beyond Resend's own delivery logs. Incoming email for our supergence.ai addresses, and for our former supergence.io addresses, is routed by Cloudflare's email routing service to the mailbox our team reads. Our team reads enquiries in our internal console, where open enquiries and the most recent closed ones are listed with your name, email, need and message, and with a status our team sets (new, contacted, became a client, or closed) and the date it was last set. Nothing else receives your enquiry today: our page counts learn only that a form was sent. A forward to our own internal operations system exists in our code but is switched off, and if we ever switch it on this policy will first say where that system runs.
How long. We keep your enquiry until you ask us to delete it, and we delete it by hand within 30 days of your request. Our code has no automatic deletion for enquiries yet; we are building it, with a period of 24 months after your last message to us. The email copy in our inbox is deleted at the same time; Resend keeps its own delivery logs under its own retention.
If we contact you to offer our services and you have not asked us to, see Text messages and commercial electronic messages, which says how we identify ourselves and how you make us stop.
08Clients: your account and your workspace
Opening an account. We create your account; there is no self-serve sign-up. When we open it, we record your email address, your business name, your plan and its fees, your status and the services included, and we create a sign-in identity for your email address and email you an invitation to your workspace, described below under Letters we send you. Nothing else is required to open an account.
Signing in. You sign in with a six-digit code sent to your email address. There is no password and we store none. A code is sent only to an email address that already has an account, is valid for ten minutes, and can be used once. The code email is sent by our sign-in provider, Supabase, through our email provider, Resend. Once you are signed in, your session is kept in your browser's local storage on that device until you sign out or clear it; we do not end sessions from our side, so sign out on any device you share. We do not offer a second sign-in factor today. Each time you sign in, with the code or with the link in the same email, we keep a record of the version of this policy you were shown and, once our Terms of service are no longer a draft, the version of them you agreed to. The record holds your email address, the document, its version and the time, is written once per version, and holds nothing else: no network address and no detail of your device.
Your account record. Your account holds two kinds of facts, and our operator may add a private note, described under Our team below. The ones you set yourself: the guardrails and autonomy dials you choose, the marketing mode, cadence, days and budget you ask for, the standing notes you ask the assistant to remember (up to twelve short facts you state about your business), your invoice registration numbers and province, the payment instructions printed on your invoices, and your city and region. And the ones our operator records after checking them: your registered legal name, your website address, which channels are connected, the dials and monthly ceiling we have confirmed in writing, the address we hold for your business, and your trade. What actually runs unattended is always the narrower of what you asked for and what we confirmed.
Requests to us. Everything you file to us in the workspace or through the assistant, every reply we give and every answer you write back are kept as the written record between us, as a conversation under each request: instructions, written mandates, plan changes, support hand-offs, notes about accounts you connected or disconnected, and every advert you approve for placement, with its wording, media plan and your note. We also keep when we first responded to each request. These records show what you authorized and what we did, and we keep them for that reason. When something is filed on your account, by you, by the assistant for you, by our systems when a connection changes, or by your phone line when a caller texts it or a call leaves your team something to do, and when you answer under a request, our operator is told by an email to our own inbox, sent through our email provider, Resend, in the United States. It names your business and your email address, says what kind of filing it is and its number, and carries the first 300 characters of the filing or of your answer, so the operator can judge whether it can wait; the whole conversation stays in your workspace. A filing marked urgent says so in the subject of that email.
Letters we send you. Besides the sign-in code, we send three kinds of letter by email to the address on your account, through Resend in the United States. When we open your account, an invitation to your workspace: it carries your account's email address, your business name, the name of the person on our team who sent it where their sign-in profile gives one, the address to sign in at and the next step on your plan; our team can send it again only when our record shows the first one did not go, or cannot show whether it did, in which case our console asks our team to check with you first. When our team changes your plan in our console, pauses your account or lifts the pause, a notice naming your former and new plan or saying that the pause began or ended. And when our operator answers or confirms one of your requests, a notice that an answer is waiting, with the request's number and kind and the operator's name where we hold one, and none of the answer's words: the answer itself is only in your workspace. A reply to the invitation or to a plan notice comes to our own inbox. For each letter we keep a record of your account's email address, which kind of letter it was, a reference to what it concerned, whether it went, the reference Resend gave it, any error, and the address of the person on our team who sent it; never the letter's text.
The assistant. What you write to the assistant is not stored on our servers. The last forty messages are kept in your browser's local storage so the conversation is still there when you return, and you can clear them at any time. Each turn sends what you wrote, the parts of your account the reply needs, and the results of any action the assistant takes on your account to our language model provider, Anthropic, in the United States; the section The assistant, the studio and the language model says exactly what that includes. Each turn also writes one row to a usage ledger in our database: your email address, your network address (IP address), whether your account has a plan, and the time, and, once the reply is finished, how many tokens (the units in which the model counts text) the turn used, including those read from and written to the model's cache, and how many rounds it took with the model. These are counts only, never words. That ledger exists only to hold daily ceilings on assistant use, in turns and, for an account with a plan, in tokens, that a restarted server cannot forget. Rows are meant to serve seven days. Today they are removed only when we run the sweep by hand; an automatic sweep is being built.
The advert studio. When you write a letter to the studio we keep the letter, your never-say line, the picture line, the words we write in English and in Canadian French, alternative headlines, a media plan (audience, channels among those you connected, spend shares, schedule, destination page and measure of success), the check we run on each frame (whether it is usable, whether it carries lettering, how many human faces it shows), a cost estimate, the frames you liked or approved, and the history of instructions you gave. Artwork and clips are stored in a private storage area in Montréal under a folder named by a scrambled form of your email address, reachable only through links that expire after one hour. The writer may run up to three web searches through Anthropic to ground the words, and those searches carry your city and region as an approximate location. Drawing artwork is not switched on for any account at the date of this policy, and uploading reference photographs is not accepted; both are described conditionally under Who handles your information for us.
Invoices. When you create an invoice we keep your customer's name and email address, the line items, tax, dates, status, and a record of every send and reminder (when, from which of your addresses, how many times, and any error). If you give us payment instructions, such as an Interac e-Transfer address, bank details or a payment link, we keep them in your account settings and print them on the invoices you send from then on and on their reminders; a void invoice carries none. The first time an invoice is sent, the business name, registration numbers and payment instructions it carried are kept on it, so its reminders and later copies show what your customer was sent; changing or removing your payment instructions afterwards does not remove them from invoices already sent, and a copy drawn from your current details because that record is missing says so. When an invoice is voided we keep the time and, where one is given, the reason, which is required for an invoice already sent and is printed on the void copy. The PDF is built in memory each time an invoice or reminder is sent or drafted, or you preview or download it, and is not stored. Invoices go out from your own connected mailbox, not from ours. We do not process payments and take no card details; bank details you put in your payment instructions are kept as this paragraph describes, and if you give them to the assistant they also pass through Anthropic like the rest of that conversation. Marking an invoice paid records what you tell us, nothing more.
Your website, read. We read the public website whose address our operator recorded for your account, and only that address, to ground the studio writer in what your business actually says and to let the assistant tell you what to fix. We also check, at most every five minutes, that the address answers. What we read is held in server memory for up to one hour and is not stored.
Visit counts on your own website. Our code can count visits to a client's own website by day, page path, referring site and the visitor's country, region and city as read at the network edge, with no cookie, no stored network address and no coordinates. This is not switched on for any account at the date of this policy. When it is, the client's own privacy notice must tell its visitors, and this policy will be updated before the first count is written.
A website we build and host for you. This is not switched on for any account at the date of this policy. Before it is, this policy will say what it stores (drafts, published versions, pictures taken from your current site) and who handles it.
Your reading. Your workspace shows a score for your account computed from live checks: whether your website answers, whether a connected mailbox still signs in, which channels are connected, and whether your records read back. It is a display for you. No decision about you is made from it.
Our team. The founder and any team member on our access list can see every account in order to run it. We keep a record of acts on your account: each change our team makes to the account itself through our console (not the private note described below, nor the letters we send you, which have their own record), such as opening or editing the account, changing its plan, pausing it or lifting a pause, a step of your setup, wiring an advertising account, opening a paused campaign draft, connecting, moving or disconnecting your phone line, answering, confirming or moving on a request, or recording where an advert was placed; and some acts of your own, such as filing a request, answering one, or connecting or disconnecting an advertising account. Each entry says when it happened, who acted, what was done, what permitted it, how it came out and which record it concerns, by a pointer: it never copies an invoice, a message or a transcript, and holds no network address. For our team, it also keeps the address of the person who acted. Your Plan view shows the most recent entries, up to twelve, leaving out attempts of ours that changed nothing, and names our side as your operator, without that address. The record does not note our team opening or reading your account, or work done directly in our database, and if an entry cannot be written the act still goes ahead and, for an act of our team, our console is in most cases told it is missing from your record. Our operator may also keep one private note about your account, for our team's own use in running it. It is not shown in your workspace, is not read by the assistant, and is kept only in our database and shown only in our team console; it is personal information about you where it concerns you, and you can ask to see it and to correct it as Your rights describes.
09Your own customers, and the people you write to
When you connect a mailbox, create an invoice, ask the assistant to write to someone, upload a picture, or, once the phone line is switched on, take a call or a text message through us, we handle information about people who have no relationship with Supergence: your customers, suppliers, staff and correspondents.
You are the organization that collected that information. We are your service provider. We handle it only on your instructions or under a written mandate you gave us and our operator confirmed, only for the purpose you gave it to us, and never for our own purposes. We do not build lists from it, we do not use it to reach those people ourselves, and we hand it back or delete it as this policy says.
What that means for you. Your own privacy notice should tell your customers that you use service providers, in Canada and the United States, including a language model provider, to run your front office. Collect any consent your customers' information needs before you give it to us. Do not put into the assistant, the studio or an invoice information you are not allowed to share. If a customer asks you what we hold, we help you answer within the time the law gives you.
What the language model sees of them. When you ask the assistant about your email, the messages it reads for you, including the sender's name and address, the subject and the full text up to 20,000 characters, are sent to Anthropic in the United States to produce that reply. When you ask the assistant about your invoices, the list it reads, with each customer's name, email address and amount owed and any reason given for voiding an invoice, is sent the same way. When you ask it about your phone line or about what is waiting for you, or hand it a text from your live report, the texts callers sent your line, with their numbers, are sent the same way. When you ask the assistant to write to someone, the text is produced by the model. Anthropic deletes what it received within its published retention period and does not use it to train models; see the next section.
A person whose information reached us through a client may write to our Privacy Officer at any time. We answer what concerns our own handling, and we pass the rest to the client, who holds the relationship and the record.
10The assistant, the studio and the language model
A language model provided by Anthropic and run on Anthropic's servers in the United States powers the assistant in your workspace, the writer in the advert studio and, once you connect a phone line, the words the line speaks on a call. Our requests to Anthropic carry a setting that keeps the inference in the United States. No other model provider is used, and we run no model of our own.
What the assistant sends. Each turn sends the conversation held in your browser, a standing description of your account (your email address, business name, plan, fees and status, and the notes you asked it to remember), the live reading of your connections, and the result of any action it takes for you: your account overview, your recent requests with our replies and your answers, your invoices with your customers' names, email addresses and amounts and any reason given for voiding one, your mailbox listing and the full text of any message you ask it to read, the texts callers sent your phone line with their numbers, and your website review.
What the studio sends. Each draw sends your letter, the same account description together with your legal name, website, services, mandate, connected channels and the last adverts you liked, a summary of your public website, any reference photographs you provide once that is switched on, and, when frames have been drawn, the finished frames as images so they can be checked. The writer may run up to three web searches through Anthropic, carrying your city and region as an approximate location and whatever the model chooses to search for from your letter and your website.
The model decides nothing on its own. Every payment, every public post and every widening of what runs unattended waits for a yes from you, given by a swipe in the workspace, and a widening is also filed to our operator, who confirms it in writing before the first unattended run. You can ask a person to review any reply, draft or action at any time by writing to the Privacy Officer.
What can run without a swipe, and only because you set it in writing. An email can be sent without a swipe only when your email dial is set to run unattended and our operator has confirmed that mandate, your account is not paused, the recipient already appears among the people your mailbox wrote to in its last forty sent messages, and the text mentions no money. Overdue invoice reminders can be sent from your mailbox without a swipe only when your payments dial is set to run unattended and confirmed and your account is not paused, at most two each time your workspace reads your invoices (the invoice desk or the live report) or our daily clock runs, once a week per invoice, and never more than three for one invoice. A monthly invoice template creates dated drafts by itself; a draft is never sent without your yes. These are rules you set, not decisions the model makes about a person.
Drafts can be wrong. Text produced by the model is a draft. It can be inaccurate or incomplete. Nothing paid or public leaves your account on the strength of a draft alone.
The picture check. When frames are drawn, the model looks at them and records whether each frame is usable, whether it carries lettering, and how many human faces it shows. That reading is shown to you and stored with the frame. It is used to tell you which frames to avoid, never to identify anyone.
Training and retention at Anthropic. Anthropic's Commercial Terms of Service, which govern our use of its service, state that Anthropic may not train models on Customer Content from its services; at the date of this policy those terms are the version effective 17 June 2025. Anthropic's published retention for its commercial service deletes inputs and outputs within 30 days of receipt, unless it must keep something longer to enforce its usage policy or to comply with law; content it flags for a usage policy violation may be kept up to two years. We do not hold a zero-retention arrangement with Anthropic today. We do not use your information to train any model of our own. If either fact changes, we tell you before it applies to you.
Automated decisions. Supergence does not make a decision about you based exclusively on automated processing of your personal information. Where the assistant or an automation prepares a draft, a suggestion or a reminder, a person has decided, in writing, what may run. If that ever changes for your account, we will tell you no later than when we tell you the decision, we will explain on request what information was used, the main reasons, factors and parameters, and your right to have that information corrected, and you may ask a person at Supergence who can review the decision to consider your observations.
11Consent, and how to withdraw it
How we ask. For the purposes a reasonable person would expect from what you asked us to do, such as answering your enquiry or running the account you opened, your consent is implied by the request. For anything sensitive or unexpected we ask expressly, at the moment it matters, in a separate step you can decline: using your microphone in the voice demonstration, connecting a mailbox or an advertising account on that platform's own consent screen, uploading a reference photograph once that is switched on, and, when you connect a phone line, transcribing its calls. Consent is asked for one purpose at a time and lasts only as long as that purpose does.
We never make a service depend on consent we do not need. Connecting a mailbox, connecting an advertising account, uploading pictures and trying the voice demonstration are your choice. Saying no to any of them does not affect the rest of your account.
Privacy by default. Every setting in your workspace starts at the most private position: nothing runs unattended, no mailbox or advertising account is connected, no budget is in force and no picture can be uploaded, until you ask in writing and we confirm. You never have to change a setting to be protected.
How to withdraw. Write to the Privacy Officer at any time, or, for a connected account, press Disconnect in your workspace. We tell you in writing what the withdrawal will mean before we act on it, and then we act.
What stops. Disconnect a mailbox and we delete its sealed credentials at once and stop reading or sending from it. For a Gmail mailbox we then ask Google to revoke the permission, and tell you whether Google confirmed it; if it did not, remove Supergence from the connected applications in your Google account yourself. Our code does not revoke the permission on Microsoft's side or an app password, so for those also remove Supergence from the connected applications in your Microsoft account, or delete the app password in your mail provider's settings. Disconnect an advertising account and we delete the stored token and ask Google or Meta to revoke it; for TikTok and LinkedIn, revoke it in that platform's own settings. Withdraw consent to the assistant and we switch it off for your account. Disconnect the phone line, or withdraw consent to it, and we stop taking and transcribing calls on that line and receiving its texts, and delete its sealed credential at once. Withdraw consent to the account as a whole and we close it.
What withdrawal does not undo. What was lawfully done before stays done. We keep the records the law or an existing contract requires us to keep, such as invoices and the record of what you approved, for the periods set out under How long we keep information.
If we contact you to offer our services, every message says it is from Supergence Technologies Inc. and gives you a way to say stop. Once you do, we stop using your information for that purpose.
12A mailbox or advertising account you connect, and the vault
What we ask for. Gmail: permission to read, modify and send mail. Microsoft 365: permission to read, write and send mail, read your profile, and keep access when you are away. Any other mailbox (iCloud Mail, Yahoo Mail, Fastmail, Zoho Mail, Proton Mail, or a mailbox on your own domain): your address, an app password, and the incoming and outgoing server settings, which we prove by signing in live before anything is stored. Advertising: Google Ads, Google Business Profile, Meta, TikTok and LinkedIn, each on its own consent screen, where you see exactly what we ask for. At the date of this policy the Google, Microsoft, Meta, TikTok and LinkedIn connections are not yet registered with those platforms, so the only mailbox that can be connected today is one by app password.
The vault. The access token or app password is sealed with AES-256-GCM before it is stored, in a table only our server can read. Your browser never sees it, it is never written to a log, and it is never returned by any request. Your mailbox address, your provider, and the mail server settings are stored in that table in readable form so the connection can be made, with any note of a sign-in your mail provider refused, described below. The consent flow is protected against being hijacked: a signed, one-time state and the short-lived cookie described above tie the connection to the browser that started it.
What we do with a connected mailbox. We read from it only when you ask, in the email desk or through the assistant, and we do not keep a copy of any message. Drafts we prepare land in your own drafts folder. Sends go out as you, and a copy of each lands in your own Sent folder: Gmail and Microsoft file it there themselves, as does Gmail's mail server for a Gmail mailbox connected by app password, and for any other mail server we file it there ourselves over the same connection, after checking that it is not already there; if there is no Sent folder or the filing fails, the message is still sent and you are told that no copy was filed. To confirm that a connection still works, our service signs in to your first two mailboxes at most once every five minutes; that sign-in reads no message. When your mail provider refuses our sign-in, we note it on that connection with a short reason in our own words, a code and the time, never the provider's own words; a second refusal, at least a minute after the first and within a day, marks the connection broken, and we stop signing in to it until you connect it again. Anything about money, and anyone you have not written to before, always drafts first.
What we do with a connected advertising account. We store the account ids and names your grant covers (up to ten), in readable form, and the sealed token. Our operator can create a campaign draft on Google Ads or Meta from a brief you approved, and every such draft is created paused; you enable it on the platform yourself, so no money moves on our word. A grant that has expired and cannot be refreshed is marked expired and switched off, and the row stays until you disconnect it.
Consent records. Each connection writes a one-time record (a random value, your email address and an expiry ten minutes later) that stops the same consent being replayed. Those records are removed only when we run the sweep by hand; an automatic sweep is being built.
Your customers' information in that mailbox remains yours to answer for under privacy law. We handle it only on your instructions, as your service provider.
13Who handles your information for us
We stay responsible for your personal information when a provider handles it for us. Each provider works under written terms that limit what it may do with your information to the task named here and require it to protect that information to a standard comparable to ours. Each receives only what its task needs.
No provider receives personal information from us before it is named in this policy, with its country. A provider that is described here as not yet switched on receives nothing until it is switched on, and this policy is updated first.
Supabase: our database, file storage and sign-in. Country: Canada. Region: Montréal (ca-central-1). Data: every record and file this policy describes, sign-in identities and one-time codes. When: always.
Vercel: runs our application and serves our site; also counts page views and presses on a few links, measures page speed and keeps our function logs. Country: United States (the provider); our application runs in Montréal (region yul1). Region: application in Montréal; page counts, speed measurements and logs on Vercel's global systems, treated as United States. Data: every request in transit; your network address at the edge, used for rate limiting and, for the visit counter once switched on, reduced to country, region and city; page views, speed, and presses on the contact, booking and switch links and enquiries our server accepted on supergence.ai, each carrying only values from a fixed list; error logs. When: always.
Anthropic: the language model behind the assistant, the studio writer and the phone line's words, including its web search and the picture check. Country: United States. Region: inference kept in the United States by a setting on every request. Data: what the section The assistant, the studio and the language model lists and, for the phone line, on each turn the transcript of the call so far, the brief you wrote, your business name, legal name, website, services and standing notes, the caller's number and the local time, then the whole transcript once more for the summary; never audio. When: whenever you use the assistant or the studio, and on every call your line takes.
Resend: delivers our email. Country: United States. Region: not pinned. Data: your enquiry (name, email, business, need, message) as an email to our inbox with your address as the reply address; one automatic reply to the address given on our contact or switch form, carrying nothing typed in the form; the sign-in code email to your address; for a client, the letters described under Letters we send you (the workspace invitation, a notice of a change of plan or of a pause, and a notice that an answer is waiting, which carries none of its words); for a client, a notice to our own inbox each time something is filed on the account or the client answers under a request, carrying the business name, the account's email address, the kind and number of the filing and its first 300 characters, or those of the answer; delivery logs. When: when you send the contact or switch form or request a sign-in code, when we open your account, change its plan, pause it or lift the pause, when our operator answers you, and when something is filed on your account or you answer under a request.
Cloudflare: routes incoming email for our supergence.ai addresses, and for our former supergence.io addresses, to the mailbox our team reads. Country: United States (the provider), on a global network. Data: any email sent to a supergence.ai or supergence.io address, including the copy of your enquiry and your replies to us. When: whenever you email us or send the contact form.
ElevenLabs: the voice demonstration on our public site. Country: United States. Data: your microphone audio and typed text, streamed from your browser directly. When: public site visitors only, and only after you press the control that starts the call.
Google: a Gmail mailbox, a Google Ads account or a Google Business Profile you connect. Country: United States. Data: your consent, the access token, your profile address, the mail we read, draft and send for you, the list of advertising accounts under your grant, paused campaign drafts, and, when you disconnect a Gmail mailbox, its token in the request asking Google to revoke the permission. When: only if you connect a Google account; not yet possible at the date of this policy.
Microsoft: a Microsoft 365 mailbox you connect. Country: United States, on Microsoft's global network. Data: your consent, the access token, your profile, the mail we read, draft and send for you. When: only if you connect a Microsoft account; not yet possible at the date of this policy.
Your own email provider (iCloud Mail, Yahoo Mail, Fastmail, Zoho Mail, Proton Mail, or the host of your own domain): the mailbox you connect by app password. Country: wherever your provider is; it depends on the provider you chose. Data: your app password on each connection, the mail we read, drafts we save, messages we send, and a copy of each sent message filed in your Sent folder. When: only if you connect a mailbox by app password.
Meta: a Meta advertising account you connect. Country: United States. Data: your consent, the access token, your advertising accounts, paused campaign drafts. When: only if you connect a Meta account; not yet possible at the date of this policy.
TikTok for Business: a TikTok advertising account you connect. Country: United States or Singapore, as TikTok's own terms provide. Data: your consent, the access token, your advertiser accounts. When: only if you connect a TikTok account; not yet possible at the date of this policy.
LinkedIn: a LinkedIn advertising account you connect. Country: United States. Data: your consent, the access token, your advertising accounts. When: only if you connect a LinkedIn account; not yet possible at the date of this policy.
Higgsfield: draws advert artwork and short clips. Country: United States. Data: the picture line and our plate instructions, the reference photographs and stills re-uploaded for each drawing (readable at a temporary address for about one hour), the shape and length requested, and a callback address that carries only a row number; its output is retained on its side for at least seven days before we copy it to our storage. When: only once drawing is switched on for accounts. Not switched on at the date of this policy.
Twilio: carries the phone line's calls and text messages, on a Twilio account that is either your own, which you connect, or one Supergence opens and holds for you when you have none, and turns the caller's speech into text and the line's words into speech. Country: United States. Region: not pinned. Data: the identifier and token of the Twilio account the line sits on, proved on connection and checked again, at most every five minutes, when your workspace verifies its connections (where the account is ours, that is a separate sub-account opened in your business's name and holding nothing but your line, and the business name is the only detail of yours we give Twilio to open it); when a number we took for you is moved to a Twilio account of your own, that account's identifier, and its token for the requests that prove it; the caller's number and the call audio, which Twilio transcribes and never passes to us as audio; the words the line speaks; the number you chose for transfers when a caller is put through; the text sent to a caller the line could not help and the number it goes to; every text message sent to your number, where your line receives its texts: the sender's number, the words and any picture, which Twilio keeps in its own message log and of which we read only how many pictures there were; the line's short answers in French to a caller who texts ARRÊT or AIDE, and the number each goes to. When: only once a number is connected or taken for you, and then on each call and each text. The line is built and is not in service for any account at the date of this policy: no number is connected and no call has been taken.
Municipal open data services: the public business licence registers behind the list of businesses we approach to offer our services. Country: Canada. Data: public records we read; nothing about you is sent to them. When: when we build that list.
Your own web host: receives requests from our application in Montréal when we read the public website recorded for your account. Country: wherever your site is hosted. Data: a plain request for your public page. When: clients with a website address on record.
Our own internal operations system: a forward of enquiries exists in our code and is switched off. When: not today; if switched on, this policy will first say where that system runs.
14Where your information is stored and processed
Your database records, your files and your sign-in are stored in Canada, in Montréal. Our application runs in Montréal. Supergence Technologies Inc. operates the service from Vancouver, British Columbia; for a person in Québec that is a holding and a use outside Québec.
Some of your personal information is processed in the United States. What you write to the assistant and the studio, together with the parts of your account and your mailbox those features read, goes to Anthropic. The enquiry you send us and the automatic reply to it, the sign-in codes and the letters we send you, and the notice our operator receives when something is filed on your account or you answer under a request go through Resend, and email to our addresses is routed by Cloudflare. The audio of the voice demonstration goes to ElevenLabs. Page counts, counted presses and server logs are held by Vercel. Once drawing is switched on, advert artwork goes to Higgsfield; once you connect a number, the phone line's calls and texts run through Twilio, each turn's transcript goes to Anthropic, and so do the texts callers send when the assistant reads them for you. If you connect a Google, Microsoft, Meta, TikTok or LinkedIn account, the information those connections carry goes to that platform. If you connect a mailbox by app password, it goes to whichever provider hosts that mailbox, in that provider's country.
While your personal information is in the United States, or in another country where a platform you connected operates, it may be accessed by the courts, law enforcement and national security authorities of that country under that country's law, and a provider there may be required to disclose it without notice to us or to you. We do not hold your information in any country other than Canada and the United States, except through a platform or mailbox provider you chose to connect.
We remain responsible for your personal information while a provider holds it. Every provider is bound by written terms that limit its use to the task, require confidentiality and security, and require it to tell us about a breach. For a person in Québec we also assess, before any of these providers receives information about them, the sensitivity of the information, the purpose, the contractual and technical protections and the law of the receiving country, and we proceed only where the information will be adequately protected.
We do not describe every part of the service as running in Canada, because that is not yet true of every provider we use. The day every provider runs in Canada, this policy will say so and record the date.
15The phone line and call transcription
What exists. Our code can take calls, and receive text messages, on a telephone number, which is either one you connect from your own Twilio account or one we take for you on ours when you have none. It is not in service for any account at the date of this policy: no account has connected a number and no call has been taken. It is described here in full before the first call, because a provider is named in this policy before it receives anything. Nothing runs for your account until you connect a number in your workspace.
How a line gets its number. There are three ways, and your workspace says which one your line uses. First, your own Twilio account: you give us its identifier and its auth token, we prove them with a live request to Twilio and list your numbers, nothing is stored until you choose one, and when you do we tell Twilio to send that number's calls to us and to report when a call ends, and, where nothing else already receives the number's text messages, to send us those too; where something does, the line leaves them there and receives none. Second, a number we take for you, for a business that has no Twilio account: we open a separate sub-account in your business's name on Supergence's own Twilio account, take one number onto it with its instructions already set so it never answers with anything but your line, and hold it for you; it is part of what you pay us, and because a number can be moved between Twilio accounts it is yours to take with you if you leave. Third, the number you already advertise: it stays with whatever carrier it is with now and you forward it to the line, so nothing is ported and your printed number keeps working. You may tell us that number so your workspace can say when a forwarded call arrives; we learn it only from you and from the calls your carrier marks as forwarded, and a carrier that does not mark them leaves us with nothing, which your workspace says rather than guessing.
How the credential is kept. Whichever account the line sits on, its auth token is sealed with AES-256-GCM in the same vault that holds mailbox credentials, only after the number is pointed at us; it is never returned to a browser and never written to a log. Disconnect a line on your own account and the number is put back exactly as we found it and the line's record is deleted at once, credentials included. A number we took for you is never simply disconnected: it leaves one of two ways, and both are yours to choose on your Phone desk. It can be moved to a Twilio account of your own: you give that account's identifier and auth token, we prove them with a live request to Twilio, and the token is used only for the requests that prove the account and, where Twilio moves the number at once, clear our address off it; it is never kept. We keep that account's identifier and name with the line until the move completes, and our operator sees them to open the transfer with Twilio, because Twilio moves a number between two separate accounts only on a request both account holders approve; Twilio then asks you to confirm it, and the line keeps answering until the number arrives. Once the number has left our sub-account, the line's record is deleted and the sub-account closed. Or it can be given up for good, which is final: only you can do that, by typing the number to confirm, and our operator's console cannot. Either way, the call records stay until you ask.
What a caller hears. Every call opens with the greeting you wrote, followed by a fixed sentence that no setting can remove: "This call is transcribed so the team can follow up." In French: "Cet appel est transcrit pour que l'équipe puisse faire le suivi." A line that answers in both languages first asks the caller to choose, and the greeting and the notice follow in the language chosen. The assistant is instructed never to claim to be a person and to say what it is if asked. A caller who continues after the notice consents to the transcription; a caller who would rather not can hang up and reach you another way.
Who handles the call. Twilio, in the United States, carries the call on your own account: it receives the caller's number and the audio, turns the caller's words into text with its speech recognition, and speaks the line's words with its speech synthesis. On each turn we send the transcript so far, the brief you wrote for the assistant, your business name, legal name, website, services and standing notes, the caller's number and the local time to Anthropic, in the United States, with the setting that keeps the inference there, to produce the next sentence; after the call the transcript is sent once more to produce the summary, together with two short labels for what the caller wanted and for anything the assistant could not answer. Separately, to write the reading of your calls that your workspace shows, we send Anthropic those labels and the counted figures they came from, and never the transcripts themselves; the figures in that reading are counted by us from your own call records, and the only thing the model decides is which labels mean the same thing. The assistant answers only from your brief, takes a message or a booking request, which a person on your team confirms because no calendar is connected to the line, and puts a caller through to the number you wrote only under the rule you chose. A call is closed politely after the number of minutes you set.
What we keep, and what we never keep. No audio is recorded or stored by Supergence: our instructions to Twilio never ask it to record, and the table that holds calls refuses any column that could hold a recording. For each call we keep the caller's number, the number called, when the call started and ended and how long it ran, the language, the transcript as turns, the summary, the caller's name and the number to call back if they gave one, whether they asked to be called back, the next step for your team, the two short labels described above, the number your carrier said the call was forwarded from where it said so, and the text sent to a caller the line could not help, if any, with when it was sent. We also keep, on the line itself, the latest reading of those labels: what callers have been asking for, with a count on each, and the questions the line could not answer. A test call you place to hear your own line is kept the same way. These records are shown to you in your workspace and to the assistant when you ask it about your calls, and they are used only so your team can follow up, never for marketing or profiling.
Texts to the line. A text a caller sends to your number reaches us through Twilio where your line receives the number's texts. We keep the sender's number, the words, up to 1,600 characters, the time, how many pictures came with it, the call it followed where the same number had called, and whether you marked it handled; we never fetch or keep a picture. A text from a short code, a named sender or a withheld number is ignored. You see these texts on your Phone desk and in your live report, and the assistant reads them when you ask it about your line or about what is waiting for you, or hand it one. We keep a text even while your account is paused. If a text cannot be kept on our side, it remains only in Twilio's own message log for the Twilio account your line is on, which you can read there when that account is your own and our team can read when it is the sub-account we opened for you. Twilio keeps its own copy of every text, with any picture, in that log, under its own retention.
Asking not to be texted. A caller who texts STOP or ARRÊT, or another of the usual words for it such as UNSUBSCRIBE or ARRÊTEZ, as the whole message, is not texted by the line again, other than the short answers to these words described below, and START, or YES from a number that had stopped, undoes it. We keep each of these with the number, the word as it was typed and the time, for your account as a whole, so it holds for any line your account has, now or later, and we keep it when other texts are deleted on request. Any text waiting to go to that number is dropped with the reason, and a yes from you cannot send it. If we cannot read whether a number has asked to stop, nothing is sent to it but those answers. A caller who texts ARRÊT receives a short confirmation in French naming your business where we hold its name, and one who texts AIDE receives how to stop; in English the line sends no reply of its own to these words, and Twilio's own handling of them applies. A text that contains one of these words and something more, such as Stop calling me, is kept as an ordinary text.
What our operator is told. A text from a caller, and a request to stop, are filed to your Requests; a further text from the same number within twelve hours is not filed again, and a START is never filed. A call that leaves your team something to do, such as a booking request to confirm, a message, a call to return, or a transcript the summary could not write up, is filed once the same way. Filing is held to a daily ceiling for each line, and texts to an hourly one as well; past it, a text or a call is still kept and shown on your Phone desk and in your live report, and is only not filed. These filings, and our operator's notice of them described under Requests to us, carry the time and, for a call, a short label our language model wrote of what it was about and whether it was in French, or, for a request to stop, the word that was used, and never the caller's name or number or any other words of theirs.
A caller the line could not help. If you leave it on, a caller who hangs up before saying anything may be texted from your line's number, through the Twilio account the line sits on, with the message you wrote. The text leaves on its own only when you asked for that and our operator confirmed your Front Desk dial in writing, outside the quiet hours of 8 PM to 8 AM in your line's own time zone, and within your daily cap; otherwise it waits for your yes in your workspace, or is held until the quiet hours end. It is never sent to a withheld number, never after a test call, never to a number that has asked not to be texted, and never while we cannot read whether it has. It must name your business and tell the caller how to stop, by replying STOP or ARRÊT: the message we propose does both, ending with Reply STOP to opt out or, on a line whose first language is French, with Répondez STOP pour ne plus recevoir de messages. A message you write in its place that does not do both is refused when you save it with the text switched on, and is never sent; a waiting text whose words fall short is replaced by your line's current message, which your workspace shows before you send it. An account with no business name on file sends none.
How long. Call records, and the texts callers sent the line, are kept while your account is open and are deleted by hand on request, except a request not to be texted, which is kept for the life of your account; our code has no deletion path for them yet, and one is being built. Disconnecting a line on your own Twilio account first tells Twilio to send the number's calls and texts where they went before, then deletes the sealed credential and the number at once, and leaves the call records and texts in place until you ask; if Twilio cannot be told, nothing is deleted until it can, and your workspace says so. A caller may ask for their own record through the Privacy Officer, and we answer as the section Your rights describes.
What this policy said would come first. Version 2.0 promised three things before the first call: the provider named with its country, the retention period stated, and, for an account holding Québec residents' information, the assessment Québec law requires. The first two are done in this version. The third is done account by account, before a line on an account holding Québec residents' information takes a call.
16Text messages and commercial electronic messages
Messages to your customers. Our code can send two kinds of text message on your behalf, both from your line's number and through the Twilio account the line sits on, and neither kind is in service for any account at the date of this policy. The first is the text to a caller the line could not help, described under The phone line and call transcription; it goes only to the number the caller called from. The second is the line's short answer in French to a caller who texts ARRÊT or AIDE; it goes only to the number that sent that word. Every text to a caller the line could not help must identify your business and give a way to stop, whether we proposed its words or you wrote them, and a number that has asked not to be texted is not texted again. A number that is not written in full international form is refused, because a misdirected message is a message to a stranger.
Messages from us. We contact businesses to offer our services, using business contact information from public sources such as business licence registers and business websites, or an address you gave us. Every such message identifies Supergence Technologies Inc., gives our mailing address, and carries a working unsubscribe: a link in the message, and the unsubscribe button your mail program shows, each of which takes your address off our list with one press. However the request reaches us, we honour it within ten business days, as Canada's anti-spam law requires; a request made another way, by replying to the message for example, is recorded by hand. If you tell us to stop, we stop, and we keep only what we need to make sure we do not contact you again: your address, the date, and how you asked. We never send a commercial message to a personal address without your consent.
For a person in Québec, telling us to stop also withdraws consent to our using your information for prospection, and we cease that use at once.
17Public registers and the businesses we approach
We use municipal business licence registers, published under open data licences, to build the list of businesses we visit or telephone to offer our services. That list carries business names, addresses and coordinates only, and it is made and kept under Canada's anti-spam law and the rules described under Text messages and commercial electronic messages.
We drop licence records for home-based businesses and records whose only name is a person's own name, so the list holds businesses and not homes. We never request a register's owner, applicant, contact, telephone, email or fax fields.
Until 15 September 2026 this workspace also carried a marketing map drawn from those registers and from Statistics Canada census counts. It was never switched on for any account, so it never ran for a client and no client information ever reached it. The map, its archives and every copy of the register reads behind it have been deleted.
18How we protect your information
We protect your information with measures that fit how sensitive it is, and we describe here only what is actually in place.
Your records are stored in Canada in a database where each client can read only its own rows, and where the most sensitive tables can be read only by our server, never by a browser. Traffic to and from Supergence is encrypted in transit. Credentials for a mailbox or advertising account you connect are sealed with AES-256-GCM before they are stored and are never logged or returned. You sign in with a one-time code valid for ten minutes; we store no passwords. Every request to our servers is rate limited. Anything paid, public or widening runs only after your swipe and, for widening, our operator's written confirmation. The studio and the email desk enforce their own ceilings in the database so a restarted server cannot forget them.
Your sign-in session is stored in your browser's local storage on the device you used, and it does not expire on our side; sign out on a shared device to end it. We do not offer a second sign-in factor today.
We are a small business. The founder is the only person with administrative access to our systems, and any team member on our access list sees client accounts only through our console, which checks that access on every request. We do not claim security certifications we do not hold, and we do not claim encryption at rest beyond what our providers apply as standard.
Our code keeps a record of the changes our team makes to an account through our console, described under Our team in the section on your account and your workspace, and your Plan view shows it. It does not note our team reading an account. Together with the written record of requests, replies and confirmations in your workspace, it is the record of what was authorized and done.
19How long we keep information
The rule. We keep personal information only as long as the purpose it was collected for requires, or as long as a law requires, and then we delete it or remove what identifies you. Where our code deletes something automatically, the line below says so. Where it does not yet, the line says we delete by hand on request, and we do so within 30 days of the request. Automatic deletion for those records is being built, and this schedule will be updated as each piece lands. Information used to make a decision that affects you is kept at least one year after the decision, as British Columbia and Québec law require.
Enquiries from our site, with the version of this policy their form linked to and the status our team set, and their email copy in our inbox: until you ask us to delete them; deleted by hand on request. Automatic deletion at 24 months after your last message to us is being built. Basis: answering and following up your enquiry.
Assistant usage ledger (email address, network address, plan flag, time, and counts of what each turn used): meant to serve seven days; removed when we run the sweep, by hand today; an automatic seven-day sweep is being built. Basis: daily ceilings on assistant use that survive a restart.
Sign-in codes: ten minutes, then invalid. Sign-in sessions: until you sign out or clear your browser storage. Sign-in identity: for the life of your account, then deleted by hand when your account closes. Basis: signing you in.
Records of the version of this policy, and of our Terms of service, in force when you signed in: for the life of your account and at least one year after it closes, longer while a legal claim is open, then deleted by hand. Basis: showing what you agreed to and what you were shown, and when.
Your account record, your settings, including the payment instructions printed on your invoices, and what our operator recorded: for the life of your account and at least one year after it closes, then deleted by hand. Basis: running the account; they record decisions that affect you and what you authorized.
Our operator's private note about your account: for the life of your account and at least one year after it closes, then deleted by hand. Basis: running your account; you can ask to see it.
The record of acts on your account: for the life of your account and at least one year after it closes, longer while a legal claim is open, then deleted by hand. Basis: the record of who did what on your account, and when.
The record of letters we sent you: for the life of your account and at least one year after it closes, then deleted by hand; the letters themselves are not kept, and Resend keeps its own delivery logs under its own retention. Basis: showing what we told you and when, and never sending the same letter twice.
Requests and the conversation under each, with our replies and your answers, written mandates and confirmations, and the notice of each filing and each answer in our own inbox: for the life of your account and at least one year after it closes, longer while a legal claim is open, then deleted by hand, the inbox notices with them. Resend keeps its own delivery logs under its own retention. Basis: the written record of what you authorized and what we did.
Invoice drafts: until you delete them, at once. Approved, sent, paid and void invoices, their send record, the business details and payment instructions kept on each when it was first sent, and the time and reason of a void: for the life of your account, because they are your business records; when your account closes we hand them to you in a structured format and delete them by hand on request. A monthly template keeps creating drafts until you delete it while it is still a draft. Basis: your bookkeeping; Canadian tax law requires a business to keep its records for six years after the end of the tax year, and how long you keep yours is your decision.
Our own records of what we billed you: six years after the end of the tax year they relate to. Basis: the Income Tax Act and the Excise Tax Act.
Sealed mailbox credentials, with any note of a refused sign-in: deleted at once when you disconnect, and for Gmail we also ask Google to revoke the permission; otherwise until your account closes, then deleted by hand. A note of a refused sign-in is removed at the next sign-in that works, replaced by a newer one, or cleared when you connect the mailbox again. Mailbox contents: never stored; read live from your mailbox. Basis: the connection you asked for.
Advertising account grants: deleted at once when you disconnect; an expired grant is marked expired and stays until you disconnect it; at closure, deleted by hand. Consent records for a connection (a random value, your email address, a ten-minute expiry): removed when we run the sweep by hand; an automatic sweep is being built. Basis: the connection you asked for and replay protection.
Studio runs. Runs that were never drawn, and drawings that failed, were refused or were cancelled: until you delete them, at once. Drawn frames, clips and approved runs: for the life of your account, because a frame that was drawn is a record of what you saw and approved. The artwork files themselves are not deleted by our code today and are deleted by hand on request. Reference photographs, once accepted: marked deleted on request, and the file removed by hand. Links to artwork expire after one hour. Basis: your creative record and the ceiling on daily use.
Assistant conversations: nothing on our servers; the last forty messages on your device until you clear them; at Anthropic, deleted within 30 days under its published retention, or up to two years if flagged for a usage policy violation. Basis: answering you.
Your website, read: up to one hour in server memory. The check that your website answers: five minutes. Basis: grounding the writer and your reading.
Visit counts on your own website, once switched on: daily counts by page, referring site and city, with no network address; not automatically deleted today; automatic deletion is being built and this line will state the period before the first count is written.
Voice demonstration: nothing at Supergence; ElevenLabs' own retention applies. Page counts, counted presses and server logs: Vercel's own retention applies; we do not read the logs except when something breaks.
Call records, once you connect a phone line: the caller's number, the times, the transcript, the summary, the caller's name and number to call back if given, and the text sent to a caller the line could not help; kept while your account is open, then deleted by hand on request; an automatic path is being built. No audio exists to keep. The line's sealed credential and number are deleted at once when you disconnect. Basis: the record of what a caller asked and what the line said, so your team can follow up.
Texts callers send to your phone line: the sender's number, the words, the time, how many pictures came with each and the call it followed; kept while your account is open, including after the line is disconnected or changed, then deleted by hand on request; an automatic path is being built. No picture exists to keep. Twilio keeps its own copy in its message log. Basis: so your team can answer the caller.
A request not to be texted, or to be texted again (STOP, ARRÊT, START and the like), with the number, the word as typed and the time: for the life of your account, whatever happens to its line, and not deleted with the other texts; deleted by hand after the account closes. Basis: what stops the line texting a number that asked it not to.
Records of privacy requests, complaints and confidentiality incidents: five years from the day we learned of the incident or closed the request, which covers the 24 months federal law requires for breach records and the five years Québec law requires for the incident register.
Business contact information used to offer our services: until you tell us to stop, after which we keep only the minimum needed to make sure we do not contact you again (your address, the date, and how the request reached us) for as long as we contact businesses, so the request goes on being honoured. Basis: Canada's anti-spam law.
20Your rights
These rights come from British Columbia's Personal Information Protection Act, from PIPEDA, and, for a person in Québec, from the Québec Act. Where one law gives you more than another, you get the more.
How to ask. Write to the Privacy Officer at hello@supergence.ai with the subject line Privacy, or by post. Tell us who you are and what you want, with enough detail for us to find the information; we help you narrow a request if needed. We may ask you to confirm your identity first, because we must not hand your information to someone else. Someone can ask on your behalf with your written authorization. If a disability makes it hard to exercise a right, tell us and we accommodate you.
How long we take. We acknowledge within five business days and answer in writing within 30 days of receiving your request. If we need longer, for example because the request is large or involves a third party, we tell you in writing before the 30 days end, say why, and give a new date. Silence is not an answer: if you have heard nothing after 30 days, treat it as a refusal and use the recourse below.
Cost. We give you your information at no cost. If a request would cost us a real sum to fulfil, for example a very large export, we tell you the amount in advance and you may withdraw the request.
Access. You can ask us to confirm what personal information we hold about you, to see it, to receive a copy, and to be told how we have used it and to whom we have disclosed it. Information held in our systems is given to you as a readable transcript if you ask. Under PIPEDA, British Columbia's Act and, in Québec, the Québec Act, this includes the record of acts on your account and any private note our operator keeps about you or your account, which your workspace does not show. On request we also tell you which categories of people at Supergence have access to your information, how long we keep it, and how to reach the person in charge. We may withhold information where the law requires or allows it: another person's personal information, information protected by legal privilege, information whose release would threaten someone's safety, or, in Québec, information that would reveal a third person's information and seriously harm them. If we withhold anything, we tell you in writing, give the reason and the provision of the law we rely on, and remind you of your recourse and its time limit.
Correction. If personal information we hold about you is inaccurate, incomplete or ambiguous, you can require us to correct it. You can change most account details yourself in your workspace. For anything else, write to us; we correct it within 30 days, and if we disagree we record your request with the information and tell you why. Where we corrected something we had shared, we tell those we shared it with in the previous six months, if you ask.
Withdrawal of consent. See Consent, and how to withdraw it.
Deletion. You can ask us to delete your personal information. We delete what we hold within 30 days, by hand where our code has no automatic path yet, except what the law or an existing contract requires us to keep for the periods under How long we keep information; we tell you what those are. A drawn advert, an approved request and an invoice that was sent are records of what you authorized and are kept for that reason. Closing your account triggers the same process.
Portability. If you live in Québec, computerized personal information you gave us, as opposed to information we created or inferred from it such as a score, a plan or a check, can be given to you in a structured, commonly used format such as CSV or JSON, or sent at your request to another person or body entitled by law to collect it, within 30 days, unless doing so raises serious practical difficulties, in which case we tell you why in writing and offer what we can. We extend the same to every client on request.
Stopping publication and de-indexing. If Supergence has published personal information about you, for example on a page we host for a client or in a public reply we posted for a client, and that publication breaks the law or a court order, or seriously harms your reputation or privacy in a way that clearly outweighs the public interest in it, you can require us to stop publishing it or to de-index links attached to your name. Write to the Privacy Officer; we answer within 30 days, and where we act, our written reply confirms what was removed or de-indexed. This right is written into Québec law; we honour it for everyone.
Automated decisions. See The assistant, the studio and the language model: we make none about you today, and the section says what you would be told and could ask if that ever changed.
Information at collection. At any time you can ask us what we collect from you, how, why, who receives it, whether it leaves Québec or Canada, and how to exercise these rights. This policy is that answer, and the Privacy Officer will restate any part of it for your situation.
Recourse. If you are not satisfied with our answer, you can complain to the Privacy Officer, and you can apply to the Privacy Commissioner of Canada, to the Information and Privacy Commissioner for British Columbia, or, if you live in Québec, to the Commission d'accès à l'information, whose details are under Questions and complaints. In Québec an application to the Commission about access or correction must be made within 30 days of our answer or of the day our answer was due.
21Québec: what binds us today, and what we do before serving a Québec client
The Québec Act applies to the personal information we hold about a person in Québec from the moment we carry on business there. Our site is offered in French and we invite Québec businesses to become clients, so the duties that come with publishing, the title and contact of the person in charge, this policy, and the description of how we govern personal information, bind us now, and this page meets them. The duties that attach to a Québec resident's own information bind us in respect of each such person from the first record we hold.
How we govern personal information. Supergence keeps written governance policies and practices, approved by the person in charge, that cover three things. Retention and destruction: the schedule under How long we keep information, and the rule that information is deleted or made anonymous when its purpose is served, subject to legal retention periods. Roles: the founder is responsible for every decision about personal information; any contractor who works on our systems signs a confidentiality undertaking and is given access only to what the task needs. Complaints: the process under Questions and complaints. A summary is this policy; the full documents are available to the Commission on request.
Privacy by default. Every workspace setting starts at the most private position, as described under Consent, and no function that identifies, locates or profiles a person is switched on by default. Our page counts do not identify you. The voice demonstration sends nothing until you press the control that starts the call. If we ever add a function that identifies, locates or profiles a person, it will ship off, this policy will say where to switch it on, and only you will be able to switch it on.
Before we serve a Québec client, and before any provider outside Québec receives a Québec resident's information, we do three things. First, for each provider outside Québec, including our own operator access from British Columbia, we carry out the assessment section 17 of the Québec Act requires: the sensitivity of the information, the purpose, the contractual and technical protections, and the law of the receiving jurisdiction; we proceed only where the information will be adequately protected, and the transfer is covered by a written agreement that limits use to the task, requires confidentiality and security, requires deletion when the task ends, and requires the provider to tell the person in charge without delay of any breach or attempted breach. Second, for any system we add or rebuild that handles personal information, including a phone line that records or transcribes calls, an image drawing service or reference uploads, we carry out a privacy impact assessment with the person in charge involved from the start, and we design the system so the information you gave us can be handed back in a structured, commonly used format; a feature that has not passed that assessment is not switched on for an account holding Québec residents' information. Third, we give the Québec client the French version of this policy and of the client agreement first, and an English version binds only if the client asks for it in writing.
Consent under Québec law is asked for one purpose at a time, in clear and simple language, separately from anything else, and lasts only as long as the purpose does. Consent that is not obtained that way is without effect, and we do not rely on it.
22Confidentiality incidents and breaches
A confidentiality incident is any access to, use of or communication of personal information that the law does not allow, or its loss, or any other breach of its protection. If we have reason to believe one has happened, we act at once to reduce the risk of harm and to stop it happening again, we involve the Privacy Officer from the first hour, and we record it in our incident register whether or not it turns out to be serious.
Under PIPEDA, we assess whether the breach creates a real risk of significant harm to you, looking at how sensitive the information is and how likely it is to be misused. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business, financial loss, identity theft, and damage to credit or property. If there is a real risk, we report the breach to the Privacy Commissioner of Canada and tell you as soon as feasible, directly, and we also tell any organization or government body that can reduce the harm. We keep a record of every breach, whether or not it met that test, for at least 24 months from the day we determine it occurred, and we give the Commissioner those records on request.
Under the Québec Act, if the incident creates a risk of serious injury to a person in Québec, judged on how sensitive the information is, what could be done with it and how likely that is, we notify the Commission d'accès à l'information and we notify the person promptly, and where we cannot reach a person directly we publish a public notice. Our register entries are kept up to date for at least five years after we learned of the incident and are given to the Commission on request.
What our notice to you will say: what happened and when, what information was involved, what we have done to reduce the harm and to stop it recurring, what you can do to protect yourself, and how to reach us with questions. Where the incident involves your customers' information, we tell you at once so that you can meet your own duties to them, and we help you do so.
Every provider named in this policy is bound in writing to tell the Privacy Officer without delay of any breach or attempted breach affecting our information.
23Children
Our service is for businesses and the people who run them. It is not directed to children, and we do not knowingly collect personal information from anyone under 19 in British Columbia, under the age of majority elsewhere in Canada, or under 14 in Québec without the consent of a parent or guardian. If we learn that we hold such information, we delete it. The voice demonstration is meant for adults.
24Changes to this policy
Each version of this policy carries a version number and an effective date, printed at the top and at the foot of this page. When we change it in a way that matters to you, we post a notice on this page and, if you hold an account, we tell you in your workspace or by email before the change takes effect. Adding a provider, changing where information is processed, or changing a retention period always counts as a change that matters. Earlier versions are available on request.
A provider is added to this policy before it receives anything, never after. A feature described here as not switched on stays off until this policy has been updated to cover it.
Version 2.8 (30 September 2026) changes nine things. First, our email provider, Resend, now carries letters to you and not only to our own inbox: an invitation to your workspace when we open your account, a notice when our team changes your plan, pauses your account or lifts the pause, and a notice that an answer is waiting under one of your requests, which carries none of the answer's words; and one automatic reply to the address given on our contact or switch form, which carries nothing the person typed. We keep a record of each letter to a client, never its text. Second, a request is now a conversation: your answers under a request are kept with our replies, our operator is told of each answer the way they are told of a filing, and the assistant reads the whole conversation. Our operator may also keep a private note about your account that your workspace does not show, and you can ask to see it. Third, we keep a record of acts on your account, including the changes our team makes to your account through our console, and your Plan view shows it; earlier versions said our code kept no separate record of our team's actions, when it had already begun keeping one for replies and confirmations to requests, and this version says so. Enquiries through our site now carry a status our team sets and the date it was set. Fourth, the phone line can receive text messages: we keep what callers send it, never a picture, and keep a request not to be texted for your whole account; every text to a caller the line could not help must name your business and say how to stop; and our operator's notice of a text, or of a call that leaves your team something to do, carries neither the caller's number nor their words, except the word a caller used to ask not to be texted. Twilio receives those texts, and the assistant reads them when you ask it about your line or about what is waiting for you, or hand it one. Fifth, our site counts presses on the links to our contact form, to book a call and to our switch page, and each enquiry sent, with values from a fixed list and nothing typed. Sixth, invoices can carry payment instructions you give us, which may include bank details, so the earlier sentence saying we hold no bank details is corrected; the details an invoice was sent with are kept on it, a void keeps its time and reason, and the PDF is built on request and not stored. Seventh, disconnecting a Gmail mailbox now asks Google to revoke the permission, which earlier versions said our code did not do; a copy of each message sent through your own mail server is filed in your Sent folder instead of being copied to your address; and a sign-in your mail provider refuses is noted on that mailbox's connection. Eighth, the assistant's usage ledger now also keeps counts of what each turn used, never its words, and they hold a daily ceiling for each account on a plan. Ninth, it corrects two sentences that were already out of date: an email leaves without a swipe only to someone your mailbox has already written to, not to someone who wrote to you, and overdue reminders are also sent when our daily clock runs or your live report reads your invoices, not only when the invoice desk is opened. No provider and no country is added, but Resend, Twilio, Vercel and Anthropic now receive information they did not receive before, and the retention schedule gains five records, which this policy counts as changes that matter. Version 2.8 takes effect on the day it is published: at that date no client account exists other than our own, so none of these changes reaches a client's information before this notice.
Version 2.7 (30 September 2026) moves our web address, and the address you write to us at, to supergence.ai: this policy is published at supergence.ai, and privacy requests go to hello@supergence.ai. Pages at supergence.io send you to the same page at supergence.ai, and mail sent to our supergence.io addresses still reaches us. No provider, country, purpose or retention period changes with the address, so it takes effect on the day it is published.
Version 2.6 (29 September 2026) changes five things. First, it corrects what the section on the phone line said about letting a number go. It said that disconnecting a number we took for you gives it back to Twilio and closes its sub-account. That is no longer what happens: such a number is never simply disconnected; it is moved to a Twilio account of your own, or given up for good only when you type the number to confirm, and our operator's console cannot give it up. A move keeps the identifier and name of the account the number moves to, until the move completes, and never that account's auth token. No line is in service for any account at its date, so no number is affected. Second, when something is filed on a client's account, our operator is told by an email to our own inbox, sent through Resend in the United States; it carries the business name, the account's email address, the kind and number of the filing and its first 300 characters, so part of a filing now reaches a provider in another country that did not receive it before. The Resend row, the section on where your information is stored and processed, Requests to us and the retention schedule say so. Third, the unsubscribe in our messages to businesses now takes an address off our list with one press, and the retention schedule says what that list keeps. Fourth, it names a record we begin keeping. When you sign in, we record the version of this policy you were shown and, once our Terms of service are no longer a draft, the version of them you agreed to; when you send our contact form, the version of this policy the line under the form linked to is kept with your enquiry. Each holds your email address, the document, its version and the time, and nothing else. Fifth, it corrects the name of the corporation. There was no change of corporate name. The corporation that operates Supergence is Supergence Technologies Inc., incorporated federally under the Canada Business Corporations Act, and that has been its name since it was incorporated. Versions 2.0 to 2.3 of this policy named it Supergence Labs Inc., and versions 2.4 and 2.5 named it Supergence Inc.; both names were our error, and version 2.5 was wrong to say that the corporation had always been called Supergence Inc. The correction changes nothing about what we collect, who processes it, in which country or how long we keep it. Where an earlier version of this policy, or a message we sent you, carries the name Supergence Labs Inc. or Supergence Inc., that was our error and it means Supergence Technologies Inc. Nothing else changed. Version 2.6 takes effect on the day it is published: at that date no client account exists other than our own, so none of these changes reaches a client's information before this notice.
Version 2.5 (20 September 2026) withdrew what version 2.4 had said about a change of corporate name: no name had changed, on that date or on any other. The name version 2.5 itself gave the corporation was also wrong, and version 2.6 corrects it.
Version 2.4 (19 September 2026) corrected the other half of the same error, and that correction stands. This policy had described the corporation as a British Columbia corporation. It is incorporated federally, under the Canada Business Corporations Act, and carries on business from Vancouver, British Columbia. Which privacy laws apply to you did not change with it, because that follows from where we carry on business and where you are, not from where we were incorporated. Version 2.5 took effect on the day it was published, without notice, for the same reason version 2.4 did: it changed nothing we do with your information.
Version 2.3 (15 September 2026) removes the marketing map. It was described in every version from 2.0 and was never switched on for any account, so it never ran for a client and no client information ever reached it; the map, the census and register archives behind it and the raw daily register reads have all been deleted. The studio's media plan no longer names neighbourhoods and says where an advert should run in words. What stays is the address we hold for your business, which decides whether Québec's advertising rules apply to your adverts, and the public licence registers we use to build the list of businesses we approach.
Version 2.2 (13 September 2026) added the second way a line gets its number, which is that we take one for you on our own Twilio account when you have none, and says what that changes: who is billed, that the sub-account is opened in your business's name, and that the number is yours to take with you. It also adds the two short labels now written after each call and the reading built from them, and says that the reading is written from those labels and counted figures and never from the transcripts. The line is still not in service for any account.
Version 2.1 (10 September 2026) describes the phone line as it is now built: the provider that carries its calls is named with its country, no audio is recorded or kept, and the notice the caller hears and the retention of call records are stated.
25Questions and complaints
Start with us. Write to the Privacy Officer at hello@supergence.ai with the subject line Privacy, or by post to the address below. We acknowledge a complaint within five business days, investigate it, and reply in writing within 30 days with what we found and what we changed. We keep a record of every complaint and its outcome.
You may also complain directly to a regulator at any time, before or after coming to us.
Office of the Privacy Commissioner of Canada. 30 Victoria Street, Gatineau, Québec K1A 1H3. Toll-free 1-800-282-1376, telephone 819-994-5444, TTY 819-994-6591. Online: priv.gc.ca (Report a concern).
Office of the Information and Privacy Commissioner for British Columbia. PO Box 9038, Stn. Prov. Govt., Victoria, British Columbia V8W 9A4. Telephone 250-387-5629; toll-free in British Columbia through Service BC at 1-800-663-7867 (Vancouver 604-660-2421), asking for a transfer to 250-387-5629. Email info@oipc.bc.ca. Online: oipc.bc.ca.
Commission d'accès à l'information du Québec. Québec office: 525, boulevard René-Lévesque Est, bureau 2.36, Québec (Québec) G1R 5S9, telephone 418-528-7741. Montréal office: 2045, rue Stanley, bureau 900, Montréal (Québec) H3A 2V4, telephone 514-873-4196. Toll-free 1-888-528-7741. Email cai.communications@cai.gouv.qc.ca. Online: cai.gouv.qc.ca. In Québec you may complain anonymously about our practices, and an application about access or correction must be made within 30 days of our answer or of the day it was due.
26Language
This policy is published in English and in French. Both are official texts. For a person in Québec the French text is available on the same terms as this one and is the text that governs; nothing in this English text reduces what the French text gives you. Where this policy forms part of a client agreement with a Québec client, we provide the French version first, and an English version binds only if the client asks for it in writing.
27Effective date, version and address
Effective 30 September 2026. Version 2.8.
Supergence Technologies Inc., Attention: Privacy Officer, Vancouver, British Columbia, Canada. Email: hello@supergence.ai, subject line Privacy.
28Who processes your information, and where
Every provider that receives personal information on our behalf, the country it operates in, what it receives and when. No provider is added to this table after it has received your information: it is named here first.
| Provider | Purpose | Country and region | What it receives | When |
|---|---|---|---|---|
| Supabase | Database, file storage and sign-in (one-time codes, sign-in identities) | Canada, ca-central-1, Montréal | Every record and file the policy describes: enquiries and their status, accounts and the operator's private notes, requests and the conversation under each, the record of acts on each account, the record of letters to clients, the assistant usage ledger with its counts, sealed mailbox and advertising credentials, consent records, studio runs and artwork, invoices with the issuer details kept at first send, visit counts (when on), sealed phone credentials, call records, texts sent to the line and requests not to be texted | always |
| Vercel | Runs the application and serves the site; Web Analytics page counts and counted presses, Speed Insights, function logs | United States (provider); application executes in Canada, Application pinned to yul1 (Montréal); analytics, speed measurements and logs on Vercel's global systems, treated as United States | Every request in transit; visitor IP at the edge for rate limiting (memory only) and, for the visit counter once on, reduced to country/region/city; page views and web vitals on supergence.ai; presses on the contact, booking and switch links and contact or switch enquiries the server accepted, each with properties from a fixed list (which link or form, where on the page, language) and nothing typed; error logs that may echo an email address | always |
| Anthropic | The language model behind the assistant, the studio writer and the phone line's words, its web search, and the picture check | United States, inference_geo us on every request; no Canadian region in use | Assistant\: transcript, account block (email, business name, plan, fees, status, standing notes), verified-reality lines, every action result (account overview, requests with the conversation under each, invoices with customers' names, emails and amounts and any void reason, mailbox listings and full message bodies up to 20,000 characters, texts sent to the phone line with the sender's number, website review). Studio: the letter, account block with legal name, website, services, mandate, channels and liked adverts, website summary, reference photographs (when on) and finished frames as images, web searches carrying the client's city and region. Phone line: on each turn the transcript so far, the assistant's brief, business name, legal name, website, services and standing notes, the caller's number and the local time; after the call the transcript once more for the summary; never audio | whenever a client uses the assistant or the studio, and on every call the phone line takes |
| Resend | Email delivery | United States, not pinned | Contact-form enquiries as email to the Supergence inbox (name, email, business, need, message, reply-to the enquirer); one automatic reply to the address given on the contact or switch form (fixed text in the form's language, a booking link, nothing typed in the form); sign-in code emails via Supabase custom SMTP; letters to a client at the account's address: the workspace invitation (account email, business name, the operator's name where their profile gives one, the sign-in address, the next step on the plan), a notice of a change of plan or of a pause (former and new plan names, pause state) and a notice that an answer is waiting (request number and kind, the operator's name where known, none of the answer's words); a notice to the Supergence inbox for each filing on a client's account (business name, account email, kind, request number, the first 300 characters of the filing, no reply-to) and for each answer a client writes under a request (the same, with the first 300 characters of the answer); delivery logs | when a visitor sends the contact or switch form, a client requests a sign-in code, an account is opened, its plan is changed or it is paused or resumed, an operator answers a request, or something is filed on a client's account or a client answers under a request |
| Cloudflare (Email Routing) | Routes incoming email for supergence.ai addresses and the former supergence.io addresses to the mailbox the team reads (MX route1/2/3.mx.cloudflare.net) | United States (provider), global network, not pinned | Any email sent to a supergence.ai or supergence.io address, including the Resend copy of each enquiry and replies from enquirers and clients | always, for inbound email |
| ElevenLabs | The voice demonstration on the public site and the unlisted /demo/bamoo page | United States, not pinned | Visitor microphone audio and typed text, streamed from the browser directly; Supergence servers receive nothing | public site visitors only, after pressing the call control |
| Gmail mailbox (OAuth, read/modify/send), Google Ads and Google Business Profile grants, paused campaign drafts, token revoke | United States, not pinned | Consent, access and refresh tokens, profile address, mail read, drafted and sent, accessible customer ids, campaign drafts; at a Gmail disconnect, the token in the revoke request | only if you connect a Google account; app credentials not yet registered, so not possible at the date of this policy | |
| Microsoft | Microsoft 365 mailbox (Mail.ReadWrite, Mail.Send, User.Read, offline_access) | United States / global, not pinned (login.microsoftonline.com, graph.microsoft.com) | Consent, access and refresh tokens, profile, mail read, drafted and sent with attachments | only if you connect a Microsoft account; app credentials not yet registered, so not possible at the date of this policy |
| Your own email provider (iCloud Mail, Yahoo Mail, Fastmail, Zoho Mail, Proton Mail, or your domain's host) | A mailbox connected by app password over IMAP and SMTP | Depends on the provider you chose, chosen by the client or a preset | The app password on every connection, inbox envelopes and bodies read, drafts appended, messages sent, and a copy of each sent message appended to the Sent folder after a search of that folder for it | only if you connect a mailbox by app password |
| Meta | Meta advertising account grant, paused campaign drafts, token revoke | United States, not pinned | Consent, token, ad account list, campaign drafts | only if you connect a Meta account; not possible at the date of this policy |
| TikTok for Business | TikTok advertising account grant | United States or Singapore, per TikTok's terms, not pinned | Consent, token, advertiser list; no revoke path in our code | only if you connect a TikTok account; not possible at the date of this policy |
| LinkedIn advertising account grant | United States, not pinned | Consent, token, token refresh, ad account list; no revoke path in our code | only if you connect a LinkedIn account; not possible at the date of this policy | |
| Higgsfield | Draws advert artwork and clips | United States, not pinned (api.higgsfield.ai) | Picture line plus plate suffix as prompt, reference photographs and stills re-uploaded to presigned storage (public URL for about one hour), aspect ratio and duration, a webhook URL carrying the row id and an HMAC; output retained upstream at least seven days | only once drawing is switched on for accounts; no key in any environment at the date of this policy |
| Twilio | Carries the phone line's calls and text messages, on the client's own Twilio account or on a sub-account Supergence opens and holds for a client who has none; speech recognition (Gather) and speech synthesis (Say) | United States, not pinned | The Account SID and Auth Token of the account the line sits on (proved live on connection, sealed in the vault, sent on every request to Twilio, checked at most every five minutes); where Supergence provides the number, the business name used to open the sub-account; when such a number is moved to the client's own Twilio account, that account's SID (kept with the line until the move completes) and its Auth Token for the requests that prove it (never kept); the caller's number and the call audio, transcribed by Twilio and never passed to Supergence as audio; the number the carrier says a call was forwarded from, where it says so; the words the line speaks; the transfer number when a caller is put through; the text to a caller the line could not help and its recipient number; every text message sent to the number where the line receives its texts (sender's number, words and any picture, kept by Twilio in its message log; Supergence reads only the number of pictures); the line's short answers in French to ARRÊT and AIDE and the number each goes to | only if a client connects a number, then on every call and every text sent to it; built and not in service for any account at the date of this policy (no number connected, no call taken) |
| Municipal open data services and Statistics Canada | Public business licence registers behind the list of businesses we approach to offer our services | Canada, not applicable | Public records read by Supergence; nothing about a client or visitor is sent | when we build that list |
| The client's own web host | Receives a plain request when Supergence reads the client's public website and checks that it answers | Wherever the client's site is hosted, requests originate from Vercel Montréal | A request for the public page with a Supergence user agent | clients with a website address recorded by the operator |
| Supergence's own internal operations system (enquiry forward) | Would receive contact-form enquiries as a signed event | Unknown host; not disclosed until switched on, not set | Nothing today (the forward's destination is not configured in any environment) | not today; named with its location before it is switched on |
29How long we keep each record
A period and a reason for every class of record we hold. Where our code cannot yet delete a record on its own, the table says so, and deletion is done by hand on request until the automatic path is built.
| Record | How long | Why |
|---|---|---|
| Contact-form enquiries (site_leads, with the policy version their form linked to, and the status the team set with the date it was last set) and the email copy in the Supergence inbox | Until deletion is requested; deleted by hand within 30 days. Automatic deletion at 24 months after last contact is being built | Answering and following up the enquiry; PIPA s.35; no DELETE path exists in code today |
| Assistant usage ledger (site_chat_ledger: email, IP, prospect flag, time, and per turn the tokens used, read from and written to the model's cache, and the number of model rounds) | Meant to serve seven days; removed only when the sweep script is run by hand; automatic seven-day sweep being built | Daily ceilings on assistant use, in turns and tokens, that survive a cold instance; counts only, never words; disclosed because a stored IP is personal information |
| Sign-in codes | Ten minutes | Supabase Auth OTP expiry (mailer_otp_exp) |
| Sign-in sessions | Until the user signs out or clears browser storage; no server-side expiry or revocation | supabase-js persistSession; what the code does |
| Sign-in identity (auth user) | Life of the account, then deleted by hand at closure | Signing in; no admin delete path in code |
| Account record, client settings (including the payment instructions printed on invoices), operator record (site_accounts) | Life of the account and at least one year after closure, then deleted by hand | Running the account; PIPA s.35(1) and Québec s.11 (decisions affecting the person); no DELETE path in code |
| The operator's private note on an account (site_account_notes: the note, when it was last saved and by which team member) | Life of the account and at least one year after closure, then deleted by hand; emptying the note leaves an empty note in place | Our team's working note for running the account; not shown in the workspace or read by the assistant; kept in our database and shown only in the team console; given to the person on an access request; no DELETE path in code |
| The record of acts on an account (site_acts: when, who acted and, for our team, that person's address, the act from a fixed list, what permitted it, the outcome, a pointer to the record concerned, a short reason for the outcome, in our own words or, where the act failed unexpectedly, the error message it produced) | Life of the account and at least one year after closure, longer while a legal claim is open, then deleted by hand | The record of who did what on the account; no content, no customer details and no network address (the migration refuses such columns); each entry written once and settled once; no DELETE path in code |
| Letters to clients (site_client_notices: the account's email address, the kind of letter, a reference to what it concerned, whether it went, Resend's reference, any error, the address of the team member who sent it) | Life of the account and at least one year after closure, then deleted by hand; the letter's text is not kept | Showing what we told the client and when, and keeping one letter per event; no DELETE path in code; Resend keeps its own delivery logs |
| Requests and the conversation under each (site_requests and site_request_messages: the client's filings and answers, our replies with the address of the team member who wrote each, the time of our first response), written mandates and confirmations, and the notice of each filing and answer in the Supergence inbox | Life of the account and at least one year after closure, longer while a claim is open, then deleted by hand, the inbox notices with them | Written record of authorization; PIPA s.35(1); no DELETE path in code |
| Invoice drafts | Until the client deletes them (immediate) | DELETE /api/invoices, drafts only |
| Approved, sent, paid and void invoices and their send ledger, the issuer details kept on each at first send (business name, registration numbers, payment instructions), and the time and reason of a void | Life of the account; handed to the client in a structured format and deleted by hand on request at closure | The client's own business records; Canadian tax law's six-year rule is the client's obligation; no DELETE path in code for non-drafts |
| Supergence's own billing records for client fees | Six years after the end of the tax year they relate to | Income Tax Act s.230 and Excise Tax Act record-keeping |
| Sealed mailbox credentials (site_mail_accounts), with any note of a refused sign-in (our code, our reason, the time; never the provider's words) | Deleted at once on Disconnect; otherwise until account closure, then by hand. A refusal note is removed at the next good sign-in, replaced by a newer one, or cleared on reconnection | The connection the client asked for; the disconnect route deletes the row and, for Gmail only, asks Google to revoke the grant (no revoke for Microsoft or an app password) |
| Mailbox contents | Not stored; read live for each request | No message table exists |
| Advertising account grants (site_channel_connections) | Deleted at once on Disconnect after best-effort revoke (Google, Meta); an expired grant is marked expired and kept until disconnect; at closure by hand | The connection the client asked for |
| OAuth consent records (site_oauth_states: nonce, email, expiry) | Ten-minute validity; rows removed only when the migration script's sweep is run by hand; automatic sweep being built | Replay protection |
| Sign-in acceptance records (site_consents: email, document, version, time) | Life of the account and at least one year after closure, longer while a legal claim is open, then deleted by hand | Evidence of the Terms agreed to and the policy version shown; written once per version; no network address or device detail; no DELETE path in code |
| Studio runs never drawn, failed, refused or cancelled | Until the client deletes them (immediate) | DELETE /api/marketing/creative, uncharged rows only |
| Drawn frames, clips and approved studio runs (rows) | Life of the account | A drawn frame is a record of what was seen and approved; daily-cap accounting |
| Artwork and clip files in the private ad-creatives bucket | Not deleted by code; deleted by hand on request | No storage object DELETE exists in code |
| Reference photographs (once accepted) | Marked deleted on request (soft delete); file removed by hand | Soft delete only in code; feature off today |
| Signed links to artwork | One hour | Signed URL expiry |
| Assistant conversations | Server: nothing beyond the request. Browser: last 40 messages until cleared. Anthropic: deleted within 30 days, up to two years if flagged for a usage policy violation | Chat route keeps no transcript; the workspace's browser storage holds the last 40 messages; Anthropic published retention |
| Client website read cache and liveness check | One hour and five minutes respectively, in server memory | sitecontext and reality caches |
| Visit counts on a client's website (site_insight_daily), once switched on | Not automatically deleted today; automatic deletion being built, period to be stated before the first count is written | Dark today (no insight key generator); no TTL in code |
| Voice demonstration audio and text | Nothing at Supergence; ElevenLabs' own retention | Browser-to-ElevenLabs stream; no Supergence server in the path |
| Page counts, counted presses and function logs | Vercel's own retention | Not controlled in code |
| Call records (site_phone_calls: caller and called numbers, times, transcript as turns, summary, caller name and callback number, the text sent to a caller the line could not help) | While the account is open; deleted by hand on request; no DELETE path in code yet, an automatic path being built. Disconnecting the line puts the number back to where its calls went before, then deletes the site_phone_lines row (sealed credential, number) at once and leaves the call records | The record of what a caller asked and what the line said, for the client's follow-up; no audio exists (scripts/site-phone-tables.ts refuses a recording column; no Record verb in the TwiML) |
| Texts sent to the phone line (site_phone_messages: sender's number, number texted, words up to 1,600 characters, time, how many pictures came with it, the call it followed, whether the client marked it handled) | While the account is open, including after the line is disconnected or changed; deleted by hand on request; no DELETE path in code yet, an automatic path being built. Twilio keeps its own copy, with any picture, in its message log | So the client's team can answer the caller; no picture is fetched or kept (the migration refuses a media, audio or recording column) |
| Requests not to be texted, and to be texted again (STOP, ARRÊT, START and the like, kept in site_phone_messages with the number, the word as typed and the time) | Life of the account, whatever happens to its line, and not deleted when other texts are deleted on request; deleted by hand after the account closes | What stops the line texting a number that asked it not to; read for the account and the number before any text leaves; no DELETE path in code |
| Privacy requests, complaints and confidentiality incident records | Five years from the day the incident was learned of or the request closed | PIPEDA s.10.3 and SOR/2018-64 s.6 (24 months); Québec Regulation A-2.1, r. 3.1 s.8 (five years) |
| Business contact information used for outreach | Until the person says stop; then only a suppression entry (site_suppressions: the address, the date, and how the request arrived), kept for as long as we contact businesses so the request goes on being honoured | CASL s.6 and s.11; Québec s.22 |