AskHelper AI

Effective: July 15, 2026

Privacy Policy

How AskHelper AI collects, uses, shares, retains, and deletes personal data across our website, dashboard, and embedded widget.

1. Operator, scope, and roles

AskHelper AI is operated by IE FEDOSEENKO N.A., TIN 20266459, Nikoghayos Adonts Street 4/3, Apt. 42, Yerevan 0014, Armenia. Contact: support@askhelper-ai.com, +374 77 828 236. This Policy covers our website, accounts, dashboard, and widget. We determine purposes for account, billing, security, and our own operations. For visitor data processed through a customer website, the customer is normally the controller and we act as its processor under the DPA.

2. Data and sources

We receive data from users and customers, visitors through the widget, Paddle, and technical providers. It may include account/Auth email, name, organization membership and role; project settings, domains, widget-key hashes, and encrypted BYOK keys; private knowledge-base originals, extracted text, chunks, and embeddings; visitor identifiers, name, email, and customer-supplied metadata; messages, history, sources, model, and ratings; subscription and usage records; raw Paddle webhook events; audit records; and network or diagnostic data. IP addresses used for abuse counters may be HMAC-transformed into pseudonymous values.

3. Purposes and legal bases

We process data to create and protect accounts; provide, configure, and support the service; index knowledge bases and generate answers; show history and analytics; enforce plan limits; administer subscriptions and support; prevent abuse; comply with law; and protect rights. Depending on context, the basis is contract performance, legitimate interests in operating and securing the service, legal obligation, or consent where required. The customer determines the applicable basis and instructions for widget visitor data.

4. Providers and recipients

We disclose only what is necessary to: Supabase for database, Auth, and Storage; Vercel for hosting, runtime, logs, and network metadata; Jina AI for knowledge-base and query embeddings; OpenRouter and the selected model for prompts containing messages, relevant history, instructions, and retrieved excerpts; Resend for transactional email; Forward Email and Google for support communications; and Telegram for optional operational alerts only when enabled. Paddle is Merchant of Record and an independent controller for checkout, payments, taxes, and billing; we retain necessary order and subscription webhook data to provide the service. Data may also be disclosed to advisers, a successor, or authorities where lawfully required.

5. International transfers

Providers and their infrastructure may process data in different countries. Where applicable law requires transfer safeguards, we or the customer, according to our role, will use an available lawful mechanism and assess appropriate supplementary measures. We do not promise Armenia-only or EEA-only storage.

6. Retention and deletion

We retain data while an account is active or as needed for the purposes above. Timing depends on data type, plan settings, customer instructions, and law. Workspace deletion removes or de-identifies active tenant data, Auth, and stored files, but limited accounting, payment, audit, fraud-prevention, security, dispute, or legal records may remain as reasonably required. Provider backups and logs expire through their ordinary cycles. We do not promise instant deletion from every backup.

7. Security

We use proportionate measures including tenant scoping and access controls, hashed widget keys in the database, server-side encryption of BYOK keys, HttpOnly authentication cookies, widget domain allowlists, server-only secrets, audit records, and abuse controls. No transmission or storage method is absolutely secure. Customers remain responsible for their accounts, domains, content, and instructions.

8. Your rights and requests

Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent without retroactive effect. Contact support@askhelper-ai.com; we may verify identity and authority. Widget visitors should normally contact the website owner first because it controls their data; we assist customers with verified requests. You may complain to a competent data-protection authority.

9. Workspace controls

Only the workspace owner can initiate deletion of the entire workspace; other members should contact the owner or support. Available exports exclude secrets, encrypted keys, and raw internal Paddle events. Deletion remains subject to the limited retention, backup, and log qualifications above. Export needed data before deletion.

10. Customer duties and children

Customers are responsible for lawful visitor data and content, their own website notices and consents, data-subject responses, metadata configuration, and avoiding unnecessary sensitive data. The service is not directed to children and must not be intentionally used to collect children's data without an appropriate legal basis and permissions. Contact us if you believe a child's data was submitted improperly.

11. Changes and contact

We may update this Policy as the service, providers, or law changes. Material changes will carry a new date and, where reasonable or required, notice through the service or email. Privacy requests: support@askhelper-ai.com or +374 77 828 236.