Privacy Policy
Last updated 2026-09-11 · Discovo · United States
This privacy policy has been compiled to better serve those who are concerned with how their "Personally Identifiable Information" (PII) is being used online. PII, as used in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read this policy carefully to get a clear understanding of how we collect, use, protect and otherwise handle your Personally Identifiable Information.
Who this policy covers
Discovo has two kinds of people in it, and they are treated differently.
Clients are the businesses who hold an account with us and install an agent on their website. Visitors are the people who encounter that agent on a Client's website. A Visitor is not our customer and usually has no account with us.
Information we collect
From Clients, when registering or subscribing, we collect your name, email address, an optional profile photo, and the business information you choose to give your agent. Payment card details are collected by Stripe and are never received or stored by us.
From Visitors, we collect an anonymous session handle, the domain the agent was used on, the time of use, and the text of the request they typed. Where the Read Screen capability is enabled by the Client, we also transmit an image of the Visitor's current viewport for interpretation.
A Visitor may optionally create a Discovo profile, in which case we hold their name and email address as well.
How we use your information
We use the information we collect in the following ways:
- To operate the cursor agent and answer the requests a Visitor makes of it.
- To show a Client analytics about how their agent is used: how many times, on which domains, and at what times.
- To let a Client read and reply to conversations their Visitors chose to save.
- To process subscription payments and send receipts and service notices.
- To respond to support enquiries.
What we do not do
We do not sell, rent or trade Client or Visitor personal information.
We do not use Visitor data to build advertising or behavioural profiles, we do not operate an ad network, and we do not run third-party advertising trackers on the dashboard.
We do not send SMS or text messages, and we therefore hold no mobile opt-in data or messaging consent of any kind.
Visitor request history
A Visitor's own record of what they have asked on a site is encrypted in their browser, under a key generated there and held in that site's localStorage. The key is never transmitted to us.
We store, return and delete that ciphertext without being able to read it. What the stored row does contain is the agent, the domain and the time, which is what a Client's usage analytics counts.
The consequence is worth stating plainly: if a Visitor clears that browser's storage, the key goes with it and those entries become unreadable to everyone, including the Visitor who wrote them. That is the cost of us not holding a key.
How we protect visitor information
Every table in our database enforces row-level security, so an account can read and write only the data it owns.
Credentials capable of bypassing those protections exist only on our servers and are never sent to a browser. No model provider API key is ever present in the embed or in any page the embed runs on.
Data is transmitted over TLS. We do not claim PCI scanning or malware scanning; card data does not reach our systems, and is handled by Stripe.
Cookies
Cookies are small files that a site transfers to your device through your web browser, enabling the site to recognise your browser and remember certain information. We use them as follows:
- A first-party session cookie on the Discovo dashboard, to keep a Client signed in.
- A first-party preference cookie, to remember a Client's light or dark theme choice.
- No advertising cookies, and no third-party tracking cookies.
Third party disclosure
We do not sell, trade, or otherwise transfer your personally identifiable information to outside parties. This does not include the processors who assist us in operating the service, so long as those parties agree to keep this information confidential, nor does it include release where we believe release is appropriate to comply with the law, enforce our policies, or protect the rights, property or safety of ourselves or others.
The processors we use are Supabase, for authentication, database and file storage; Stripe, for subscription payments; and a third-party vision model provider, for interpreting a request and, where enabled, a viewport image. An image sent for interpretation is used transiently to produce a response.
Third party links
Occasionally we may include or offer third party products or services on our website, and an agent may direct a Visitor to a page on a third party website. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.
CalOPPA
According to CalOPPA we agree to the following:
- Users can visit our site anonymously.
- A link to this privacy policy appears in the footer of our home page and in the dashboard.
- Our Privacy Policy link includes the word "Privacy" and can easily be found on the page specified above.
- Users will be notified of any privacy policy changes on this Privacy Policy page.
- Users are able to change their personal information by signing in and editing their profile.
- We do not allow third-party behavioural tracking.
COPPA (Children's Online Privacy Protection Act)
When it comes to the collection of personal information from children under 13, COPPA puts parents in control. The Federal Trade Commission enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children's privacy and safety online.
We do not market to children under 13 and do not knowingly collect personal information from them. A Client is responsible for their own compliance where they install an agent on a site directed to children.
Fair Information Practices
The Fair Information Practices Principles form the backbone of privacy law in the United States. In order to be in line with Fair Information Practices, we will take the following responsive action should a data breach occur: we will notify affected Clients by email within 14 business days, and will notify Visitors through the affected Client where we do not hold a means of contacting them directly.
We also agree to the individual redress principle, which requires that individuals have a right to pursue legally enforceable rights against data collectors and processors who fail to adhere to the law, including recourse to courts or a government agency.
CAN-SPAM Act
We collect your email address in order to:
- Send information, respond to enquiries, and answer other requests or questions.
- Send service notices, receipts, and information about your subscription.
- Send occasional product updates to Clients who have not opted out.
To be in accordance with CAN-SPAM we agree to
- Not use false or misleading subjects or email addresses.
- Identify any marketing message as an advertisement in a reasonable way.
- Include the physical address of our business.
- Monitor any third party email marketing service we use for compliance.
- Honour opt-out and unsubscribe requests quickly.
- Allow users to unsubscribe using the link at the bottom of each marketing email.
Retention and deletion
Deleting your account from Settings removes your Client data (profile, agents and configuration) and cascades to the data attached to them.
Visitor sessions are pruned automatically after a period of inactivity. A Visitor can erase their own request history at any time from the profile panel in the embed.
If at any time you would like to unsubscribe from future emails, or to request deletion of data we hold about you, email support@discovo.app and we will act on it promptly.
Contacting us
If there are any questions regarding this privacy policy you may contact us using the information below.
Discovo United States support@discovo.app