Discovo
← Back

Privacy Policy

Last updated 2026-09-11 · Discovo · United States

This privacy policy has been compiled to better serve those who are concerned with how their "Personally Identifiable Information" (PII) is being used online. PII, as used in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read this policy carefully to get a clear understanding of how we collect, use, protect and otherwise handle your Personally Identifiable Information.

Who this policy covers

Discovo has two kinds of people in it, and they are treated differently.

Clients are the businesses who hold an account with us and install an agent on their website. Visitors are the people who encounter that agent on a Client's website. A Visitor is not our customer and usually has no account with us.

Information we collect

From Clients, when registering or subscribing, we collect your name, email address, an optional profile photo, and the business information you choose to give your agent. Payment card details are collected by Stripe and are never received or stored by us.

From Visitors, we collect an anonymous session handle, the domain the agent was used on, the time of use, and the text of the request they typed. Where the Read Screen capability is enabled by the Client, we also transmit an image of the Visitor's current viewport for interpretation.

A Visitor may optionally create a Discovo profile, in which case we hold their name and email address as well.

How we use your information

We use the information we collect in the following ways:

What we do not do

We do not sell, rent or trade Client or Visitor personal information.

We do not use Visitor data to build advertising or behavioural profiles, we do not operate an ad network, and we do not run third-party advertising trackers on the dashboard.

We do not send SMS or text messages, and we therefore hold no mobile opt-in data or messaging consent of any kind.

Visitor request history

A Visitor's own record of what they have asked on a site is encrypted in their browser, under a key generated there and held in that site's localStorage. The key is never transmitted to us.

We store, return and delete that ciphertext without being able to read it. What the stored row does contain is the agent, the domain and the time, which is what a Client's usage analytics counts.

The consequence is worth stating plainly: if a Visitor clears that browser's storage, the key goes with it and those entries become unreadable to everyone, including the Visitor who wrote them. That is the cost of us not holding a key.

How we protect visitor information

Every table in our database enforces row-level security, so an account can read and write only the data it owns.

Credentials capable of bypassing those protections exist only on our servers and are never sent to a browser. No model provider API key is ever present in the embed or in any page the embed runs on.

Data is transmitted over TLS. We do not claim PCI scanning or malware scanning; card data does not reach our systems, and is handled by Stripe.

Cookies

Cookies are small files that a site transfers to your device through your web browser, enabling the site to recognise your browser and remember certain information. We use them as follows:

Third party disclosure

We do not sell, trade, or otherwise transfer your personally identifiable information to outside parties. This does not include the processors who assist us in operating the service, so long as those parties agree to keep this information confidential, nor does it include release where we believe release is appropriate to comply with the law, enforce our policies, or protect the rights, property or safety of ourselves or others.

The processors we use are Supabase, for authentication, database and file storage; Stripe, for subscription payments; and a third-party vision model provider, for interpreting a request and, where enabled, a viewport image. An image sent for interpretation is used transiently to produce a response.

Third party links

Occasionally we may include or offer third party products or services on our website, and an agent may direct a Visitor to a page on a third party website. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.

CalOPPA

According to CalOPPA we agree to the following:

COPPA (Children's Online Privacy Protection Act)

When it comes to the collection of personal information from children under 13, COPPA puts parents in control. The Federal Trade Commission enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children's privacy and safety online.

We do not market to children under 13 and do not knowingly collect personal information from them. A Client is responsible for their own compliance where they install an agent on a site directed to children.

Fair Information Practices

The Fair Information Practices Principles form the backbone of privacy law in the United States. In order to be in line with Fair Information Practices, we will take the following responsive action should a data breach occur: we will notify affected Clients by email within 14 business days, and will notify Visitors through the affected Client where we do not hold a means of contacting them directly.

We also agree to the individual redress principle, which requires that individuals have a right to pursue legally enforceable rights against data collectors and processors who fail to adhere to the law, including recourse to courts or a government agency.

CAN-SPAM Act

We collect your email address in order to:

To be in accordance with CAN-SPAM we agree to

Retention and deletion

Deleting your account from Settings removes your Client data (profile, agents and configuration) and cascades to the data attached to them.

Visitor sessions are pruned automatically after a period of inactivity. A Visitor can erase their own request history at any time from the profile panel in the embed.

If at any time you would like to unsubscribe from future emails, or to request deletion of data we hold about you, email support@discovo.app and we will act on it promptly.

Contacting us

If there are any questions regarding this privacy policy you may contact us using the information below.

Discovo United States support@discovo.app