Trust
Privacy Policy
Version 2026-08-21. Effective 21 August 2026.
Privacy Policy
Version 2026-08-21. Effective 21 August 2026.
https://super.ai/trust/privacy-policy
This notice covers the super.AI website and self-service accounts on the super.AI platform.
Version 2026-08-21. Effective 21 August 2026.
This notice explains what personal data we collect on the super.AI website and in self-service accounts on the platform, what we do with it, how long we keep it, and what you can ask us to do about it. It is written to be read, so it says what happens rather than what could conceivably happen.
This page is the policy. The contract for a self-service account is the Self-Service Terms of Service, and the vendors that process data for us are listed on our sub-processor page.
1. Who we are, and how to reach us
Super.AI Inc., a Delaware corporation, is the controller of the personal data described in this policy. It is the only company behind this website, the platform and our services, and it has no affiliates. Our postal address for privacy enquiries is Super.AI Inc., 455 Market St Ste 1940 PMB 577536, San Francisco, CA 94105-2448, USA.
For anything about privacy, write to privacy@super.ai. That address reaches the person responsible for handling requests. You can write to us in English or in German.
You can complain to a data protection supervisory authority. Because we have not established a main establishment in the European Union, you may approach any supervisory authority in the European Economic Area, including the one for the place where you live or work. In the United Kingdom that authority is the Information Commissioner's Office. We would rather hear from you first, and we will answer.
This page is the policy. There is no other version of it and nothing to request by email.
2. What this policy covers, and the role we play
This policy covers our website at super.ai and the self-service super.AI platform. It describes what we do with personal data when you visit the site, when you create a self-service account, and when you use chat, documents and flows in that account.
Where we process content under a negotiated agreement with a business customer, we act as a processor on that customer's instructions. That customer's own privacy notice describes that processing. This section describes only our role and our sub-processors.
The same is true of our data labeling business: for the content our labeling customers send us, we act on their instructions and their notices describe that processing.
This policy is a notice about what we do. It is not a contract, and it does not change any agreement you or your organisation has with us. Where you use a self-service account for business purposes and the content you submit contains other people's personal data, section 16 of the Self-Service Terms of Service is the data processing agreement between us.
3. The data we collect
Super.AI Inc. (Delaware, USA) is the controller of the personal data described below. Postal address for privacy enquiries: Super.AI Inc., 455 Market St Ste 1940 PMB 577536, San Francisco, CA 94105-2448, USA. You can reach us at privacy@super.ai.
This is what we collect at or before the point of collection: the categories, what we do with each one, how long we keep it, and whether it is sold or shared. Section 11.1 explains the one thing that is shared and how to stop it, because a reader arriving at this section from a signup link would otherwise never reach that disclosure. We do not buy personal data, and we do not build profiles of you from data brokers or public sources.
| Category | What it is | Why we collect it | How long we keep it | Sold or shared? |
|---|---|---|---|---|
| Account and identity data | Email address, name, password credentials held by our authentication provider, and the organisations you belong to. | To create and operate your account and to provide the service under our contract with you. | For as long as the account exists, and then as needed to close it out. | No |
| Content you submit | Chat messages, files and documents you upload, text extracted from them, and the definitions and run records of the flows you build. | To provide the processing you asked for. Content is processed by the cloud infrastructure and cloud-hosted AI models listed on our sub-processor page. | For as long as you keep it in your account. Deleted when you delete it or when the account is deleted. | No |
| Usage and credit records | What you ran, when, and the credits it consumed. | To meter and bill the service, to enforce plan limits, and to keep accurate billing records. | For the life of the account, and afterwards for as long as tax and accounting law requires us to keep the underlying records. | No |
| Review records | The record of an automated or human review of a self-service account under section 5, including what was flagged, the verdict and the decision. | To operate the trial and to detect misuse of the free tier. | 36 months for review records. Records of a suspension episode are kept for 3 years after the episode closes. | No |
| Payment data | Billing details and transaction records. Card numbers are collected and held by our payment processor; we do not store them. | To take payment and to meet our tax and accounting obligations. | For the retention period tax and accounting law sets for those records. | No |
| Support correspondence | The messages you send us and our replies, including anything you attach. | To answer you and to keep a record of what was asked and decided. | For as long as needed to resolve the matter and to handle any follow-up. | No |
| Technical data | IP address, browser and device information, and the pages and endpoints you requested. | To serve the site and the platform, to keep them secure, and to diagnose faults. | In server and delivery logs, for a short operational window. | No |
| Cookie and consent records | Your cookie choices and the record of when you made them. | To apply your choices and to be able to show what you chose. Required by law. | For as long as the choice is stored in your browser and in our consent provider's log. | No |
| Marketing attribution identifiers (cookies) | Campaign tags and advertising click identifiers from the link you arrived on, stored in first-party cookies on your device. Collected only if you consent to marketing cookies. | To measure which campaigns produce sign-ups. See section 11.1. | 90 days from the visit, or until you withdraw consent, whichever is first. | Shared for advertising measurement |
| Marketing attribution record (your account) | If you go on to create an account, the campaign tags and click identifiers above are stored against that account, together with a one-way hash of your email address where you consented to marketing cookies. | To measure which campaigns produce sign-ups, including by reporting the conversion to the advertising platform. See section 11.1. | Kept for the life of the account and deleted when the account is deleted. Unlike the cookie, this record has no fixed expiry. | Shared for advertising measurement |
| Website analytics data | How you move through this website: pages viewed, referrer, approximate location from your IP address, and, where session analytics is running, a replay of pointer movement and clicks. Collected only if you consent to statistics cookies. | To understand which pages work. Google Analytics and Hotjar process it for us. | For the retention window configured with each provider. | No |
| Product analytics data | How you use the platform after signing in: events, pages, and session replay with all form inputs masked, so what you type is not captured. Processed by PostHog in the EU. | To understand which product features work and where people get stuck. | For the retention window configured with PostHog. | No |
| Sensitive information inside submitted content | Health information, government identifiers, racial or ethnic origin and similar information, only where it happens to be contained in a document or text you choose to submit. We do not ask for it and we do not seek it out. | It reaches us as part of the material you asked us to process, and it is used only for that. | For as long as the document that contains it, and deleted with it. | No |
| Enquiry and marketing data | What you type into a form on this site (name, work email, company, message) and your marketing preferences. | To answer your enquiry, and to send you marketing only if you asked us to. | In our CRM for as long as the relationship or enquiry is live, and until you unsubscribe for marketing. | No |
Your email address is the one thing we have to have: without it we cannot create an account, cannot enter into the contract with you and cannot provide the service. Confirming your age is required by our terms. Everything else is optional, and where a form asks for something optional it says so; not giving it costs you nothing but the feature it was for.
3.1 Sensitive information
We do not ask for sensitive personal information, and we do not use or disclose it for any purpose that would require your opt-in consent under state law. Submitting special category personal data is prohibited on the free tier, and that rule is section 6.3 of the terms. What can still reach us is whatever a document you choose to submit happens to contain: health information, government identifiers such as passport, licence or national insurance numbers, racial or ethnic origin, and other information the law treats as sensitive. We process it only to provide the processing you asked for, we keep it for as long as the document that contains it and delete it with that document, we do not infer sensitive characteristics from it, and we disclose it to nobody other than the sub-processors that operate the service. Health-related information is covered separately in our Consumer Health Data Privacy Notice.
3.2 Age
The service is for people aged 18 and over. We ask for your date of birth at signup, we use it only to check that you are 18 or over, and we do not keep it: what we store is the fact that the check passed and when. Section 15 says what happens if we learn that an account holder is under 18.
4. Why we use it, on what legal basis, and for how long
The table below sets out each purpose, whether we act as a controller or as a processor for it, the lawful basis we rely on, and how long the data is kept. Where we rely on legitimate interests we have weighed them against your rights, and you can ask us for that assessment.
| What we do | Our role | Lawful basis | How long |
|---|---|---|---|
| Providing the service | Controller | Performance of our contract with you | For the life of the account, then the windows in section 8.3 of the terms |
| Operating the trial, including recommending an account for continued free use (self-service accounts only) | Controller | Our legitimate interests in offering a free trial we can afford to run | Review records: 36 months |
| Detecting misuse and breaches of the acceptable use rules (self-service accounts only) | Controller | Our legitimate interests in keeping the service lawful and safe, and the conditions described in section 5 where special category data is involved | Suspension episode records: 3 years after the episode closes |
| Analysing trials and conversions to understand how the product is adopted (self-service accounts only) | Controller | Our legitimate interests in understanding our own funnel. This is the basis that supports the 36-month review-record retention, and it is not the same thing as the consent-based product analytics below | 36 months |
| Product analytics on the website and in the product | Controller | Your consent | Until you withdraw consent |
| Measuring advertising, by reporting conversions to Google | Joint controller with Google | Your consent | 90 days from the visit, or until you withdraw consent |
| Keeping the service secure and available, and preventing fraud | Controller | Our legitimate interests, and our legal obligation to keep the service secure | A short operational window in logs |
| Billing, tax and accounting | Controller | Performance of our contract, and our legal obligations | As long as tax and accounting law requires |
| Answering support requests | Controller | Performance of our contract, and our legitimate interests where you are not a customer | As long as needed to resolve the matter |
| Sending marketing emails, including about the end of a trial | Controller | Your consent, given at signup or later | Until you unsubscribe |
| Meeting legal obligations and defending legal claims | Controller | Our legal obligations, and our legitimate interests in defending claims | 3 years after the matter closes, which is the German general limitation period, and longer where a law requires it |
Retention periods are periods, not exemptions. Where we keep a record of a suspension episode after the account is gone, we keep it because we may need it to establish, exercise or defend a legal claim, and we keep it for three years after the episode closes rather than indefinitely.
5. The analysis we carry out on self-service accounts
This section applies to self-service accounts only. Accounts under a negotiated agreement are not analysed in the way described here.
An AI model reads the messages you send in chat and the names of the files you upload. It does not read the contents of the documents you upload for this purpose. It does two things: it identifies accounts that look like a good fit for continued free use, and it flags possible breaches of the acceptable use rules in section 6 of the terms.
A person decides every recommendation about continued free use. Nothing about your free-tier request is decided by a machine alone.
Automatic suspension applies to the illegal-use category only. A person reviews every automatic suspension within the window stated in the notice we send, and an unconfirmed suspension is lifted automatically when that window expires. Anything that is prohibited by our terms but not unlawful, including sexually explicit content, is decided by a person before any restriction takes effect.
The logic differs between the two purposes. For continued free use, a model summarises how the account is being used and produces a recommendation, with no confidence threshold applied and no automated consequence. For misuse, a classification model returns a verdict with a confidence score, and a restriction follows only above a set threshold. The possible consequences are a recommendation about continued free use, a restriction on what the account can do, a suspension, or termination. We tell you which clause we relied on and how to contest the decision, and you can ask for a person to look at it again. We may also run this analysis on our own initiative, or as part of a batch review of accounts, rather than only in reaction to something you did.
5.1 Special category data
Special category data can arise here in two ways: inside content a user chooses to submit, and in a verdict about a user, since a stored finding that someone produces sexual content is itself data about their sex life. We keep those verdicts to the minimum, we restrict access to them, and we rely on the substantial public interest in detecting and preventing unlawful acts, and, where we need the record to establish, exercise or defend legal claims, on that condition. Submitting special category data on the free tier is prohibited in the first place: see section 6.3 of the terms.
6. Your right to object to this analysis
7. AI model providers, and what happens to your content
The service runs models from Anthropic, OpenAI and others, hosted for us by Google Cloud (Vertex AI) and Microsoft Azure; Fireworks AI is a direct provider. The model makers are named here because that is the question people actually ask; the parties that process your content are the cloud providers, and each one is listed with its location and transfer mechanism on our sub-processor page.
We do not use your content to train AI models for general use or for other customers. At your request, we can fine-tune models solely for your own use. This statement is about self-service accounts; content under a negotiated agreement is governed by that agreement.
Our AI processors are contractually prohibited from training any model on your content.
Microsoft may retain prompts sent to Azure OpenAI for up to 30 days for abuse monitoring, and that monitoring can include review by a person at Microsoft. We tell you because it is true and because you cannot see it from the outside.
By default, model processing is not restricted to one region: it takes place in the regions listed on the sub-processor page, which include regions outside the European Economic Area. An organisation can restrict model processing to the EU in its settings in the product, and that setting is the organisation's instruction to us about where processing takes place. The model that runs the analysis in section 5 is processed in the EU regardless of that setting.
8. International transfers and government access
We are a US company, and some of our sub-processors are in the United States. Where personal data leaves the European Economic Area or the United Kingdom, we rely on the European Commission's standard contractual clauses, or on the EU-US Data Privacy Framework where the recipient organisation is certified under it. The mechanism for each sub-processor is stated on our sub-processor page, and you can ask us for the transfer impact assessment behind it.
Being a US company has a consequence worth stating plainly: US law, including the CLOUD Act, can in principle require a US company to produce data it controls, wherever that data is stored. We think you should know that from us rather than discover it.
Requests from law enforcement go to legal@super.ai. We check that a request is valid and properly served, we produce the narrowest set of data that answers it, we do not hand over content without legal process that requires it, and where a request concerns a customer we tell that customer unless we are legally prohibited from doing so or there is a risk to someone's life. Where the data belongs to a business customer we direct the requester to that customer wherever we can.
9. People named in the content you submit
Documents and text submitted to the service often name other people: an invoice names a customer, a contract names signatories, an email thread names its participants. For the processing our customers instruct us to do, those people's data is handled under our customer's own notice. For the analysis in section 5, which is our own purpose, we are the controller, and this section is the information those people are owed.
The source is always the account holder who submitted the material. We do not obtain it from anywhere else: not from data brokers, not from public sources, and not by enrichment. What we hold about them is whatever the submitted material contains. We do not use it to build a profile of them, and we do not use it to contact them. It is kept for as long as the account holder keeps the material, and the review records are kept for the periods in section 4.
We cannot write to each of those people individually: we usually have no reliable contact details for them, and writing to them would mean processing more of their data than we already hold. Publishing this section is how we make the information available instead. If you believe your data is inside material someone has submitted, write to privacy@super.ai and we will help you exercise your rights, including asking the account holder to act.
10. Organisations and their members
An account can belong to an organisation with several members. For what members do inside their organisation's workspace, and for the content they put there, the organisation is the controller and we act as its processor. Administrators of an organisation can see its content and its usage records.
Our own analysis under section 5 looks at each user's own messages and file names, and the right to object in section 6 belongs to the individual, not to the organisation.
Enforcement can have effects beyond the person who caused it: entitlements and content sit at the organisation level, so a measure triggered by one member can affect the organisation and its other members. When we suspend an organisation we notify its members.
12. Measuring advertising with Google
When you arrive from an advertisement and later create an account, we report that conversion to Google, together with the advertising click identifier from your visit and a one-way hash of your email address, which Google uses to match the conversion. Only with your consent to marketing cookies.
For that measurement we and Google Ireland Limited are joint controllers, and we have an arrangement between us that allocates our responsibilities. In essence: we decide to run the measurement and are responsible for collecting your consent, for giving you this information, and for handling requests you make to us; Google is responsible for the processing inside its own systems, for the security of it, and for the information and rights it owes you as a controller in its own right. Whichever of us you contact, you can exercise your rights against both of us, and we will point you to Google where its systems hold the answer.
Withdrawing consent stops it. Sections 11.1 and 11.3 give three ways to do that.
13. The UK and other countries
United Kingdom: the UK GDPR applies to our processing of UK residents' data, you have the same rights as described in section 16, and you can complain to the Information Commissioner's Office.
- Brazil: the LGPD applies where we offer the service to people in Brazil, and requests reach the same address as everything else in this policy.
- Switzerland: the revised Federal Act on Data Protection applies, and Swiss residents can complain to the Federal Data Protection and Information Commissioner.
- Canada: PIPEDA applies, including its breach reporting rules.
- Australia: the Privacy Act and the Notifiable Data Breaches scheme apply.
- Quebec: Law 25 gives a right to have an automated decision reviewed by a person. We give that right to everyone rather than only in Quebec, which is the same safeguard as section 5 describes.
15. Children
The service is for people aged 18 and over. It is not directed at children and we do not knowingly collect data from them.
If we learn that an account holder is under 18, we close the account and delete the data associated with it, including anything the account submitted. If you believe a child has created an account, tell us at privacy@super.ai and we will act.
16. Your rights under the GDPR and UK GDPR
You can ask us for a copy of your personal data, ask us to correct it or delete it, ask us to restrict how we use it, object to processing based on our legitimate interests, including the analysis in section 5, ask for your data in a portable form, and withdraw a consent you have given at any time. Withdrawing consent does not affect what we did lawfully before you withdrew it.
Write to privacy@super.ai. We answer within one month and tell you inside that month if we need longer. There is no fee.
One limit worth stating: where an account is under investigation for illegal use, access to the records of that investigation may be restricted, case by case, to the extent the law requires or permits, because handing over the evidence would defeat the investigation and can prejudice someone else's rights. We assess it individually rather than as a blanket rule, and we tell you when we rely on it.
You can also complain to a supervisory authority: see section 1.
17. Marketing
We send marketing email only if you asked us to, and asking is optional: the checkbox at signup is unticked and leaving it unticked does not affect your account. Every marketing email has an unsubscribe link, and you can also write to us.
That includes email about the end of your trial and about upgrading. A free trial is not a purchase, so we do not treat you as an existing customer for the purposes of the exception German law makes for those, and we rely on your consent instead.
Service email is different: messages about your account, security, billing and changes to these documents are part of providing the service and are not marketing.
Questions about this policy, or a request about your data? Contact us or email privacy@super.ai.