Back to Home

Privacy Policy

Last updated: January 9, 2026

1. Introduction

LeadOp Studio ("we", "us", "our", or "Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered customer communication platform. Please read this Privacy Policy carefully. By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address (for authentication via Supabase)
  • Phone number (for verification via Twilio Verify)
  • Account creation and last login timestamps

2.2 Company Information

When you set up a company profile, we collect:

  • Company name
  • Website URL
  • Company description
  • Company facts and information used for AI training

2.3 Communication Data

We collect and store messages and conversations from:

  • SMS Messages: Phone numbers, message content, timestamps, and message direction (inbound/outbound) via Twilio
  • WhatsApp Messages: Phone numbers, message content, message types, timestamps, and conversation IDs via Kapso
  • Widget Messages: Messages sent through web widgets, session IDs, and timestamps

2.4 AI Training Data

We collect Q&A pairs and company-specific information that you provide to train and configure the AI system for your company's use cases (lead qualification, customer support, FAQ, appointment scheduling).

2.5 Integration Credentials

We securely store (encrypted via Supabase Vault):

  • Twilio Account SID, Auth Token, and phone numbers
  • Kapso customer IDs and connection information

2.6 Widget Analytics

We collect widget usage data including:

  • Total widget visits
  • Engaged visits (visits where users interacted with the widget)
  • Session IDs for conversation tracking

2.7 Usage and Analytics Data

We collect analytics data including:

  • Message counts and trends
  • Channel usage (SMS, WhatsApp, Widget)
  • AI settings and configurations
  • Feature usage patterns

2.8 Technical Data

We automatically collect certain technical information:

  • IP addresses
  • Browser type and version
  • Device information
  • Log data and error reports

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: To provide, maintain, and improve our Service
  • Authentication: To authenticate users and manage accounts
  • Communication: To process and deliver messages via SMS, WhatsApp, and widgets
  • AI Processing: To generate AI-powered responses using Groq based on your company data and Q&A pairs
  • Integration Management: To manage third-party integrations (Twilio, Kapso)
  • Analytics: To provide analytics and reporting on message activity and usage
  • Customer Support: To respond to your inquiries and provide technical support
  • Security: To detect, prevent, and address technical issues and security threats
  • Compliance: To comply with legal obligations and enforce our Terms of Service

4. Data Storage and Security

Your data is stored and processed using:

  • Supabase: Database and authentication services with Row Level Security (RLS) policies
  • Encryption: Sensitive data (API keys, credentials) is encrypted using Supabase Vault
  • Access Controls: Data is scoped by company_id with RLS policies ensuring users can only access their own company data
  • Secure Transmission: All data transmission is encrypted using HTTPS/TLS

While we implement industry-standard security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

5. Third-Party Services and Data Sharing

We share data with the following third-party services to provide our Service:

5.1 Supabase

We use Supabase for database storage, authentication, and real-time features. Your account information, company data, messages, and configurations are stored on Supabase's infrastructure. See Supabase's Privacy Policy for details.

5.2 Twilio

We use Twilio for SMS messaging and phone verification. Phone numbers and SMS message content are shared with Twilio to deliver messages. See Twilio's Privacy Policy for details.

5.3 Kapso

We use Kapso for WhatsApp messaging. Phone numbers and WhatsApp message content are shared with Kapso to deliver messages. See Kapso's Privacy Policy for details.

5.4 Groq

We use Groq for AI-powered conversation processing. Message content and company context may be sent to Groq to generate responses. See Groq's Privacy Policy for details.

5.5 Other Sharing

We may share your information:

  • When required by law or to respond to legal process
  • To protect our rights, privacy, safety, or property
  • In connection with a merger, acquisition, or sale of assets (with notice to users)
  • With your explicit consent

6. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. Specifically:

  • Account Data: Retained while your account is active and for a reasonable period after account deletion
  • Messages: Retained to provide conversation history and analytics
  • Analytics Data: Retained for reporting and service improvement purposes

You may request deletion of your data at any time by contacting us or using account deletion features if available. Some data may be retained for legal or legitimate business purposes.

7. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request access to your personal information
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request a copy of your data in a portable format
  • Opt-out: Opt out of certain data processing activities
  • Account Management: Update or delete your account through the Service dashboard

To exercise these rights, please contact us through the Service or using the contact information in your account dashboard.

8. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us, and we will take steps to delete such information.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using our Service, you consent to the transfer of your information to these countries.

10. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:

  • The right to know what personal information is collected, used, shared, or sold
  • The right to delete personal information held by us
  • The right to opt-out of the sale of personal information (we do not sell personal information)
  • The right to non-discrimination for exercising your privacy rights

11. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including:

  • The right to access your personal data
  • The right to rectification of inaccurate data
  • The right to erasure ("right to be forgotten")
  • The right to restrict processing
  • The right to data portability
  • The right to object to processing
  • Rights related to automated decision-making

Our legal basis for processing your data includes: consent, contract performance, legal obligations, and legitimate interests.

12. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Maintain your session and authentication state
  • Remember your preferences
  • Analyze Service usage and performance

You can control cookies through your browser settings. However, disabling cookies may affect the functionality of the Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Material changes will be communicated through the Service or via email. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through the Service or at the contact information provided in your account dashboard.

For data protection inquiries, you may also contact your local data protection authority.

15. Related Policies

This Privacy Policy should be read in conjunction with our Terms of Service. By using our Service, you agree to both this Privacy Policy and our Terms of Service.