Privacy Policy
Last updated: July 26, 2026
This Privacy Policy explains how Supovia LLC (Supovia, we, us, or our) processes personal information when you use Supovia's website, applications, APIs, customer-support tools, and Model Context Protocol (MCP) integrations (collectively, the Service). Supovia LLC is responsible for the account, website, and service data described in this policy.
Organizations also use Supovia to communicate with their own customers. Those organizations decide why they collect and use customer-support content. If you are an organization's customer, its privacy notice also applies, and you should normally direct requests about that content to the organization.
Information we process
We process information that you, your organization, its customers, connected services, and authorized AI clients provide, including:
- Account and organization information: name, email address, phone number, avatar, language, country, organization, role, subscription, and billing-status information.
- Workspace and configuration information: website names and domains, agent settings, support documents, campaign metadata, team settings, channel connections, phone configuration, and integration identifiers.
- Customer-support content: customer names, contact details and user identifiers; conversation status and channel; messages, attachments, and internal notes; campaign recipient data; and, when voice features are enabled, call metadata, recordings, transcripts, and summaries.
- MCP and connected-client data: the authenticated user, organization, granted OAuth scopes, requested tool and arguments, information returned by the authorized tool, and the result of an approved action.
- Technical, security, and usage information: IP address, browser and device information, session and request timestamps, referring page and marketing-attribution information, cookie identifiers, feature usage, diagnostics, and error information.
Please provide only information that you are authorized to place in Supovia. You must not use the ChatGPT MCP integration to collect, submit, retrieve, or otherwise process payment-card data, protected health information, government identifiers, passwords, API keys, authentication codes, or other restricted credentials.
How and why we use information
We use information to:
- create and secure accounts, authenticate users, enforce organization boundaries, and manage permissions;
- provide the requested customer-support workspace, route communications, display conversation history, operate campaigns and support documents, and provide enabled AI and voice features;
- answer authorized MCP requests and perform approved actions, such as sending a message or resolving or reopening a conversation;
- provide customer support, troubleshoot errors, prevent fraud and abuse, and protect Supovia, its users, and others;
- understand and improve the Service using limited usage information and aggregated or de-identified information; and
- process billing, comply with legal obligations, resolve disputes, and enforce our agreements.
Depending on where you live, our legal bases include performing our contract with you, your consent, compliance with law, and our legitimate interests in operating, securing, supporting, and improving the Service where those interests are not overridden by your rights.
ChatGPT and other MCP clients
When you connect Supovia to ChatGPT or another MCP client, you authorize that client through OAuth. Supovia supports separate read and write scopes. Read access can return tenant-scoped website information, conversation status and aggregate activity, support documents, campaign metadata, and related results. Read tools do not return message bodies, previews, or message IDs. Write access can send the exact customer message you approve or change whether a conversation is resolved. The exact result depends on the tool you ask the client to use and the scopes you approve.
Supovia's embedded inbox and conversation views receive only safe status, unread, timestamp, and aggregate activity fields. They do not receive message bodies, previews, message IDs, customer details, or internal notes. Supovia does not request or reconstruct your full ChatGPT conversation; it receives the specific MCP request and information the client sends to execute it.
The connected client handles information under its own privacy terms and settings. You can disconnect Supovia from the client or revoke its authorization to prevent new access tokens and future renewal. An access token issued before revocation can remain usable until it expires, for up to one hour. Revocation does not remove information that the client received before it was disconnected.
AI, messaging, and voice providers
When an organization enables an AI agent, messaging channel, email service, phone number, or voice receptionist, Supovia sends the information needed to provide that feature to the selected provider. This can include message content and recipient details for delivery, or call audio, transcripts, prompts, and phone metadata for voice processing. The organization controls which optional connections it enables and is responsible for providing any required notice or consent to its customers.
Recipients and disclosures
We disclose information only as needed to:
- authorized users and administrators of the relevant Supovia organization;
- providers that host, store, authenticate, secure, monitor, support, analyze, and help operate the Service;
- connected AI clients and the messaging, email, telephony, voice, and other integration providers selected by the organization;
- professional advisers, regulators, courts, law enforcement, or other parties when required by law or reasonably necessary to protect rights, safety, and the Service; and
- a successor in connection with a merger, financing, reorganization, or sale of all or part of our business, subject to appropriate confidentiality protections.
Cookies and analytics
Supovia uses cookies and similar browser storage to keep the Service working, maintain sessions, remember preferences, measure usage, and record referral or campaign attribution. Supovia's attribution cookies can remain for up to one year. Analytics providers may use their own cookies or identifiers under their published privacy and retention terms. You can block or delete cookies in your browser, although some Service features may not work correctly.
Retention
- Account, workspace, customer, conversation, message, document, campaign, and voice records generally remain while the organization uses the Service. Their retention afterward depends on account status, the organization's instructions, operational and security needs, and applicable legal obligations.
- Deleting a customer removes the customer profile and associated conversations and messages from Supovia's active database. Linked voice, integration, security, or operational records may require separate handling. An eligible organization administrator can start organization-account deletion after ending any active subscription. Contact us if linked records also need to be reviewed for deletion.
- OAuth authorization records remain while the connection is active or as needed for security. Supovia MCP access tokens expire after one hour, and refresh tokens expire after 90 days.
- Temporary processing records expire when their operational purpose ends. Limited backups, security records, billing records, and legal records may remain for the provider's backup cycle or for as long as needed to investigate incidents, comply with law, resolve disputes, and enforce agreements.
We review retained information against these purposes and delete or de-identify it when it is no longer needed. MCP telemetry is limited to operational details such as the tool name, success, duration, and result size; it does not record tool arguments or result content.
Security and international processing
We use reasonable technical and organizational safeguards, including encrypted network connections, authentication, tenant-scoped authorization, access controls, and limited tool outputs. No online service can guarantee absolute security.
Supovia and its providers may process information in countries other than your own. Processing locations depend on the features and providers the organization uses. We take steps required by applicable law when information is transferred internationally.
Your controls and privacy rights
Supovia users can update profile and workspace information, delete customers and websites, delete an eligible organization account, and disconnect authorized AI clients. Depending on applicable law, you may also have rights to access, correct, delete, restrict, or receive a copy of your personal information; object to certain processing; withdraw consent; or complain to a data-protection authority.
Contact the organization that operates the relevant support channel for requests about its customer-support content. For Supovia account data or if you need our help with a request, email info@supovia.com. We may need to verify your identity and authority before completing a request.
Business use and children's data
The Service is designed for organizations, not for children to create or administer Supovia accounts. Organizations must have an appropriate legal basis and provide any required notices or consents before placing a child's information in their customer-support workspace. Do not send personal information of a child under 13 or the applicable age of digital consent through the ChatGPT MCP integration.
Changes and contact
We may update this Privacy Policy when our practices or legal obligations change. We will post the current version on this page and update the date above. For privacy questions or requests, contact Supovia LLC at info@supovia.com.