Last updated: 23 September 2026.
Core data flows
Account and workspace data
Supabase provides the primary database, authentication, realtime services, and Edge Functions. Records can include users, workspaces, permissions, contacts, messages, configuration, and operational metadata.
Files
Uploaded chat and workspace files can be stored in Cloudflare R2 or Supabase storage. File names, MIME types, ownership, and access metadata are stored with the service.
AI text and knowledge
When AI features are enabled, relevant instructions, customer messages, conversation context, website/help content, and embeddings may be sent to OpenAI to generate answers, translations, summaries, or indexes.
Voice and avatars
When enabled, Vapi coordinates voice calls; ElevenLabs may process text or voice samples; Simli may process avatar inputs. Call metadata, transcripts, audio, and provider identifiers can be generated depending on configuration.
Email and connected channels
Resend handles selected transactional email. Google/Gmail/Calendar, Meta/WhatsApp, Telegram, and Slack process data only when the customer connects or uses those channels.
Payments and delivery
Stripe processes billing and payment data. Cloudflare serves application and website traffic. GitLab stores source code and CI artifacts; it is not the primary customer-content database.
Customer responsibilities
- Tell visitors which organization controls their data and why it is processed.
- Choose a lawful basis and enable only the providers and channels needed for that purpose.
- Give workspace, bot, inbox, and file access only to authorized people; remove access promptly.
- Do not submit passwords, full payment-card data, private keys, or unnecessary sensitive data.
- Set retention and deletion procedures appropriate to the customer's legal duties.
- Sign a DPA and review the subprocessor list before regulated production use.
EU-only requirements
Customers that require all in-scope personal data to remain in the EEA should not assume the standard service meets that requirement. Contact [email protected] before deployment. An EU-only architecture would require separate EU-region infrastructure and eligible provider configurations, migration and validation; it is not activated merely by selecting a language or adding GDPR wording.
Retention and deletion
Workspace data remains available while needed by the active account unless an authorized user deletes it or a contractual closure workflow applies. Security logs, billing records, provider logs, and backups may follow separate schedules. Verified deletion requests are handled according to the applicable controller instructions, contract, technical dependencies, and legal obligations.