Privacy Policy

Last updated:

Who we are

Questme.ai is operated by C-Vids Productions (UEN 53119647W), 9002 Tampines Street 93, #03-36, Singapore 528836. This policy explains what personal data we handle when you use Questme, why we handle it, and what you can ask us to do with it.

Our handling of personal data is governed by Singapore’s Personal Data Protection Act (PDPA).

What we collect from businesses that use Questme

  • Account data — your email address and password, used to sign you in.
  • Bot settings — bot names, welcome messages, and any contact details you choose to show in your bot (phone, WhatsApp, email, address, website and social links), plus the email address that receives handoff alerts.
  • Knowledge sources — the website pages you ask us to crawl, text and FAQ pairs you paste, text extracted from PDFs you upload, and images you upload. A PDF itself is not stored: we extract its text and keep only the text. Uploaded images are stored in a public file bucket so your bot can link to them, so do not upload images you would not publish.
  • Embeddings — numerical representations of your knowledge text, used to find the passages that answer a question.
  • Billing data — your plan, subscription status and Stripe customer reference. Card details are collected and held by Stripe; we never see them.

What we collect from visitors who chat with a bot

  • Chat messages — every question a visitor asks and every answer the bot gives, stored with the time and a random session identifier.
  • Lead details — the name, email address and phone number a visitor enters in a bot’s contact form, and the message that prompted it.
  • A random visitor identifier for each chat session. It is generated at random and is not derived from the visitor’s device or identity.
  • A visitor’s browser keeps the name, email and phone they entered in its own local storage, so they are not asked again on that site. This stays on the visitor’s device; clearing browser data removes it.
  • IP addresses are used only in memory to limit request rates. They are not written to our database.
  • If our database ever refuses to save a lead, its details are emailed to our support team and written to our server logs, so we can re-enter it for the business by hand.

Your visitors’ data, and our role

Most of the personal data inside Questme is not about you — it is about the visitors who chat with your bot. You decide to put a bot on your website, what it says, and whether it asks for contact details.

For that data you are the data controller and C-Vids Productions acts as a data intermediary: we process it on your behalf and on your instructions, to answer your visitors and show you their conversations and leads. We do not use your visitors’ data for our own purposes.

If you chatted with a bot on a business’s website and want to see, correct or delete what you shared, contact that business. They control that record. We will assist them as their data intermediary.

Subprocessors

We use the following third parties to run the service. Each processes data only to provide its part of the product.

  • Supabase — database, authentication and file storage, hosted in AWS ap-southeast-1 (Singapore).
  • Vercel — application hosting (Singapore region) and cookie-free page-view analytics on questme.ai pages, including the chat widget page.
  • OpenAI — knowledge text and visitor questions are sent to OpenAI’s API to create embeddings (text-embedding-3-small) and generate answers (gpt-4o-mini).
  • Stripe — subscription payments.
  • Resend — email delivery: handoff alerts to the address you set, and messages you send us through the in-app feedback form.

What we do not do

  • We do not sell personal data.
  • We do not use your content or your visitors’ messages to train AI models.
  • We do not use advertising trackers.

How long we keep data

Nothing is deleted automatically. Your data is kept while your account exists, so your bots, knowledge and conversation history stay available to you.

You can delete a knowledge source or a lead from your dashboard at any time; that removes it from our database immediately. An uploaded image file stays in file storage after its knowledge source is deleted; ask us and we will remove it. Deleting a bot hides it and stops it answering, but its stored conversations are kept until you ask us to erase them.

There is no self-service account deletion yet. To delete your account and everything in it — bots, knowledge, conversations and leads — or to erase specific conversations, email support@questme.ai.

Security

  • HTTPS for all traffic, with HTTP Strict Transport Security.
  • Every dashboard request is scoped to the signed-in account, so one business’s bots, knowledge, conversations and leads are not reachable from another’s.
  • The database is encrypted at rest by our database provider.

Cookies and local storage

The dashboard sets session cookies that keep you signed in; they are required for it to work.

The chat widget sets no cookies. It uses the visitor’s browser storage only as described above.

Your rights under the PDPA

You may ask us for access to the personal data we hold about you, ask us to correct it if it is inaccurate or incomplete, and withdraw consent for its use.

Send requests to support@questme.ai.

Changes to this policy

When this policy changes we update the date at the top of this page.