Privacy Policy

Last updated: 19 March 2026 ยท Effective immediately

๐Ÿ”’ HTTPS Encrypted ๐Ÿ‡ช๐Ÿ‡บ GDPR Compliant ๐Ÿ‡ฎ๐Ÿ‡ณ DPDP Act 2023 ๐Ÿ‡ฆ๐Ÿ‡ช UAE PDPL ๐Ÿ” SOC2 In Progress

1. Who We Are

Percepto AI ("we," "us," "our") operates a voice-first AI agent that scores visitor intent and personalises website conversations. This Privacy Policy explains how we collect, use, and protect your personal data, and what rights you have.

Contact us at: privacy@perceptoai.com

2. Jurisdictions We Comply With

3. Data We Collect & Why

3.1 Visitor Signals (with your consent)

When you visit a website running Percepto AI, we collect:

Purpose: Score intent level and personalise Percepto AI's opening conversation.
Legal basis: Explicit consent (consent banner).
Retention: 30 days in Redis, then automatically deleted.

3.2 Conversation Data (if you engage Percepto AI)

Purpose: Enable real-time conversation and provide a CRM-ready summary to the website owner.
Legal basis: Consent (you initiated the conversation).
Retention: Session transcript: 24 hours. Extracted summary: 90 days.

3.3 Signup / Waitlist Form Data

Purpose: Create your Percepto AI account and send product updates.
Legal basis: Consent (form submission).
Retention: Until you request deletion.

4. Data Processors

Percepto AI shares your data with the following sub-processors, each under a Data Processing Agreement:

ProcessorLocationPurposeData Shared
Groq, Inc.USALLM inference + Whisper STTVisitor signals, conversation
AnthropicUSAClaude Haiku (LLM fallback)Visitor signals, conversation
ElevenLabsUSAText-to-speech synthesisConversation text only
SupabaseUSADatabase + authenticationAll collected data
UpstashUSARedis session cacheVisitor signals, session data
RenderUSABackend server hostingVisitor data (in memory)
CloudflareUSACDN, DDoS protectionWidget JS, request headers
ip-api.comUSAIP geolocation lookupIP address only

All processors are USA-based. For GDPR users, transfers are made under Standard Contractual Clauses (Art. 46 GDPR).

5. Your Rights

RightGDPRDPDPUAE PDPLHow to exercise
Access your dataArt. 15ยง8Art. 13Email privacy@perceptoai.com โ€” "Data Access Request"
Delete your dataArt. 17ยง10Art. 14Email โ€” "Data Deletion Request" โ€” actioned within 30 days
Correct your dataArt. 16ยง8Art. 14Email โ€” "Data Correction Request" โ€” actioned within 14 days
Withdraw consentArt. 7(3)ยง6Art. 8Click "Decline" on the consent banner at any time
Data portabilityArt. 20ยง9Art. 13Email โ€” "Data Portability Request" โ€” delivered as CSV/JSON

We respond to all requests within 30 days. If you are unsatisfied, you may lodge a complaint with your local data protection authority.

6. Data Retention

Data TypeRetentionStorage
Visitor signals + visit history30 daysUpstash Redis
Session transcripts24 hoursUpstash Redis
CRM lead summaries90 daysSupabase PostgreSQL
Signup form dataUntil deletion requestedSupabase
_scout_vid cookie365 days (browser)First-party cookie

7. Security

Found a vulnerability? Email security@perceptoai.com.

8. Breach Notification

In the event of a data breach, we will notify affected individuals within 72 hours as required by GDPR, DPDP, and UAE PDPL โ€” by email to the address you provided.

9. Children's Privacy

Percepto AI is not intended for individuals under 13. We do not knowingly collect data from children. Contact privacy@perceptoai.com if you believe we have.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated by email or via a notice on our website. Continued use of Percepto AI constitutes acceptance.


Percepto AI ยท privacy@perceptoai.com ยท Last updated 19 March 2026