Privacy Policy
Legal reference
Last updated: July 22, 2026
This policy explains what Communicate collects, why we collect it, and the choices you have. In plain terms: we use your data to run the product you pay for, we do not sell it, and we never use your data or your end users conversations to train third-party AI models.
Overview
Communicate is an AI customer-support platform operated by TinyCheque, Inc. We help businesses answer their customers with an AI support agent trained on their own knowledge base, a shared inbox where AI and human agents collaborate with human takeover, embeddable chat widgets, in-app messages and nudges, analytics, and actions.
This policy covers two distinct kinds of data. The first is account data about the businesses and people who sign up for and administer a Communicate workspace. The second is end-user conversation data, meaning the messages and details exchanged between a customer business and its own end users through our widgets and inbox. Our role and responsibilities differ between these two, and section 5 explains the difference in detail.
The legal entity responsible for Communicate is TinyCheque, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA. If anything here is unclear, contact us at [email protected] and we will walk you through it.
By creating an account or using Communicate, you agree to the collection and use of information as described here. If you do not agree, please do not use the service.
Information we collect
We collect only what we need to provide, secure, bill, and improve the service. The categories below reflect a customer-support product, so most of the sensitive material we handle is content that our customers choose to put into their own workspaces.
Account and workspace information
- Your name and email address.
- A hashed password. We never store passwords in plain text.
- Your organization name and workspace configuration, such as agent settings, team members, roles, and channel setup.
- Billing contact details and billing preferences.
Knowledge base and data sources
To train a customer AI agent, our customers upload or connect content such as help articles, documents, FAQs, and other reference material. We store and process this content so the AI agent can answer questions accurately. The customer decides what to include and can update or remove these sources at any time.
End-user conversation data
- Messages exchanged between a customer end user and the AI agent or a human agent.
- Contact identifiers an end user submits during a chat, such as an email address or name.
- Metadata about the conversation, such as timestamps, channel, and whether the AI or a human handled a given turn.
Usage data
- IP address and approximate location derived from it.
- Browser type, device, and operating system.
- Pages viewed, features used, and actions taken inside the product.
- Timestamps and error logs used to diagnose problems and keep the service reliable.
Billing metadata
We store your plan, credit balance, and invoice history so you can manage and review your account. We do not store card numbers or CVVs. Card details are handled directly by our payment provider, as described in section 6.
Cookies
We use essential authentication cookies to keep you signed in and optional first-party analytics cookies to understand how the product is used. You can read the full detail in our Cookie Policy at https://communicate.so/cookies.
How we use your information
We use the information above to run Communicate and for no undisclosed secondary purposes. Specifically:
- To provide the service: authenticate you, load your workspace, train your AI agent on the sources you connect, route conversations between the AI and human agents, and deliver widgets, in-app messages, analytics, and actions.
- To process billing: apply your one-time account activation, track credit usage, generate invoices, and maintain your billing history.
- To support you: respond to your questions, investigate issues you report, and communicate service-related notices.
- To secure the platform: detect and prevent abuse, fraud, and unauthorized access, and maintain audit and error logs.
- To improve the product: understand aggregate feature usage through privacy-respecting analytics and fix reliability problems.
- To meet legal obligations: retain billing records and respond to lawful requests where required.
We do not use your information for advertising, and we do not sell personal data. See section 4 for how AI processing works and what we specifically do not do with your data.
AI processing and model use
The AI agent runs inference on gpt-4o-mini accessed through OpenRouter. Inference means the model reads the relevant knowledge-base content and conversation context in order to generate a reply. That is the only thing the model is used for.
We do not use your data or your end users conversations to train third-party foundation models. Content you connect and messages exchanged in your workspace are used to answer questions in your own workspace, not to train or fine-tune any external model. gpt-4o-mini is used for inference only.
AI responses can be imperfect. Because the agent generates answers from the sources a customer provides, the quality and accuracy of answers depend on the quality of those sources. The shared inbox lets a human agent take over a conversation at any time, so a person can step in when a question needs judgment the AI should not make on its own.
Controller and processor roles
Data-protection law distinguishes the party that decides why and how data is processed, the controller, from the party that processes data on the controllers instructions, the processor. Communicate sits in both roles depending on the data.
Account data: we are the controller
For information about the businesses and individuals who sign up for and administer a Communicate workspace, TinyCheque, Inc. is the controller. We decide how that account data is used to provide, secure, and bill the service, and the rights in section 9 apply to us directly.
End-user conversation data: we are the processor
For the messages and contact details that a customer collects from its own end users through Communicate, the customer is the controller and Communicate is the processor. We process that data only to run the service on the customers behalf and according to their configuration. If you are an end user chatting with a business that uses Communicate, please direct requests about your data to that business, which controls it. We will support them in responding.
Data retention
We keep data only as long as it is needed for the purposes described here.
- Active data is retained while your account is active so the service can function.
- When you request deletion, we delete the relevant personal data within 30 days, subject to the legal retention below.
- Billing records are retained for 7 years to meet tax, accounting, and other legal requirements.
For end-user conversation data, retention is directed by the customer who controls that data. When a customer deletes content or closes their workspace, we delete the associated data on the same timelines above, except where a legal obligation requires us to keep specific records for longer.
Your privacy rights
Depending on where you live, you have rights over your personal data. We honor these rights for the account data we control. Where we act as a processor for end-user conversation data, we support the relevant customer in responding to their end users requests.
If you are in the EEA or the UK (GDPR)
- Access: obtain a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data.
- Portability: receive your data in a portable, machine-readable format.
- Restriction: limit how we process your data in certain circumstances.
- Objection: object to certain processing.
- Withdraw consent: withdraw any consent you previously gave, without affecting prior processing.
We respond to verified GDPR requests within 30 days. You also have the right to lodge a complaint with your local data-protection authority.
If you are in California (CCPA)
- Know: request the categories and specific pieces of personal information we have collected about you.
- Delete: request deletion of your personal information.
- Opt out: opt out of the sale of personal information. Note that we do not sell personal data, so there is nothing to opt out of, but the right is stated for clarity.
- Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service because you exercised a privacy right.
We respond to verified CCPA requests within 45 days. To exercise any right under GDPR or CCPA, email [email protected]. We may need to verify your identity before acting on a request to protect your data.
International data transfers
Communicate is operated from the United States, and our infrastructure and subprocessors are located there. If you access the service from outside the United States, your data will be transferred to and processed in the United States.
For personal data that leaves the EEA or the UK, we rely on Standard Contractual Clauses (SCCs) as the legal transfer mechanism, together with appropriate technical and organizational safeguards. A copy of the relevant transfer terms is available on request at [email protected].
Data Processing Agreement
Business customers who need a Data Processing Agreement (DPA) to govern our processing of end-user conversation data on their behalf can request one. The DPA sets out our obligations as a processor, including confidentiality, security, subprocessor terms, and support for data-subject requests and international transfers.
To request a DPA, contact [email protected].
Children’s privacy
Communicate is not directed at anyone under the age of 16, and we do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, contact [email protected] and we will delete it.
Security
We take reasonable technical and organizational measures to protect the data we hold, and we are deliberately careful not to claim certifications we do not hold. Rather than repeat those details here, we keep them in one place. See our security page at https://communicate.so/security for exactly what we protect and how.
No system is perfectly secure. If you discover a vulnerability or suspect an incident, please report it to [email protected] so we can investigate promptly.
Changes to this policy
We may update this policy from time to time to reflect changes in the service, our practices, or legal requirements. When we make a material change, we will update the date at the top of this page and, where appropriate, notify account holders by email or in-product notice.
Your continued use of Communicate after an update takes effect means you accept the revised policy. We encourage you to review this page periodically.
Contact us
For any question, request, or complaint about this policy or your data, contact us and we will respond.
- Email: [email protected]
- Postal address: TinyCheque, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.
This policy is governed by the laws of the State of Delaware, USA, and any disputes are subject to the courts of Delaware.