Privacy Policy

Effective August 20, 2026

This Privacy Policy explains what information AskEmbed ("we", "us", or "our") collects when you use our website and services at https://askembed.com (the "Service"), and how we use, share, and protect that information. It applies to account holders ("you", "customers"), visitors who interact with chatbots embedded on our customers' websites, and anyone who uses our free tools.

Information We Collect

We collect the following categories of information:

  • Account information. When you sign up, we store your email address with your account. Sign-in itself is handled by our authentication provider, Clerk, which also processes your sign-in credentials and profile details (such as your name and profile image).
  • Content you submit. Documents you upload (PDF, Markdown, HTML, or plain text), URLs you ask us to ingest, and the text we extract from them. Original files are stored in object storage, extracted text and metadata in our database, and vector embeddings in a per-chatbot index namespace.
  • Chat conversations. Messages exchanged between your website visitors and your chatbots, along with feedback signals such as thumbs-up and thumbs-down ratings. Conversations are tied to a random visitor identifier - not to a name or account.
  • Usage and billing data. Message counts and quota usage (needed to enforce your plan's limits), your subscription plan, and billing status. Payments are processed by Creem, our Merchant of Record - we never receive or store your full card number.
  • Technical data. IP addresses (used to rate-limit the free public tools and processed by our edge network for routing and abuse prevention), request timestamps, and error logs.
  • Analytics data. If you accept our cookie banner, we collect product analytics through PostHog; for signed-in users this may include your account ID and email address, so events can be tied to your account. Error reports are always sent, as described below.
  • Free tools (no account needed). Our free tools - the FAQ generator, chatbot demo, and docs-to-chatbot preview - process the URL or text you submit without an account. Submitted content is indexed into a temporary demo session that expires within minutes and is never attached to an account. To prevent abuse, these tools are rate-limited per IP address.

How We Use Information

We use the information we collect to:

  • Provide the Service - indexing your documents, answering your visitors' questions with cited sources, and enforcing the quotas of your plan.
  • Process payments and manage your subscription, including renewals and receipts (together with Creem).
  • Communicate with you about your account, security issues, support requests, and (occasionally) product updates.
  • Improve the Service - for example, understanding which answers were helpful, monitoring error rates, and preventing abuse.

We do not sell your personal information, and we do not use your documents or chat conversations for advertising.

Where a legal basis is required (for example under the GDPR), we rely on: performance of our contract with you (providing and billing for the Service), legitimate interests (security, abuse prevention, and service improvement), and your consent (product analytics).

AI Processing of Your Content

To answer questions, the text of your documents and the visitor's question are processed by AI models running on Cloudflare Workers AI: your text is converted into vector embeddings for retrieval, and a large language model generates the answer.

We do not use your documents or conversations to train AI models, and Cloudflare states that it does not use Workers AI customer content to train its models.

Each chatbot's vectors are stored in an isolated namespace, and every retrieval query is filtered to that namespace, so one customer's content is never mixed with another's.

Cookies and Local Storage

  • Essential cookies: session cookies set by Clerk keep you signed in to the dashboard.
  • Consent record: your cookie-banner choice is stored in your browser's local storage so we do not ask again.
  • Analytics: PostHog product analytics and account identification run only after you accept the banner. Error reporting (for example, JavaScript exceptions) is always on so we can find and fix problems; it is not used for tracking.
  • Widget: the embedded chatbot stores only a random visitor identifier in the visitor's browser local storage, so their messages thread into one conversation. The transcript itself is not stored in the browser; clearing site data removes the identifier.

How We Share Information

We share information only with service providers that process it on our behalf, solely to operate the Service:

  • Clerk - user authentication and session management.
  • Cloudflare - website hosting, database (D1), object storage (R2), vector search (Vectorize), cache (KV), and AI inference (Workers AI) on its global edge network.
  • Creem - payment processing as Merchant of Record; it receives the billing details you provide at checkout.
  • PostHog - product analytics (only if you have consented) and error reporting.

We may also disclose information if required by law, legal process, or to protect our rights, and in connection with a merger or acquisition (with notice where practical). Data we retain is governed by this policy in any such transfer.

Data Retention and Deletion

We keep your information only while your account is active, plus a short window afterwards for backups and logs.

  • Delete a chatbot: deleting a chatbot from the dashboard immediately purges its uploaded files, extracted text, vector embeddings, and conversation history.
  • Delete documents: you can delete individual documents from the dashboard at any time; deletion removes the stored file along with its indexed text and vectors.
  • Conversations: conversations are removed together with their chatbot. If you want specific conversations removed earlier, contact us.
  • Delete your account: contact us and we will delete your account along with all chatbots, documents, and conversations.
  • Free tools: temporary demo sessions expire automatically within minutes, and their indexed content is deleted.

Some residual copies may persist in encrypted backups and service logs for a limited period before they are purged.

Your Rights

Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing.

You can export your data yourself: Dashboard -> Settings downloads all of your account data as a JSON file, and each chatbot's Analytics tab can download that bot's conversations (Pro plans and above).

For anything else, email us at support@askembed.com - from your account's address where you have one. We will respond within a reasonable timeframe and will not discriminate against you for exercising your rights.

Website visitors can withdraw analytics consent at any time by clearing site data for this site - the banner will reappear on your next visit.

Data Security

All traffic to and from the Service is encrypted with TLS. Your data is stored on Cloudflare's global edge infrastructure, with per-chatbot isolation as described above, and access to production systems is limited and logged.

No method of transmission or storage is completely secure, however. We cannot guarantee absolute security, and you use the Service at your own risk.

International Data Transfers

We operate on Cloudflare's global network, so your data may be processed or stored in countries other than your own. Cloudflare provides the safeguards required for such transfers, and we only transfer data where we can rely on appropriate protections.

Children's Privacy

The Service is not directed to children. You must be at least 13 years old (16 in the European Economic Area) to create an account, and visitors under that age should not use the embedded chatbots. If you believe a child has given us personal information, contact us and we will delete it.

Changes to This Policy

We may update this Privacy Policy as the Service evolves. The “Effective date” at the top of this page shows the latest revision. For material changes we will notify you by email or in-product before the change takes effect.

Contact Us

Questions about this policy or your data? Email support@askembed.com. You can also read our Terms of Service.