Use page and workflow hints; avoid secrets and private records
Privacy Policy
Last updated: August 13, 2026
This policy explains how AnswerLattice handles information for its public website, product dashboard, help widget, and support knowledge features.
Use page and workflow hints; avoid secrets and private records
Owner-selected support material and capped extracted text
Owners manage team access, widget settings, and published support content
AnswerLattice handles account, team member, workspace, widget, hosted-help domain, and ticket details needed to operate the service.
It also handles product support content, knowledge-base imports, FAQs, changelog entries, safe page context that a customer chooses to send through the widget, and capped ticket debugging context when a ticket is created.
Knowledge intake sources can include selected public URLs, pasted support text, starter answers, and supported document text. Customers should avoid importing unnecessary personal data.
Page context should describe the product page, route, feature, workflow, role, or plan needed to answer support questions. It should not include passwords, payment card data, secrets, private tokens, or unrelated personal information.
During signup, a customer may optionally select a closed-list source describing where they first heard about AnswerLattice. The field does not accept free text.
AnswerLattice uses workspace and support content to power help centers, hosted docs, approved answers, widget responses, ticket fallback, changelog relevance, readiness summaries, and support-gap review queues.
Operational logs and ticket debugging context are used to keep the service reliable, investigate reported failures, protect the service from abuse, and understand whether support knowledge is stale or incomplete.
Optional self-reported signup sources are used to compare broad acquisition channels, including AI assistants, search, communities, and referrals.
The current operational provider map includes Vercel for application hosting, Google Firebase and Google Cloud for database, authentication, storage, and functions, Google Gemini for configured AI-assisted processing, Razorpay for billing, a configured SMTP service for email, Upstash Redis when configured for cache or rate limiting, and consent-gated Plausible or Google Analytics for the public website.
AnswerLattice does not make a public no-training or zero-data-retention promise for Gemini processing. Those conditions depend on the deployed billing tier, enabled provider features, abuse-monitoring status, and account configuration and must be verified for a buyer that requires them.
The public Trust and Data Handling page describes how each provider category is used. It is factual product documentation, not a contractual subprocessor schedule.
AnswerLattice does not sell customer support content or widget conversation data.
The public AnswerLattice website may use essential browser storage to keep the site working and remember basic preferences such as cookie choice or theme.
Optional Plausible and Google Analytics on the public website load only after analytics is accepted in the cookie preference banner and the relevant measurement setting is configured. If analytics is declined or no measurement setting is configured, the public website stays on essentials only.
The public website banner does not claim ads or personalization tracking.
Workspace owners can manage team access, widget settings, allowed origins, blocked routes, product details, support content, tickets, changelogs, and approved answers from the AnswerLattice dashboard.
Customers are responsible for choosing what content they import and what page context their product sends to AnswerLattice.
AnswerLattice keeps data for as long as it is needed to provide the service, support the customer workspace, meet operational needs, or satisfy legal requirements.
Implemented windows include 30 days for query embedding cache, 90 days for raw answer/search history, 90 days for selected operational logs, 2 days for notification rate-limit counters, 365 days for public contact enquiries, 365 days for raw signal events, and 90 days for friction daily statistics.
Imported source metadata and capped extracted text stay with the intake job so owners can review drafts and lineage. Raw file retention is not required for day-one browser-extracted intake.
Access controls, tenant separation, validation, and bounded payload handling are used to reduce accidental exposure and protect support data.
For privacy questions, contact hello@answerlattice.com.
The Trust and Data Handling page lists current provider categories, implemented retention windows, and the compliance or contractual claims AnswerLattice does not currently make.
Open trust facts