Attractable Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Attractable ("Attractable," "we," "us," or "our") collects, uses, and shares information when a company (the "account holder") signs up for and uses the Attractable dashboard, and when a visitor to that company's website (an "end visitor") interacts with the AI chat widget the account holder has embedded on their site. Attractable is described as an AI support agent that turns every conversation into product intelligence, combining a chat widget powered by Anthropic's Claude model with an account holder dashboard that surfaces conversation insights and summaries.

By using Attractable, whether as an account holder or as an end visitor interacting with an embedded widget, you agree to the collection and use of information as described in this policy.

1. Information We Collect

We collect different information depending on whether you are an account holder using our dashboard or an end visitor chatting with a widget embedded on an account holder's website.

1.1 Information We Collect From Account Holders

When you create an account, log in, and use the Attractable dashboard, we collect:

Your name, provided when you sign up or, if you sign up using Google, taken from the name associated with your Google account.

Your email address, provided when you sign up or log in, or taken from the email address associated with your Google account if you use Google to sign in.

A securely hashed and salted representation of your password if you create an account directly with us. If you sign up using Google, we do not store a password for your account at all, since Google handles that authentication for us.

Your company name, company website, and job role, which you may provide during onboarding.

Timestamps recording when your account was created and when you completed onboarding.

We do not collect billing or payment information, phone numbers, or physical addresses from account holders, and our systems do not currently have fields for storing that information.

1.2 Information We Collect From End Visitors Through the Embedded Widget

When an end visitor opens and uses the chat widget embedded on an account holder's website, we collect:

A randomly generated identifier created by the visitor's browser and stored in that browser's local storage. This identifier lets us recognize that the same browser is likely the same visitor across multiple visits, without requiring the visitor to log in or provide identifying information.

The full text content of every message sent in a widget conversation, including both the end visitor's messages and the AI generated replies. This content is stored in our database.

Conversation level information such as whether a conversation is open, resolved, or was abandoned partway through, along with timestamps for when the conversation and each message occurred.

Optionally, a name and email address for the end visitor. These fields exist in our system and can be supplied by whatever software calls our chat service, but the chat widget we currently provide to account holders does not itself ask visitors for their name or email or send that information. These fields are populated only if an account holder integrates their own systems to supply them.

Optionally, a monetary or subscription value associated with an end visitor. This field exists in our database, but it is not populated by any active, currently used feature of the product. There is no dashboard action, API, or any other account holder facing feature that allows anyone to enter a value into this field. It is only ever set through internal demonstration seed data used to illustrate the product, or by someone with direct access to the underlying database.

From these underlying conversations, we also generate two additional types of derived content that account holders see on their dashboard:

An Insights feed, which uses Claude to review clusters of conversation transcripts and identify recurring themes such as common pain points, feature requests, and conversations that were abandoned partway through. This content is a summary built from conversation data rather than a copy of any individual message.

A Weekly Digest, a summary written by Claude that account holders use to understand activity across their conversations. Because this digest is designed to help account holders spot visitors who may be at risk of leaving, it may specifically name individual end visitors by name or email address, and may reference their plan value, where that information is available in our records.

Account holders also have access to an internal Assistant chat feature that lets them ask questions about their own dashboard data. Questions asked through this feature, and the answers generated by Claude in response, are stored so that a conversation with the Assistant can continue across messages.

1.3 Information Related to Our Website Tools

Attractable also offers a small set of standalone tools, such as an SEO audit tool and a broken link checker, that let any visitor submit a website address for our servers to fetch and analyze. These tools include safeguards intended to prevent the tools from being used to reach internal or private network addresses. We do not maintain a personal data record tied to any individual in connection with these tools.

2. How We Use Information

We use account holder information to create and administer accounts, authenticate log ins, operate the dashboard, personalize onboarding, and operate the service generally.

We use end visitor information to operate the chat widget, recognize a returning visitor's browser so a conversation can continue across sessions, generate AI replies to the visitor's messages (optionally grounded in a knowledge base the account holder maintains), and to generate the Insights feed and Weekly Digest described above so that account holders can better understand and respond to their own customers.

We use information submitted to our website tools solely to perform the requested audit or check and return results to the person who submitted the request.

We do not use any information collected through Attractable to serve advertising, and we do not currently operate any analytics or tracking tools within the product beyond what is described in this policy.

3. Third Parties Who Process Your Information

We share information with a limited number of service providers who help us operate Attractable. Each is listed below along with why we use them.

Anthropic, provider of the Claude model that powers Attractable's AI features. Conversation transcripts from the widget are sent to Anthropic to generate replies to end visitors; an account holder's own questions and their aggregated dashboard data are sent to Anthropic to power the internal Assistant feature; and conversation transcripts are sent to Anthropic to generate the Insights feed and Weekly Digest. Anthropic processes this content on our behalf in order to provide these AI features.

Supabase, which hosts the Postgres database that stores all of the information described in this policy, including account holder records, end visitor records, conversations, messages, generated insights, and digests. Supabase acts as our infrastructure provider for data storage.

Supabase Auth, which we use only to support the "Continue with Google" sign in option for account holders. When an account holder chooses to sign in with Google, Supabase Auth completes the Google sign in exchange on our behalf, after which we read the resulting Google account's email and name to create or match the account holder's record with us.

We do not use, and Attractable does not integrate with, any payment processor or analytics and tracking service. Any mention of other companies that may appear within example or demonstration content used for internal testing purposes is not an indication that we share data with those companies.

4. Cookies and Local Storage

We and our service providers use a small number of cookies and browser local storage entries, described below.

attractable_session: a cookie set only for account holders when they log in, sign up, or complete sign in with Google. It authenticates the account holder to our dashboard, is set to be readable only by our server, is marked secure in production, and expires after 30 days or when the account holder logs out. This cookie is not set for end visitors interacting with a widget.

Supabase Auth cookie or cookies: set temporarily during the "Continue with Google" sign in flow to complete the handshake with Google before we issue our own attractable_session cookie. The exact name of this cookie is determined by the authentication library at the time it runs rather than being fixed by us.

attractable_visitor_id: a randomly generated identifier stored in an end visitor's browser local storage by the chat widget, so that the same browser can be recognized as the same visitor if they return to chat again.

attractable_conversation_id: a randomly generated identifier stored in an end visitor's browser local storage by the chat widget, so that an in progress conversation can be resumed if the visitor reloads the page or reopens the widget.

We do not use cookies or local storage for advertising purposes.

5. Data Retention

Conversations, individual messages, end visitor records, and records related to the internal Assistant feature are retained indefinitely once created. We do not currently have an automated process that deletes or expires this information after a set period of time.

The Insights feed is regenerated periodically, and each time it is regenerated, the previous set of generated insights is replaced with a newly computed set. This affects only the generated summary content shown in the Insights feed, not the underlying conversations or messages those insights were derived from.

Account holders can delete individual knowledge base entries and individual uploaded widget icons that they no longer want stored. Logging out of the dashboard removes the session cookie from an account holder's browser but does not delete any of their account data.

We do not currently offer an automated, self service way for an account holder to delete their own account, or for deleting a specific end visitor, conversation, or message record. If you would like any such information deleted, please contact us as described in the Contact Us section below, and we will address your request.

6. Security

We take reasonable steps designed to protect the information we collect. Account holder passwords, where we store one at all, are never kept in plain text. Instead, we store a salted cryptographic hash of the password. Accounts created by signing in with Google do not have a password stored with us at all, since Google handles that authentication.

Our authentication cookie is transmitted with protections intended to prevent it from being read by scripts on other websites, to prevent it from being sent over an unencrypted connection in production, and to limit the situations in which it is sent along with cross site requests. Access to the dashboard requires a valid, signed session token that is checked before any account data is returned.

No method of storing or transmitting information is completely secure, and we cannot guarantee absolute security.

7. Children's Privacy

Attractable is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13, whether as account holders or as end visitors interacting with an embedded widget. If we become aware that we have unknowingly collected information from a child under 13, we will take steps to delete that information.

8. Your Rights

Depending on where you are located, you may have rights regarding the personal information we hold about you, including the right to request access to that information, to request that inaccurate information be corrected, and to request that your information be deleted.

If you are an account holder, you can update much of your own information directly within the dashboard. For requests we cannot currently fulfill through the dashboard itself, including deletion requests, you may contact us using the details in the Contact Us section below, and we will respond within a reasonable time.

If you are an end visitor who has interacted with a widget on an account holder's website and would like to exercise these rights, you may contact us directly, or you may contact the account holder whose website you interacted with, since they operate the widget you used.

9. International Data Transfers

Attractable relies on cloud infrastructure and service providers that may store and process information in countries other than the country in which you are located. Where information is transferred internationally, we expect our service providers to apply appropriate safeguards and protections consistent with applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make changes, we will update the Last updated date at the top of this policy. We encourage you to review this policy periodically.

11. Contact Us

If you have questions about this Privacy Policy or would like to exercise any of the rights described above, please contact us at hello@attractable.co.