Who this covers
ESLAI is a platform businesses use to run an AI chat assistant on their own website and to manage the leads and conversations that result. This document describes, in general terms, what data ESLAI's platform itself collects and processes — both about the businesses that use ESLAI ("customers") and about the visitors who chat with a customer's ESLAI-powered assistant.
Categories of data collected
- Account data — a customer's name, email, and business details, used to operate their account and business record.
- Conversation data — messages exchanged between a website visitor and a customer's ESLAI assistant, including any contact details or qualification answers a visitor voluntarily shares during that conversation.
- Lead data — information ESLAI derives from a conversation (e.g. name, contact information, interest, an internal qualification score) for the customer's own follow-up.
- Usage data — technical records of AI requests, token counts, and estimated cost, used for billing, abuse prevention, and service reliability.
- Billing data — subscription and payment status. ESLAI does not store full payment card details itself; those are handled directly by Stripe (see Vendors below).
Use of AI
Conversation content is sent to a third-party AI provider (OpenAI) to generate the assistant's replies and to extract structured information (such as contact details or service interest) from a conversation. ESLAI does not sell conversation data, and does not use one customer's conversation data to train or improve another customer's assistant.
Vendors and subprocessors
The following third-party providers process data on ESLAI's behalf as part of operating the service:
- Supabase — database, authentication, and data storage.
- OpenAI — AI language model provider for assistant replies and information extraction.
- Stripe — payment processing and subscription billing.
- Vercel — application hosting and deployment.
This list reflects the vendors actually integrated into ESLAI today; it will be kept current as that changes.
Retention, deletion, and export
ESLAI retains conversation, lead, and usage data for as long as a customer's account is active, so that the platform's core features (conversation history, lead records, analytics) continue to work. Specific retention periods, a self-service deletion process, and a self-service data export tool are not yet finalized as of this document's last update — this is an area we are actively defining, and it will be reflected here, and made available in-product, before broad commercial launch. Until then, a customer or visitor requesting deletion or export of their data can reach out directly to request it be handled manually.
Security
Customer data is isolated per business account, with access enforced on ESLAI's servers rather than left to the application's user interface. Administrative access to the platform is restricted to a small, explicitly authorized set of ESLAI operators. Payment details are never handled or stored directly by ESLAI's own servers.
Questions
Questions about this policy can be directed to the ESLAI team through your account contact.