Privacy Policy
Last updated: September 9, 2026
How SupaIntent collects, uses, shares, and protects information for its B2B AI visibility service.
Who we are
SupaIntent provides a B2B software service that helps teams monitor how brands, domains, prompts, competitors, and sources appear in AI-generated answers and AI search experiences.
For privacy questions or requests, contact us at support@supaintent.com.
Information we collect
We collect information that users provide directly, information generated through use of the service, and limited technical information needed to operate and secure the service.
- Account and support information, such as email address, name, company, login details, and messages sent to support.
- Product data, such as domains, brand names, competitors, prompts, project settings, monitoring results, and related AI visibility data.
- Chat data, including messages, AI replies, conversation summaries, timestamps, and usage statistics. We also store MCP credentials, request counts, and last-use information to manage access and service limits.
- Payment information handled by Stripe, such as billing details, payment status, card brand, and partial card details. SupaIntent does not store full card numbers.
- Technical and usage information needed for security, diagnostics, product analytics, and service operation, such as pages viewed, actions taken, browser type, approximate location, device data, and timestamps.
How we use information
We use information to provide, maintain, secure, improve, and support SupaIntent.
- Create and manage accounts, projects, access, and subscriptions.
- Run monitoring, prompt analysis, competitor analysis, source analysis, and related AI visibility features.
- Respond to support requests and communicate about the service.
- Process payments, prevent fraud, and keep billing records.
- Measure product usage, diagnose issues, improve reliability, and protect against abuse.
- Send product and marketing emails where permitted. Users can opt out of marketing emails, but service, account, security, and billing emails may still be sent.
AI processing
Some SupaIntent features use AI systems and data services through OpenAI, Bright Data, and other providers. To provide those features, prompts, brand names, domains, competitor names, project context, and related content may be sent for processing.
Project chat sends your question, relevant conversation history or a saved summary, project context, and data retrieved from your project to OpenAI to generate answers. We save completed conversations and summaries so you can reopen and continue them. Archiving a conversation hides it from your history but does not delete its messages or summary.
Users should not submit confidential, regulated, or highly sensitive personal information unless they are authorized to do so and have confirmed the service is appropriate for that data.
Connected agents and MCP
When you connect a third-party agent or application using a SupaIntent MCP key, that client can read supported data from the authorized project, including analytics, prompts, AI answers, sources, and related evidence. MCP access is read-only and requires current project access.
The connected client and any AI providers it uses may receive and process the retrieved data under their own terms and privacy policies. Only connect clients you trust and are authorized to share project data with. You can revoke an MCP key in the application to block subsequent requests; revocation does not remove data already received by a third party.
Public research and tools
We publish selected research results through public tools, including brand benchmarks, citation-domain statistics, and an advertising library. The advertising library may include ads observed during customer monitoring, such as advertiser names, ad copy, destination links, images, and appearance details including market category, country, AI provider, and dates.
These public exports exclude account details, project identifiers, customer-submitted prompts, and private chat conversations. Publishing selected advertising observations does not make the underlying customer project or monitoring history publicly accessible.
Service providers
We use trusted service providers to operate SupaIntent. These providers process information only as needed to provide their services to us.
- Supabase for database, authentication, and backend infrastructure.
- OpenAI, Bright Data, and other providers for AI-related processing and data services.
- Stripe for payment processing and billing.
- PostHog for product analytics. On the public website, PostHog is configured without persistent browser storage.
Cookies and local storage
We use only storage that is necessary for the service to function, stay secure, remember user preferences, process payments, or operate required product features.
The public website stores the selected theme in localStorage so the site can keep the user's light or dark preference. Product analytics on the public website is configured without persistent cookies or localStorage identifiers, but still collects usage events and technical information. The application also uses cookies and browser storage for authentication, the active project, and interface preferences.
Legal bases and rights
Where privacy laws such as the GDPR apply, we process personal data based on the need to provide the service, our legitimate interests in operating and improving a secure B2B product, compliance with legal obligations, and consent where required.
Depending on location and applicable law, users may have rights to access, correct, delete, export, restrict, or object to processing of personal data, and to withdraw consent where processing is based on consent. Requests can be sent to support@supaintent.com.
Retention and security
We keep information for as long as needed to provide the service, maintain business records, resolve disputes, comply with legal obligations, and protect the service.
We use reasonable technical and organizational measures designed to protect information. No system is perfectly secure, so users should protect account credentials and notify us about suspected unauthorized access.
Changes
We may update this Privacy Policy as the service changes. The updated version will be posted on this page with a revised last updated date.