01Introduction
Optiphoenix Xperts Private Limited (“we,” “us,” or “our”) provides Sahayta AI (the “Service”), a conversational assistant that answers questions by combining a large language model with retrieval-augmented generation (“RAG”) — meaning it searches a knowledge base of documents to find relevant information before generating a response.
This policy explains what information we collect when you use the Service, how we use it, which third parties we share it with — including the AI model providers that generate responses — and the choices you have. It applies to Sahayta AI across [web app / WhatsApp / mobile app / API — list your channels], and to anyone who interacts with it: end users, business customers, and their team members.
By using the Service, you agree to the collection and use of information as described here. If you don't agree, please don't use the Service.
02Information we collect
Information you provide directly
- Account details — name, email address, phone number, company name, and password (if you create an account).
- Conversation content — every message you send to the chatbot, and the responses it returns, including follow-up questions, corrections, and feedback (e.g. thumbs up/down).
- Uploaded content — documents, files, links, or text you upload or paste, which may be indexed into the knowledge base the RAG system retrieves from.
- Support requests — anything you send us directly, such as emails or in-app support messages.
Payment information
If you or your organization subscribes to a paid plan, we collect billing details such as your billing address and business/tax information. Full payment card or bank details are handled directly by our payment processor, [Payment Processor — e.g. Razorpay, Stripe], and are not stored on our own servers.
Information collected automatically
- Usage data — session timestamps, message counts, feature interactions, and which knowledge-base sources were retrieved for a given answer.
- Device & log data — IP address, browser type, operating system, device identifiers, and referring URLs.
- Cookies and similar technologies — see Cookies below.
Information from third parties
If you access the Service through a connected platform (for example, WhatsApp, Slack, or a customer's own app via our API), we receive the profile information and message content that platform passes to us — typically your name, phone number or user ID, and the message itself.
03How we use your information
- To operate the Service — generating responses, retrieving relevant knowledge-base content, and maintaining conversation history and context.
- To improve the Service — analyzing usage patterns, retrieval quality, and response accuracy; this may include human review of a sample of conversations. Where we use conversation content to improve our own models or features, we de-identify it first, and you can opt out by contacting us at sales@optiphoenix.com.
- To personalize responses — remembering context within a conversation, or across conversations if the product has memory enabled.
- To communicate with you — service updates, security alerts, and support.
- To maintain safety and security — detecting abuse, fraud, or violations of our terms.
- To comply with legal obligations.
We do not use your conversation content to sell you advertising, and we do not sell your personal information to third parties.
04How the RAG system handles content
Retrieval-augmented generation works in two stages, and each stage touches your data differently:
1. Indexing the knowledge base
Documents added to the knowledge base — whether uploaded by Optiphoenix Xperts Private Limited, by a business customer, or by you — are broken into smaller chunks, converted into numerical representations called embeddings using OpenAI's embedding models, and stored in pgvector (a vector-search extension for PostgreSQL) along with the original text. This lets the system later find the passages most relevant to a given question.
2. Answering a query
When you send a message, the system searches the vector database for the chunks most relevant to your question, and sends those chunks — together with your message and recent conversation history — to a large language model, which generates the reply you see.
| Data type | Where it's stored | Who can access it |
|---|---|---|
| Uploaded source documents | AWS (S3), region [specify] | Optiphoenix staff with access controls; not shared beyond what's needed to answer queries |
| Embeddings / vector index | pgvector, hosted on AWS | Used only to power retrieval; not human-readable on its own |
| Conversation messages | AWS-hosted database | Optiphoenix staff for support/debugging; the LLM provider processing that specific request |
Retrieved passages and your message are sent to a third-party LLM provider to generate each response — see the next section for how that data is handled once it leaves our systems.
05Third-party AI model providers
To generate responses, the Service sends your message, relevant retrieved passages, and recent conversation context to one or more third-party large language model providers. Depending on configuration, this may include:
- Anthropic (Claude models), via its commercial API
- OpenAI (ChatGPT / GPT models), via its commercial API
- [Any other model providers you use — e.g. Google Gemini, Azure OpenAI, open-weight models hosted by you]
OpenAI is also used separately to generate the embeddings that power our knowledge-base search (see the previous section) — that use is limited to converting text into numerical vectors and does not involve generating conversational responses.
What these providers do and don't do with your data: we send requests to these providers under their commercial/enterprise API terms, under which — as of this writing — they do not use API data to train their models and generally retain it only briefly for abuse monitoring, unless we've separately configured otherwise. This can change, and terms differ by provider, so we keep this section aligned with our current provider agreements and update it when those change.
These providers act as our data processors (or “sub-processors”): they process the data we send them solely to return a response, under contractual terms that restrict further use. We choose providers that meet our security and privacy requirements, and we do not send more of your data to them than is needed to generate an answer — for example, we don't send your account password or payment details.
If you'd like the current, specific list of model providers and their data-handling terms, contact us at sales@optiphoenix.com.
07Data retention
- Conversation history is retained for [X months/years] or until you delete it, whichever comes first.
- Uploaded documents and their embeddings are retained for as long as they're part of an active knowledge base, and deleted within [X days] of removal or account closure.
- Account information is retained while your account is active. Following account closure, we delete account data, conversation history, and uploaded documents within 30–60 days, except where we must retain information to meet legal obligations, resolve disputes, or enforce our agreements.
- Log and usage data is retained for [X months] and then aggregated or deleted.
We retain data only as long as needed for the purposes described in this policy, or as required by law.
08Security
We use technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit (TLS) [and at rest, if applicable], access controls limiting who can view conversation and document data, and regular review of our third-party providers' security practices. No system is completely secure, and we can't guarantee absolute security, but we work to protect your information and will notify you as required by law if a breach affects your data.
09Your rights & choices
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to fix inaccurate information.
- Deletion — ask us to delete your account, conversation history, or uploaded documents.
- Portability — request your data in a portable format.
- Objection / opt-out — object to certain processing, such as use of your conversations to improve the Service.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at sales@optiphoenix.com. We'll respond within the timeframe required by applicable law (for example, 30 days under GDPR, 45 days under CCPA/CPRA).
11Children's privacy
The Service is not directed to children under [13 / 16 — set per your applicable law], and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at sales@optiphoenix.com and we'll delete it.
12International data transfers
Your information may be processed in countries other than your own, including [list countries — e.g. the United States, where our LLM and hosting providers operate]. Where required, we rely on appropriate safeguards for these transfers, such as Standard Contractual Clauses or equivalent mechanisms.
13Links to other sites
The Service may reference or link to third-party websites we don't operate — for example, sources cited in a chatbot response, or a business customer's own site. We aren't responsible for the privacy practices of those third parties, and we encourage you to review their policies before sharing information with them.
14Changes to this policy
We may update this policy from time to time. If we make material changes, we'll notify you by [email / in-app notice] and update the “Effective date” above. Continued use of the Service after changes take effect means you accept the updated policy.
15Contact us
Questions about this policy or your data can be sent to:
Optiphoenix Xperts Private LimitedOffice No. 1012A, 11th Floor, Westend Mall, Janakpuri,
New Delhi, Pin Code - 110058
Email: sales@optiphoenix.com