askmana

Privacy Policy

Last updated: 2026-05-15

This Privacy Policy describes how AskMana ("we", "us", "our") handles personal data when you use our website (askmana.com), our hosted chatbot service, and the embeddable widget.

1. Who we are

AskMana is an AI customer-support platform operated as a sole proprietorship registered in Türkiye, hosted on infrastructure in Falkenstein, Germany (Hetzner Online GmbH). For any privacy questions reach us at privacy@askmana.com.

2. What we collect

Account data (workspace owner)

  • Full name and email address you provide at signup.
  • Workspace name, slug, default language, and billing country.
  • Encrypted AI provider API keys (OpenAI / Gemini). We use AES-256-GCM at rest. We never log or display the plaintext key.
  • Optional integration credentials (e.g. WooCommerce consumer keys), also AES-256-GCM encrypted.

Visitor data (people chatting with the widget)

  • Chat messages sent to the widget and the assistant's replies, stored under the workspace owner's account.
  • An anonymous visitor identifier (random ID stored in the visitor's browser localStorage) for conversation continuity. We do not set tracking cookies and do not fingerprint visitors.
  • Approximate IP address (used for rate-limiting and fraud prevention only) and User-Agent string.

Payment data

  • We use Paddle as Merchant of Record. Card details are processed by Paddle, never touch our servers. We receive metadata only: customer email, subscription status, plan, country, invoice ID.

3. How we use it

  • To run the service you signed up for (chat, KB, analytics).
  • To bill you via Paddle and remit applicable taxes.
  • To respond to your support requests and bug reports.
  • To detect abuse (rate-limiting, fraud) — no profiling, no advertising.

We do not sell your data, share it with advertisers, or use chat content to train any AI model.

4. Sub-processors

The third parties we share data with, each only for a specific purpose:

  • Hetzner Online GmbH (Germany) — hosting and backups.
  • Paddle.com Market Limited (UK) — payment processing and invoicing.
  • OpenAI / Google (Gemini) — chat generation. Each workspace owner brings their own API key; their chat content is processed by the provider they chose. OpenAI and Google both contractually agree not to train on API traffic by default.
  • Resend Inc. (USA) — transactional emails (verification codes, password reset, receipts).

5. Where data is stored

All primary data (workspaces, KB articles, conversations, vectors) lives on servers in Falkenstein, Germany (EU). Sub-processor data flows are limited to what's strictly necessary for that function.

6. How long we keep it

  • Account data: while your workspace exists, plus 30 days after deletion for backup retention.
  • Conversation messages: configurable per-workspace from 7 to 365 days (default 90). After that period messages are deleted.
  • Payment records: retained for 10 years as required by Turkish tax law.

7. Your rights (GDPR + KVKK)

Under GDPR (EU) and KVKK (Türkiye), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and personal data (some payment records retained as legally required).
  • Export your data in a portable format (JSON).
  • Withdraw consent for marketing emails (we don't send any by default).

To exercise any of these, email privacy@askmana.com from the email registered to your account. We respond within 30 days.

8. Cookies

We use a single first-party cookie (NEXT_LOCALE) to remember your language preference, plus secure session cookies for authenticated users. No third-party tracking or advertising cookies.

9. Changes to this policy

Material changes will be announced via email to workspace owners at least 30 days before they take effect. The "Last updated" date at the top reflects the latest revision.

10. Contact

Privacy questions: privacy@askmana.com
General contact: hello@askmana.com

Privacy Policy · AskMana · AskMana