1. Who this notice covers
SwitchCase Studios operates Companion. This notice covers the Companion website, dashboard and embedded chat, and explains information we handle about account users and visitors. Contact us at hello@switchcasestudios.com with “Companion privacy” in the subject line.
For account administration, service security and our own business communications, we determine the purposes of processing. When a business uses Companion to answer its visitors’ questions, that business determines what content to index and how to configure support and analytics; we process its visitor data to provide the service. That business’s privacy notice also applies. Send requests about its support records to the business first; we can assist it where appropriate.
2. Information we receive
- Account and workspace details: authentication identifiers, account contact and profile information supplied through Clerk or the selected sign-in provider, organization membership, settings and service usage. We do not receive your Google or GitHub password.
- Knowledge content: uploaded documents, images, video clips, supplied or extracted transcripts, text, selected website pages, source URLs, titles, extracted passages, indexing metadata and numeric representations used for retrieval. An upload can contain personal data; Customers must decide what is appropriate to make available through their assistant.
- Cloud file connections: the provider you connect, encrypted access and refresh credentials, selected file and folder identifiers, names, formats, sizes, revision metadata, sync schedules, errors, imported document content and import usage. Folder sync includes supported documents in the selected folder and its subfolders, within the limits shown in the dashboard. You authorize a connection at Dropbox, Google Drive or OneDrive; we do not receive your cloud account password.
- Chat and support: questions, generated answers, source citations, feedback, timestamps, session identifiers, escalation choices, ticket details and name and email shared through the contact form. A Customer may require contact details before starting a chat. Its administrators can review its conversations and the contact details the visitor agreed to share.
- Requested transcript emails: when enabled, the saved recipient address, any business-copy address, the transcript requested for sending, timestamps and provider processing status. Administrators can review the email audit for their companion.
- Optional voice input: when a Customer enables voice input and a Visitor starts it, the Visitor’s browser or device speech service processes microphone audio. Companion does not receive or store that audio. We receive the resulting text only after the Visitor reviews and sends it, and then handle it like a typed chat question.
- Optional usage analytics: page origin and a reduced path, coarse device/browser category, interaction stages such as opening chat, asking a question and beginning or submitting a ticket, an encrypted IP address, masked network prefix and workspace-scoped network hash. Paths have query strings removed and common identifying segments redacted, but a custom path may still reveal context.
- API and MCP access: key names, non-secret prefixes, hashed keys, permissions, companion scope, creation and expiry times, revocation, last operation time and usage totals. Text-creation retry records retain content hashes and reference IDs for 24 hours; cleanup runs periodically. Query text is sent to the retrieval service when searching, but is not saved as a Companion conversation by these endpoints.
- Billing details: selected plan, subscription and payment status, billing periods, complimentary grant status and timing, internal grant reason and operator record, and Stripe customer, checkout and subscription identifiers. Stripe collects payment method and billing information in its checkout and billing portal. Companion does not receive or store full payment card numbers. Stripe processes this information under its Privacy Policy.
- Operational data: requests, security signals, errors, network information processed by hosting and authentication services, and information you send when contacting us. Integration secrets are used to authenticate configured services and are not exposed in public embed configuration.
3. Why information is used
We use information to authenticate users, isolate workspaces, store and index content, import and refresh selected cloud documents, retrieve relevant passages, generate answers, provide configured support handoffs, prevent abuse, troubleshoot errors, enforce usage limits, process subscriptions and payments, respond to requests and meet legal obligations. Optional analytics help the Customer identify unanswered questions, support needs and where visitors leave a flow.
Names and emails entered through a pre-chat or optional contact form are linked to that conversation when the visitor agrees, so the Customer can follow up about support. These contact fields are not included in AI prompts or shared answer-cache payloads. Email addresses are visitor supplied and are not verified. When the business enables transcript email, a visitor can explicitly request a copy at their saved email address. The business may configure a blind copy to its own address; the request screen explains that a business copy may be sent. Closing the chat does not request an email. Ticket details are collected for the support request the visitor chooses to submit. The app does not infer sensitive traits, match identities across unrelated Customers, or make automated decisions with legal or similarly significant effects. We do not sell personal information or use it for cross-context behavioral advertising.
Where a data-protection law requires a lawful basis for our own processing, we rely on performing our agreement for account services, legitimate interests in operating and securing the service where balanced against individuals’ rights, legal obligations where applicable, and consent for processing that requires it. Customers must establish their own appropriate basis for visitor processing; our settings do not replace that responsibility.
4. AI, storage and other recipients
To answer a question, relevant source passages, the question and conversational context may be sent to OpenAI. Selected source text and query text may also be processed by the configured embedding or vector service. Companion uses retrieval-augmented generation, not a separate model trained on each Customer’s documents. Our application does not run model training on visitor conversations. Provider handling and retention are governed by their applicable contracts and settings; disabling response storage in our API requests is not a promise of zero provider retention.
Optional chat voice input uses speech recognition supplied by the Visitor’s browser or device. Depending on that browser and its settings, microphone audio may be processed by the browser provider’s online speech service under that provider’s terms. Companion does not send that audio to our API or OpenAI and does not store it. The recognized text enters Companion only when the Visitor chooses to send the question.
When a Customer enables media extraction, an uploaded image or audio extracted from an uploaded video is sent to OpenAI for description or transcription. The resulting text is stored and indexed for retrieval. Supplying your own description or transcript avoids that extraction call. Referenced uploads can be viewed by chat visitors; media files are loaded on request through an authorized conversation. External video links open the original provider, whose privacy terms apply. We do not automatically download linked videos or analyze their visual frames.
| Provider | Role in Companion |
|---|---|
| Clerk; your selected identity provider | Sign-in, sessions and organization access |
| Microsoft Azure; Fly.io | Website delivery, API and background processing |
| Microsoft Azure Communication Services | Requested transcript email delivery, including configured business copies |
| Railway / PostgreSQL | Workspace settings, sources, conversations, profiles and operational records |
| Cloudflare R2 | Uploaded files, crawl content and public avatar images |
| Upstash | Vector retrieval and expiring answer caching |
| OpenAI | AI responses, optional image analysis and video-audio transcription, and embedding operations where configured |
| Stripe | Subscription checkout, payment processing, invoices and customer billing management |
| Google Fonts | Font delivery; requests may disclose IP and browser information to Google |
| Customer-selected cloud storage, such as Dropbox, Google Drive or OneDrive | Read access to selected files, folder listings and revision metadata for imports and scheduled syncs. Provider files are not modified. Imported copies are stored and indexed by Companion using the services described above. |
| Customer-selected helpdesk, such as Zendesk or Freshdesk | Ticket details and a transcript only when the visitor includes it and submits the request |
Cloud account access controls do not carry over to an imported reference. By selecting a file or folder, you make its imported content available to your companion’s answers and any authorized API or MCP clients. Select only content you are entitled to share in those channels. Syncing is periodic, so provider changes may not be reflected until the next successful sync. These connections request read access and do not edit or delete your originals.
Enabling API or MCP access lets clients holding an authorized key receive source metadata and indexed passages from its selected companion. Write-enabled keys can add text knowledge. Those clients process returned content under their own terms and privacy practices; review the client before sharing a key. These endpoints do not provide access to visitor conversations or customer profiles.
Customer administrators receive their workspace’s records. Citations can expose indexed passages; avatars are publicly accessible by design. Links to ticket portals or source websites lead to independently operated services with their own practices. We may disclose relevant information to professional advisers, to comply with valid legal requirements, to protect people or rights, or in a business transaction subject to applicable safeguards and notice requirements.
5. Cookies, analytics and your choices
Authentication uses cookies and similar session technologies supplied by Clerk and the selected identity provider. Browser settings can block or clear cookies, but this may prevent sign-in. The optional installed app stores a public offline fallback; it does not intentionally cache private dashboard or chat API responses for offline access.
When enabled by the Customer, embedded chat collects optional usage analytics when a chat session starts, including when an inline panel loads. The chat shows a notice and “Privacy & choices.” Use that control to turn off analytics and remove that session’s existing usage data. Supported Global Privacy Control and Do Not Track signals disable optional widget analytics at session creation. Customers can also disable collection for their companion. These choices do not disable the processing needed to deliver chat, authentication or infrastructure security.
A business may require your name and email before a conversation starts or offer optional contact sharing. The form explains the purpose and asks for your agreement. Shared details stay associated with the conversation. The chat’s reset control deletes its conversation and associated saved details. Deleting a conversation does not delete tickets already delivered to another platform; contact the business about those records. An inline panel lets you start a fresh session after deletion. For other privacy requests, see the contact instructions below.
Browser signals are not used to authorize optional processing. Where consent is legally required before collection, the website operator must obtain it before loading the widget or disable optional analytics. Do not enter sensitive information in questions or upload it as public knowledge.
6. Retention and deletion
The current service schedules regular cleanup using the following periods. Cleanup is asynchronous, so removal may follow the expiration time during the next successful maintenance run.
- Conversations, messages and linked profiles: the Customer selects a period from seven to 30 days on Free or Basic, or seven to 90 days on Pro, from the start of the conversation. Every plan defaults to 30 days, or sooner when deleted. Workspace access is limited by the current plan. A downgrade hides older records but preserves their previously selected deletion deadline; an upgrade can restore access only while those records remain retained. Shortening the saved period removes older history; extending it does not recover records already deleted.
- Transcript email audit: encrypted addresses and the requested transcript, with sending status and timestamps, follow the conversation's retention and deletion. Separate delivery counters prevent abuse and enforce sending limits. Deleting a chat cannot recall copies already sent to a recipient or the business's mailbox.
- Optional analytics: encrypted full IP addresses expire after seven days; usage events, masked network data and context expire after no more than 30 days, or the shorter conversation retention. Visitors can remove a session’s usage data earlier.
- Sources: maintained while needed for the Customer’s active knowledge. Archived sources are excluded from new retrieval and scheduled for permanent removal after seven days unless restored. Removing a source does not remove historical messages, previously generated answers or copies a visitor already received.
- Cloud connections and imported files: disconnecting an account removes its stored access and refresh credentials, stops its syncs and archives its imported knowledge in that companion. Removing a knowledge set archives that set’s imported files. Successful folder syncs archive files no longer present in the selected folder; incomplete scans do not treat missing files as deletions. Archived copies follow the source retention period above. You can also revoke Companion’s authorization in the cloud provider’s settings. Neither action deletes originals in your cloud account.
- Temporary data: website previews expire after 24 hours. Eligible general-question answers may be cached for up to 24 hours, with invalidation when knowledge changes. This answer cache is scoped to a companion and is not a shared personal profile.
- Account, configuration and operational records: kept while the account or purpose remains active, or as needed for security, dispute resolution and legal requirements. Contact us about workspace closure. We assess records that must be retained separately.
Provider logs, disaster-recovery backups, legal holds and independently submitted helpdesk tickets may follow different schedules. Public avatar images may remain in browser caches temporarily after replacement. We do not promise immediate erasure from every provider or a recipient’s independent copy.
7. Privacy requests and complaints
Depending on applicable law, you may have rights to access, correct, delete or receive a copy of your personal data; restrict or object to processing; withdraw consent without affecting earlier lawful processing; appeal a denied request; and complain to your local data-protection authority. We do not discriminate against people for exercising applicable rights.
You can object to processing based on legitimate interests by contacting us. To make a request, email hello@switchcasestudios.com. Tell us whether you are an account user or a visitor and identify the relevant website or workspace. We may request proportionate information to verify identity or an authorized agent’s authority, and will respond within applicable legal deadlines. Do not send passwords, government IDs or extra sensitive data unless a secure, necessary verification process has been agreed.
When the Customer controls the requested records, we may direct the request to it or assist under its instructions. Some requests may be limited by another person’s rights or a legal retention requirement; we will explain applicable restrictions.
8. Security, locations and children
We use controls including authenticated administration, logical separation by workspace and companion, website-origin restrictions for widgets, TLS for network connections, and encryption of integration secrets and retained full IP addresses. No service is completely secure. Report suspected exposure promptly to hello@switchcasestudios.com. We will provide incident notices when required by applicable law.
SwitchCase Studios is based in the United States. Service providers may process information in the United States and other countries with different data-protection laws. Customers that require a specific data location, processing agreement or transfer mechanism should contact us before deployment. This notice does not represent a data-residency guarantee, certification or executed international-transfer agreement.
Workspace administration is for adults. Companion is not directed to children under 16, and Customers must not knowingly use it to collect their information. If you believe a child’s data has been submitted, contact us or the relevant business so the records can be investigated and removed as appropriate.
9. Updates and contact
We will update the date and version when this notice changes, and provide additional notice or obtain consent for material changes where required. A later notice does not retroactively authorize an incompatible use of previously collected information.
Contact SwitchCase Studios at hello@switchcasestudios.com or visit switchcasestudios.com. This notice applies specifically to Companion; the studio’s main website has its own privacy notice.