Skip to content

Security and data

Where your customers’ conversations go

The people who ask this run clinics, schools and practices. Here is where Sublex Chat keeps what your customers write, who can read it, and how long it stays. Including the parts that are ordinary.

The guarantees

The four that matter

Each one is enforced by the database itself, not by code remembering to. That is the difference between a promise and a guarantee.

One business cannot see another's data

Every table is protected by row-level security in the database itself. A query that forgets its filter returns nothing, not somebody else's customers, and an automated test suite proves that against a real database.

Our own staff cannot read your conversations

Not for support, and not while looking at your account. The support view excludes the tables holding messages, leads, and private notes, by the same database rules, so this is not a promise we could quietly stop keeping. Your transcripts are yours.

Nothing is used to train a model

Your customers' messages go to the AI provider to produce that one answer and for nothing else. We do not sell data or build a model out of your business.

Contact details are hidden by default

Phone numbers and email addresses are masked in the transcripts your team reads. They appear in full on the leads screen, where calling the person back is the point, and you can switch the masking off.

On your own website

What the script you paste can and cannot do

Adding somebody's code to your site is an act of trust. Here is exactly what ours does there.

It cannot slow your site

The line loads async, after your page, and the loader is under five kilobytes over the wire. Your pages render exactly as they did before.

It cannot touch your page

The widget draws inside its own sealed shadow root. It cannot read or change your pages, your forms, or anything your visitors type outside the chat window.

The key in it is not a secret

It is public by design and grants one thing: chatting with your assistant. Your domain allowlist decides which sites may use it, enforced on our servers.

What it knows about the page

Which page of your site the visitor is on, as host and path only. Never the query string, where addresses and booking references live.

The specifics

The ordinary details

Less dramatic, and exactly what a data question wants answered.

Where it is stored
Our database, file storage and sign-in run on Supabase, hosted in the EU. Answers are generated by an AI provider whose processing may happen outside that region. We keep what is sent to it to the question being answered and the material you gave us.
Who you are trusting
Sublex Chat is the processor and you are the controller: they are your customers, and the data is yours. Our subprocessors are listed in the privacy policy: the database and sign-in, the hosting, the AI and search providers, the email service, the payment provider, and error monitoring.
How long it is kept
For as long as you want. Retention is a setting on your account: pick a period and older conversations are deleted automatically, leads and messages included. It is off by default, so nothing is deleted until you say so.
Card details
We never see them. Payments run through Paddle as merchant of record; card numbers are entered with them and never reach us.
What we never put in an email
A customer's message. Notifications say a conversation needs a person and link to it behind your sign-in. Our error reports follow the same rule: request bodies, cookies, and headers are stripped before anything leaves.
Addresses
We rate-limit abuse using a one-way hash of a visitor's network address. The address itself is never stored in a form anyone can read.

Said before you sign

What we have not built yet

Data residency inside your own country, single sign-on, and a signed uptime commitment are real requests, and none of them exists today. If your organisation needs one before it can buy, ask us, and we will answer honestly before you sign anything.

If you find something

Tell us, and you will get a straight answer

Write to info@sublexdigital.com with “security” in the subject, and you will hear back within two working days. Please work against your own account and stop at the point of proof — if you reach something that is not yours, that is the finding, and you do not need to go further to show it matters. There is no bounty; there is credit, if you want it, and a straight answer either way.

The formal versions of all of this are in the privacy policy and the data processing addendum. A question they do not answer is worth asking us directly: info@sublexdigital.com.