superbot
back

superbot.gg privacy notice

Version 2026-09-24. What superbot collects, where it goes and how long we keep it. For superbot, this notice replaces the general EZO Labs Inc privacy policy at ezolabs.io.

The short version

In detail: account and billing, imports, connections, chats and files, calls and teams, logs, who processes it and your rights.

Short view

1. Who we are

The controller of your data is EZO Labs Inc, 1007 N Orange St, 4th Floor, Suite 5765, Wilmington, DE 19801, USA. For a privacy request or question, email privacy@superbot.gg.

2. What we collect, and what happens to it

The Helper on your computer reads some kinds of data only after you allow it, and each item's When line says which. Our servers create the rest as you use superbot. Open a group to see each item: what it is, when we collect it, where it goes and how long we keep it (Kept).

Account and billing

Sign-in, payment and invites 4 items

Account and billing identity

Your account id, email address, sign-in session token, device records (name, kind, a short network fingerprint and push token) and payment records.

When
When you create the account, add a device or pay
Where
Held on our servers. Card details are held by Stripe; we keep only Stripe's customer, subscription and payment-method references.
Kept
Until you delete the account. Billing records are kept after that (see "Deleting your account" below); we have no automatic deletion schedule for them.

Auto-recharge settings

Whether auto-recharge is on, the amount per charge and the monthly cap.

When
Off until you turn it on at /account/billing
Where
Held on your account. Stripe makes each charge on the payment method it saved at checkout.
Kept
Until you delete the account.

Beta invites, TestFlight and referrals

Invite codes and invited emails (stored as keyed hashes), the email on a pending pass, your Apple ID email if you ask for TestFlight, and your referral code and its uses.

When
When you are invited, redeem a code, ask for TestFlight or refer someone
Where
Our servers. Your Apple ID email is sent to Apple to invite you to TestFlight.
Kept
The email on a pass only as long as the pass. We have no automatic deletion schedule for TestFlight and referral records.

Profile picture

The image you upload as your avatar.

When
When you upload one
Where
Our servers. Anyone with its link can open it.
Kept
Until you replace it or delete the account.

Things you choose to import

Read only once you allow it 6 items

Browser cookies and site storage

The cookies and site storage of each browser profile you import, sealed on your device before it leaves it.

When
Opt-in: off until you allow session import. Then every 12 hours, and when you ask.
Where
Sealed under a key only your devices hold, so we cannot read it. We can see which site each row is for.
Kept
Until you delete the row or the account. See "Deleting a vault item" below.

Saved passwords

Entries from 1Password, Bitwarden, LastPass, KeePass, Chrome, Chromium and Firefox. Your macOS Keychain is looked up only for the site being signed into, never listed.

When
Opt-in: off until you allow the password scan. Then once a day and at startup.
Where
Sealed under a key only your devices hold, so we cannot read the passwords. We can see the site, the password manager and the username of each row.
Kept
Until you delete the row or the account. See "Deleting a vault item" below.

SSH private keys

The private keys in your ~/.ssh folder, keyed by their public fingerprint.

When
Opt-in: off until you allow the password scan (the same permission). Then once a day.
Where
Sealed under a key only your devices hold, so we cannot read them.
Kept
Until you delete the row or the account.

MCP server headers

The authentication headers of MCP servers you add, and of servers set up in your other apps if you allow config import.

When
Config import is off until you allow it. Headers you add yourself are sent when you add them.
Where
Imported headers are sealed on your device, and we cannot read them. Headers you add by hand reach us in cleartext over an encrypted connection; we store them encrypted, and our servers can read them.
Kept
Until you delete the server or the account.

Imported chat histories

Your Claude, Codex and Cursor conversation files, and chat-export archives in Downloads, Desktop and Documents.

When
Opt-in: off until you allow chat import. Then every 5 minutes.
Where
Stored on our servers as readable text, so search and your other devices can use it. No redaction runs over the messages.
Kept
Until you delete the import or the account.

Session presence

Whether your browser is signed in to a short fixed list of delivery and restaurant services (yes or no per site).

When
At startup, only if you allowed session import or the password scan
Where
Sent to us as a list of those sites.
Kept
We keep it in memory only while your device is connected. Deleting your account removes it.

Connections and publishing

Services you link or publish to 6 items

Model-connection credentials

The sign-in or API key for each model provider you connect.

When
When you connect a provider
Where
A sign-in sealed on an enrolled device is used only through your device, and we cannot read it. An API key you paste is stored encrypted, and our servers decrypt it to make each request that uses it.
Kept
Until you disconnect the provider or delete the account.

Custom endpoints and external APIs

The address and key of each endpoint or API you add, such as OpenRouter, DeepSeek, Hugging Face, Perplexity or any compatible URL.

When
When you add one
Where
Stored encrypted under a key we hold. We hold your key so we can call the endpoint for you: our servers decrypt it and make each request, so the request passes through us.
Kept
Until you remove it or delete the account.

Git provider tokens

GitHub and GitLab tokens you paste into the Helper or grant through a device sign-in. A token held by the gh or glab command-line tool stays on your Mac and is never uploaded.

When
When you connect Git with a pasted token or a device sign-in
Where
The Helper seals them on your device under a key only your devices hold, so we cannot read them. Older Helper versions sent them in cleartext over an encrypted connection, and we stored those encrypted under a key our servers hold, so we could read them. The current Helper replaces such a copy with a sealed one when it next starts.
Kept
Until you disconnect Git or delete the account. See "Deleting a vault item" below.

Connected accounts

Sign-in tokens for Google, GitHub, Notion, Slack and similar services you connect, and what the assistant reads through them for a task.

When
When you connect one
Where
Stored encrypted. When a task uses the connection our servers make the call, so we see what the service returns.
Kept
Until you disconnect it or delete the account.

Published apps

The access grant for your Cloudflare or Railway account. Your app's code, content, logs and analytics stay in your account with that provider.

When
When you connect Cloudflare or Railway
Where
The grant is sealed on your device, and we cannot read it. Deploys run from your Mac, and your list of apps is kept on your Mac.
Kept
Until you disconnect the account. See "Deleting a vault item" below.

superbot.sh addresses

For each visit to an app at a superbot.sh address: the address, the method, the visitor's country, the status, the timing and the size. Not the IP address, path, query, cookies or headers.

When
Always, for apps on a superbot.sh address
Where
Cloudflare's analytics and our own log store.
Kept
Our copy 90 days.

Your chats and files

What you write, save and make 10 items

Sync data

Your chats with the full text of every message, projects (including the folder path on your computer), rules, skills and context documents, MCP servers, settings, spaces, shares and access grants.

When
Whenever a signed-in device saves a change. Chats sync while Sync chats across devices is on. It is on by default, and you can turn it off.
Where
Stored on our servers, encrypted at rest under a key we hold, so we can read it. It is not end-to-end encrypted.
Kept
No automatic deletion. Deleting an item stops it syncing; see "Deleting a vault item" below.

Project folder mirror

The files in a project folder you choose to mirror, as a git repository.

When
Opt-in: off until you turn it on for a project
Where
Stored on an encrypted disk on our servers, and our servers can read it. The copy on your Mac is not encrypted.
Kept
We have no automatic deletion schedule, and deleting your account does not yet remove it. Ask us through section 7.

Finished replies

A copy of each finished reply and the id of its chat session, so an app that dropped its connection can still pick the reply up.

When
For every reply, for every user
Where
Our servers.
Kept
Up to 24 hours, then deleted.

Uploads and attachments

Files you upload or attach to a chat.

When
When you attach one
Where
Our servers.
Kept
7 days by default, and never more than 30 days.

Screenshots and screen recordings

Screens the assistant captures when a task asks it to, and recordings you start.

When
Off unless you turn computer use on
Where
Uploaded to your workspace.
Kept
Until you delete the artifact or the account.

Monitoring summaries

Summaries of mail, messages and calendar items the assistant prepares from your own connected accounts.

When
Off unless you switch monitoring on
Where
Held on your account.
Kept
Until you delete them or the account.

Cloud agent runs

The instructions you give a cloud agent, its status, summary and output files, and the repository and access you give it.

When
When you start a cloud run
Where
Runs in containers on our servers. The run record is stored on our servers.
Kept
We have no automatic deletion schedule, and deleting your account does not yet remove run records. Ask us through section 7.

Super mode runs

The run record of a super mode message, and a working folder for its agents.

When
When you use super mode
Where
Our servers, which send each leg to its provider.
Kept
Working folder 24 hours. The run record stays until you delete your account.

Media generations

The prompt you give and the image, video, audio or 3D file that comes back.

When
When you ask for one
Where
Sent to the provider that makes it (section 5). The file is stored on our servers and served from an unguessable link that anyone with the link can open.
Kept
We have no automatic deletion schedule for generated files.

Shared chat links

A chat you choose to share by link.

When
When you share one
Where
Anyone with the link can open it.
Kept
The link stops working after 30 days by default, and never lasts more than 365 days.

Calls, voice, rooms and teams

Voice, phone and shared spaces 5 items

Voice sessions

Your live microphone audio, and the text of the assistant's spoken replies.

When
Only during a voice session you start
Where
Audio streams through our servers to Deepgram for transcription. Reply text goes to ElevenLabs for speech. Both run under our accounts with them.
Kept
We do not store the audio. The transcript is kept with the conversation. A session log (ids and times) has no automatic deletion schedule.

Calls, text messages and faxes

The numbers, times, duration, status and outcome of each call, and the text of each message and fax record.

When
When you place or receive one
Where
Telnyx carries them, ElevenLabs voices the calls, and Twilio carries text messages in rooms. The records are stored on our servers.
Kept
No automatic deletion. Deleting your account removes text-message records. Call and fax records are not yet removed with the account, so ask us through section 7.

Voice clones

A recording you upload to make a voice clone, and the speaker's consent record.

When
When you make a clone
Where
The recording goes to ElevenLabs. We keep a fingerprint of it and the consent record.
Kept
Until you delete the account. Deleting it removes our fingerprint and the consent record, and asks ElevenLabs to delete the voice.

Rooms

Messages, members and email invites in a shared room.

When
When you join or create a room
Where
Our servers. Other members of the room can see them.
Kept
Messages 180 days. The room text-message log 90 days.

Teams and organisations

Team name, members, roles and directory groups, signed policy revisions and the receipts devices send when they apply them, the team's pooled rules, skills and MCP servers, and the team vault.

When
When you create or join a team
Where
Pooled rules, skills and MCP servers are encrypted under a key our servers hold, so we can read them. Team vault items are sealed under a team key only members' devices can open, so we cannot read them.
Kept
Until you delete the account. Deleting it removes you from each team and deletes a team you were the only member of. A team with other members keeps its own records, and items you added to its vault are revoked, but their encrypted copies stay. The last owner must hand over ownership first. A member the team removes is kept as a removal record.

Logs and diagnostics

Records of how it runs 7 items

Request logs

For each request to our servers: the time, path, status, timing, browser and network fingerprints, your account and device ids, and your IP address as a keyed hash. The words you send to a tool and the reply it gets are kept only if you turn on Share chat text. Without it they are stored empty.

When
Always, while you use the service
Where
Our own log store.
Kept
180 days.

Model request records

For each model call our servers make: the model, the timing and the outcome. The reply and any error text are kept only if you turn on Share chat text. Without it they are stored empty.

When
Always, while you use the service
Where
Our own log store.
Kept
180 days.

Product telemetry

Device events (install, locale, time zone, a count and sample of your installed apps, heartbeats). The prompt, reply and any error of each turn (about the first 4,000 characters in and 2,000 out) are kept only if you turn on Share chat text, and we use them to fix bugs. Without it that text is stored empty.

When
Device events automatically. Share chat text is off until you turn it on.
Where
Our own telemetry store.
Kept
Device events 365 days. The latest record per device 730 days. Conversation text 180 days.

Helper relay and tool logs

The full request and reply of each model call the Helper relays for you, and the arguments and results of each tool it runs on your computer, including jobs our servers send to it. Also the timing and size of each piece of a streamed reply, and the journal of each agent session the Helper runs, with its messages. The text in these records (requests, replies, tool arguments and results, and session messages) is kept only if you turn on Share chat text. Without it that text is stored empty.

When
Automatically while the Helper runs
Where
Our own telemetry store. It is not end-to-end encrypted.
Kept
Request and reply bodies 180 days. Streamed-reply timing 90 days. Agent session journals 180 days. Tool calls 365 days. Request summaries and Helper events 400 days.

Model gateway logs

The prompt of each model call we send through our model gateway, including its instructions, message history and tool definitions, and metadata for each request (model, timing, size and outcome).

When
Always, for calls through our gateway. Share chat text does not turn this off yet.
Where
Our own gateway log store, for debugging. It is not end-to-end encrypted.
Kept
Prompts about 15 days, and up to about 45 days while storage partitions age out. Request metadata 200 days. Deleting your account does not remove them sooner.

Crash reports

Error and crash reports from the desktop and mobile apps, sent without your account or device identity. No request bodies.

When
On by default in released apps. You can turn it off with Send crash reports.
Where
Sentry. We set it to discard IP addresses and location.
Kept
Sentry's retention applies.

Bug reports

What you write, and any screenshot, pasted image or screen recording you attach.

When
When you send one
Where
Our servers.
Kept
180 days, or until you delete it or the account. A summary without the attachments is kept 730 days.

Retention. Where an item gives a period, it is deleted on that timer. Otherwise it stays until you delete it, and deleting your account removes it only where the item says so. The law may also require us to keep some records.

Deleting your account also reaches our analytics and logs. Rows tied to your account are hidden within a day and physically removed within 30 days, and our log files are scrubbed of them. We keep the billing ledger, payment events behind invoices already issued, metered usage behind charges already billed, the record of your deletion request, and Stripe's own records as our payment processor. Rows stored without your account, because you anonymized your data or sent them without signing in, cannot be found by your account, so deleting it does not remove them. They expire on their own timers.

Deleting a vault item revokes it at once, but its encrypted copy stays in an append-only record until you delete your account. We can see which sites and account names you hold credentials for, not the secrets.

Anonymize my data is on by default in new installs, and you can turn it off. While it is on, analytics and log rows are stored with no account id and no free text, and your device id is replaced by a keyed hash. The key is held only in memory and discarded at each UTC midnight, so one day's rows cannot be joined to the next. Two records keep the raw device id, without your account: the latest record for each device, and our security events. It does not cover your account, billing, the chats and credential vault you choose to sync, the keys of custom endpoints you add, a bug report you file, or model gateway logs. With it off, telemetry is tied to your account and device.

Training. Superbot does not use your conversations, prompts, files or code to train or fine-tune any model. When you connect your own vendor account or key, that vendor's terms and your settings with them apply. Some models we run for you are provided by vendors (section 5) under their own terms.

The apps use no advertising or product-analytics service. Our web pages may use Google Analytics (section 4).

3. What the Helper reads

The Helper reads nothing from your browsers, password managers, ~/.ssh folder or other AI apps until you allow it. Each is a separate permission:

How often each runs, where it goes and how long we keep it is under things you choose to import. Turning a permission off stops future reads. Delete what was already synced in your vault.

4. Cookies

superbot sets one first-party, strictly necessary cookie, sbk, which holds your sign-in session for up to 90 days. There are no advertising cookies. Clearing it signs you out. Where Google Analytics is on (below), it may set its own first-party _ga cookies.

Google Analytics

Our web pages (superbot.gg, beta.superbot.gg and this site) may use Google Analytics 4 to count visits and sign-up steps: the pages you view, with invite codes, one-time codes, tokens and email addresses removed from every address before it is sent, the links and buttons you click, your approximate location and your browser and device type. Email addresses and codes are never sent. In the EEA, the UK and Switzerland analytics storage is off by default, so no analytics cookie is set there. All of Google's advertising features are off: no Google signals, no ad personalization, no ad storage. The apps do not use Google Analytics. To opt out on any site, install Google's opt-out browser add-on.

5. Who else processes your data

Each processor receives only what its purpose needs:

Some processors are in the United States. Transfers out of the EEA or the UK rely on the Standard Contractual Clauses, or on the EU-US Data Privacy Framework where the processor is certified under it.

6. Services you connect

Model providers and endpoints you connect (including each leg of a super mode message), MCP servers and connected accounts such as Google, GitHub, Notion and Slack, Cloudflare and Railway when you publish, and sites the agent signs in to for you each receive your data because you connected them. Each is a separate controller under its own terms. Disconnect a credential in your account to stop future requests.

7. Your rights, and how to make a request

You can ask for a copy of your data, or ask us to correct, delete, restrict or move it, or object to a use of it. Use the export and delete controls at /account, or email privacy@superbot.gg (also if you cannot sign in).

Export your data at /account gives you a copy that includes your conversation turns, relay messages, device events and bug reports, up to 1,000 of the newest rows of each. Rows stored without your account are not in it.

Requests are free, and we may confirm your email first. We answer within 30 days in the EEA and the UK (GDPR Art. 12(3)) and within 45 days everywhere else (CCPA §1798.130). We extend only by telling you before the deadline. You can also complain to your data protection authority.

We do not sell your personal data or share it for advertising. We may make de-identified or aggregated data from how superbot is used, data that cannot reasonably be linked to you or your household, and use, share or sell it. We keep that data de-identified, do not try to re-identify it, and require anyone who receives it to promise the same in writing (CCPA §1798.140(m)). Before we first sell any, we email you as section 11 describes.

8. Automated decisions

No decision about you, such as your billing, your account standing or deleting your data, is made solely by automated processing with a legal or similarly significant effect (GDPR Art. 22). If an automated step gets something wrong, ask us through section 7 and a person will review it.

9. Children

superbot is for people aged 13 or older, and you must be 18 or older to buy. We do not knowingly collect data from anyone under 13. If you believe a child has given us data, write to privacy@superbot.gg and we will delete it.

10. Security

Only your devices can read

Sealed on your device under a key only your devices hold, so we cannot read them:

  • browser sessions
  • saved passwords
  • SSH keys
  • imported MCP headers
  • publishing grants
  • team vault items
  • Git tokens the current Helper sends
  • model sign-ins sealed on an enrolled device

We can read

Encrypted at rest under keys our servers hold:

  • synced chats and settings
  • pasted API and endpoint keys
  • Git tokens an older Helper sent
  • MCP headers you add by hand
  • connected-account tokens
  • project mirrors

Stored as readable data:

  • imported chat histories
  • logs and telemetry

If a breach is likely to put your rights at risk, we tell the supervisory authority within 72 hours and tell you without undue delay (GDPR Art. 33 and 34). Report a security issue to security@superbot.gg.

11. Changes

We may change this notice at any time, and publish each change here with a new version date. A minor change, such as a correction or a clarification, takes effect when we publish it.

A material change is emailed to you before it takes effect: at least 30 days before if you live in the EEA or the UK, and at least 7 days before everywhere else. Material changes include any new recipient or processor of your data, any new transfer of it out of the EEA or the UK, any new purpose, any new class of data and any longer retention. The email links to the new version, says what changes and the date it takes effect. Where the law needs your consent, we ask for it.

If you do not accept a material change, you can delete your data or account before it takes effect, and a consumer can end a paid plan free of charge with the refund in section 12 of the terms.

Change log.