Privacy & security

How SupportPrime AI handles your data

This page is maintained by the SupportPrime AI team to answer common security and privacy questions about the product. It describes the controls that are actually enabled in the application today. It is not an audit report, a certification, or independent verification of any kind.

Demonstration workspace. The tickets, customers, CSAT scores and AI impact figures in this app are generated sample data. No real end-customer support conversations are stored in the demo, and no claims on this page should be read as regulatory compliance, certification, or a guarantee of outcomes.

Access and authentication

  • Every workspace is behind email/password or Google sign-in. Application pages other than the marketing site and this page require an authenticated session.
  • Data is scoped per account at the database layer with row-level security policies, so one workspace cannot read or modify another workspace's tickets, articles, automation rules, teammates or settings.
  • Sessions are issued and refreshed by the managed authentication service; tokens are stored by the browser client and cleared on sign-out.
  • Passwords are never stored by the application itself — authentication is delegated to the managed auth provider.

Platform and hosting

  • The application runs on Lovable Cloud infrastructure. Application traffic is served over HTTPS/TLS.
  • The database, authentication and file storage are provided by the managed Postgres backend that ships with Lovable Cloud.
  • Database credentials and service keys are held as server-side secrets and are never exposed to the browser bundle.
  • Server-side logic runs in an isolated serverless runtime rather than on shared long-lived servers.

These are platform capabilities we rely on. They describe how the product is built — they are not a certification of the platform or of this application.

What data the app stores

  • Account data: your email address, display name and workspace profile.
  • Support content: ticket subjects, message bodies, customer names and emails you enter or import, categories, priorities, statuses and SLA targets.
  • Operational data: knowledge base articles, automation rules, teammate records, report schedules and AI preference settings.
  • We do not ask for or intentionally store payment card data, government identifiers, or health records in support tickets. Avoid pasting those into ticket bodies.

AI processing

  • In this demonstration build, ticket summarisation, priority suggestions, sentiment detection and reply drafting are produced by deterministic in-app logic. Ticket content is not sent to an external model provider.
  • AI suggestions are advisory. A person reviews and sends every reply — nothing is sent to a customer automatically.
  • If a live model provider is enabled in a future release, this section will be updated to name the provider and describe what content is transmitted.

Subprocessors and integrations

  • Lovable Cloud — application hosting, database, authentication and storage.
  • Google — optional single sign-on, only when a user chooses to sign in with Google.
  • Report exports (PDF/CSV) are generated locally in your browser and are not uploaded anywhere unless you explicitly send them.

Ask us for the current subprocessor list before relying on it contractually.

Cookies and analytics

  • The app sets storage entries required to keep you signed in and to remember interface preferences such as sidebar state and onboarding progress.
  • No third-party advertising or cross-site tracking pixels are used in the application.

Retention and deletion

  • Support records stay in your workspace until you delete them. Deleting a ticket, article, rule or teammate removes that row from the database.
  • Teammates and report recipients can be removed at any time from Settings, which stops them receiving scheduled reports.
  • To delete an entire workspace and its data, contact us using the address below and we will remove the account records.
Manage workspace data

Privacy requests

  • You can request a copy of the data held in your workspace, ask for corrections, or request deletion by emailing the contact below.
  • We will confirm receipt of the request and tell you what we can action and in what timeframe.
  • If you are handling personal data of people in a regulated jurisdiction, review your own obligations — this app is a tool you operate, and you remain the controller of the customer data you put into it.

Shared responsibility

  • Lovable Cloud is responsible for the underlying hosting, database and authentication infrastructure.
  • The SupportPrime AI team is responsible for application-level access rules, data scoping, and how the product handles the content you enter.
  • You are responsible for who you invite into your workspace, what customer data you paste into tickets, and for reviewing AI-drafted replies before sending them.

Security & privacy contact

Questions about this page, a privacy request, or an incident?

privacy@supportprime.ai

Report a vulnerability

Report suspected issues privately with steps to reproduce. Please do not test against other people's workspaces.

security@supportprime.ai

Last reviewed August 2026. This page is app-owned editable content and may change as the product changes.