Skip to content
SupportOS

Legal

Privacy Policy

Last updated 8 October 2026

SupportOS is an AI-assisted helpdesk made by BlueForge Studio. This policy explains what personal data we process when you use SupportOS and this website, why, and what rights you have.

1. Who is responsible

For the data of people who sign up for SupportOS (account holders and agents), BlueForge Studio (“we”) is the data controller. For the content a workspace puts into SupportOS — its customers’ names and e-mail addresses, conversations, messages and attachments — the workspace owner is the controller and we are the processor acting on its instructions.

Contact BlueForge Studio through www.blueforge.studio.

2. What we process

  • Account data: name, e-mail address, a hashed password (we never store the password itself), workspace name and your role in it. If you sign in with Google, we receive your name and e-mail address from Google.
  • Workspace content: the customers, conversations, messages, attachments, tags, assignments and knowledge-base articles that your team and your customers create in SupportOS — including messages sent through the chat widget, by e-mail or from connected Slack channels.
  • AI processing data: the text of messages and conversations that you ask SupportOS to triage, summarise, draft replies for, or auto-reply to, and the suggestions generated from it (see section 4).
  • Billing data: your plan, and a Stripe customer reference. Card details are entered at Stripe and never reach our servers.
  • Technical data: a session cookie when you are signed in, server logs (IP address, requests, errors), and usage and error events from the app that help us operate and fix the service.

3. Why we process it, and on what basis

  • To provide SupportOS to you and your workspace — performance of our contract with you (GDPR art. 6(1)(b)).
  • To keep the service secure, prevent abuse, and understand and improve how it performs — our legitimate interests (art. 6(1)(f)).
  • To handle payments and meet accounting and legal obligations (art. 6(1)(b) and (c)).
  • Where we ask for your consent (for example optional cookies, should we ever add them), you can withdraw it at any time (art. 6(1)(a)).

4. AI features

SupportOS uses large language models to categorise and prioritise conversations, suggest replies, suggest knowledge-base articles and, if a workspace turns it on, send automatic replies. To do this, the relevant message text is sent through our AI gateway to a model provider (OpenAI, Anthropic or Google). Internal notes are left out when drafting a customer-facing reply (suggested or automatic); triage and article suggestions analyse the whole conversation.

We do not use your content to train models. Providers process the data under their own API terms; we recommend reading them. AI output can be wrong: suggestions are meant to be reviewed by a person, and automatic replies are optional and governed by a confidence threshold that the workspace sets.

5. Who we share data with

We do not sell personal data. We share it only with service providers that help us run SupportOS:

  • AI model providers: OpenAI, Anthropic and Google (section 4).
  • Stripe, for subscription billing and payments.
  • Infrastructure providers that host the service and its database, storage and e-mail delivery.
  • Slack, only for workspaces that connect a Slack integration.

We may also disclose data where the law requires it. A current list of providers is available on request.

6. Cookies and local storage

  • Session cookie (SupportOS app): keeps you signed in. Strictly necessary.
  • NEXT_LOCALE (this website): remembers your language for one year. Strictly necessary for the language you chose.
  • Theme preference (this website and the app): your light/dark choice, kept in your browser’s local storage. It is never sent to us.

We do not use advertising cookies or cross-site tracking.

7. How long we keep data

We keep account and workspace data for as long as the account is active. When a workspace is closed, or on request, we delete or anonymise its data, except where we must keep something to meet a legal obligation (for example accounting records) or to resolve a dispute.

8. Security

Data is encrypted in transit, passwords are stored only as hashes, and every request is scoped to the workspace it belongs to. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.

9. Your rights

Under the GDPR you can ask for access to your data, correction, deletion, restriction, a portable copy, and you can object to processing based on legitimate interests. You can also complain to your local data protection authority. If you are a customer of a SupportOS workspace, please contact that workspace first — it controls your data; we will help it respond.

Contact BlueForge Studio through www.blueforge.studio.

10. Children

SupportOS is a business tool and is not directed at children under 16.

11. Changes

We will update this policy as the service changes and publish the new date above. Significant changes will be announced in the product or by e-mail.