Effective Date: November 15, 2025
Last Updated: November 15, 2025
Version: 1.7
SumGeniusAI LLC ("Company", "we", "our", or "us") values your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://sumgenius.ai (the "Site") or use any services or features we provide (collectively, the "Services").
By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree, please do not access the Site.
1. Information We Collect
a. Personal Information You Provide to Us:
- Name, email address, phone number, company name
- Billing and payment information
- Project or service inquiry details
- Any other data you voluntarily submit through contact forms or service requests
b. Information We Automatically Collect:
- IP address and browser type - Collected for security monitoring, rate limiting, fraud prevention, and abuse protection
- Device type, operating system, and geographic location
- Pages visited, referring website, and usage patterns (via cookies and tracking tools like Google Analytics and Microsoft Clarity)
- Session recordings and interaction data - Mouse movements, clicks, scrolling behavior, and page interactions captured via Microsoft Clarity (with automatic masking of sensitive fields)
Security & Fraud Prevention Logging:
For security purposes, we log IP addresses in the following scenarios:
- Authentication & Access Control: IP addresses are logged during login attempts, failed authentication, and CSRF token validation failures
- Rate Limiting: IP addresses are temporarily tracked to prevent abuse, denial-of-service attacks, and excessive API requests (e.g., 200 requests per 60 seconds on webhook endpoints)
- Security Incidents: IP addresses are logged when suspicious activity is detected, including failed authorization attempts, invalid requests, or potential attacks
- Meta Webhook Security: IP addresses of incoming Meta Platform webhooks are logged for signature verification and abuse prevention
Legal Basis (GDPR): Article 6(1)(f) - Legitimate interests in maintaining system security, preventing fraud, and protecting our services from abuse.
IP Address Protection: IP addresses in security logs are automatically anonymized by masking the last two octets (e.g., 192.168.***.***) to minimize personal data exposure.
Retention & Rotation: Security log files are automatically rotated when they exceed 10MB to prevent indefinite growth. Older rotated logs may be archived or deleted as part of routine system maintenance.
c. Information from Third Parties:
We may receive information from third-party sources including partners, service providers, and publicly available databases.
2. How We Use Your Information
We use your information to:
- Provide and improve our Services
- Respond to inquiries or support requests
- Personalize user experience
- Send marketing and promotional materials (if you opt in)
- Process payments and manage subscriptions
- Comply with legal obligations or enforce our terms
3. Sharing Your Information
We do not sell your personal information. We may share your data with:
- Service providers (e.g., hosting, analytics, payment processors)
- Contractors or business partners under confidentiality obligations
- Legal or governmental authorities as required by law
- In case of a business transfer (e.g., merger or acquisition)
4. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. We now provide a cookie consent banner that allows you to control which types of cookies you accept. You can also manage cookie settings through your browser.
Types of Cookies We Use:
Essential Cookies (Always Active)
These cookies are necessary for the website to function properly and cannot be disabled.
- PHPSESSID - Session cookie for maintaining login state (expires when browser closes)
- sumgenius_visitor_id - Unique visitor identifier for chat widget (persistent)
- sumgenius_session_id - Chat widget session identifier (session)
- sumgenius_chat_history - Stores your chat conversation history (persistent)
Functional Cookies (Optional)
These cookies remember your preferences and enhance your experience.
- sumgenius_sound_enabled - Your notification sound preference (persistent)
- sumgenius_dark_mode - Your theme preference (persistent)
- sumgenius_lang - Your language preference (persistent)
- sumgenius_visit_count - Number of visits to our site (persistent)
- sumgenius_cookie_consent - Your cookie consent preferences (persistent)
Analytics Cookies (Optional)
These cookies help us understand how visitors use our website (includes session recordings and heatmaps).
- Google Analytics (_ga, _gid, _gat) - Website traffic analytics and user behavior tracking
- Microsoft Clarity (_clck, _clsk) - Session recordings, heatmaps, and user interaction analytics
Marketing Cookies (Optional)
These cookies track the effectiveness of our marketing campaigns. Currently not implemented.
Managing Your Cookie Preferences
You can manage your cookie preferences at any time by:
- Using our cookie consent banner that appears on your first visit
- Clicking the "Cookie Settings" button in the consent banner
- Clearing your browser's cookies and localStorage
- Adjusting your browser settings to block or delete cookies
Note: Disabling essential cookies may prevent you from using certain features of our website, such as the customer portal and chat widget.
Session Recording & Heatmap Analytics
We use Microsoft Clarity to understand how visitors interact with our website through session recordings and heatmap analytics. This helps us identify usability issues, improve user experience, and optimize our website design.
What Microsoft Clarity Collects:
- Session Recordings: Visual playback of user sessions showing mouse movements, clicks, scrolling, and page interactions. Sensitive form fields (passwords, credit cards, email addresses) are automatically masked and never visible in recordings.
- Heatmaps: Aggregated visual maps showing where users click and how far they scroll on each page.
- User Behavior Insights: Rage click detection (repeated clicking indicating frustration), dead clicks (clicks on non-interactive elements), JavaScript errors, and excessive scrolling.
- Technical Data: Mouse movements, clicks, touch gestures, scrolling behavior, page elements interacted with, browser type, device type, screen resolution, time spent on pages, and navigation paths.
- IP Address: Collected and automatically anonymized by Microsoft to comply with privacy regulations.
Microsoft Clarity Cookies:
- _clck - Persistent cookie that stores a unique user ID and session information (expires after 1 year)
- _clsk - Session cookie that groups multiple page views into a single session recording (expires after 1 day)
Third-Party Data Processing:
Microsoft Clarity processes session data in accordance with the Microsoft Privacy Statement. Microsoft does not sell personal data collected through Clarity or use it for advertising purposes. Session recordings are stored on Microsoft's secure servers and are accessible only to authorized SumGeniusAI personnel.
Privacy Protections for Session Recordings:
Automatic Data Masking:
- ✓ Password fields are always masked (shown as ••••••)
- ✓ Email addresses are automatically masked
- ✓ Credit card numbers and payment information are masked
- ✓ Phone numbers are masked
- ✓ IP addresses are anonymized by Microsoft
- ✓ Text masking mode: "Balanced" - masks user-entered data while showing site content
How to Opt-Out of Session Recordings:
You can disable Microsoft Clarity session recordings and heatmaps by:
- Rejecting or disabling "Analytics" cookies in our cookie consent banner
- Enabling Global Privacy Control (GPC) in your browser (automatically blocks all analytics)
- Using browser privacy extensions like Privacy Badger or uBlock Origin to block third-party analytics
- Adjusting your browser settings to block third-party cookies
Data Retention for Session Recordings:
- Session Recordings: Stored by Microsoft Clarity for up to 30 days, then automatically deleted
- Heatmap Data: Aggregated anonymized data retained indefinitely for performance analysis
- Analytics Reports: Summary statistics retained to track improvements over time
Legal Basis (GDPR): Article 6(1)(f) - Legitimate interests in improving website usability and user experience. You can object to this processing by disabling Analytics cookies.
5. Data Security
We implement industry-standard security measures to protect your data, including SSL encryption, firewalls, and regular vulnerability scanning. However, no method of transmission over the internet is 100% secure.
Security Monitoring & Audit Logging
To maintain the security and integrity of our services, we implement comprehensive security logging:
- Access Logging: All authentication attempts, including successful logins and failed attempts, are logged with timestamps and IP addresses
- CSRF Protection Logging: Failed CSRF token validations are logged to detect and prevent cross-site request forgery attacks
- Rate Limiting: Request patterns are monitored to identify and block abusive traffic or potential DDoS attacks
- Webhook Security: All webhook requests are verified using cryptographic signatures, with verification failures logged for security analysis
- Data Access Auditing: Sensitive data operations (conversations deletion, consent changes, etc.) are logged with full audit trails
Security logs are stored securely with restricted access. IP addresses in logs are automatically anonymized by masking the last two octets. Log files are automatically rotated when they exceed 10MB to prevent indefinite storage growth.
Data Protection Measures
- Encryption at Rest: OAuth tokens and sensitive credentials are encrypted using AES-256-CBC encryption before storage
- Encryption in Transit: All data transmission uses TLS/SSL encryption
- Access Controls: Role-based access control (RBAC) ensures only authorized personnel can access sensitive data
- Transaction Safety: Database operations use transactions with automatic rollback on errors to maintain data integrity
- Input Validation: All user inputs are validated and sanitized to prevent SQL injection, XSS, and other injection attacks
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal information
- Opt out of data processing or marketing communications
- Request data portability
- File a complaint with a data protection authority
For these requests, please contact us at info@sumgenius.ai.
7. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.
Your California Rights:
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collect information, our business purposes for collecting information, and the categories of third parties with whom we share information.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: You have the right to opt-out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information to purposes necessary to perform our services.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights.
Global Privacy Control (GPC):
We honor Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we will automatically opt you out of the "sale" or "sharing" of your personal information and limit the use of sensitive personal information.
Do Not Sell or Share My Personal Information:
We do not "sell" personal information as defined by the CCPA. We may share certain information with third-party service providers and analytics partners to provide and improve our services. You can opt-out of this sharing by:
- Enabling Global Privacy Control (GPC) in your browser
- Adjusting your cookie preferences in our cookie consent banner
- Contacting us at privacy@sumgenius.ai
Categories of Personal Information We Collect:
We collect the following categories of personal information as described in the CCPA:
- Identifiers (name, email, IP address)
- Commercial information (purchase history, service usage)
- Internet or network activity (browsing behavior, interactions with our services)
- Geolocation data (approximate location based on IP address)
- Professional or employment-related information (if voluntarily provided)
- Inferences drawn from the above to create user profiles
Business Purposes for Collection:
We collect personal information for the following business purposes:
- Providing and improving our AI services
- Customer support and communication
- Fraud prevention and security
- Analytics and service optimization
- Marketing communications (with consent)
- Legal compliance
Third Parties We Share With:
We may share personal information with:
- Service providers (hosting, analytics, AI processing)
- Payment processors (Stripe)
- Communication platforms (Twilio, Meta)
- Analytics providers (Google Analytics, Microsoft Clarity)
Exercising Your California Rights:
To exercise your California privacy rights, please contact us at:
We will verify your identity before processing your request and respond within 45 days.
Authorized Agent:
You may designate an authorized agent to make requests on your behalf. We will require written proof of the agent's authority before processing the request.
8. Data Retention
We retain your information only as long as necessary for business purposes or legal compliance. Data may be anonymized for research or analytical purposes.
9. Children's Privacy
Our Services are not intended for individuals under 13 (or 16 in the EU). We do not knowingly collect data from children.
10. Third-Party Links
Our Site may contain links to third-party websites. We are not responsible for their privacy practices or content. Please review their policies individually.
11. VibeCheck AI Chrome Extension
If you use our VibeCheck AI Chrome Extension, the following additional terms apply:
a. Data Collection and Processing:
- Message Analysis: Text you analyze is sent to our servers for AI processing but is NEVER stored, logged, or saved. Analysis happens in real-time and data is immediately discarded after processing.
- AI Processing: We use OpenAI's API to analyze text tone and sentiment. OpenAI processes the text temporarily and does not store or use your data for training. The analysis is performed in real-time and results are not retained.
- Usage Tracking: We track the number of daily checks per user account to enforce free tier limits (10 checks/day for free users).
- Authentication: Your login credentials create a secure token stored locally in your browser. Passwords are hashed using industry-standard bcrypt encryption.
- Platform Detection: The extension detects which website you're on (Gmail, LinkedIn, Twitter, etc.) to provide context-appropriate analysis. URLs are not stored.
- Data Retention: Usage statistics are retained for 90 days. Account information is retained until you delete your account.
b. Extension Permissions:
- activeTab: To detect text input fields on the current tab
- storage: To save your authentication token and track daily usage locally
- scripting: To inject the VibeCheck analysis interface into web pages
- clipboardRead: To enable the Ctrl+Shift+V (Cmd+Shift+V on Mac) keyboard shortcut for analyzing copied text
- host_permissions: To communicate securely with sumgenius.ai servers for AI analysis
c. Data Security for VibeCheck:
- All communication uses HTTPS encryption
- No message content is ever stored in our databases
- Authentication tokens expire after 30 days of inactivity
- You can delete your account at any time, which removes all associated data
d. Premium Subscriptions:
If you upgrade to VibeCheck Pro, payment processing is handled by Stripe. We store only your subscription status and customer ID, never your payment details.
e. Your VibeCheck Rights:
- Request deletion of your VibeCheck account and all associated data immediately
- Export all your personal data in machine-readable JSON format
- Access your account information and usage statistics anytime
- Correct or update your personal information through the dashboard
- Cancel your subscription at any time via Stripe's customer portal
- Opt out of any future features that may collect additional data
- Disable the extension at any time through Chrome's extension manager
- Contact us at privacy@sumgenius.ai for any privacy concerns
VibeCheck Privacy Commitment: We built VibeCheck with privacy as a core principle. Your messages are your business - we just help you communicate better without compromising your privacy.
12. AI Voice Services & SMS Consent Collection
Voice AI Infrastructure Services
SumGeniusAI provides AI voice agent infrastructure to businesses. When you interact with an AI agent using our phone numbers:
- Your call may be recorded for quality assurance and service improvement
- Information you provide during calls is collected to fulfill service requests
- Voice recordings and data are retained for up to 90 days unless legally required longer
- You may request deletion of your recordings and associated data at any time
SMS Consent Collection Process
Our AI agents collect explicit verbal consent before sending any text messages:
- Agents ask: "May I send you a text message with this information? Standard message and data rates may apply."
- Your verbal response (yes/no) is captured and recorded in our consent management system
- SMS messages are only sent if you explicitly agree
- Each consent interaction is logged with timestamp and conversation reference
Types of SMS Messages
After obtaining consent, you may receive:
- Appointment confirmations and reminders
- Service details and follow-up information
- Booking confirmations
- Time-sensitive notifications related to your inquiry
SMS Opt-Out Process
- Text STOP to any message to immediately unsubscribe from all SMS communications
- Text HELP for assistance
- Opt-out requests are processed immediately and permanently
- Re-subscription requires new explicit consent
SMS Data Privacy Commitment
We guarantee that:
- ✓ Your phone number will NEVER be sold or shared with third parties for marketing
- ✓ Mobile information is only used for the specific services you've requested
- ✓ Consent records are securely stored with full audit trails
- ✓ No SMS will be sent without your explicit verbal consent
- ✓ You maintain complete control over your communication preferences
13. ChatGenius - Meta Messenger Integration
Overview
SumGeniusAI's ChatGenius platform enables businesses to manage automated AI-powered conversations with their customers through Facebook Messenger and Instagram Direct Messages. This section explains how we handle data when businesses use ChatGenius to communicate with their customers on Meta's platforms.
Who We Serve
Data Controller: The business (our client) that uses ChatGenius is the Data Controller for their end users' data.
Data Processor: SumGeniusAI acts as a Data Processor, processing conversation data on behalf of the business.
Data Subjects: End users who message businesses through Facebook Messenger or Instagram DM.
Data We Collect Through ChatGenius
When end users message a business using ChatGenius, we collect:
- Message Content: All messages sent and received in conversations
- Profile Information: Name, profile picture, and public profile data from Meta platforms
- Platform Metadata: Message timestamps, conversation status, platform type (Facebook/Instagram), and unique platform user IDs
- Appointment Data: Booking details, scheduled times, and appointment status if applicable
- Conversation Context: Historical conversation data to maintain context across multiple interactions
Lead Ads Data Collection
When businesses use ChatGenius with Facebook and Instagram Lead Ads, we collect additional information:
- Lead Form Submissions: Contact information submitted through Lead Ad forms including name, email address, phone number, and custom field responses
- Form Metadata: Lead form ID, form name, ad ID, ad name, and submission timestamp
- Lead Source Attribution: Which ad campaign and form generated the lead
- Messenger Opt-In Status: Whether the user opted to start a Messenger conversation when submitting the form
How We Collect Lead Ads Data
When a user submits a Lead Ad form on a business's Facebook or Instagram ad:
- We receive a webhook notification from Meta containing the lead submission ID (leadgen_id)
- Using the ads_read and leads_retrieval permissions, we call Meta's Graph API to retrieve the full lead data
- The lead information is stored in the business's ChatGenius dashboard under "Captured Leads"
- If the user opted-in to Messenger, an automated welcome message is sent within seconds
- A conversation record is created for the business to follow up with the lead
How We Use Lead Ads Data
- Lead Capture: Displaying lead information in the business's ChatGenius dashboard for immediate follow-up
- Automated Outreach: Sending personalized welcome messages if Messenger opt-in was granted
- Lead Management: Creating conversation records and tracking lead status
- Analytics: Providing businesses with lead capture metrics and conversion tracking
- Service Integration: Syncing lead data with business CRM systems if configured
Lead Ads Privacy Protections
Important Lead Ads Safeguards:
- ✓ Lead data is only retrieved for businesses' own ad accounts
- ✓ Automated messages are sent ONLY if the user opted-in to Messenger
- ✓ Lead information is never shared with third parties
- ✓ Businesses can delete lead records at any time through their ChatGenius dashboard
- ✓ Lead data follows the same encryption and security standards as all ChatGenius conversation data
- ✓ Users can request deletion of their lead information by contacting the business or SumGeniusAI
Lead Data Retention
- Active Leads: Retained indefinitely until the business deletes them or the account is closed
- Lead Form Data: Stored separately from conversations for lead tracking and CRM purposes
- Deletion: Businesses can delete lead records through the "Captured Leads" section, which permanently removes all associated lead data including email, phone, and form responses
How We Use ChatGenius Data
We process ChatGenius conversation data for two distinct purposes:
1. Service Delivery (Required - Covered by TOS)
- Providing AI-powered conversation responses to end users
- Maintaining conversation context and memory across interactions
- Managing appointment bookings and scheduling
- Generating conversation analytics for business clients
- Delivering customer support and service features
Legal Basis: GDPR Article 6(1)(b) - Performance of contract with our business clients to provide messaging services.
2. AI Training & Model Improvement (Optional - Requires Explicit Consent)
- Using anonymized conversation data to improve AI response quality
- Training custom AI models for better industry-specific responses
- Developing new features and capabilities
Legal Basis: GDPR Article 6(1)(a) - Explicit consent from business clients (Data Controllers).
Consent Mechanism: Business clients can opt in or opt out of AI training data usage at any time through their ChatGenius portal settings. This consent is separate from our Terms of Service and can be withdrawn freely without affecting service delivery.
Third-Party AI Processing
We use OpenAI as our AI service provider for ChatGenius conversations:
- Message data is sent to OpenAI's API for generating AI responses
- OpenAI processes data in accordance with their Privacy Policy and Business Terms
- Per OpenAI's API terms, data sent via API is not used for training their models unless explicitly opted in
- We do not share conversation data with any other third parties except as required by law
Data Retention & Deletion
Retention Period:
- Active Conversations: Retained indefinitely to maintain service quality and conversation continuity
- Resolved Conversations: Automatically deleted after 90 days from last activity
- AI Training Data: If consent is granted, anonymized data may be retained longer for model training purposes
Deletion Process:
- Business clients can delete conversations immediately through their portal's conversation management page
- Deletion is permanent and includes all messages, appointments, conversation context, and related data
- AI analytics metrics are anonymized (personal information removed) rather than deleted to preserve performance insights
- End users can request deletion by contacting the business directly or emailing us at privacy@sumgenius.ai
Data Rights for ChatGenius Users
End users messaging businesses through ChatGenius have the following rights:
- Right to Access: Business clients can export conversation data as CSV through the ChatGenius portal; end users can request their data from the business or SumGeniusAI
- Right to Deletion (GDPR Article 17): Request immediate deletion of all conversation data and related information
- Right to Rectification: Request correction of inaccurate personal data
- Right to Object: Object to data processing for AI training purposes (this does not affect service delivery)
- Right to Data Portability: Receive personal data in machine-readable format (CSV export available)
- Right to Withdraw Consent: Business clients can withdraw AI training consent at any time without service impact
Privacy & Security Commitment
We guarantee that:
- ✓ Conversation data is encrypted in transit (TLS/SSL) and at rest
- ✓ Access controls ensure only authorized personnel can view data
- ✓ AI training is 100% optional and requires separate explicit consent
- ✓ Personal information is removed before any data is used for training
- ✓ Meta Platform Policies are strictly followed for all messaging interactions
- ✓ GDPR compliance is maintained for all EU data subjects
- ✓ Automated 90-day retention policy protects against indefinite data storage
- ✓ Business clients maintain full control over their conversation data
Compliance Standards
- GDPR Compliance: Articles 5 (data minimization), 6 (lawful basis), 13/14 (transparency), 17 (right to erasure), 25 (data protection by design)
- Meta Platform Policies: Full compliance with Facebook Platform Terms, Instagram Platform Policy, and Messenger Platform Policy
- Data Processing Agreement: Available upon request for business clients requiring formal DPA documentation
Contact for ChatGenius Data Requests
For data access, deletion, or privacy concerns related to ChatGenius conversations and Lead Ads data:
- Business Clients: Use the conversation deletion feature or Captured Leads section in your ChatGenius portal, or contact privacy@sumgenius.ai
- End Users: Contact the business you messaged first, or email us directly at privacy@sumgenius.ai
- Data Protection Inquiries: dpo@sumgenius.ai
14. Law Enforcement & Legal Requests
If we receive legal requests for user data from public authorities, we follow strict procedures to protect user privacy:
Our Legal Request Handling Process:
- Legality Review: All legal requests are reviewed by our legal team to verify authenticity, proper authorization, and compliance with applicable law
- Right to Challenge: We reserve the right to challenge requests that appear unlawful, overly broad, or improperly issued through appropriate legal channels
- Data Minimization: We disclose only the minimum information legally required to comply with valid requests, not entire datasets
- Documentation & Transparency: All legal requests, our responses, legal reasoning, and involved parties are documented in secure audit logs
User Notification: Where legally permitted, we will notify affected users before disclosing their information, giving them an opportunity to seek legal protection. However, we may be prohibited from providing notice in certain cases (e.g., national security letters).
Transparency Reporting: We are committed to transparency about government requests for user data and may publish aggregate statistics about such requests when legally permitted.
15. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Any changes will be reflected on this page with a revised "Last Updated" date. Your continued use of the Site after changes indicates your acceptance.
16. Contact Us