Privacy
What Media Yard LLC collects, why, and who else sees it. Last updated 15 September 2026.
These are drafted documents, not legal advice. They have not been reviewed by a lawyer. If you are signing the data-processing agreement on behalf of a company, have your own counsel read it first.
Two different relationships
There are two kinds of data here and they are governed differently.
Your account data - your name, your email address, your plan, your usage - is data we control. For it, Media Yard LLC is the controller, and this notice covers it.
Your customers' conversations are data you control and we process on your instructions. We are a processor for that data and you are the controller. The data-processing agreement governs it, and this notice does not grant us any use of it beyond running the service for you.
What we collect about you
- Your email address, because sign-in is a link sent to it.
- Your name and the accounts you belong to.
- Usage counts, for billing and for the allowance on your plan.
- If you subscribe, your plan and subscription status. Your payment details are entered on Stripe's pages and held by Stripe, not by us.
- Server request logs, including IP addresses, kept for security and debugging.
If you join the beta list
We keep the email address you enter, which page the form was on, and the date. We use it only to invite you to the beta. Nothing else is collected with it: no name, and no IP address stored against it. It is deleted when the beta ends, or sooner if you ask; if you create an account, the address becomes part of your account record instead.
If you use the free website check
When you type a website address into the free website check, we read up to 8 public pages of that website, following its robots.txt, and send the text of those pages to our AI provider (listed below) to list common customer questions and find which ones the pages answer. We do not ask for your name or email address, and you do not need an account.
We keep the address you typed, the addresses of the pages we read, and the report - the questions, and for each one a page answers, a short passage quoted from that page - for 7 days, and then delete them. Anyone who has the report's link can open it. The rest of the page text is not kept. The pages are public, but they can contain personal data, such as a staff member's name or contact details, and a quoted passage can include it; it is deleted with the report.
To limit how often the check can be used, we turn your IP address into a one-way code using a random value that we delete at the end of each day, and count checks by that code. We do not store your IP address with the check, and once the day's random value is deleted the code cannot be connected to any address, including by us. Our server request logs (above) still record IP addresses as they do for any visit.
Why we are allowed to use it
Where the UK or EU GDPR applies, each use rests on one of these bases.
| What we do | Lawful basis |
|---|---|
| Sign-in, running your account, and providing the service you signed up for | Performing our contract with you (Art. 6(1)(b)) |
| Billing, and keeping invoices and payment records | Performing the contract (Art. 6(1)(b)), and the tax and accounting law that requires us to keep records (Art. 6(1)(c)) |
| The beta list | Steps you asked us to take before a contract (Art. 6(1)(b)) |
| The free website check, and limiting how often it can be used | Our legitimate interest in offering the check and preventing its misuse (Art. 6(1)(f)). You can object; see your rights below. |
| Server request logs kept for security and debugging, and the audit log of consequential actions | Our legitimate interest in keeping the service secure and being able to show who did what (Art. 6(1)(f)). You can object; see your rights below. |
| Answering a court order, regulator or other lawful demand | Legal obligation (Art. 6(1)(c)) |
Selling and sharing
We do not sell personal data, and we do not share it for cross-context behavioural advertising. It reaches the sub-processors below only to run the service.
What the audit log records, and what it does not
The service keeps an audit log of consequential actions - who changed a setting, who invited someone, when a refund request was filed. It records which fields were present on a lead, never their values.
Who else sees data
We engage the following sub-processors. This is the same list the data-processing agreement renders, because two versions of it would eventually disagree.
| Who | Why | What reaches them | Where |
|---|---|---|---|
| xAI |
Generates the agent's replies from a tenant's knowledge base. | Message text from a conversation, and the passages retrieved to answer it. | United States |
| OpenAI |
Turns knowledge-base documents and messages into embeddings, so the agent can find the passage that answers a question. | Knowledge-base document text, and message text at query time. | United States |
| Supabase |
Hosts the database. Everything the service stores is stored here. | Conversations, knowledge-base documents, account and user records, usage counts, the figures behind a published trust page, and the email addresses of people who joined the beta list. | United States (AWS us-east-1) |
| Cloudflare |
Runs the application, in a container on its network, and is the registrar and DNS for supportproof.com. Every request a customer or their end user makes passes through it and is served by it. | Everything in transit: message text, account records, and the IP addresses requests arrive from. Also the application's own logs, which it keeps for seven days, and the nightly database backups, which are encrypted before they reach it with a key it does not hold. | Requests are received and decrypted at the Cloudflare data centre nearest the visitor, which may be outside the United States. The application itself runs, and the backups are stored, in eastern North America. |
| GitHub |
Runs the nightly database backup. The job copies the database, checks the copy restores, encrypts it, and uploads it to Cloudflare. | A complete copy of the database, unencrypted, on a temporary machine for the few minutes the job runs. It is deleted when the job ends and is never stored at GitHub. | Temporary machines that GitHub runs in Microsoft Azure data centres, in a region GitHub chooses. |
| Resend |
Delivers sign-in links and account email. | Email addresses, and the contents of the messages we send to them. | United States |
| Stripe |
Takes payment for a paid plan, runs the subscription, and hosts the billing portal where an owner changes plan or cancels. |
The subscribing owner's email address, the account and plan being bought, and the payment details the owner enters on Stripe's own pages. Card numbers go to Stripe directly and are never stored here. | United States |
| Deepgram |
Speech to text, and text to speech, for voice conversations. |
Audio of a voice conversation, and the transcript produced from it. | United States |
The Verified Index
The index is built only from accounts whose trust page is public, and only from counts, rates and dates - never a customer's words. It refuses to report on a cohort smaller than 5 accounts, and an account is excluded from its own cohort. Withdrawing a trust page removes those figures from the next read.
How long we keep things
Account records last as long as the account, and are deleted within 30 days of closure. Conversation data is yours: it is kept while your account is open until you delete it, and you can delete a single conversation or everything before a date yourself, which is how you set your own retention period. Free website check reports are deleted 7 days after the check. Server logs roll off. Backups are kept for disaster recovery and are overwritten in the ordinary course.
Cookies
This site sets one cookie, sa_session, and only after you sign
in. It keeps you signed in, and nothing works without it once you are. It
is strictly necessary, set by this site alone, readable by no page script
(HttpOnly), sent only over HTTPS (Secure), and
not sent with requests from other sites (SameSite=Lax). It
lasts 30 days, or until you sign out.
There are no analytics cookies and no advertising cookies. Browsing the public pages, using the calculator or joining the beta list sets no cookie of ours. The one exception is not ours to switch off entirely: Cloudflare, which runs the site, can set a short-lived security cookie of its own when it challenges a request it suspects is automated.
The chat widget you install on your own site sets no cookies and stores nothing in your visitors' browsers: no cookies, no local storage. If you connect it to your own sign-in, it asks your server who the visitor is, using the cookies your site already sets.
When a chat starts, the widget sends the address of the page it was opened
on, without anything after a ? or #, and that
address is stored with the conversation.
If you turn on Understand how visitors use your site, which is off
unless you do, the widget also measures each page view it runs on: the
page's address without anything after a ? or #,
how long the page was visible, how far down it was scrolled, where clicks
landed on a coarse grid, which links and buttons were clicked by the words
on them, the page on your website or the name of the other website the
visitor came from, and whether a conversion happened. It sends this once,
when the page is left. It still sets no cookies and stores nothing in the
browser, gives the visitor no identifier, and sends nothing when the
browser has Do Not Track or Global Privacy Control turned on. We add each
report into daily totals for your account and keep neither the report nor
the visitor's IP address or browser details.
International transfers
Media Yard LLC is established in the United States, and your account data is processed there, apart from the edge processing described in the sub-processor table. If you are in the UK or the EEA, that means your data is handled under United States law, which does not give the same protection as yours. For your customers' conversation data, the transfer terms are in the data-processing agreement.
Children
The service is for businesses and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us their details, write to us and we will delete them. What your own customers type into your agent is your data, governed by the data-processing agreement.
If the business changes hands
If Media Yard LLC is part of a merger, acquisition or sale of assets, account data may pass to the new owner, who will be bound by this notice. We will tell you by email before your data becomes subject to a different privacy notice.
Your rights
You can ask us for a copy of your personal data, to correct it, to delete it, to restrict how we use it, to receive it in a portable format, and you can object to uses that rest on our legitimate interests. If you are in the UK, EU, or a US state with a privacy statute, those rights are statutory and we honour them without argument.
Write from the email address on your account, so we know the request is yours. We answer within one month. If a request is complex and we need longer, which the law allows, we will tell you why within that month.
If you are unhappy with how we have handled your data, you can complain to the data protection supervisory authority where you live or work: in the UK, the Information Commissioner's Office. We would like the chance to put it right first.
Contact
Media Yard LLC, New Jersey, United States. Support is the fastest route.