findbusinessclient portal
Privacy

Privacy Policy

This is the master privacy policy for FindBusiness. It covers two groups: businesses that sign in to the client portal to manage what we run for them, and visitors who chat with a website assistant. It says what we collect from each, who else processes it, and how long we keep it.

Effective August 14, 2026

The short version. We collect what we need to run the portal, carry out the changes you request, run billing, generate assistant answers, and keep the service secure. When you chat with an assistant, your messages and its replies are kept for 90 days, plus a one way hash of your IP address for 7 days to stop abuse. It all lives on Google Cloud, not on servers of our own. We set no advertising cookies, we do not sell your data, and you can ask us to delete your information at any time: admin@dependableaisolutions.com.

1. Who we are and what this covers

Dependable AI Solutions LLC, a California limited liability company ("we", "us", "our"), based in Corona, California, operates FindBusiness and is the controller of the data described here. This policy covers two things: the client portal that businesses use to manage the site or agent we run for them, and the website assistant, the chat panel in the corner of a business's site.

If you are a visitor chatting with an assistant, the business whose website you are on is a separate company with its own privacy policy covering the rest of their site. If you asked the assistant to put you in touch with that business, what they do with that request is governed by their policy, not this one.

2. What the portal collects (businesses)

If you are a business with a portal account, we collect:

CategoryWhat it is
AccountYour email address and display name from sign-in, the website you tell us you want access to, your account status, and the sites we have linked to your account.
Requests and uploadsThe change requests you submit (title and details) and any files you attach to them, such as images or PDFs.
MessagesSupport messages you send us through the portal.
Usage and billingYour agent's usage, conversation counts, and remaining credits as shown to you, and a record of credit purchases (the payment itself is handled by Stripe).
TechnicalStandard server and security logs, and a bot-protection token used to guard checkout.

We do not ask for or store a password: sign-in is passwordless (a Google account or a one-time email link).

3. What the assistant collects (visitors)

When you chat with an assistant, we collect only what it needs to answer you, to bill the business fairly, and to stop abuse.

  • Your messages and the assistant's replies. The text you type (up to 2,000 characters per message) and the answer generated for you. These are stored.
  • A session identifier. A random id generated in your browser, not by us, and not linked to any account. It groups the messages in one conversation.
  • A hashed IP address. We take a one way cryptographic hash of your IP address and store only that, to count requests and block abuse. We do not store your raw IP address. A hash of this kind is a pseudonym rather than true anonymization, so we treat it as personal information and retain it as briefly as we can.
  • The page you are on. The path and title of the page carrying the chat panel are sent to the assistant so it can answer in context, and where the business has enabled it, a short extract of that page's own visible text goes with them. This is stored, as part of our record of what we asked the assistant, and it expires on the same schedule as your message (see section 7).
  • Usage counters. Token counts and cost per answer, used for metering and billing the business.

What the assistant does not collect. There are no accounts for visitors. We do not record your browser's user agent string, we run no advertising or cross site tracking, we do not build a profile of you, and we do not collect your name, email, or phone number unless you type one into the chat yourself.

Please do not type confidential or sensitive information into the chat. It is an automated assistant on a public web page, your messages are stored for 90 days, and they are processed by a third party AI service. Do not enter payment card numbers, government identifiers, health information, passwords, or anything you would not want handled that way.

4. How we use it

For businesses using the portal, we use your data to:

  • give you access to the portal and connect you to the site or agent we manage for you;
  • carry out the changes you request and keep you updated on them;
  • run billing for credit purchases and keep a record of them;
  • send you service emails, such as when a request is queued, declined, or done, usage alerts, and a monthly recap (you can turn the optional ones off in Settings);
  • keep the portal secure, prevent abuse, and meet legal obligations.

For visitors chatting with an assistant, we use your data to:

  • generate an answer to your question and keep the conversation coherent across your messages;
  • meter usage and bill the business, and enforce the limits that keep costs bounded;
  • detect and block abuse (rate limiting, and screening for attacks on the assistant);
  • improve the product. We review what visitors actually ask so the assistants answer better. This is why we keep the conversation text for 90 days. It means our staff can read stored conversations. It is not the same as training an AI model on your messages; see section 8.

We do not sell your personal information, we do not share it with advertisers, and we do not use it for cross context behavioral advertising.

5. Cookies and browser storage

The assistant sets no cookies. It uses your browser's local storage, on the site you are visiting, for two things:

Stored itemWhyExpires
fb.agent.sessionIdGroups your messages into one conversation14 days
fb.agent.messages.*Keeps your transcript visible when you return14 days

Both expire 14 days after your last activity and are swept automatically. You can remove them at any time by clearing your browser's site data, which also ends the conversation on your side. If your browser blocks storage (private mode), the assistant keeps them in memory for the page visit and nothing is persisted.

The portal and the assistant sites run no analytics. They do load Google reCAPTCHA Enterprise, which inspects browser signals to tell a person from a bot, so that checkout and the free demo builder are not abused. That is a Google service; see below.

6. Who processes it

We share data only with the service providers that help us run FindBusiness, and only as needed. We do not sell your data or share it for advertising.

ProviderWhat reaches them
Google Cloud and FirebaseSign-in, database, file storage, hosting, and the functions that run the portal and the assistant. Stored data lives here, in the United States.
Google Vertex AI (Gemini, and our agent on Vertex AI Agent Engine)A visitor's message, the recent conversation, the page context, and facts about the business, in order to generate the reply. Vertex also keeps its own copy of the conversation session. This runs on Google's global endpoint, so we cannot promise the request is processed in a specific country.
Google Model ArmorA visitor's message, and the generated reply, sent for screening for prompt injection, jailbreaks, and unsafe or sensitive content.
Google SearchThe assistant can search the web when the business's site does not answer a question. A search query derived from the question goes to Google Search; the message is not sent verbatim and the visitor's IP address is not exposed to it.
The business's own websiteThe assistant reads pages of the business's site live to answer. It sends only the page address and its own identifier. The visitor's IP address and message are not sent; the request comes from our infrastructure.
StripePayment processing for credit purchases and orders: the business's email and order details. Card details go to Stripe directly and never pass through our systems. Nothing about site visitors reaches Stripe.
Trello (Atlassian)We place a portal request's details and links to its attachments on an internal work card so it can be carried out.
ResendDelivery of the service emails described above.
Google reCAPTCHA EnterpriseBot protection on checkout and the free demo builder.
Fulfillment toolsThe code-hosting and AI automation we use to carry out a portal request may process the request's contents to do the work.

We may also disclose data if the law requires it, to protect our rights or the safety of others, or as part of a business transfer, in which case this policy continues to apply. Like most websites, our hosting provider records standard request data for security and reliability, under Google's own schedule.

7. How long we keep it

For businesses, we keep your account data while your account is active. If we close or delete your account, we remove your account profile, your portal messages, and your sign-in. We retain your change-request records, including the files you attached to them, as a record of the work we did for you and for legitimate business and audit purposes; those are not automatically deleted along with your account. We also keep records we are legally required to keep, such as billing records. You can ask us to delete specific requests or files, and we will remove what we are not required to keep (see Your choices and rights).

For assistant conversations, the items below expire automatically; we do not keep conversation data indefinitely.

WhatKept forCounted from
Visitor messages, the assistant's replies, and the page context sent with them90 daysWhen the message was sent
Conversation state (usage counters, limits)14 daysLast activity
The conversation held by Google Vertex AI30 daysWhen the session was created
Hashed IP address (abuse prevention)7 daysLast request
Transcript in the visitor's own browser14 daysLast activity, and it can be cleared sooner
Usage counters and spend limits for the businessUp to about 3 monthsThe billing period

Free demo agents. A demo agent built from our home page stops working seven days after it is created, and the demo and its entire conversation history are permanently deleted about seven days after that.

8. About the AI itself

  • Answers are generated automatically and may be wrong. They are general information, not professional, legal, financial, or medical advice. For anything that matters, confirm it with the business directly.
  • No decisions are made about you. The assistant answers questions. It does not profile you and it makes no automated decision that produces a legal or similarly significant effect.
  • On training. We do not use your conversations to train our own AI models, and we do not sell or give them to anyone to train theirs. Your messages are processed by Google Vertex AI to generate the reply, and Google's handling of that data is governed by Google Cloud's service terms. Separately, and as stated in section 4, our staff may read stored conversations for 90 days to improve how the assistants answer.

9. Your choices and rights

If you are a business with a portal account:

  • Email preferences. Turn the optional usage and digest emails on or off in the portal's Settings tab.
  • Access and deletion. Email admin@dependableaisolutions.com to see or correct your data, or to close your account. Closing it removes your profile, messages, and sign-in; we retain your request history and its attachments as described in How long we keep it, and will delete specific items on request where we are not required to keep them.
  • Sign-in. Because sign-in is tied to your Google account or your email inbox, you control access through those.

If you are a visitor who chatted with an assistant:

  • Do not chat. The assistant only receives what you type into it.
  • Clear it yourself. Clearing your browser's site data removes the session id and transcript immediately.
  • Ask us to delete it. Email admin@dependableaisolutions.com and we will delete your stored conversation. Because we hold no account for you, tell us the website you were on and roughly when you chatted so we can find the conversation. If we cannot identify it, we may not be able to act on the request.
  • Everything expires on its own regardless; see section 7.

10. California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request deletion or correction, and not to be discriminated against for exercising those rights. Exercise them at admin@dependableaisolutions.com.

We do not sell your personal information and we do not share it for cross context behavioral advertising. For visitors, the categories we collect are internet activity (your messages to the assistant) and identifiers (a hashed IP address and a random session id); for businesses, identifiers and account records as described in section 2. We may need to verify a request before acting on it, and we may be unable to locate a conversation you cannot help us identify.

11. Security

We do not run our own servers. FindBusiness runs entirely on Google Cloud, in the United States. Your data is held in Google Cloud (Firestore) and processed by Google's AI services. What we operate is the configuration and the connections between those services: which data is sent, what the assistant is allowed to do, and how long anything is kept. Google's physical, network, and platform security is what protects the underlying infrastructure.

On top of that, the specific protections we run:

  • Passwordless sign-in for the portal, with app-attestation and bot-protection checks on sensitive actions like checkout, and access rules that keep each client's data to their own account.
  • Messages are screened by Google Model Armor before the assistant runs, and we also screen the assistant's answers. It screens for sensitive data, prompt injection and jailbreak attempts, malicious links, and hateful, harassing, dangerous, or sexually explicit content. When it matches, the turn is blocked and the visitor gets a safe message instead. Like any automated filter it is not perfect and can miss things; a turn can pass unscreened if the screening service is unreachable, and answer screening in particular is a best-effort safety net rather than a guarantee, so do not rely on it.
  • Repeated blocked messages pause the chat. If several messages are blocked in a row, the assistant stops answering that browser for a short cooling-off period that grows if it keeps happening. It is keyed to a network address rather than any account, and it lapses on its own.
  • The assistant cannot go wandering. It may only fetch pages on a per business allowlist, and it is refused outright if a domain resolves to a private network address, so it cannot be tricked into reading internal systems.
  • The chat panel is locked to the business's domain. It only runs on the web addresses that business is registered for, so the panel cannot be lifted onto someone else's site to impersonate them.
  • Encrypted in transit with TLS. Access to stored data is limited to staff who need it.

What we keep when a message is blocked. We record that a block happened and which filter caught it. We only keep the message text itself when the filter caught an attack on the assistant, like a prompt injection or a malicious link, because that is something the business is entitled to see about its own traffic. In every other case, including sensitive data, abusive or explicit content, and anything our filters flag but cannot categorize, the text is discarded and only the category is stored.

An honest limit. That protection only works for what the filter actually catches, and it does not catch everything. Payment card numbers it spots reliably, while things like government identifiers or health details can pass straight through, reach the assistant, and be recorded in the conversation log like any other message, ageing out on the schedule in section 7. So screening is a safety net, not a reason to send us something sensitive.

No system is perfectly secure, and we cannot guarantee absolute security.

12. Children

FindBusiness is intended for businesses and adults. The assistant is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent information to the assistant, email admin@dependableaisolutions.com and we will delete it.

13. Changes and contact

We may update this policy. Material changes will be reflected by updating the effective date at the top. Questions or requests: admin@dependableaisolutions.com. See also our Terms of Service.