Privacy Policy
Last updated April 30, 2026
Who we are
Rigox ("we", "us") is operated by Kshitiz Sharma, an Indian sole proprietorship registered under MSME (Udyam). Our registered contact is rigoxlabs@gmail.com and our website is rigox.com.
Information we collect
- Account information: name, email, password (hashed), and the plan you selected — provided when you sign up.
- Bot configuration: bot names, system prompts, welcome messages, color preferences — provided by you.
- Knowledge content: any text, files, or website URLs you upload to train your bots. We store both the original content and vector embeddings of it.
- Conversations: messages exchanged between end-visitors and your bots, plus a per-visitor anonymous ID.
- Leads: any contact info (name, email, phone) submitted via your bots' chat widget or website forms.
- Usage telemetry: API request counts, error traces, and rate-limit metadata, stored for up to 90 days.
- Payment records: processed by Razorpay; we store only the subscription ID and last-4 digits, never the full card number or CVV.
How we use it
- To run your AI chatbots and answer end-visitor messages.
- To send retrieval-augmented prompts to OpenAI (model: gpt-4o-mini) so your bots can give relevant answers. OpenAI does not retain or train on data sent via our API integration.
- To send transactional emails: signup confirmation, lead notifications, daily activity digests.
- To enforce plan limits and bill subscriptions through Razorpay.
- To investigate abuse and respond to support requests you send us.
Who we share it with
- OpenAI (LLM provider). Conversation messages and relevant knowledge chunks are sent to generate replies. See their API data policy.
- Supabase (database + auth). Hosts user accounts and all stored data.
- Vercel (hosting). Receives request logs.
- Resend (transactional email).
- Razorpay (payments). Receives only billing- relevant identifiers.
- We do not sell, rent, or share your data with advertisers or data brokers.
Where it's stored
All customer data is stored in Supabase's primary region (currently AWS Mumbai / ap-south-1). Backups are encrypted at rest. Transit is always over HTTPS.
Your rights
You can: access, correct, export, or delete your account data at any time through the dashboard, or by emailing rigoxlabs@gmail.com. We respond within 7 working days. Deletion removes your account, bots, knowledge, conversations, and leads from our active database; backups are purged on a 30-day rolling schedule.
Cookies
We use only first-party session cookies for keeping you signed in. We do not use third-party advertising or tracking cookies.
Children
Rigox is a B2B service not directed at people under 18. Do not use our service on behalf of, or to collect data from, minors.
Changes to this policy
If we materially change how we handle data, we'll email all active account holders at least 14 days before the change takes effect.
Contact
Questions, complaints, or rights requests: rigoxlabs@gmail.com
+91 94164 43248 (Mon–Sat, 9 AM – 7 PM IST)
Made in India. Serving worldwide.