Privacy policy
This policy describes how Supportifier processes personal data, including data retrieved through Google’s APIs. It applies to the Supportifier service at app.supportifier.se and to the website supportifier.se.
This is a translation. The Swedish version is the original and prevails in the event of any discrepancy.
Data controller
Supportifier is provided by Successifier AB, company registration number 559566-3864, Stensövägen 6, 138 30 Älta, Sweden.
Questions about personal data and erasure requests go to mc@successifier.com.
When we process email and customer data on behalf of a customer, the customer is the data controller and Supportifier is the data processor. A data processing agreement is signed with every customer as standard.
Permissions we request from Google
Supportifier requests the following permissions. We request no others.
- openid, userinfo.email, userinfo.profile
- Used solely to identify the agent signing in to Supportifier. We read name, email address and profile picture to create the account and show who is signed in.
- gmail.modify
- Used on the mailboxes the customer explicitly connects to Supportifier. We read incoming email to create and answer support tickets, and change labels and read status so that tickets are not handled twice. We never delete email permanently and do not move it to the bin.
- gmail.send
- Used to send the replies an agent has reviewed and approved, from the customer’s own address.
What data is processed
From the connected mailboxes we process message content, sender and recipients, subject line, timestamps, thread and message ids, and attachments. This data is needed to create tickets, avoid duplicates, measure response times and generate draft answers.
Google API Services User Data Policy
Limited Use. Supportifier’s use of information received from Google’s APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In concrete terms, data from Google APIs is:
We do not use Gmail data to train, fine-tune or improve generalised AI or machine learning models.
No human at our company reads the content of your email, except with the customer’s explicit consent, during a security investigation, or where required by law.
How data is used in the AI features
The content of a ticket is sent to our language model provider to generate a draft answer. The draft is never sent to the customer automatically — an agent reviews and approves every reply before it goes out.
Approved replies improve the drafts within the customer’s own account. That learning happens only there. The data is never used to train the provider’s models and is never shared with other customers.
Our language model provider runs with zero data retention. Content is processed while the answer is generated and is not stored at the provider afterwards. The storage that does take place is therefore the storage set out in section 7 below, with us.
Where data is stored
All customer data in the service is stored within the EU/EEA. We make no transfers of customer data in the service to third countries.
Visitor statistics and ad measurement on the website supportifier.se are processed by Google and OpenAI, who may transfer data to the United States. This only happens after your consent — see the cookie page.
How long we keep data
- Email content (body, attachments)
- Deleted 30 days after the ticket is closed.
- OAuth tokens
- Kept until the customer disconnects the mailbox. Deleted within 24 hours of revocation.
- Application and access logs
- 90 days. Contains metadata such as message id, timestamp and account — not message content.
- Security logs
- 12 months, for incident investigation.
- Backups
- 30 days rolling, then overwritten.
On disconnection or account deletion, all Gmail-derived content is removed within 30 days. Access tokens are revoked immediately.
Sign-in details (account id, email address, name and profile picture) are kept for as long as the user account is active and deleted within 30 days of the account being removed.
Sub-processors
The following providers process data on our behalf:
- Anthropic
- Language model generating draft answers. Runs with zero data retention — content is not stored at the provider after the answer is generated, and is never used to train their models.
- Vercel
- Operation and hosting of the application.
- Resend
- Sending email from the system.
Security
Your rights
You have the right to request access, rectification, erasure, restriction of processing and data portability, and to object to processing. Contact mc@successifier.com and we will respond within 30 days.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
Changes
We may update this policy. Material changes are communicated to affected customers before they take effect. The date and version are stated at the top of the page.
Contact
Successifier AB · Stensövägen 6, 138 30 Älta, Sweden · mc@successifier.com