ConvoScore

Security

How ConvoScore handles your data

A plain-language summary of where your data lives, who touches it, and the choices you control.

Last updated September 2026.

On this page

Where your data is stored

Lead and conversation data

All leads, chat transcripts and scores are stored in a managed PostgreSQL database (Neon) hosted in the EU, in Frankfurt (AWS eu-central-1).

The application

The ConvoScore dashboard and API run on Vercel's serverless platform. The embeddable widget is served as a small static script from a CDN.

Backups

The database provider keeps point-in-time backups. Backups inherit the same EU location and retention as the primary database.

Who processes your data (sub-processors)

Vercel

Dashboard and API hosting, plus the CDN that serves the widget script.

Neon

Managed PostgreSQL database for all lead, conversation and account data.

Google (Gemini API)

Each visitor message is sent to Google's Gemini API to run the conversation and generate the qualification score. Google's paid API terms state this data is not used to train Google's models.

Brevo

Transactional email only: lead notifications and account emails. Not used for marketing.

Paddle

Our payment provider and Merchant of Record. Paddle handles checkout and billing data; ConvoScore never sees full card details.

How your data is used

Qualification and scoring

Visitor messages are used to run the conversation and produce the HOT / WARM / COLD score and summary that your team sees.

No third-party training

Your conversations are never sold, and never added to a third-party model's training data.

No cross-customer mixing

Each account's data is isolated. One customer's conversations are never used to shape another customer's results.

Retention and deletion

How long data is kept

Lead and conversation records are kept while your account is active, so your history stays searchable.

Deleting data

You can delete individual conversations from the dashboard. To delete an entire account and its data, contact us and we will remove it.

After cancellation

If you cancel, your data is retained for a short grace period in case you return, then deleted.

Access and transport security

Encryption in transit

All traffic between visitors, the widget, the dashboard and our API uses HTTPS/TLS.

Authentication

Dashboard passwords are stored hashed. Google sign-in is supported so you can skip a separate password entirely.

Who can see your data

Only you and the teammates you invite. Operator access is limited to support and debugging, on request or when investigating an issue.

Your choices

Cookie consent

Analytics only load after you accept. You can change your choice any time from the cookie preferences link in the footer.

Data processing agreement

Need a signed DPA for your procurement process? Contact us and we will sort it out.

Reporting a vulnerability

Found a security issue? Contact us and we will respond quickly. Please give us a reasonable window to fix it before disclosing.

Security question, or need a signed DPA?

Contact us