Teleperson
Security

Privacy & data retention

What the TelepersonLens browser extension accesses, how long Teleperson keeps your data, how to delete it, and the rights you have under GDPR and US privacy laws.

This page is the plain-English summary of what the TelepersonLens browser extension can access, how long Teleperson keeps your data, and how you can delete it. The full internal policy that engineering and our auditors work from is the Data Retention & Deletion Policy (TLP-SEC-RET-001), and the two are kept in sync.

What the browser extension accesses

TelepersonLens is a browser extension, so this section spells out exactly what it can see, and when.

The page you're on. To recognize which company's site you're visiting, the extension reads the current tab's public page content — its hostname, title, meta description, headings, and a short excerpt of the visible text. It reads the site in the foreground when the panel is active; it is not a background crawler of your browsing history. That context identifies the company and generates the company overview, which is cached so the next visitor doesn't have to regenerate it. The broad host permission (https://*/*) exists for one reason: the company you need help with could be any website, so the panel has to be able to run anywhere. It is not used to build a record of everywhere you go.

Your email — only if you connect it. The Mail tab is off until you explicitly connect a Google account. When you do, the extension requests read-only access and uses it narrowly: it searches only for recent messages (roughly the last two weeks) from companies already in your Hub, so it can surface a shipping update or a bill next to that company. Connected-account tokens are stored encrypted; the small set of matched messages is cached to render the tab and is pruned automatically. Disconnecting removes the tokens and the cache. Teleperson never reads mail unrelated to your Hub companies, never sends email on your behalf, and never uses your mail for advertising.

Your saved passwords stay on your device. The password vault is a local, AES-256-encrypted store in your browser. Credentials you save are never transmitted to Teleperson's servers — autofill happens entirely in the page and is gated to the matching site. What may be recorded on the server is an access-audit event (that a fill happened, and when) — never the username or password itself.

Your finances — only if you link them. Bank and card connections go through Plaid; Teleperson never sees your banking username or password (see the retention table and subprocessors below).

AI processing. When you use Ask AI, the spend review, or the chat co-pilot, the relevant context — the company, the page you're on, or your aggregated spend figures — is sent to Anthropic's Claude to generate the response. Per Anthropic's API terms, this is not used to train their models. If you haven't supplied your own key, the call is proxied through Teleperson's backend (which holds the key); we don't retain the prompt beyond returning the answer.

Diagnostics. To keep the beta stable, the extension may send anonymous crash reports (an error message, stack trace, extension version, and the hostname where it happened — never full URLs or page contents) and a one-time anonymous "installed" signal. These carry no account data when you're signed out.

What we keep, and for how long

DataHow long we keep it
Your profile (email, name, plan, optional demographic fields)While your account exists. Deleted when you close your account.
Your Hub (followed companies)Same as your profile.
A Plaid bank/card connection (token + transactions + balances)While the connection is active. Deleted on disconnect. No grace window.
A vendor account connection (eBay, etc. — token + cached orders, invoices, shipments)While the connection is active. Deleted on disconnect.
A connected email account (Gmail OAuth token + a cache of recent messages from your Hub companies)While connected. Deleted on disconnect. Cached messages are pruned automatically. Access is read-only and scoped to your Hub companies.
Your password vault (site credentials you save)Stored locally in your browser, AES-256 encrypted. Never sent to our servers. Removed when you clear it or uninstall the extension.
Voice Concierge transcriptsStreamed live in the panel. Persistence is opt-in; if you opt in, transcripts are kept for 90 days unless you explicitly retain them.
Chat co-pilot transcriptsStay in your browser by default. Backend recording is opt-in; if you opt in, kept for 90 days.
Stripe billing (subscription + invoices)Subscription is cancelled when you close your account. Stripe itself retains payment records as required for tax / dispute handling, governed by Stripe's DPA.
Security logs (auth events, deletions we performed for you)Up to 7 years, so we can prove on regulatory request that we deleted what we said we would. Your user_id is removed from these rows when you close your account; what remains is the audit trail, not your identity.
Anonymous crash reports (error message, stack trace, extension version, hostname — never full URLs or page content, and no account data when signed out)Kept for beta diagnostics and triage.
Edge Function logsPer Supabase platform default — typically up to 90 days.
Database backupsPer our Supabase point-in-time-recovery window. If you delete data and we later restore from a backup that pre-dates the deletion, we re-run the deletion as part of the restore.

Disconnect = deletion

When you disconnect a Plaid item or a vendor account, deletion is hard, not soft:

  1. We attempt to revoke the token at the third party (best-effort).
  2. We delete every row scoped to that connection: tokens, transactions, orders, shipments, invoices.
  3. We append an entry to our internal audit log so we can prove the deletion if asked.

The data is gone. There is no grace window and no soft-delete flag.

Your rights

If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR)

You have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Delete your data — the "right to be forgotten" (Art. 17)
  • Restrict processing in certain circumstances (Art. 18)
  • Receive a portable copy of your data in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Not be subject to legal or similarly significant decisions made solely by automated means (Art. 22). Teleperson does not make such decisions about you.

You also have the right to lodge a complaint with your national data protection authority.

If you are in the United States

You have rights under your state's privacy law. The substantive set is similar across California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), and Teleperson applies the strictest applicable standard:

  • Know what categories of personal information we collect and what we do with it (this page; the Security overview)
  • Access the specific pieces of personal information we hold
  • Delete your personal information
  • Correct inaccurate personal information
  • Opt out of sale or sharing for cross-context behavioral advertising — not applicable here: Teleperson does not sell or share your personal information for advertising
  • Limit the use of sensitive personal information (your bank-link tokens, vendor tokens, and 2FA secrets are used only to provide the service you asked for)
  • Appeal if we decline a request (VCDPA / CPA / CTDPA require this; Teleperson honors it for residents of any state)

We do not discriminate against you for exercising any of these rights.

How to exercise your rights

The fast paths are in the product:

  • Disconnect a Plaid item or a vendor account → settings → disconnect. Deletes everything scoped to that connection.
  • Close your account → settings → close account. Triggers the account-deletion flow described above.
  • Export your data → request an export and we generate a JSON file for you. The download link is valid for 30 days.

For anything else — a formal access, correction, restriction, objection, or appeal — email security@teleperson.com.

  • We acknowledge within one business day.
  • We respond within 30 days (GDPR) or 45 days (CCPA and most US state laws). When the request is complex or requires verification with a subprocessor, we may extend by the period each statute allows — and we will tell you when we do.

To verify it's really you, we ask you to demonstrate control of the account email, and (if you have MFA enabled) complete an MFA challenge.

Subprocessors

Teleperson uses these third parties to provide the service. Each one holds a Data Processing Agreement and acts as a service provider under CCPA / processor under GDPR.

SubprocessorWhat they handle for us
SupabaseDatabase, authentication, and Edge Functions.
PlaidBank and card connections. Plaid handles the credential exchange — Teleperson never sees your bank username or password.
GoogleGmail API, only when you connect your email. Access is read-only and used to find recent messages from the companies in your Hub. Governed by Google's API Services User Data Policy, including the Limited Use requirements.
StripeSubscription billing. Stripe handles all card data; Teleperson never sees raw card numbers.
VapiVoice AI infrastructure for Voice Concierge calls.
ElevenLabsText-to-speech for voice features.
AnthropicThe Claude language model that powers Ask AI and the chat co-pilot. Per Anthropic's API terms, your prompts are not used for training.
VercelHosting for the marketing site and this docs site. End User application data does not pass through Vercel.

What we don't sell or share

Teleperson does not sell your personal information and does not share it for cross-context behavioral advertising. Subprocessors above process data only for the purposes we direct.

On this page