The everyday essentials

Privacy policy

Your conversations can be personal. Here’s what the Service processes, why, and the choices you have.

Effective September 27, 2026TermsPrivacy

1. Who is responsible

Twolabs Inc., doing business as Superbly AI, based in Delaware, United States, operates superbly and is responsible for the personal information described in this policy. Contact team@twolabs.ai with privacy questions or requests. This policy covers our website, chat, agent, and API services.

2. Information we process

  • Account information: your email, account identifier, sign-in information, and preferences. If you sign in with a third-party provider, we receive the account information it shares for authentication.
  • Conversations and tasks: your prompts, replies, chat titles, model choices, scheduled-task instructions, agent activity and results, and information included in them.
  • Memory: conversation information and inferred facts used to personalize the Service when memory is enabled. Inferences may be inaccurate.
  • Connected services: connection identifiers, status and permissions, and information the agent reads or sends through apps you authorize. An agent workspace may also hold files and task state needed for your work.
  • Billing and usage: payment identifiers, credit balances, purchases, transactions, model and tool usage, timestamps, and costs. Payment details entered at checkout are handled by Stripe; our application does not collect full card numbers.
  • Technical and support information: authentication cookies, browser storage, service request and error information, and messages you send us. Infrastructure providers may also process IP addresses and device or network information to operate and secure their services.

Do not include passwords, access keys, or sensitive personal information in a conversation unless it is necessary for your task and you understand the services that will receive it. Information about other people should be shared only when you have a lawful basis to do so.

3. How we use it

We use information to authenticate you, generate replies, run requested and scheduled tasks, personalize conversations with memory, operate connected apps, calculate charges, deliver service emails, provide support, and detect or resolve abuse and technical problems. We also process information when needed to meet legal obligations and protect legal rights.

Where a law requires a legal basis, we rely on performing our agreement with you for the features you request, legitimate interests in operating and securing the Service where appropriate, compliance with legal obligations, and consent where required. You can withdraw consent for optional processing without affecting processing already carried out lawfully.

4. Services that help us deliver superbly

Providing an AI service requires sending relevant information to other services. The data depends on the feature you use and your instructions. Our service providers include:

  • Supabase and Google Cloud: account authentication, database, hosting, and infrastructure.
  • Anthropic, OpenAI, OpenRouter and other model providers: prompts, relevant conversation context, and tool results needed to generate answers. Anthropic and OpenAI models are called directly through their APIs under their own data terms; other models go through OpenRouter's zero-data-retention endpoints.
  • Honcho: conversation memory and personalization when enabled.
  • Agent37: the computing environment used for agent tasks and their working data.
  • Composio and your connected apps: account connections and the data needed to carry out authorized actions.
  • Upstash QStash: scheduling and delivery of task triggers.
  • Stripe: checkout, credit purchases, receipts, and fraud prevention.
  • Resend: authentication and service email delivery, including task results when email delivery is selected.

Web searches and browsing can also send queries or requested content to search services and destination websites. Connected services you choose have their own privacy practices. A message sent or a file created in another app may remain there after you disconnect it from superbly.

Our model catalog filters for models with a zero-data-retention endpoint. This is a provider routing characteristic, not a claim that superbly keeps no conversation history or that every service above has the same retention policy. Provider settings and terms matter; OpenRouter’s zero-data-retention documentation also describes temporary in-memory prompt caching. We do not make a blanket promise about every provider’s training or retention practices.

We may disclose information when legally required, to address fraud or security threats, or to protect people’s rights. If our business is acquired or reorganized, information may transfer as part of that transaction, subject to applicable law and required notice.

5. Memory, connections, and browser storage

The Memory page controls Superbly’s recording of memories after conversations and lets you delete individual remembered facts. Existing facts remain until you remove them. Agent workspaces also maintain their own context and memory, which these settings do not fully control. Turning this setting off does not guarantee that an agent stops using or retaining information in its workspace. Contact us if you need help clearing agent workspace data. These controls do not delete stored chats, account records, or data already sent to another service.

You can manage connected apps in Connections and scheduled tasks in Jobs. You can also revoke access in the connected service itself. Revoking access does not undo actions already taken.

We use cookies for sign-in and session continuity. Browser storage remembers interface preferences and can temporarily hold an unsent draft while you create an account. You can clear these in your browser, although clearing authentication cookies signs you out. The current app does not include advertising trackers or sell personal information for targeted advertising.

6. Retention and account deletion

Archiving a chat hides it from your recent list and can be reversed. Deleting a chat removes its transcript from your chat history, but does not clear saved memories, agent workspace data, billing records, or scheduled jobs. Manage those separately through Memory, Jobs, or an account deletion request.

Conversations, memory, tasks, and account records are stored to support your ongoing use. Retention depends on the type of information, your choices, operational needs, and applicable legal requirements. There is no single retention period covering all records and providers.

Delete your account in Settings to start removal of your agent workspace, memory, connected accounts, and account data. These steps run across several systems. If a step fails, deletion may be incomplete until retried or resolved; contact us if you need help. Deleting the account also removes access to your remaining credit.

Deletion does not necessarily remove transaction records a payment provider must keep, information needed for legal obligations or disputes, temporary backup copies, or content already sent to another person or service. Ask us about a particular record if you need more detail. We do not promise immediate deletion from every backup or third-party system.

7. Security and international processing

We use access controls and authenticated connections to protect account data. Our application request logs omit prompt bodies, and database records for API keys and agent router and MCP authentication tokens use hashes instead of storing those raw tokens. These measures do not mean all credentials or content can be handled in the same way: authentication sessions and connected-service credentials are processed as needed by the relevant providers.

No online service is completely secure. Protect your sign-in credentials and contact us if you suspect a security issue. Our infrastructure and providers may process information in the United States and other countries, where privacy laws may differ from those where you live. Any international transfers remain subject to applicable legal requirements.

8. Your privacy rights

Depending on where you live and which laws apply, you may have rights to access, correct, delete, or receive a portable copy of personal information, restrict or object to certain processing, withdraw consent, or opt out of sale, targeted advertising, or certain automated profiling. You may also have a right to information about recipients of your data and to complain to a privacy regulator.

Send requests to team@twolabs.ai. We may need to verify your identity and, where relevant, an authorized representative’s authority. We will respond within the time required by applicable law and explain if we cannot fulfill a request. If you disagree with our response, reply to the same address asking for a privacy appeal. We will not discriminate against you for exercising applicable privacy rights.

9. Children and policy updates

The Service is not intended for children under 13. If you believe a child has provided us with personal information, contact us so we can investigate and take appropriate steps.

We may update this policy as our practices change. We will update the effective date and provide notice of material changes where required. You can always contact us with questions about the current policy or a previous version.