Privacy notice
Effective 14 September 2026
Who provides Frontdesk
Frontdesk AI is operated by შპს ატმოსგეითი (Atmosgate), registered in Georgia, company identification number 406568129. Contact levani.parastashvili@gmail.com for privacy questions and data requests.
Our role and your business’s role
We manage information needed to provide and secure Frontdesk accounts and support. A business using Frontdesk decides which accounts to connect, what knowledge to upload and how to use its customer conversations. We process that business’s customer content to provide the service on its instructions. If you contact a business through a connected channel, its privacy notice also applies.
Information we process
This includes account details, workspace membership, business inventory, uploaded knowledge and files, connected-account identifiers and authorization credentials, messages and replies, customer contact information provided in conversations, delivery records and operational logs. The connected platform controls what it makes available through its official interfaces. The service does not automatically import every historical message from every channel.
Why we use information
We use information to authenticate users, connect authorized business accounts, generate replies from relevant business information, provide a shared inbox, route human handoffs, maintain the service, handle requests and investigate abuse or errors. Where a legal basis is required, account and service administration relies on providing the requested service, protecting the service and complying with applicable obligations. The business is responsible for a valid basis for the customer content it instructs us to process and for required notices or consent.
Service providers and data flow
- Convex provides the backend, authentication data, database and file storage. Our application deployment is in Ireland.
- Vercel hosts and delivers the web application and processes web-request information. When file features are enabled, Vercel also processes uploaded file content in isolated conversion environments and delivers authorized file downloads. Convex remains the database and file-storage provider.
- Microsoft Azure provides AI model APIs. Relevant message context, selected inventory and knowledge are sent for reply generation and search embeddings. Rendered document pages and images are sent to Azure models for reading when required. Azure is used here for AI models.
- Meta provides the Facebook Messenger, Instagram and WhatsApp interfaces for accounts a business connects, subject to Meta’s own terms and privacy practices.
- Google Gmail, when account email is enabled, sends verification and password-reset messages through our temporary support mailbox. Google processes the recipient address and email content. The sender grant is send-only and does not connect a customer’s inbox. Emailing support also sends your request to Google.
- GitHub Actions runs backup export and encryption. A hosted runner temporarily processes the export before encrypting it; retained backup artifacts are encrypted.
File reading uses Vercel conversion and Azure models when the feature is enabled. Supported formats, file-size limits and processing results are shown in the workspace. Reading a file is not an antivirus certification or a guarantee that every extracted detail is correct.
We do not sell conversations or use them to train our own shared AI model. Service providers may process data for their service operations, security or abuse monitoring under their applicable terms. We do not promise that provider monitoring is disabled.
Where processing happens
Our operating and support team accesses data from Georgia. That does not mean all cloud processing occurs there or only in Ireland. Azure chat uses a Global Standard deployment; relevant inference may occur in other supported geographies. Embeddings use a Microsoft-defined European data zone. File conversion and delivery are configured for Vercel’s Frankfurt region; this does not limit all provider operations to that region. Vercel, Google, GitHub and other providers also have international infrastructure and support operations. Applicable contracts and transfer requirements govern that processing; we do not claim a single-country or EU-only service.
Retention
Conversations have no automatic expiry. Conversation history, inventory and business knowledge remain until an authorized user removes them or an applicable deletion request is completed. Deleting an account or workspace is separate from disconnecting a channel or pausing AI.
Short-lived verification codes, delivery metadata, logs and backups have separate lifecycles. Account-email payloads are encrypted while queued and removed after dispatch or expiry; account-email delivery metadata is kept for up to 30 days. Routine encrypted backup artifacts currently expire after 14 days. A completed live-data deletion does not instantly remove an older backup. Records required for security, a dispute or a legal obligation may be retained for the applicable purpose.
Access and safeguards
Workspace access depends on account authentication and membership. Connected credentials are encrypted. Authorized business teammates can read and answer their workspace’s conversations; necessary platform support and infrastructure providers may process information to operate the service. Authenticator enrollment is optional. No online service can guarantee that every security risk will be eliminated.
Your choices and requests
You can manage the connected accounts and data controls offered in your workspace. Contact us to request access, correction, export or deletion of information, or to raise a privacy concern. Identify the account, business or conversation involved without sending passwords or codes. We verify identity and authority and explain any applicable limitation. If your request concerns a business’s customer records, we may need to coordinate with that business. Rights and complaint routes depend on the law applicable to you.
Updates
We publish material changes here and provide additional notice where required. New channels and processing providers are described before they are made available. See support and data requests for help, or review the terms.
Back to workspace