Skip to content
SayGday.ai
How it worksExamples↗(opens in a new tab)Try itPricingQuestionsWhat’s nextStory
Log inTry it free

Privacy Policy

Last updated: 1 October 2026

Who we are

SayGday.ai is operated by HEAR.IS Pty Ltd (ABN 37 702 004 608), in Canberra, providing website assistants and a customer conversation dashboard for small businesses. SayGday.ai is the company’s registered business name. Contact us at hello@saygday.ai.

The website assistant: at a glance

You can ask a business's website assistant a question without creating an account. Messages and the assistant's replies are sent to our service and saved so the business's authorised team can review what customers asked. If you choose to leave an enquiry for a personal response, an email address is required and the business follows up by email.

An enabled AI provider may process questions and relevant context. Our providers may process information outside Australia. The sections below explain what is stored, who receives it and how to request access, correction or deletion.

The public homepage practice demo answers most questions with preset answers within the page. A question the presets don't recognise is sent to our service and may be processed by an AI provider to write a short reply; demo questions are not saved, and the demo cannot submit an enquiry. The original FAQ widget and any separately enabled services are explained in their own sections below.

Information we collect and why

  • Client accounts: email address, account identifier, business membership and role, and sign-in records. Supabase and the configured email sender process the emailed sign-in code. Browser storage keeps your authenticated session so you can use the dashboard; sign out on shared devices.
  • Website setup: the website address you provide, source page addresses and public page content imported into your workspace. When you ask us to read your website, we fetch up to eight of its public pages and may send their text to an AI provider to prepare draft answers. Imported information is saved as private drafts for you to review; it becomes customer-facing business knowledge only after you approve it.
  • Website verification: the unique verification value, website address, check results and verification timestamps. We check a public DNS TXT record to confirm that you can manage the saved website's domain and associate its verification with your account. Earlier verified setups may retain a website tag, which we check in the published page. DNS records and website tags are public.
  • Billing (when payments are available): checkout, customer and subscription identifiers, subscription status, payment period and billing event records. These associate your payment with your business and control activation. Stripe handles payment card details through its hosted checkout; our dashboard does not collect your card number or security code.
  • Website conversations: customer messages, assistant replies, timestamps, channel identifiers, summaries and conversation status. These let the assistant answer questions and give the business a read-only history of what customers asked. We also save a conversation identifier and access token in your browser tab to reconnect you to that conversation.
  • Enquiries: name, required email address, request notes, the recorded time of your agreement to share the request and any phone number retained from an older or separately enabled flow. The current website enquiry form requires email so the business can respond using its normal email service. When the business has email notifications switched on, its owners and staff also receive the enquiry by email. This is not agreement to marketing.
  • Business information: profile details, approved knowledge, availability and assistant settings supplied by an authorised client. Published profiles and approved answers are intended for customers; a public profile can also be read by other software when the business enables it.
  • Contact form and email: we receive the name, email, business name and message you send us, to answer your request and provide support.
  • Service and security records: account activity, request and delivery identifiers, usage counts and errors help us run the service and investigate problems. Hosting providers may process IP addresses and request metadata; the website chat and the homepage demo also use an IP-derived identifier to limit abusive requests, and those counters are deleted within two days.

Please do not include passwords, payment card details or sensitive personal information in chats or request notes. Personal information you include in a message is part of that message's processing and storage. You can contact the business directly using its published contact details instead.

Who can receive or access information?

Access to a business's private workspace is restricted by business membership and role. Authorised service operations and support may also access information where needed to operate, secure or troubleshoot the service. The business receiving your enquiry is responsible for how its team uses and follows up on it; its own privacy policy may also apply.

  • Netlify: website hosting, server functions and contact-form processing.
  • Supabase: client authentication and storage of business, website setup, verification, subscription, conversation, enquiry and service records.
  • Stripe: payment checkout and subscription management. Stripe receives the account and billing information required for checkout, along with the payment details you provide to it. We receive payment and subscription identifiers and status updates so we can manage access to the service.
  • Anthropic (Claude): when enabled, receives the question, recent chat context and relevant approved business answers to write or choose a reply, and, when a business asks us to read its website, the text of that website's public pages to prepare draft answers. This can include personal information typed into the conversation.
  • OpenAI, through Netlify's AI gateway: when enabled, receives the question, recent chat context and relevant approved business answers to choose a matching answer. This can include personal information typed into the conversation.
  • Without a configured AI service, these AI steps are not used, and approved answers are matched without one.
  • Configured email provider: receives the account email address and sign-in message to deliver your login code, and handles any email you send to our support address.
  • Resend: when a business has enquiry notifications switched on, delivers each new enquiry by email to that business's owners and staff, including the visitor's name, email address and request notes, any phone number given, and the last few questions asked in that conversation. It also emails the person who asked us to read a business's website, at their account email address, when the draft answers are ready.

Processing outside Australia

Our hosting, database, AI, email and connected-channel providers may process information outside Australia. Locations depend on the providers and account settings used for the particular service. We do not promise Australian-only storage or processing. Contact us for the current provider and location details relevant to your business before submitting information that has location restrictions.

Retention and browser storage

Website chat conversations, the messages in them, the enquiries left in them and the emails we sent the business about them are deleted automatically 12 months after the conversation's last message or enquiry. A business owner can delete all of their conversation history sooner from Settings → Your data, and can download a copy first. Account, website setup, verification, subscription and activity records remain stored while the account is in use and until they are removed through an authorised process; billing records are kept for as long as Australian tax law requires. Deleted records can persist in encrypted backups for a short period before those backups are overwritten. There is no self-service account deletion yet: contact us to close an account. Closing a chat, resolving an enquiry, signing out or clearing browser storage does not delete the server's copy.

Website chat uses browser tab storage to reconnect you to a conversation. Client login sessions use browser storage to keep you signed in. These stores support the service rather than advertising profiles. Storage for the original FAQ widget is explained below.

Access, correction, deletion and complaints

Email hello@saygday.ai to request access to, correction of or deletion of information we hold, or to raise a privacy concern. Tell us which business and conversation or account the request relates to; do not send a login code or password. We may need to verify your identity and work with the relevant business. We will review the request, explain the steps we can take and tell you about any information that must be retained or remains in provider backups.

For a complaint, describe what happened and how you would like it resolved. We will investigate and respond using the contact details you provide. You can also find information about privacy complaints through the Office of the Australian Information Commissioner.

Separately enabled services and future upgrades

Social channels, phone triage, automatic bookings and connected business tools are not part of the current self-service release. This section explains processing only if those services are separately enabled for a business; it does not mean they are included in the website plan.

Where an enabled service accepts booking requests, we may store the name, email, optional phone number, request notes, selected time, booking status and the recorded time of agreement to share the request. Those booking records are stored in Supabase and remain until removed through an authorised process, as described in the retention section.

Where a business connects SMS, social messages or phone triage, we receive messages or transcripts, sender identifiers and related delivery details from that provider for the business's inbox. A connected phone provider also handles any call transcription. We store connected-account details supplied by the authorised business.

Twilio can process SMS, phone triage and enabled owner notifications; Meta can process Facebook and Instagram messages. Square, ServiceM8 and Xero receive details needed for actions the business chooses to perform through its connected account. These providers receive data only for features connected and used, and their own privacy terms also apply.

For visitors and businesses using the original FAQ widget

The original widget downloads public business answers and matches questions in your browser. It does not send its conversation to our inbox or an AI provider. It keeps chat history in browser tab storage so it can continue between pages. How long that history, and any state retained from retired demos, remains available depends on the browser and its session-restore behaviour.

Public business configuration for the original FAQ service is maintained through GitHub and published with the website. Private website conversations and enquiry records are not published in that configuration.

Existing FAQ customers can email hello@saygday.ai for help with that service. New customers should follow the website assistant information above.

SayGday.ai

Made in Canberra. For Australian small business.

How it worksPricingQuestionsStoryContactPrivacyTerms
© 2026 SayGday.ai · Canberra, Australia

SayGday.ai acknowledges the Ngunnawal and Ngambri peoples, the Traditional Owners and Custodians on the land where we live, learn and work. We recognise their continuing connection to lands, waters and communities and give our respects to their Elders past, present and emerging.