Privacy Policy
Last updated: April 2026
GPA Bot ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (gpabot.ai) and Chrome extension (collectively, the "Service").
1. Information We Collect
Information You Provide
- Account information: Email address and password when you create an account
- Payment information: Billing details processed securely through Stripe (we do not store your full credit card number)
- Support communications: Any messages you send to our support team
Information Collected Automatically
- Usage analytics: Feature usage frequency, session duration, and interaction patterns to improve the Service
- Device information: Browser type, browser version, and operating system
- Log data: IP address, access times, and referring URLs
Screenshots and Content
Important: When you use GPA Bot's screenshot-based features, screenshots are transmitted to our servers for AI processing only. Screenshots are processed in real-time and are not stored permanently. They are automatically deleted from our servers after processing is complete.
2. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your subscription and manage billing
- To send you important updates about your account or the Service
- To respond to your support requests
- To analyze usage patterns and improve user experience
- To detect, prevent, and address technical issues or abuse
3. Third-Party Services
We use the following third-party services to operate GPA Bot:
- Firebase (Google): Authentication and user management. Subject to Google's Privacy Policy.
- Stripe: Payment processing. Subject to Stripe's Privacy Policy. We do not have access to your full payment card details.
- AI Providers (OpenAI and others): Processing of screenshots and content for AI-powered features. Content sent to AI providers is used solely to generate responses and is subject to their respective data processing agreements.
4. Cookies and Tracking
We use essential cookies and local storage to:
- Keep you signed in to your account
- Remember your preferences and settings
- Ensure the Service functions properly
We do not use third-party advertising cookies or sell your data to advertisers.
5. Data Retention
- Account data: Retained as long as your account is active. Upon account deletion, your data is removed within 30 days.
- Screenshots: Processed in real-time and deleted immediately after processing. Not stored permanently.
- Usage analytics: Aggregated analytics data may be retained for up to 24 months.
- Payment records: Retained as required by financial regulations and tax laws.
6. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL), secure authentication, and access controls. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
For All Users
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your data in a portable format
GDPR Rights (EEA Residents)
If you are in the European Economic Area, you have additional rights under GDPR, including the right to object to processing, the right to restrict processing, and the right to data portability. Our legal basis for processing is your consent and the performance of our contract with you.
CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information is collected and how it is used
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell your personal information)
- Non-discrimination for exercising your privacy rights
8. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected data from a child under 13, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
support@gpabot.ai