Invocursor
About Customers Pricing Try It Out
Log in Book 15 minutes

Privacy and data handling

Updated: September 14, 2026 · Invocursor Inc.
Scope: The managed-service description below applies to the new managed integration and updated public synthetic demo. Existing customer deployments, including Attendify, are not migrated by this release. Their existing agreements and applicable previous policy remain in place. Material changes for an active customer require notice as described below.

1. Who we are and what we do

Invocursor Inc., Ontario, Canada, provides in-product assistance using OpenAI through our managed API account. Customers choose approved workflows, permitted roles, and the purpose of processing. We process end-user requests to provide that service. We also handle our own account administration, security, and business communications.

2. Temporary processing is different from storage

Requests and a short recent conversation window pass through Invocursor's backend to OpenAI. They are processed in application memory. The new managed application does not write conversation content, field values, page URLs, or support-ticket text to its database, application logs, analytics records, or backups. Its dashboard has no transcript viewer. This is not end-to-end encryption or a claim that our systems can never access content while processing it.

Hosting and model providers also process network requests under their own controls. Infrastructure access logs may contain connection metadata such as IP addresses and timestamps. We do not represent this service as independently audited, certified, or incapable of retaining content under every infrastructure or incident condition.

3. What is sent to the assistant

The new managed widget sends the user's request, up to four recent conversation entries, an approved page identifier, and explicitly approved numeric or boolean field states. It does not send page tables, arbitrary headings, complete page text, query strings, or unapproved form fields. Tenant and role permissions are assigned through the customer's authenticated backend, using short-lived sessions.

Email addresses and recognized phone numbers are replaced with temporary placeholders before transmission by the widget. The replacement map remains in browser memory. Recognized credentials, government-ID patterns, and payment-number patterns are redacted rather than restored. These controls are limited pattern checks, not complete anonymization. Names, unusual identifiers, or sensitive free text can still appear in messages. Only submit data approved for the workflow.

4. Sensitive information and human control

Do not submit passwords, access tokens, payment-card details, government identification, protected health information, or sensitive children's records through this managed integration. Sensitive pages should be excluded from approved coverage. A dedicated application field does not make its contents safe to transmit. Regulated or more sensitive deployments require a separate data-flow, security, contractual, and legal review before activation; a generic DPA alone is not sufficient.

The assistant prepares approved steps. Consequential saves and sends require human review through the host application. Browser checks are distinguished from host-verified outcomes. A resolution is counted only when a user or the customer's support system explicitly confirms it.

5. Customer-controlled conversation and support storage

When configured, an end user can review and send selected conversation or support context directly from the browser to the customer's own authenticated endpoint. That content does not pass through Invocursor for delivery. The customer controls its database, staff access, retention, deletion, and onward support integrations. Delivery is not represented as confirmed until that endpoint acknowledges durable receipt. A copied demo handoff draft is not a delivered support ticket.

The new widget keeps its working history and placeholder map in browser memory, rather than persistent local or session storage. Clear the conversation or close the page to end that widget history. This does not delete records the user already sent to the customer's systems.

6. What Invocursor retains

Our separate private metrics store contains randomly generated request references, tenant identifiers, dates, and fixed event categories: requests, returned answers, failures, prepared workflows, browser checks, host confirmations, explicit resolutions, and handoff status. These events contain no free-text payload. Metric records older than 30 days are removed by scheduled cleanup; a storage outage can delay deletion until maintenance recovers. Operational model logs contain model settings and numeric token usage, not prompts or answers.

We also retain reviewed product configuration, approved knowledge instructions, role and origin settings, integration-key hashes, and necessary business or dashboard-account information. Configuration must not contain end-user records or secrets. Configuration and business records are separate from conversation metrics. Contact us to arrange account closure and removal; legal obligations and provider backup cycles can affect final deletion timing.

7. OpenAI and other service providers

OpenAI processes model requests. Its API data is not used for model training by default. We send requests with response storage disabled, but that does not remove all provider retention. Standard abuse-monitoring retention can include content for up to 30 days, with exceptions and additional endpoint-specific processing described in OpenAI's data controls. Approved Zero Data Retention is not asserted for this service.

Railway hosts our backend and, when configured, a separate store for managed metrics and configuration. The new managed integration uses Railway for this metadata and does not use Supabase. The customer's own providers handle records sent to its endpoint. Processing may occur outside Canada; required locations and contractual safeguards must be agreed before a deployment that has residency restrictions. A regional website address or customer-owned database alone does not establish model-processing residency.

8. Security and permitted access

The managed integration uses HTTPS, server-held credentials, hashed integration keys, short-lived origin- and role-bound sessions, scoped request validation, rate limits, and a private metrics store. Browser session keys do not grant support-team or operator privileges. Customers must enforce their host application's authorization for data access and saves, secure their endpoint, and review supported workflow controls before launch.

We do not sell conversation data or use it for advertising. Removing transcript storage reduces exposure; it does not eliminate security risk or our responsibilities while processing. Security reviews, provider settings, incident handling, and deployment-specific agreements remain necessary.

9. Website and account information

The updated public pages and demo do not load the Google Analytics tag or Apollo visitor tracker. The site may retain a browser theme preference, and dashboard sign-in uses an authentication cookie. Third-party font and icon services can receive connection metadata when those assets load. External booking links are provided by Apollo; information submitted there is processed under the booking provider's terms. Archived policies and existing deployments can have different integrations, as described in their applicable agreements.

10. Requests, questions, and incidents

Contact the customer operating your application for access, correction, or deletion of conversation and support records in its systems. Contact privacy@invocursor.com about Invocursor's processing, retained account or configuration data, privacy questions, or suspected incidents. We will coordinate with the relevant customer as appropriate. Individuals may also contact the applicable privacy regulator, including the Office of the Privacy Commissioner of Canada.

11. Updates and customer review

New customer deployment terms are reviewed before activation. Material changes to the policy applying to an active customer will be communicated by email at least 14 days before taking effect. This publication does not assert that such notices have already been sent or automatically amend an existing customer's deployment. The managed integration is an engineering control set, not a blanket claim of legal compliance or certification.

12. Contact

Privacy and data-processing agreement inquiries: privacy@invocursor.com. Invocursor Inc., Ontario, Canada.

Invocursor Inc. · Waterloo, Ontario, Canada · Terms of Service
© 2026 Invocursor Inc.
About Customers Pricing Privacy Terms Contact