Superstrate is a managed service built and provided by Build Your Buzz Creative Studio (ABN 23 514 748 772) ("BYB", "we", "us" or "our"). This policy explains how we collect, use, hold and disclose personal information when people visit our website, contact us, use our business platform, interact with Superstrate on a customer’s website, or are contacted by us about Superstrate.
We comply with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It can include an AI-generated inference about a person, even if the inference is inaccurate.
Our privacy contact details are in section 15.
1. Superstrate and the business you are visiting
Superstrate provides AI-assisted website conversations, voice interactions, enquiry capture, supported booking and business integrations, and analytics.
Superstrate is an AI assistant, not a person. At the start of every text and voice conversation it tells you that you are talking to an AI assistant, and it always answers truthfully if you ask whether it is a person.
When you interact with Superstrate on another business’s website, that business decides how its deployment is configured and how it uses enquiries, bookings and reports. We process information to provide and support the service for that business. We also handle information for our own account administration, billing, security, support and legal obligations.
The website business’s privacy policy applies to its own collection and use of your information, including information delivered to its staff, email, CRM or booking system. This policy describes our handling of information. Contact either us or the relevant business if you are unsure who can help with a privacy question; we will explain our role and assist in directing your request.
2. Information we collect
The information involved depends on the website, enabled features and what you choose to provide.
| Category | Examples |
|---|---|
| Business account and contact details | Names, business names, work email addresses, phone numbers, account roles and communications with us. |
| Billing information | Billing contact details, invoice information, subscription status, transaction references and payment status. Our payment provider handles payment credentials through its payment facilities. |
| Conversation information | Messages, questions, responses, timestamps, language, session identifiers, summaries and relevant website context. |
| Voice information | Audio streamed for speech recognition, the resulting transcript, text sent for speech generation and technical session information. |
| Enquiry and booking details | Contact information you provide, the service you are interested in, requested dates, selected appointments, callback requests and relevant notes. |
| Website and device information | Pages visited, referring pages or sources, interaction events, browser or device information, approximate location, network information and technical request data. |
| Browser identifiers and preferences | A random visitor identifier, session information, conversation continuity information, assistant interface state and privacy-notice preferences. |
| Derived information | AI-generated summaries, topics, expressed needs, apparent intent, sentiment, objections, enquiry priority and business-level trends. These are estimates, not verified facts. |
| Customer-supplied materials | Website content, business information and other materials supplied or approved for the service, which may contain names or other personal information. |
| Business outreach details | Business contact details published on a business’s website or in public business directories, such as a business email address and a contact person’s name and role. |
| Support and security records | Support correspondence, diagnostic information, access events, error records, misuse indicators and records of privacy requests. |
Our network provider derives an approximate location (country, region and city) from your connection. We store that approximate location, not your IP address. Hosting, network and security providers may still process IP addresses to deliver requests, detect abuse and distinguish human and automated traffic.
Approximate location is derived from network information; it is not the same as precise GPS location. You should not assume a visitor identifier or a redacted transcript is anonymous if it can still be connected with other information about you.
Businesses we contact. We may contact businesses that we think could benefit from Superstrate. To do this, we collect business contact details published on the business’s own website or in public business directories. We may also analyse the business’s public website, including with the help of our website retrieval and research providers, to prepare an assessment of how well the website serves visitors and search. We use these details only to contact the business about Superstrate and to prepare that assessment. If you would rather not hear from us, reply to our email or write to [email protected], and we will stop contacting you.
3. How we collect information
We collect information:
- Directly when you create an account, contact us, send a message, speak to the assistant, submit a form or request a booking or callback.
- Automatically through the website integration, browser storage, network requests and operational logs.
- From the business whose website you are using, its authorised staff and systems it connects to Superstrate.
- From public business websites, public business directories and other public sources, used to prepare approved business information, reports and our outreach to businesses.
- By deriving summaries, classifications and insights from interactions and related activity.
If a business enables website-observation features, some page and technical activity may be processed when the page loads, even if you never open the assistant or send a message.
Businesses can publish machine-readable information and an agent endpoint so that external AI systems can ask questions about the business. Questions received that way are processed like visitor conversations and are logged with personal details removed. An external AI assistant or agent acting at your direction has its own privacy practices; we process information received by Superstrate as described here.
You can generally ask questions without giving your name or contact details, although technical identifiers may still be processed. Some actions, such as receiving a callback, completing a booking or administering a paid business account, require identifying information. If you choose not to provide it, we may be unable to complete that action.
4. Why we use information
We use personal information where reasonably necessary to:
- Operate and configure Superstrate and provide relevant responses and website guidance.
- Transcribe speech and generate spoken responses when voice is used.
- Capture and deliver enquiries, contact requests and authorised booking actions.
- Maintain conversation continuity and show the relevant business its interactions and enquiries.
- Produce summaries, reports and insights about visitor questions, demand, service gaps and interaction outcomes.
- Administer accounts, collect payments and communicate about the subscription.
- Contact businesses that may benefit from Superstrate and prepare assessments of their public websites.
- Diagnose problems, evaluate response quality, improve reliability and maintain security.
- Detect misuse, enforce our agreement and meet legal obligations.
- Respond to privacy requests and resolve complaints or disputes.
We do not use conversations, visitor information or business content to train or fine-tune AI models, whether our own or anyone else’s.
Authorised personnel may review relevant information when needed for support, quality assessment, security or the above purposes. Access is limited according to role and need.
We do not sell visitor contact details or use customer enquiries to send unrelated Superstrate advertising. A visitor’s request for a reply from a website business is not, by itself, permission for unrelated marketing.
Where we send our own marketing communications, we will do so in accordance with applicable law. Every marketing email we send includes a way to unsubscribe, and we act on unsubscribe requests within 5 business days. Essential billing, security and service messages may continue while they remain necessary.
5. AI processing and automated insights
Superstrate uses external AI services to generate responses, translate or summarise information, retrieve relevant business material and produce classifications and insights. Depending on the feature, information sent for processing can include conversation content, relevant business context and previous interaction summaries.
Common personal details, such as email addresses, phone numbers, Medicare, tax file and card numbers, and names you introduce in a conversation (for example, “my name is”), are removed from conversation text before AI processing and before storage, where detected. Voice transcripts are also stored with these details removed. Detection is automatic and is not perfect, so we do not claim that all personal information is removed. Information you speak is processed as audio by our speech provider before text redaction can occur. Relevant personal information can also appear in free text, business materials or authorised integration payloads.
Contact details you type into the assistant’s secure contact or booking forms go to the relevant business and its connected systems without passing through the AI models.
AI providers and training: We use AI services provided by Google Cloud (Vertex AI, now called Gemini Enterprise Agent Platform) and Amazon Web Services (Amazon Bedrock). Under their terms for business customers, Google and Amazon Web Services do not use the content we send to train AI models. Amazon Bedrock does not store the content we send or its responses, and does not share them with the companies that make the models. Google does not keep the content we send beyond what is needed to produce a response, except that it may temporarily store prompts and responses, encrypted, for up to 24 hours to speed up later responses, and, if its automated safety systems flag possible misuse, it may log the relevant prompts for up to 90 days to check whether its usage policies have been breached.
When the assistant searches the web, our search provider, Brave Search, receives a search query based on the visitor’s question. Before a web search, our AI writes the search query and leaves out your own name and contact details. Names of businesses or people you mention as part of your question may be included in the query. Brave keeps a record of search queries for up to 90 days for billing and troubleshooting. How our speech provider handles audio and transcripts is explained in section 6.
Automated decisions: We do not use computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests, and no such decision is made solely by a computer program. We use conversation content, and the details you choose to share, to generate responses and to classify and summarise an enquiry’s topic, intent, sentiment and priority for the business. These outputs help the business decide how to follow up; the business, not Superstrate, makes those decisions.
AI-generated summaries and classifications can be wrong. You can contact the business or us to ask how your information was used, or to question or seek correction of an inference associated with you.
6. Voice interactions
Voice is optional where offered. Starting voice requires microphone access through your browser. Audio is streamed to operate speech recognition, and text is sent to a speech provider to generate the assistant’s replies.
When voice starts, a caption tells you that you are talking to an AI assistant and how your speech is handled.
Microphone permission is a browser control; it does not replace the privacy notice or any additional consent required by law. You can stop a voice session, revoke microphone permission in your browser or use text instead where available.
Audio retention: Superstrate does not store recordings of your voice. We keep a text transcript of the conversation as part of the conversation record described in section 11. Your speech is streamed to our speech provider, ElevenLabs, which converts it to text, and the assistant’s replies are sent to ElevenLabs as text to be spoken. ElevenLabs keeps the audio it receives, the transcript it produces and the speech it generates in our account history in the United States until they are deleted. After deletion, ElevenLabs may keep copies in its backups for up to 30 days and may keep related debugging and moderation records.
We have switched off the setting that allows ElevenLabs to use our account data to train its models, with effect from 27 September 2026. ElevenLabs’ terms may nonetheless allow it to use speech-to-text transcripts to improve its services.
Avoid speaking passwords, card details, identity-document numbers or unnecessary sensitive information. If you need to discuss sensitive matters, contact the business through an appropriate direct channel.
7. Browser storage and website analytics
The assistant stores a random, anonymous identifier in your browser’s local storage to recognise return visits, together with short-lived session storage entries that keep the conversation and interface state across page changes. The identifier has no set expiry; it is removed when you clear your browser storage.
Session storage usually lasts for a browser tab’s session, although browser restore behaviour can vary. Related account and third-party services may use cookies or similar technologies for authentication, security and service delivery.
Where website-observation features are enabled, small page resources and network requests help measure page activity, referral information and visits by human users or automated agents. These functions may operate independently of a conversation.
You can control cookies, microphone access and stored site data through your browser. Blocking or clearing storage may affect conversation continuity and other functions. It does not automatically delete information already held on our servers or by the website business. Conversely, a server-side deletion request does not necessarily clear information stored in your browser.
The website business may use its own analytics, advertising or consent-management tools. Those tools are governed by its notices. Where consent is required for a particular use of storage or tracking, it must be obtained before that use; this policy alone is not a substitute for that consent.
8. Who receives information
We may disclose relevant information to:
- The business whose website you are using and its authorised staff, so it can view interactions, respond to enquiries and manage its service.
- The CRM, booking, email, messaging, Slack, webhook or other systems that business has authorised us to connect, where needed for the configured action or notification.
- Our subprocessors, the service providers that host, secure, process or support our service.
- Professional advisers, insurers or authorities where reasonably necessary and lawfully permitted.
- A prospective or actual business successor where necessary for a genuine transaction, subject to appropriate confidentiality and privacy protections and any required notice.
The subprocessors we use to provide Superstrate are listed below. We update this list when our subprocessors change.
| Subprocessor or recipient | Function and information involved |
|---|---|
| Google Cloud | Application hosting and logs in Sydney, AI processing and search embeddings, including relevant conversation or business context and operational information. |
| Amazon Web Services, including Amazon Bedrock | AI processing in Australia, including relevant prompts, context and summaries. |
| Supabase | Database, account authentication and related storage for business and service records, in Sydney. |
| Upstash | Short-lived session data needed to complete a conversation, booking or enquiry, in Sydney. |
| Cloudflare | Network delivery and security for all website and voice traffic to Superstrate, including approximate location derived from your connection and other technical request information. |
| ElevenLabs | Speech recognition and speech generation when voice is used, including streamed audio and text required for spoken responses. |
| Brave Search | Web search when the business’s own information does not answer a question, using a search query based on the visitor’s question. |
| Resend | Service emails, business notifications (for example, lead alerts containing a visitor’s contact details) and reports. |
| Stripe | Payment and subscription processing for business customers, including billing details and transaction information. |
| Scrapfly and DataForSEO | Retrieval and analysis of public website and business information, including personal information appearing in that material. |
| The customer’s connected systems | Authorised enquiry, booking and notification delivery; information varies with the connection and requested action. |
Subprocessors do not all receive every category of information. In particular, enabling text does not itself require sending your voice to a speech provider.
Public-discovery features can make approved business information available to search engines and external AI services. Material approved for public publication may be indexed or copied by those services. Private visitor conversations and enquiry contact details are not designated for publication through those features.
We remain responsible for obligations applicable to our handling of information. Referring to another provider’s policy does not remove those obligations.
9. Overseas processing
Conversations, leads, bookings and account data are stored in Australia (Sydney). Our application runs in Sydney and our application logs are stored there, and AI processing through Amazon Bedrock stays within Australia (Sydney and Melbourne). Some information is processed or stored outside Australia:
- AI processing through Google Cloud may take place in any country where Google operates cloud data centres. Google does not commit to a particular country for these requests, even for requests we send to its Sydney endpoint.
- Our speech provider, ElevenLabs, stores voice data in the United States and may process it in the United States, the Netherlands or Singapore. Its affiliates may also handle it in Poland, Japan, India or the United Arab Emirates.
- Our search provider (Brave Search), email provider (Resend) and website retrieval provider (Scrapfly) handle information in the United States. Our payment provider (Stripe) handles information in Ireland and the United States. Our website research provider (DataForSEO) handles information in Estonia, the United States, Germany and the United Kingdom.
- Our network provider, Cloudflare, operates data centres worldwide and may handle website and voice traffic outside Australia.
- Businesses using Superstrate may connect their own booking, CRM, messaging or webhook systems, which may be hosted overseas; the business can tell you where.
The countries in which our overseas recipients are likely to handle personal information therefore include the United States, Singapore, the Netherlands, Ireland, the United Kingdom, Germany and Estonia, and, for our speech provider, Poland, Japan, India or the United Arab Emirates as described above. Where a provider uses global infrastructure and we cannot practicably identify every likely country, we have identified that limitation above and will explain the available information on request.
We assess overseas arrangements and take reasonable steps required by applicable law to protect personal information, including appropriate provider terms and configuration. We do not treat use of the service as a blanket waiver of protections for overseas disclosure.
10. How we protect information
We use a combination of technical and organisational measures designed to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. These include access controls, customer separation, protected service connections and privacy controls in relevant processing paths.
No internet service or security measure is infallible. Customers must also protect their account access and the external systems to which they send information.
If a data breach occurs, we will assess it and take appropriate containment and remedial steps. If it is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and we will notify affected customers.
11. How long we keep information
We keep personal information only for as long as reasonably needed for the purposes described in this policy or as required or permitted by applicable law. Different records have different requirements:
- Conversations: conversation text and the personal details in it are removed automatically 365 days after the conversation’s last activity. A record without personal information, such as the date, page and outcome, is kept so the business’s analytics stay accurate.
- Enquiries and bookings: these are the business’s records and are kept until the business deletes them.
- Reports and aggregated insights: kept for the business’s service; they contain no personal details.
- Voice recordings: Superstrate does not store them (see section 6).
- Account and subscription records: retained to administer the relationship and meet applicable accounting, tax and legal obligations.
- Diagnostic and security records: retained for the troubleshooting, security or audit purpose for which they were collected, subject to applicable expiry and access controls.
- Privacy requests and disputes: retained as reasonably necessary to respond, demonstrate the outcome and meet legal obligations.
- Backups and provider copies: may remain for the applicable backup or provider retention cycle after removal from active systems, with access restricted and further use limited appropriately.
When information is no longer required, we take reasonable steps to delete it or de-identify it. De-identification requires more than simply removing a name where a person could still reasonably be identified from remaining information.
Deleting personal fields may leave non-identifying statistical counts or records needed to document an event. We may also retain limited information where necessary to comply with law, resolve a dispute or record and honour a privacy request. Where an exception prevents complete deletion, we will explain it when responding, unless legally prohibited.
Deletion from Superstrate does not automatically recall emails or remove information already transferred to the business’s CRM, calendar or other systems. Those recipients must address the copies they hold. We will reasonably cooperate with requests affecting our providers and explain what action is needed with independent recipients.
12. Access, correction, deletion and choices
You may contact us at any time to ask what personal information we hold about you, request access, correction, export or deletion, or raise a concern about its use. Applicable law determines the extent of any legal entitlement, and we will also consider reasonable requests beyond the minimum required by law.
If the information concerns an interaction on a customer’s website, identify that business or website and, if possible, the approximate date and the contact details or session information used. Avoid sending unnecessary identity documents or sensitive information. We may request proportionate information to verify identity and protect other people’s records.
Where the customer controls the relevant records, we may need to coordinate with it. This does not prevent you from contacting us directly or remove obligations that apply to us.
We usually respond to access and correction requests within 30 days, and will meet any applicable legal deadline. If we refuse a request in whole or part, we will explain the reason and available complaint options unless the law prevents us from doing so. There is no fee to make a request; if a lawful charge for providing access is necessary, we will explain it before proceeding.
Where processing relies on your consent, you can withdraw that consent by contacting the relevant business or us. Withdrawal applies to future processing dependent on that consent, does not undo processing already lawfully undertaken and may prevent us from providing the associated function. Retention or processing required on another lawful basis may continue, which we will explain where relevant.
13. Sensitive information and children
The ordinary service is designed for business enquiries and website assistance, not for collecting sensitive health, biometric, identity or similarly sensitive records. Please do not provide unnecessary sensitive information. A business must agree suitable safeguards and satisfy applicable legal requirements before configuring a sensitive-information use case.
The subscription account service is intended for adults acting for businesses. If a website deployment may be used by children, the website business must consider appropriate notices, consent and safeguards for its audience. If you believe a child’s information has been collected inappropriately, contact us so we can investigate and take appropriate action.
14. Complaints and policy changes
If you have a privacy complaint, contact [email protected] with the relevant facts and the outcome you seek. We will acknowledge your complaint, investigate it and aim to respond substantively within 30 days. If more time is reasonably needed, we will explain why and give an expected response date, subject to applicable legal deadlines.
If you are not satisfied with our response, or we have not responded within 30 days, you may contact the Office of the Australian Information Commissioner at oaic.gov.au. Its ability to investigate depends on whether the matter falls within its jurisdiction. You may also have rights to complain to another applicable regulator.
We may update this policy as our practices or legal obligations change. We will update the "Last updated" date and provide additional notice of a material change where appropriate or required. An updated policy does not, by itself, authorise a new use of previously collected information that requires separate consent or another legal basis.
15. Contact us
Privacy contact
Build Your Buzz Creative Studio
ABN: 23 514 748 772
Australian Capital Territory
Email: [email protected]