Privacy policy
Last updated: 8 August 2026
Lobby gives a business an AI concierge that talks to its visitors. That means two very different sets of people’s data pass through this product, and they are treated differently. This page says exactly what happens to each.
The two roles we play
When you are a business owner using Lobby, we are the data controller for your account: your email address, your concierge’s configuration, and your billing records.
When someone talks to a business’s concierge, that conversation belongs to the business. They decide why they are collecting it and what they do with it; we hold and process it on their instructions. In UK/EU terms they are the controller and we are the processor. If you are a visitor and want your conversation deleted, the business is the right first stop, but you can also write to us and we will action it and tell them.
What we collect from visitors
Everything typed into a concierge, and everything it replies. Each conversation is stored with a timestamp and an anonymous session identifier.
Contact details when a visitor offers them: name, email address, phone number. The concierge asks for these; it does not take them from anywhere else. Alongside them we store a short summary of what the visitor said they needed, a 0-100 score for how ready to buy they appear, and a suggested reply for the business. That package is what we call a lead.
We do not use cookies to track visitors across sites, we run no advertising pixels, and we do not build a profile of anyone across different businesses’ concierges.
What we collect from business owners
Your email address, used to sign you in (there is no password; we email you a single-use link) and to send you a lead the moment your concierge captures one.
Your concierge’s configuration: business name, services, tone, boundaries, published contact details, and any source material you paste or upload for it to answer from.
If you subscribe, Stripe handles the payment and holds the card details. We never see or store a card number; we keep the Stripe customer and subscription identifiers so your plan and your billing portal work.
Why we process it
To generate the concierge’s replies, which requires sending the conversation to our model provider.
To capture a lead and deliver it to the business that owns the concierge, by email and in their dashboard.
To operate the service: signing owners in, counting conversations against a monthly allowance, taking payment, and keeping an audit trail of changes.
We do not sell personal data, and we do not use one business’s conversations, leads or source material to serve any other business.
Who else processes it
These are our subprocessors. Each one only receives what it needs, and personal data may be processed in the United States.
- Anthropic: runs the AI model that generates each reply and extracts the lead. Conversation content is sent to it.
- OpenAI: converts the concierge’s replies to speech and a visitor’s speech to text, when voice is switched on. The text of each reply, and any audio a visitor records, are sent to it.
- Railway: hosts the application and the PostgreSQL database where conversations, leads and configuration are stored.
- Vercel: hosts and serves this website and the hosted concierge pages.
- Twilio SendGrid: sends the sign-in links and the lead notification emails.
- Stripe: takes subscription payments and holds card details.
How long we keep it
Conversations, messages and leads are kept for as long as the business’s concierge exists, because they are that business’s record of its own enquiries. There is no automatic expiry today; if that changes, this page changes with it.
Owner accounts and billing records are kept while the account is open, and afterwards only as long as tax and accounting rules require.
Ask us to delete something and we will, within 30 days.
Your rights
Depending on where you live you can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. There is no self-service export yet, so email us and a person will handle it.
You can complain to your local data protection authority. We would rather you told us first so we can fix it.
Security
Traffic is encrypted in transit. A business’s leads, transcripts and source material are readable only by the account that owns that concierge. That isolation is enforced on every request, not assumed, and it is covered by a regression test we keep in place deliberately.
A lead notification is only ever emailed to the owner’s own address. It is never rerouted to us, even when a delivery fails.
Children
Lobby is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If a concierge has collected a child’s details, tell us and we will delete them.
Changes
If we change this policy materially we will email account holders rather than quietly editing the page. The date at the top always reflects the current version.
Contact us
Privacy questions, deletion requests, and anything you think this page gets wrong.