Who this covers
Offload sits between two groups of people, and it is worth separating them.
- Workspace owners — the indie developers and small teams who sign up for Offload. Offload is the data controller for their account data.
- End customers — the people who write to a workspace owner through the widget or the support address. Offload processes their messages on the owner's behalf, as a data processor. The owner decides what is collected, answered and kept.
If you wrote to a company's support and landed here, the company running that support inbox is your point of contact. We will forward any request we receive to them.
What is processed
- Workspace accounts — email address, display name, workspace name and members, sign-in codes, plan and billing state, connected integrations.
- Support conversations — messages sent by end customers through the in-app widget or the React Native SDK, the drafts and replies produced for them, confidence scores, sources used, approvals and corrections, and any file a customer attaches.
- Inbound and outbound email — messages received at a connected support address and the replies sent back, including sender address, subject and body.
- Knowledge base — the documentation, crawled pages, synced repository files and internal notes a workspace owner adds so the agent has something to answer from.
- Feedback and roadmap — feature requests and bug reports extracted from conversations, and the votes cast on a public board.
- Technical data — application logs, errors, rate-limit counters, and the app version, OS version and device model the SDK attaches to a new message so the agent can diagnose without asking. No device identifier and no advertising identifier is collected.
Why it is processed
To run the service: answer support questions from the workspace's own knowledge base, hold back drafts below the owner's confidence floor, route email in and out, keep the feedback board up to date, bill the account, and keep the whole thing secure and available.
The legal bases are the performance of the contract with the workspace owner, the legitimate interest in securing and operating the service, and legal obligations where they apply (accounting, for instance). Offload does not sell personal data, and does not use it for advertising.
Processors
Offload uses a short list of providers. Each one only receives what its function needs.
| Provider | Role | Region |
|---|---|---|
| Convex, Inc. | Application backend, database and file storage — conversations, knowledge base, accounts | United States |
| Google Firebase Hosting (Google Ireland Ltd) | Static hosting for offload.support and the web application | Ireland / global CDN |
| Postmark (ActiveCampaign) | Inbound and outbound support email for connected addresses | United States |
| Resend | Transactional email — sign-in codes, invitations, roadmap notifications | United States |
| Stripe | Subscription payment. Card numbers go to Stripe, never to Offload | United States / Ireland |
| Google (Gmail API) | Reading and sending mail on a support address, only when the owner connects one | Global |
| OpenAI, Anthropic, Google | Language models that read a conversation plus the matching knowledge-base extracts to produce a draft reply | United States |
Transfers outside the EU rely on the European Commission's standard contractual clauses, as published by each provider.
AI processing
Producing a draft means sending the conversation and the knowledge-base extracts that match it to a language model provider. What is sent is limited to that: the thread and its grounding sources.
Content sent through those providers' APIs is not used to train their models, per their API terms. Offload does not train shared models on customer data either — corrections and calibration stay inside the workspace that made them and are never pooled across workspaces.
Cookies and trackers on this site
This marketing site sets no cookies and loads no analytics, no tag manager, no advertising pixel and no third-party script. Fonts, icons and images are served from offload.support itself, so no request leaves this domain while you read a page.
One thing is stored locally: your light/dark preference, saved in your browser's localStorage when you use the theme switch. It never leaves your device and is not a cookie. If you submit the waitlist form, the email address you typed is sent to the Offload backend at that moment, and only then.
The application at app.offload.support does use a session cookie to keep you signed in. That is strictly necessary and carries no tracking.
Retention
- Conversations, knowledge base and feedback are kept as long as the workspace exists, so the agent can stay grounded and calibrated.
- Deleting a workspace deletes its conversations, knowledge base, attachments and feedback. Backups roll off within 30 days.
- Application and security logs are kept for a rolling 90 days.
- Billing records are kept for the period French accounting law requires.
Your rights
Under the GDPR you can ask for access to your personal data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interest. Write to hello@offload.support — requests are answered within one month.
End customers of a workspace should address their request to the company whose support they contacted; Offload will help that company fulfil it. If you believe your data is mishandled, you can lodge a complaint with your national supervisory authority — in France, the Commission nationale de l'informatique et des libertés (CNIL).
Changes
Offload is in private beta and this policy will get more specific as the product does. Material changes are announced by email to workspace owners before they take effect, and the date at the top of this page always reflects the current version.
Questions about your data? Ask before you sign up.
Join the waitlist