Privacy Policy
How Roundtable AI collects, uses, stores, shares, and safeguards information for its software platform and Second Opinion service.
Last updated August 19, 2026
What this policy covers
Webb Technologies LLC owns and operates Roundtable. This policy explains what we collect, why we use it, who receives it, how long we keep it, and the choices you have.
- The Roundtable AI workspace and the separately purchased Second Opinion service.
- Account, payment, service, security, analytics, and communication information.
- Service providers used for AI, payments, scheduling, meetings, hosting, and email.
- Retention periods and ways to access, correct, download, or delete eligible information.
Introduction
Webb Technologies LLC (“Webb Technologies,” “we,” “us,” or “our”) owns and operates the Roundtable product and brand, including the Roundtable AI workspace and the separately purchased, human-facilitated Second Opinion service. Webb Technologies is the business/controller responsible for the direct-customer information described in this policy, except where a different role is expressly stated. We limit collection to information needed for the selected service, use contracted infrastructure and service providers, and provide methods for account and no-account customers to exercise applicable privacy rights. This policy explains what we collect, why we collect it, who receives it, how long we keep it, and the controls you have.
Information We Collect
Account & Billing
- Identity: name, email address, workspace identifiers.
- Authentication: hashed passwords or identity-provider references.
- Billing: Stripe customer ID, payment method metadata, plan selections (Roundtable Lite or Roundtable Standard). Raw card data never touches our servers.
Product Usage
- Conversations: prompts, AI responses, compaction summaries, message metadata (timestamps, agent IDs, token counts). These records allow agents to replay recent conversation history with full attribution.
- Agent Settings: provider, model, temperature, system prompts, and friendly names for custom agents.
- Token Accounting: provider-reported token totals plus the converted “platform token” value used for quotas and billing transparency.
Operational Data
- Diagnostics: request/response IDs, latency metrics, and failure reason codes for troubleshooting.
- Security and Routing Signals: IP address, user agent, and approximate country/region derived at the server or trusted content-delivery boundary. We use these signals for fraud detection, rate limiting, and to select the consent rules that apply when you sign up. IP-derived location can be wrong (for example, when you travel or use a VPN), so we do not treat it as verified residence. If the location signal is missing or not trusted, we apply the more privacy-protective rule.
- Consent-Free Analytics: We use Plausible Analytics for basic audience measurement. Plausible sets no cookies and accesses no device storage. It uses a daily-rotating hash of your IP address and user agent to count unique visitors; the hash key is deleted every 24 hours, making the data fully anonymous and not linkable to you. No persistent personal data is retained. This processing is based on legitimate interest under GDPR Article 6(1)(f) and does not require consent. Data collected includes: page views, referrer domain, country, browser family, operating system, device type, and UTM campaign parameters. Data is hosted in the EU (Hetzner, Germany) by Plausible Analytics. This analytics layer operates independently of the consent-gated analytics described below. Under GDPR Article 21, you have the right to object to this processing. To exercise this right, contact privacy@round-table.ai.
- Consent-Gated Analytics: We use Google Analytics 4 (GA4) and Customer.io to understand marketing performance and measure conversions. In regions where consent is not legally required, we may process analytics data based on legitimate interest. In regions where opt-in consent is required (such as the EU, UK, and Canada), analytics processing begins only after you grant consent. GA4 sets first-party cookies (such as
_ga) to assign a pseudonymous identifier. Customer.io sets cookies (such as_cioanonid) to track anonymous activity before signup and merge it with your account afterward. We also capture UTM parameters and click IDs (e.g., gclid, fbclid) to attribute signups to specific campaigns. When you withdraw consent, we immediately stop processing your data for consent-gated analytics purposes, reset Customer.io identity, and delete analytics cookies. Minimal identifiers may be retained for compliance and audit purposes, as permitted under GDPR Article 17(3)(b). - Bug Reporting Diagnostics: only when you submit a bug report and explicitly opt in—we capture up to the last 10 provider requests/responses for the affected conversation. These payloads are double-encrypted (per-user and server-held keys), retained for 30 days, and decrypted solely to create the GitHub issue you approve.
Second Opinion Service (No Account Required)
The Second Opinion is separate from the software subscription and does not create a Roundtable AI account. Depending on how far you proceed, we collect:
- Screener information: email address; the business decision stated in your words; timing and financial-stakes ranges; business-size ranges; prior attempts to obtain AI input; adviser status; and your selected answers to the eligibility questions.
- Eligibility information: business name; public website or business-listing URL; review status; limited reviewer notes and neutral reason codes; purchaser authority, age, U.S. business purpose, and participant-location confirmations.
- Purchase and contract information: the selected offer, server-authoritative price, currency, tax if applicable, Stripe payment and refund identifiers and status, receipt history, fraud/security signals, and evidence of the legal documents and versions you accepted, including time, IP address, and user agent. Stripe—not Webb Technologies—collects full card details.
- Booking and meeting information: purchaser and invited-participant contact information, requested and scheduled time, time zone, attendance, reschedule/no-show status, and meeting-platform technical metadata. At launch, we do not record or transcribe the human meeting and do not enable automated meeting notes, voiceprints, face templates, emotion analysis, or speaker identification.
- Session and deliverable information: the minimized business question, prompts sent to the four AI services, their responses, facilitator notes, the AI Interaction Transcript, written perspective-comparison brief, delivery status, correction requests, and refund-window timestamps. “AI Interaction Transcript” means the prompts and AI responses, not a transcript of the human meeting.
- Service communications: payment, eligibility, booking, reminder, delivery, support, privacy, and refund messages and delivery status.
Use ranges, role labels, and anonymized facts. Do not provide names or identifying details of employees, applicants, customers, patients, students, or other people; credentials; payment/account or government-ID numbers; health or biometric information; privileged legal material; trade secrets; source code; NDA-protected material; or anything you are not authorized to share with Webb Technologies and the AI providers. The Second Opinion Service Terms contain the complete safe-data and topic boundaries.
Email Communications & Engagement Measurement
- Service email: We send messages needed to provide something you requested or operate your account, such as verification, receipts, security notices, and delivery of a requested training or workbook.
- Marketing email: We may send product education, onboarding, and offers where applicable law permits it. Where prior opt-in is required, we send these messages only after you choose them. In other locations, we may send them under a permitted legitimate-interest or similar basis, subject to your right to opt out. Every marketing email provides an unsubscribe method.
- Open and link measurement: Customer.io can add a small image to report that an email was opened and can route links through a measured redirect to report clicks. We enable this only when our server-side location and preference policy permits it. In locations where consent is required, measurement remains off until you explicitly grant it. A missing or untrusted location is treated the same way. In locations where applicable law permits measurement without prior opt-in, we may use it to evaluate deliverability and engagement unless you opt out or send a Global Privacy Control signal.
- Separate controls: Receiving email and measuring engagement are separate choices. The footer of measured marketing and requested-toolkit emails includes a hosted link to change open and link measurement without unsubscribing. When you use that link, Customer.io applies the choice to its email measurement immediately, and our server periodically reconciles the provider setting into our consent record. Unsubscribing stops marketing delivery; changing the measurement preference does not by itself stop delivery.
- Consent evidence: We keep the current decision and an audit record of the choice, policy version, approximate routing evidence, source, and time so that a later passive location update cannot silently override an explicit denial. An observed Global Privacy Control denial is also preserved until you make a fresh explicit choice, and an active Global Privacy Control signal continues to take priority.
How We Use Your Information
- Provide the product – render conversations, stream real-time responses, store transcripts, and enforce quotas.
- Route AI traffic – deliver prompts to Anthropic, OpenAI, xAI, and Google based on the agents you target.
- Maintain reliability – investigate errors, detect abuse, and keep offline-safe completions accurate if you close your browser.
- Handle billing – manage Stripe subscriptions, plan changes, and invoices.
- Improve the platform – analyze anonymized usage trends to prioritize features (for example, which agents are added most often).
- Debug issues you report – when you opt into a bug report, we decrypt the selected provider logs in-memory, post them to GitHub along with your description, and then discard the plaintext.
- Communicate and measure responsibly – deliver requested and permitted email, protect deliverability, and understand aggregate email engagement under the location and preference rules described above.
- Screen and fulfill the Second Opinion – assess eligibility, prevent prohibited or high-risk uses, confirm the one-time quote and assent, process payment, arrange the session, route a minimized question to four AI services, prepare and deliver the transcript and brief, administer rescheduling/refunds, and respond to corrections and support requests.
- Protect the Second Opinion service – prevent duplicate charges and fraud, maintain an auditable purchase and fulfillment history, enforce geographic and subject-matter limits, investigate incidents, and establish, exercise, or defend legal claims.
Webb Technologies does not use Customer Content, Second Opinion answers, AI interactions, or briefs to train a Roundtable model, and we do not sell personal information for money. We use organization-controlled commercial AI services rather than personal or free consumer chat accounts for the Second Opinion. Provider business/API terms generally restrict training use, but providers may retain content for abuse monitoring or service operation, and feature-specific rules vary. The current provider categories, relevant retention limitations, and configuration gates appear in our Compliance Overview.
Data Sharing
- AI Providers: for the software platform, prompts and relevant conversation slices are forwarded to the provider API selected by the targeted agent. For the Second Opinion, an approved, minimized version of the question is intentionally sent through organization-controlled accounts to the Anthropic API (Claude), OpenAI API, X.AI LLC's xAI API (Grok), and paid Google Gemini Developer API. Personal data may be sent through the xAI API only using the contractually required zero-data-retention configuration. Provider systems are not independent fact-checkers, and their agreement is not verification. These factual recipient identifications do not imply sponsorship, partnership, approval, or endorsement.
- Payments: billing information is processed by Stripe.
- Infrastructure, scheduling, meeting, and communications vendors: AWS hosts operational data. Customer.io processes email addresses and service-message delivery for Second Opinion receipts, eligibility results, booking, deliverables, and refunds; transactional Second Opinion email is sent with open and link measurement disabled. Calendly processes booking contact details, availability, and appointment metadata. The remote-meeting provider processes invitation, connection, and attendance metadata; the specific provider is identified in the invitation and current subprocessor list before the session. Plausible Analytics processes cookie-free audience measurement data (EU-hosted, legitimate interest). Google Analytics 4 processes consent-gated website analytics data under the applicable legal basis for your region.
- Advertising platforms: Where you grant explicit consent (or where you reside in a jurisdiction that permits default sharing absent your opt-out, such as the United States under CCPA/CPRA and equivalent state laws), we may share conversion data with Meta (Facebook) and Google Ads to measure advertising performance. Meta receives hashed (SHA-256) email addresses, click identifiers (
_fbc,_fbp), and — as required by the Meta Conversions API for event matching — your IP address and user-agent string. Google Ads receives conversion signals via GA4 imported conversions. If you have opted out of data sharing (via "Your Privacy Choices," Global Privacy Control, or in opt-in jurisdictions by withholding or withdrawing consent), no data is shared with advertising platforms. - Second Opinion advertising boundary: We do not include screener answers, business URLs, AI prompts or responses, meeting content, facilitator notes, or brief content in analytics or advertising events. Where permitted by your choices and applicable law, bounded funnel-stage data and conversion identifiers may be used as described above.
- Bug tracking: when you submit a bug report, we post the details (including conversation snippets and optionally decrypted provider logs) to our private GitHub repository so engineers can triage the issue.
We use written commercial terms with service providers and review feature-specific data handling before enabling a provider or feature. A vendor's role may be processor/service provider or an independent controller depending on the data and applicable law; contact privacy@round-table.ai for the current description.
Storage & Security
- Data at rest lives in encrypted databases on AWS.
- Provider API keys, Stripe secrets, and signing keys are stored in a managed secrets vault.
- All traffic (web, WebSocket, API) is served over HTTPS with TLS 1.2+.
- The application enforces rate limiting and standard request safeguards.
- Conversation exports and compaction summaries inherit the same encryption and access controls as the source conversation.
Retention & Deletion
- Conversation history persists until you delete the thread or close your account.
- Billing records are kept for the period required by law (typically 7 years for US accounting rules).
- Support logs and analytics data are retained for up to 12 months.
- Bug-report diagnostics (encrypted provider logs and associated metadata) are automatically deleted 30 days after collection.
- Email suppression records and consent evidence may be retained as needed to honor opt-outs and demonstrate compliance, even after related marketing data is removed.
- You can delete any conversation at any time from the product UI. Account-wide deletions can be requested by emailing privacy@round-table.ai.
For the Second Opinion, our launch retention schedule is:
- incomplete or abandoned screener and unpaid-attempt information: deleted or de-identified within 30 days after the last activity;
- AI prompts and responses, facilitator working notes, the AI Interaction Transcript, and delivered brief: deleted from active service systems within 90 days after delivery, unless you request earlier deletion or choose to retain them in another Roundtable AI service;
- eligibility, booking, attendance, delivery, correction, and refund-workflow metadata: retained for up to 24 months after the engagement closes so we can administer promises, resolve complaints, and audit consistent eligibility treatment;
- security and application logs: retained for up to 12 months unless a shorter operational period applies; and
- payment, refund, tax, contract-acceptance, and dispute records: retained for seven years or another period required by applicable tax, accounting, contract, or financial law.
When a legal claim, complaint, chargeback, security incident, government request, or preservation duty is pending, we may place a narrow hold on relevant records until the matter and required preservation period end. Suppression lists and consent/opt-out evidence may also remain as needed to honor your choice. Deletion from active systems and service providers occurs according to the applicable workflow; residual encrypted backups age out on their normal protected cycle and are not restored for ordinary use.
Your Privacy Choices
You can manage your analytics and advertising preferences at any time using the "Your Privacy Choices" link in the website footer. This opens a modal where you can:
- Enable or disable analytics tracking — controls whether GA4 and Customer.io collect data about your visits.
- Enable or disable advertising and data sharing — controls whether analytics data may be shared with advertising partners. This option is only available when analytics tracking is enabled.
When you disable analytics, we immediately stop consent-based processing (Google Analytics 4 and Customer.io), delete analytics cookies (_ga, _ga_*, _cioanonid, _cioid), reset Customer.io identity, and remove attribution data. Your preference is stored in the rt_consent cookie for up to 1 year. Anonymous audience measurement via Plausible Analytics continues independently as it uses no cookies and retains no persistent personal data (see "Consent-Free Analytics" above).
Website analytics controls do not replace the email controls described above. Use the unsubscribe link in an email to stop marketing delivery, or the email-measurement preference link to keep receiving email without open/link measurement.
Do Not Sell or Share My Personal Information
Under the California Consumer Privacy Act (CCPA/CPRA), "sharing" includes making personal information available to third parties for cross-context behavioral advertising. When analytics cookies are active, pseudonymous identifiers may be shared with Google (via GA4) and Meta (via Meta Pixel and Conversions API) for this purpose.
You can opt out of the sale or sharing of your personal information by:
- Using the "Your Privacy Choices" link in the website footer and disabling the "Advertising & Data Sharing" toggle.
- Enabling Global Privacy Control (GPC) in your browser, which we honor as a legally binding opt-out.
When you opt out, we set the rt_dns cookie to record your preference and immediately suppress all advertising-related data signals. Analytics tracking may continue if you leave it enabled, but your data will not be shared for advertising purposes.
We do not sell personal information for monetary consideration.
Global Privacy Control
We detect and honor Global Privacy Control (GPC) signals sent by your browser. When a GPC signal is detected:
- All consent-based analytics (Google Analytics 4, Google Tag Manager, and Customer.io) and data sharing is automatically denied.
- Email open and link measurement is denied and that denial is preserved in our consent record.
- Analytics cookies are deleted and Customer.io identity is reset.
- The "Your Privacy Choices" modal displays a confirmation that your GPC preference is being honored.
- A "GPC Honored" indicator appears in the website footer adjacent to the "Your Privacy Choices" link.
Consent-free analytics (Plausible Analytics) continues to operate because it retains no persistent personal data and does not "sell or share" personal information as defined by the CCPA — the regulation that GPC is designed to enforce.
We treat GPC as a legally binding opt-out of the sale and sharing of personal information per California regulations (CCPA §7025). Disabling GPC stops the browser from sending a new signal, but does not silently erase a denial we already recorded; use an explicit preference control if you want to make a new choice.
Your Rights
- Access – download conversation transcripts and billing statements.
- Correction – update account details or agent metadata.
- Deletion – remove conversations or request full account deletion.
- Portability – request data exports in JSON or CSV.
- Objection – use "Your Privacy Choices" for website analytics and advertising, use the unsubscribe link in an email for marketing delivery, or use the separate email-measurement link for open/link tracking. You can also contact us. We honor Global Privacy Control (GPC) signals as a legally binding opt-out.
Users in the EU/EEA or UK may also exercise GDPR rights (erasure, objection, restriction). California residents can invoke CCPA rights via the same contact channels.
Second Opinion purchasers do not need an account to make a request. Email privacy@round-table.ai from the purchase address and identify the Second Opinion request. We verify control of that address and may request limited additional information where necessary to protect the record. Subject to applicable law and narrow tax, transaction, security, dispute, and preservation exceptions, you may request access, correction, a portable copy, or deletion of Second Opinion personal information. We will not discriminate against you for exercising a right. If we deny a request, you may appeal by replying with “Privacy Appeal” in the subject line; we will explain the result and any regulator-contact method required by applicable law.
Children's Privacy
Roundtable is built for professional teams. Webb Technologies does not target or knowingly allow sign-ups from individuals under 18. The Second Opinion purchaser and every session participant must be at least 18.
Changes & Contact
We will update this policy when regulations or product functionality changes. Material updates are announced through an appropriate service notice. A revised policy does not retroactively expand use of completed Second Opinion content without a lawful basis and any consent required by law.
Questions about this policy can be sent to privacy@round-table.ai.