What we store
What your assistant keeps
Your account
Your email, a hashed password, your plan, and billing references from Stripe. Card details are entered on Stripe's own checkout page and never reach us.
What it knows
The facts read from your website, your FAQs and corrections, your settings and opening hours.
Documents you add
The text of any price list, menu or brochure you upload. We keep the words, never the file itself, and removing a document deletes its text.
Conversations
What customers wrote and what your assistant replied, with what each answer was based on.
Leads and bookings
The names, phone numbers, emails and details customers chose to give, and bookings made in the chat.
Calendar connection
If you connect Google Calendar, an encrypted token that lets it check when you're busy and add bookings.
Abuse prevention
IP addresses are used to limit abuse of the chat and demo, and those records are deleted within a day.
Subprocessors
Every service that receives your data
- Google (Gemini API)
- Always. Writes your assistant's answers and reads your website's pages and documents. It receives conversations, your facts, FAQs and the text of documents you add.
- Neon, on Amazon Web Services
- Always. Our database: stores your account, what your assistant knows, conversations, leads and bookings.
- Application hosting
- Always. Runs the app that serves your dashboard and the chat. We will name the provider here when the app goes live.
- Resend
- Always, for email: delivers your lead alerts, password resets and account emails. It receives the lead details in each alert.
- Twilio or Plivo
- Only if you use text alerts, WhatsApp or phone calls: carries those messages and calls, so it receives the lead details in an alert, or the conversation itself on WhatsApp or a call.
- Meta (WhatsApp)
- Only if customers chat with you on WhatsApp: carries those messages, under WhatsApp's own terms.
- Google Calendar
- Only if you connect it: checks when you're busy and adds bookings.
- Stripe
- Only if you pay for a plan or add-on: handles the subscription. It receives your account email; card details go to Stripe directly.
- Your own webhook
- Only if you add one: receives each new lead's details.
How it's protected
Security controls
HTTPS throughout
Your dashboard and the chat are served over HTTPS, and we call the services above over HTTPS.
Encrypted calendar tokens
Google Calendar tokens are encrypted with AES-256-GCM, and short-lived access tokens are never stored.
Checked on every request
Every dashboard page and action checks that the account signed in owns the website it's acting on.
Signed links and webhooks
The "I've got this" link in alerts and every webhook are signed, so they can't be forged.
Your domain only
Your assistant only reads pages on your own domain, and blocks requests to private network addresses.
Limits on public endpoints
The chat, demo and forms are rate limited to stop abuse.
Only on your websites
Your chat only appears on your own domain and any sites you add. Your browser refuses to show it anywhere else, so nobody can copy your snippet onto their site.
You choose how long it's kept
Set conversations and leads to delete themselves after 3, 6, 12 or 24 months, or keep them until you delete your account. Off by default, because it's your data to decide about.
Two-step sign-in
Turn on codes from an authenticator app, with one-time backup codes, so a stolen password alone can't open your account. Its secrets are stored encrypted.
What we don't claim
What we don't offer yet
Security pages tend to list badges. Here's what we don't have, so you can decide with the facts.
- We don't sign HIPAA business associate agreements. Don't use it to collect patients' health information; dental assistants are set up never to ask for it.
- We don't have a SOC 2 report or other third-party audit yet.
- There's no single sign-on or team accounts yet.
Questions
Chatbot security questions
Is my data used to train AI models?
We don't train AI models on your data. Conversations are sent to Google's Gemini API to write your assistant's answers, under Google's terms for that service.
Is the chatbot HIPAA compliant?
No. We don't sign business associate agreements, so don't use it to collect patients' health information. Dental assistants are set up never to ask for symptoms, medical history or medications.
What are the security risks of a website chatbot?
The main ones are a chatbot inventing information, customers sharing sensitive details in chat, and unprotected integrations. Ours answers only from your facts, business types are set up never to ask for sensitive details like SSNs or card numbers, and alerts and webhooks are signed.
Can customers tell they're talking to an AI?
Yes. Every chat shows "AI assistant for" your business at the top before a customer types, and law firm assistants also say they aren't a lawyer.
How do I delete my data?
Delete your whole account yourself from the page listing your assistants. It cancels any subscription, disconnects Google Calendar, and erases your websites, conversations, leads and bookings.
Where can I ask a security question?
Email us from the contact page. For anything about data we hold on you, the privacy policy explains your options.