Security and privacy

Chatbot security and privacy: what we store, who sees it, and how to delete it

Your assistant handles your customers' messages and contact details. This page says plainly what we keep, who else receives it, how it's protected, and what we don't claim.

What we store

What your assistant keeps

Subprocessors

Every service that receives your data

We share data only with the services needed to run your assistant, and each receives only what its job needs. We don't sell data, and nothing here is used for advertising.
Google (Gemini API)
Always. Writes your assistant's answers and reads your website's pages and documents. It receives conversations, your facts, FAQs and the text of documents you add.
Neon, on Amazon Web Services
Always. Our database: stores your account, what your assistant knows, conversations, leads and bookings.
Application hosting
Always. Runs the app that serves your dashboard and the chat. We will name the provider here when the app goes live.
Resend
Always, for email: delivers your lead alerts, password resets and account emails. It receives the lead details in each alert.
Twilio or Plivo
Only if you use text alerts, WhatsApp or phone calls: carries those messages and calls, so it receives the lead details in an alert, or the conversation itself on WhatsApp or a call.
Meta (WhatsApp)
Only if customers chat with you on WhatsApp: carries those messages, under WhatsApp's own terms.
Google Calendar
Only if you connect it: checks when you're busy and adds bookings.
Stripe
Only if you pay for a plan or add-on: handles the subscription. It receives your account email; card details go to Stripe directly.
Your own webhook
Only if you add one: receives each new lead's details.

Privacy policy →

How it's protected

Security controls

  • HTTPS throughout

    Your dashboard and the chat are served over HTTPS, and we call the services above over HTTPS.

  • Encrypted calendar tokens

    Google Calendar tokens are encrypted with AES-256-GCM, and short-lived access tokens are never stored.

  • Checked on every request

    Every dashboard page and action checks that the account signed in owns the website it's acting on.

  • Signed links and webhooks

    The "I've got this" link in alerts and every webhook are signed, so they can't be forged.

  • Your domain only

    Your assistant only reads pages on your own domain, and blocks requests to private network addresses.

  • Limits on public endpoints

    The chat, demo and forms are rate limited to stop abuse.

  • Only on your websites

    Your chat only appears on your own domain and any sites you add. Your browser refuses to show it anywhere else, so nobody can copy your snippet onto their site.

  • You choose how long it's kept

    Set conversations and leads to delete themselves after 3, 6, 12 or 24 months, or keep them until you delete your account. Off by default, because it's your data to decide about.

  • Two-step sign-in

    Turn on codes from an authenticator app, with one-time backup codes, so a stolen password alone can't open your account. Its secrets are stored encrypted.

What we don't claim

What we don't offer yet

Security pages tend to list badges. Here's what we don't have, so you can decide with the facts.

  • We don't sign HIPAA business associate agreements. Don't use it to collect patients' health information; dental assistants are set up never to ask for it.
  • We don't have a SOC 2 report or other third-party audit yet.
  • There's no single sign-on or team accounts yet.

Questions

Chatbot security questions

Is my data used to train AI models?

We don't train AI models on your data. Conversations are sent to Google's Gemini API to write your assistant's answers, under Google's terms for that service.

Is the chatbot HIPAA compliant?

No. We don't sign business associate agreements, so don't use it to collect patients' health information. Dental assistants are set up never to ask for symptoms, medical history or medications.

What are the security risks of a website chatbot?

The main ones are a chatbot inventing information, customers sharing sensitive details in chat, and unprotected integrations. Ours answers only from your facts, business types are set up never to ask for sensitive details like SSNs or card numbers, and alerts and webhooks are signed.

Can customers tell they're talking to an AI?

Yes. Every chat shows "AI assistant for" your business at the top before a customer types, and law firm assistants also say they aren't a lawyer.

How do I delete my data?

Delete your whole account yourself from the page listing your assistants. It cancels any subscription, disconnects Google Calendar, and erases your websites, conversations, leads and bookings.

Where can I ask a security question?

Email us from the contact page. For anything about data we hold on you, the privacy policy explains your options.

Your customers are asking right now

Paste your website and hear your assistant answer as your business. It takes about a minute.

Try it free