Trust and security
What we do with your data today, stated plainly, including what isn’t in place yet. Last reviewed 3 October 2026. If something here is wrong or unclear, tell us.
Where your data is
- Everything runs on one server at Amazon Web Services in the United States (us-east-1). The database and uploaded files are on that server.
- Connections to the site, the dashboard, the API and the chat widget use HTTPS.
- Secrets you give us (API keys for your actions, integration and channel credentials, single sign-on secrets) are encrypted in the database with a key kept outside it, and are never shown again after you save them.
- We haven’t confirmed disk-level encryption of the server’s volume.
How organizations are kept apart
- Every organization’s data is separated by the database itself (PostgreSQL row-level security), so a mistake in our application code still can’t show one organization another’s data.
- Inside an organization, roles (owner, admin, editor, viewer) and workspaces limit who sees which assistants and conversations.
- Single sign-on (SAML or OpenID Connect) is available, and can be required for your email domains.
- Our own admin tools show account details and usage counts, not your conversations or knowledge.
Audit log
Changes that matter (team members and roles, API keys, secrets, integrations, single sign-on, assistants and their releases, data erasures) are recorded with who made them. The log can’t be edited or deleted through the application, and each entry is chained to the one before by a hash, so admins can check nothing was changed.
The assistants
- The chat widget and the messaging channels tell people they’re talking to an AI.
- Answers come from your own content, with the sources shown; website text is treated as data, never as instructions.
- You can set rules it follows, topics it won’t discuss, and messages that get a fixed reply without the AI (for example, emergencies).
- For healthcare staff assistants, messages that look like they contain patient details can be refused before they’re stored or sent to the AI. We don’t accept patient health information: we don’t have the agreements in place that it requires.
Keeping and deleting data
- Conversations are deleted after 12 months by default; admins can choose a shorter or longer period.
- Admins can erase everything about one person (by email, phone or the id your site gives us): their conversations, leads, messaging threads and webhook deliveries. The erasure is checked and recorded without keeping who it was.
- Counts without personal data (usage, daily statistics) are kept after deletion.
- Backups: before each database upgrade we take a copy, which stays on the same server. Erased data can remain in those copies until they’re removed. We don’t have scheduled offsite backups yet.
What we don’t do
- We don’t train AI models on your data, and we don’t sell it. Under OpenAI’s API terms, data sent through their API isn’t used to train their models unless the customer chooses to share it.
- We don’t use your conversations in marketing or case studies without your written permission.
- We don’t store payment card numbers.
Subprocessors
| Company | What for | Data | Where |
|---|---|---|---|
| Amazon Web Services (EC2) | Hosting: the application, its database and uploaded files run on one server | All customer data | United States (us-east-1, N. Virginia) |
| OpenAI (API) | Writing answers and making search embeddings | Visitors’ messages, the knowledge passages used to answer, assistant instructions | United States |
| Our email delivery provider | Sign-in codes and notifications (new leads, handoffs, alerts) | Email addresses and the notification’s content | United States |
Only when you choose to use them:
- Email replies through Mailgun, WhatsApp through Meta, Slack and Microsoft Teams bots: these run on your own accounts with those providers, under your agreements with them, and only when you connect them.
- Webhooks and integrations (Slack, HubSpot, Zapier and similar) send data where you point them.
- Payments: if paid plans are offered, Stripe processes billing details. Paid plans aren’t live yet.
We’ll update this list before adding a subprocessor.
Data processing agreement
We’re preparing a data processing agreement. If you need one, contact us.
Accessibility
How accessible the widget and dashboard are, how we checked, and what doesn’t work fully yet: see accessibility. Our conformance report (VPAT 2.5, self-assessed) is available on request.
Reporting a vulnerability
If you think you’ve found a security problem, please contact us with the details and don’t access other people’s data. We’ll reply and keep you updated until it’s fixed.