Privacy Policy

Privacy Policy

Last updated September 2026.

1. Who this covers

This policy covers two groups: practitioners who sign in to a dashboard, and visitors who chat with a practitioner's embedded widget. What we collect and why differs between the two, and both are described below.

2. What we collect from a practitioner

  • Your email address, used only to sign you in and to reach you about your account.
  • The content, brand settings and pages you publish through your dashboard.
  • Billing details, handled by Stripe. We store which subscription state you are in, not your card number.
  • Basic usage: how many conversations your widget handled and roughly what that cost.

3. What we collect from a visitor to a practitioner's widget

  • The messages a visitor sends the widget and the replies it gives, so the practitioner can review the conversation and so an escalated conversation reaches them with full context.
  • A session identifier scoped to that one conversation. We store a signed version of it, not the raw value, so a database copy on its own cannot be replayed as that session.
  • The page the conversation started from, if the practitioner's site sends it.

A visitor should treat the widget the way they would treat any other contact form on that practitioner's site: what they type may be read by that practitioner, and, when a conversation is escalated, sent to them by email.

4. How the agent uses what is published and what is typed

To answer a question, the service sends the practitioner's own published content and the visitor's message to a language model, which drafts a reply grounded in that content. Nothing from one practitioner's content or conversations is used to answer a different practitioner's visitors.

5. Who we share data with

  • A language model provider, to generate replies from the content supplied for that conversation only.
  • Stripe, to process subscription payments.
  • An email delivery provider, to send sign-in links and escalation emails.
  • Our hosting provider, which stores the underlying data and runs the service.

We do not sell any of this data, and we do not share it for advertising.

6. How long we keep it

A practitioner's published content and conversation history stay available until they delete it or close their account. Deleting a document or a conversation from the dashboard removes it from active use immediately.

7. Your choices

A practitioner can export or delete their content and view or delete a conversation from their dashboard. A visitor who wants a conversation removed can ask the practitioner whose widget they used, or reach us through the application form.

8. Security

Data is stored with the hosting provider named above, access to a dashboard requires a signed-in session, and every account's data is kept separate from every other account's by how the service is built, not only by policy.

9. Changes to this policy

We will post the new date at the top of this page whenever this policy changes.