Skip to content
ChatKit

Security & privacy

What we do with your data, in plain words.

You're trusting us with your website content and your customers' questions. Here's exactly how we handle them — including what we don't have yet.

  • Hosted in the EU

    Our app servers and database run in the European Union.

  • Never used for training

    Your content and your visitors' chats don't train any AI model.

  • Encrypted

    HTTPS for all traffic. Integration secrets encrypted with AES-256-GCM.

  • GDPR-ready

    We act as your processor and sign a DPA on request.

01Where your data lives

The ChatKit application and its Postgres database run on servers in the European Union. That includes your knowledge content (pages, files, Q&A), conversations, images visitors send in the chat, leads and account settings.

A few specialist providers process limited data outside the EU, such as the AI model provider and our sign-in provider. They're listed under subprocessors, and transfers rely on Standard Contractual Clauses. When a public page only renders with JavaScript, our crawler may fetch it through a rendering service; only the public URL is sent.

02How AI answers are generated

When a visitor asks a question, we search your knowledge for relevant passages and send the question plus those passages to our AI model provider to write the answer. Your content is also turned into embeddings (numeric vectors) so it can be searched.

  • We use API terms under which this data is not used to train the provider's models.
  • We don't use your content or your visitors' conversations to train models for anyone else.
  • In strict mode (the default) the agent only answers from your content, and says it doesn't know instead of guessing.

03Encryption

  • All traffic to the dashboard, the API and the chat widget uses HTTPS (TLS).
  • Secrets you give us for integrations — API keys and tokens for Shopify, Stripe, Slack and custom HTTP actions — are encrypted with AES-256-GCM before they're stored. The key is kept outside the database.
  • Visitor sessions in the widget use signed tokens, so one visitor can't read another visitor's conversation.
  • Webhooks can be signed with HMAC, so your systems can check a request really came from us.
  • Inbox push alerts are sent through your browser's push service with encrypted payloads.

04Accounts and access

  • Sign-in is handled by Clerk, a dedicated authentication provider. We never see or store your password.
  • Every dashboard request is checked against your workspace on the server, not just in the browser.
  • Sensitive actions — billing, API keys, deleting an agent — are limited to workspace admins.
  • If your site has logged-in users, you can sign their identity with a secret from your dashboard, so visitors can't pretend to be someone else in a chat.

05Protecting the platform

  • Our website crawler, HTTP actions and webhooks refuse to connect to private, internal or cloud-metadata network addresses. The check happens at connect time, so redirects and DNS tricks are caught too.
  • Chat messages, actions, lead capture, the live demo and the API are rate limited per visitor, per IP and per agent.
  • The chat widget runs in an iframe served from our domain, separate from your page.
  • Images visitors upload are checked by their actual file contents, not just the extension, and can only be opened by the visitor who sent them and your team.
  • Usage caps are enforced atomically, so a burst of traffic can't push you over your plan without your opt-in.

06Retention and deletion

Deleting an agent deletes its knowledge, conversations and leads. Account data is deleted within 30 days of closing your account, except invoices we must keep by law. Need specific conversations or a visitor's data removed? Email [email protected] and we'll handle it.

The full details are in our privacy policy.

07Subprocessors

Subprocessors
ProviderPurposeLocation
Vercel (AI Gateway)Routing AI requests to model providersUSA (SCCs)
OpenAIGenerating AI answers, image understanding and embeddingsUSA (SCCs)
CohereRe-ranking knowledge snippets for each questionUSA (SCCs)
ClerkAccount authenticationUSA (SCCs)
StripePayments and invoicingUSA / EU (SCCs)
ResendTransactional emailUSA (SCCs)
EU hosting providerApplication servers and database (including images visitors send)European Union
Jina AI ReaderRendering public web pages that need JavaScript, when the crawler can't read them directly (can be turned off)Public page URLs only
Browser push services (Apple, Google, Mozilla)Delivering inbox push alerts; message payloads are encryptedDepends on your device

We'll tell customers about material changes to this list in advance.

08Compliance, honestly

  • GDPR: for chats on your website you're the controller and we're your processor. We sign a DPA on request — ask for one.
  • Certifications: we don't hold SOC 2, ISO 27001 or HIPAA certification today, and we won't claim them until we do. If you need them, tell us — it helps us prioritize.

09Report a vulnerability

Found a security issue? Email [email protected] with the details and steps to reproduce. Please give us a reasonable chance to fix it before sharing it publicly. We'll acknowledge your report and keep you posted.

Live in about a minute

Your best support agent is one paste away.

Start on the free plan or try Growth free for 14 days. No credit card, no auto-upgrades, cancel in two clicks.