Privacy Policy
Your privacy matters. Here's how we handle your data.
Last updated: March 6, 2026
1. Information We Collect
We collect information in the following ways:
Information you provide
- Account information — Name, email address, password, and country when you sign up.
- Organization data — Organization name, team member details, and configuration settings.
- Conversation content — Messages, notes, tags, and attachments created through the Service.
- Payment information — Billing details processed through Razorpay. We do not store credit card numbers.
Information collected automatically
- Usage data — Pages visited, features used, and actions taken within the Service.
- Device information — Browser type, operating system, screen resolution, and device identifiers.
- Network data — IP address, approximate location, and referral URLs.
- Visitor data — For visitors interacting with the chat widget: browser information, pages visited, and conversation history. Visitors are identified by a persistent cookie.
2. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the Service.
- Process transactions and send billing-related communications.
- Send service notifications, security alerts, and support messages.
- Analyze usage patterns to improve performance and user experience.
- Prevent fraud, abuse, and enforce our Terms & Conditions.
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your conversation data to train AI models.
3. Data Storage & Security
Your data is stored on Amazon Web Services (AWS) infrastructure, including RDS PostgreSQL databases and S3 storage. All data is encrypted in transit (TLS) and at rest.
We implement industry-standard security measures including:
- Encryption of data in transit and at rest.
- Rate limiting on all API endpoints.
- Multi-factor authentication (MFA) support.
- Granular role-based access control with 43 permission keys.
- Audit logging of administrative actions.
- Regular security reviews and updates.
4. Third-Party Services
We use the following third-party services to operate Chattsy:
- Amazon Web Services — Cloud infrastructure and data storage.
- Razorpay — Payment processing.
- Firebase Cloud Messaging — Push notification delivery.
- Cloudflare — DNS and content delivery.
- AI Providers — When AI features are enabled, conversation data may be sent to your configured AI provider (e.g., OpenAI, Anthropic) to generate responses. This is controlled by your organization's settings.
Each third-party service is subject to its own privacy policy. We only share the minimum data necessary for each service to function.
5. Cookies
The Chattsy application uses session cookies for authentication. The chat widget uses a persistent cookie to identify returning visitors on your website.
We do not use third-party tracking cookies on our marketing website or within the application.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Organization owners can configure custom data retention policies to automatically delete old conversations.
When you delete your account or organization, we will delete your data within 30 days, except where we are required to retain it by law.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict processing of your data.
- Request a copy of your data in a portable format.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
8. Children's Privacy
The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we discover that a child under 18 has provided us with personal information, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last updated” date and, where appropriate, by sending an email notification.
10. Contact
If you have questions or concerns about this Privacy Policy, please contact us at [email protected].