Privacy Terms Early access
Home Join early access

Privacy Policy

Effective as of August 20, 2026

This Privacy Policy is adapted from the General Legal Privacy Policy (GDPR Enhanced) template (CC0) for Chatlio LLC dba bot.dev. It is a first public draft for the bot.dev beta and is not legal advice. See the State privacy rights notice and Notice to European users below.

Chatlio LLC dba bot.dev (“bot.dev,” “we”, “us” or “our”) provides AI-assisted support chat: a hosted workspace, knowledge base, and embeddable widget. This Privacy Policy describes how bot.dev processes personal information that we collect through our digital or online properties or services that link to this Privacy Policy (including our website, hosted workspaces, widget, and related communications) as well as our marketing activities and other activities described in this Privacy Policy (collectively, the “Service”).

bot.dev is a business product. When a customer embeds our widget or uploads support material, we process that customer’s visitor and operator data as a service provider / data processor. This policy describes (1) information we process as a controller about people who visit bot.dev or create an account, and (2) how we handle Customer Content we process on a customer’s behalf. If you are a visitor chatting with a bot.dev customer, that customer’s privacy policy applies to your conversation; contact that business first for access, correction, or deletion.

Personal information we collect

Information you provide to us

Personal information you may provide to us through the Service or otherwise includes:

  • Contact data, such as name, email address, company name, and phone number.
  • Profile data, such as workspace name, role, and account settings.
  • Communications data based on our exchanges with you, including when you contact us through the Service, email, or chat.
  • Transactional data, such as plan, invoice history, and workspace identifiers needed to bill and operate the account.
  • Marketing data, such as your preferences for receiving our marketing communications.
  • Customer Content, such as documents, FAQs, URLs, transcripts, tickets, widget configuration, operator messages, and visitor messages you submit to or generate through the Service, and associated metadata.
  • Payment data needed to complete transactions. Card details are collected and processed by Stripe; we do not store full payment card numbers.

We do not ask for government-issued identification numbers, precise geolocation, or demographic data such as date of birth. Please do not upload special-category or highly regulated data (for example HIPAA protected health information) unless we have agreed in writing.

Third-party sources

We may combine personal information we receive from you with personal information from:

  • Service providers that help us operate the Service (hosting, email, payments, model providers).
  • Payment processors, such as Stripe, for billing status and invoices.
  • Business transaction partners, in connection with an actual or prospective financing, acquisition, or similar transaction.

We do not buy personal information from data brokers, and we do not use social-network login.

Automatic data collection

We, our service providers, and our infrastructure providers may automatically log information about you, your computer or mobile device, and your interaction with the Service, such as:

  • Device data, such as browser type, operating system, IP address, language, and coarse location derived from IP address (city/region/country).
  • Online activity data, such as pages viewed, referring URL, access times, and whether you have opened our emails.

We do not collect precise GPS location. We do not use advertising pixels for interest-based ads on bot.dev.

Data about others

If you invite teammates or load visitor conversations, you may provide their contact details or messages. Please do not share someone else’s information with us unless you have a right to do so.

Tracking and other technologies

Cookies and similar technologies. The Site and Service use cookies and similar technologies that are needed to operate the Service (for example session or authentication cookies) and, on the public site, may use cookies from infrastructure providers such as Cloudflare. We do not use a separate advertising cookie stack. You can control cookies in your browser; blocking them may prevent sign-in or widget sessions from working.

Chat and AI technologies. Visitor and operator messages, retrieved knowledge snippets, and prompts are processed by model providers we use through our LLM proxy (currently OpenRouter, which may route to providers such as OpenAI, Anthropic, or Google). Those providers may receive the prompt content, limited account/workspace identifiers needed for routing and abuse prevention, and usage metadata. We contractually require providers to maintain appropriate safeguards and, where the provider allows it, we disable use of that data for the provider’s own model training.

If you connect your own agent (BYOA), that agent processes Customer Content under your control and its own terms.

How we use your personal information

We may use your personal information to:

  • provide, secure, troubleshoot, and operate the Service, including workspaces, widgets, knowledge retrieval, and AI replies;
  • create and maintain your account and workspace;
  • communicate with you about the Service, including login codes, security alerts, billing, and support;
  • process payments and prevent fraud;
  • analyze usage in aggregate to improve the Service;
  • send optional product updates (you can opt out of marketing emails); and
  • comply with law, enforce our terms, and protect the Service, our users, and others.

We may create aggregated, de-identified, or anonymized data from personal information and use that data to operate and improve the Service. We will not attempt to reidentify that data except to test whether our deidentification works. We do not use Customer Content to train our own foundation models.

We do not use personal information for interest-based advertising, and we do not sell personal information.

Retention

We retain personal information for as long as needed to provide the Service, including while an account is active, and thereafter as needed for legal, accounting, security, or dispute-resolution purposes. Workspace and Customer Content is generally retained until you delete it or close the account, then removed from live systems as soon as practicable. Backups may persist for a short period. Minimal billing and account records may be kept longer (for example invoice records at Stripe). Web access logs are typically purged within 90 days.

How we share your personal information

We may share personal information with:

  • Service providers that host or help operate the Service. Current categories include Hetzner (hosting), Cloudflare (DNS, CDN, and the public site), Stripe (payments), Zoho ZeptoMail (transactional email), and OpenRouter / model providers (AI completions and embeddings).
  • Payment processors. Stripe processes payment data under Stripe’s privacy policy.
  • Third parties you designate, such as an agent you connect in BYOA mode.
  • Professional advisors, such as lawyers and accountants.
  • Authorities and others when we believe in good faith it is necessary to comply with law, protect rights or safety, or investigate abuse.
  • Business transferees in connection with a financing, merger, acquisition, or similar transaction.

Workspace operators can see Customer Content in that workspace. Visitor chats are visible to the customer that operates the widget, not to the public.

We do not share personal information with advertising partners for interest-based ads.

Your choices

This section describes rights and choices available to users. Residents of certain U.S. states and Europe have additional rights below.

  • Access or update your information. If you have an account, you may review and update certain account information by signing in, or by emailing us.
  • Opt-out of marketing. Follow the unsubscribe link in a marketing email, or contact us. You will still receive service emails such as login codes and billing notices.
  • Cookies. Use your browser controls. Essential cookies cannot be turned off if you want the Service to work.
  • Do Not Track. We do not currently change behavior in response to browser DNT signals.
  • Declining to provide information. If you do not provide information we need to operate an account, we may not be able to provide the Service.
  • Close your account / delete Customer Content. Delete sources and conversations in the product where those controls exist, or email [email protected] or [email protected] to request account closure or deletion. Visitors should contact the bot.dev customer they chatted with first.

Other sites and services

The Service may contain links to websites and services operated by third parties. We do not control those services and are not responsible for their practices.

Security

We employ technical, organizational, and physical safeguards designed to protect the personal information we collect, including encryption in transit, access control, and hosting with reputable providers. Security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal information.

International data transfer

We are headquartered in the United States and use service providers that operate in the United States and other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country. European users should read the Notice to European users.

Chatlio LLC participates in the EU-U.S. Data Protection Framework (DPF), the Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF. Chatlio LLC complies with the DPF Principles with respect to personal data transferred from the EEA, Switzerland, and UK to the United States in reliance on the DPF. If there is any conflict between this Privacy Policy and the DPF Principles, the DPF Principles govern. Learn more at dataprivacyframework.gov. Chatlio LLC is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.

Children

The Service is not intended for use by anyone under 18 years of age. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us. If we learn that we have collected personal information through the Service from a child without required consent, we will delete it as required by law.

Changes to this Privacy Policy

We may modify this Privacy Policy at any time. If we make material changes, we will update the date at the top and post the revised policy on the Service or provide other appropriate notice. Your use of the Service after the effective date of a modified Privacy Policy indicates that the modified policy applies to your subsequent interactions with the Service.

How to contact us

If you have questions or want to exercise a privacy right, contact us:

  • Email: [email protected] or [email protected]
  • Mail: Chatlio LLC dba bot.dev, 1329 N 47th St #31231, Seattle, WA 98103 United States
  • Phone: +1 206-438-3846

State privacy rights notice

Except as otherwise provided, this section applies to residents of U.S. states to the extent they have privacy laws applicable to us that grant their residents the rights described below (collectively the “State Privacy Laws”).

We may not be able to process your request if we cannot confirm your identity or understand the request. We verify requests by matching them to the email address on the account or other information reasonably needed to confirm you are the person to whom the data relates. If we process visitor data as a service provider to a bot.dev customer, send the request to that customer first.

The State Privacy Laws may provide some or all of the following rights, which are not absolute: information about our collection and use; access; correction; deletion; appeal of a denied request; and nondiscrimination for exercising these rights.

  • Targeted advertising. We do not process your personal information for targeted advertising purposes.
  • Profiling / automated decision-making. We do not use your personal information to engage in profiling or automated decision-making that results in significant legal or similarly significant effects (housing, employment, credit, health care, or criminal justice).
  • Sale / sharing. We do not sell your personal information within the meaning of State Privacy Laws, and we do not share it for cross-context behavioral advertising.
  • Consumers under 16. We do not have actual knowledge that we collect, sell, or share the personal information of consumers under 16 years of age.
  • Sensitive personal information. We do not process sensitive personal information to infer characteristics about consumers. Customer Content may include information a customer chooses to upload; we process it only to provide the Service.

Because we do not sell or share personal information for advertising, we do not change site behavior in response to Global Privacy Control signals at this time. To exercise other state privacy rights, email [email protected]. You may use an authorized agent as permitted by law; we may require proof of authorization.

Information practices (current and past 12 months)

Personal information we collect CCPA statutory category Purposes Disclosed for a business purpose to Sold or shared
Contact, profile, and account data Identifiers; customer records Service delivery, support, security, billing Hosting, email, and payment providers None
Communications with us Identifiers; customer content Support and operations Hosting and email providers None
Transactional / billing data Commercial information Payments, accounting, fraud prevention Stripe and hosting providers None
Customer Content (knowledge, chats, widget data) Customer content; inferences used only to answer questions in-product Provide the Service, including AI replies and retrieval Hosting providers and model providers None
Device and online activity data Internet / electronic activity; coarse geolocation Operate, secure, and debug the Service Hosting and CDN providers None

Additional information for California residents

Under California’s Shine the Light law (Civil Code Section 1798.83), California residents may ask companies with whom they have formed a business relationship primarily for personal, family or household purposes for certain information about third-party direct marketing disclosures. Send requests to [email protected] with the subject “Shine the Light Request,” your name, mailing address, and a statement that you are a California resident. bot.dev is a business product and we do not disclose personal information to third parties for their own direct marketing.

Additional information for Nevada residents

Nevada residents may opt out of the sale of certain personal information for monetary consideration. We do not currently engage in such sales. Email [email protected] if you would like to record an opt-out of any potential future sales.

Notice to European users

This section applies only to individuals in the United Kingdom and the European Economic Area (“Europe”). References to “personal information” include “personal data” as defined in the GDPR.

Controller

Chatlio LLC dba bot.dev is the controller of personal information covered by this policy about people who visit bot.dev or create an account. See How to contact us above. We have not appointed a separate EU or UK representative. For customer/visitor data processed on a customer’s behalf, that customer is the controller and we are the processor.

Legal bases

Purpose Categories Legal basis
Service delivery and operations Contact, profile, communications, transactional, Customer Content, device data Contractual necessity
Security Contact, device, online activity Compliance with law; legitimate interests in keeping the Service secure
Service improvement and analytics Device and online activity data; limited account data Legitimate interests in operating a reliable product; consent for any optional cookies
Direct marketing Contact and marketing data Legitimate interests in telling customers about the product; consent where required
Compliance and protection Contact and other data relevant to the request Compliance with law; legitimate interests in protecting rights and investigating abuse
Aggregated / de-identified data As relevant in the circumstances Legitimate interests in understanding and improving the Service

We do not use personal information for interest-based advertising. We do not engage in automated decision-making that produces legal or similarly significant effects. Please do not send us sensitive personal information (health, biometrics, political opinions, and similar categories) through the Service.

Your rights

You may ask us to access, correct, delete, or transfer your personal information, restrict or object to certain processing, and withdraw consent where processing is based on consent. Email [email protected]. You may lodge a complaint with your local supervisory authority. EEA authorities: edpb.europa.eu. UK: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk, +44 303 123 1113.

Transfers outside Europe

We are a U.S. company. Using the Service means your personal information is processed in the United States. Where we transfer personal information from Europe, we use appropriate safeguards such as the Data Privacy Framework described above and/or standard contractual clauses. You may contact us for more information about the mechanism used for a particular transfer.

AI-assisted support chat.
From the team behind Chatlio.

Product

Features Pricing

Company

Contact Chatlio

Legal

Privacy Terms

© 2026 Chatlio LLC dba bot.dev. All rights reserved.