← Back to ChatbotReply
🔒 Security & Privacy
Last updated: September 26, 2026
🔐 TLS everywhere
🔑 Hashed passwords
🚫 No data selling
🇪🇺 GDPR-aware
How we protect your data
- Encryption in transit: all traffic to ChatbotReply (dashboard, widget, API, webhooks) runs over HTTPS/TLS.
- Passwords: admin passwords are stored as salted hashes — never in plain text — and are shown exactly once at signup.
- API keys & secrets: widget keys are scoped to a single business; webhook secrets are hashed; third-party tokens can be stored encrypted.
- Least privilege: every admin session is scoped to one business; nobody can see another store's conversations.
- Abuse protection: rate limiting on chat, login, signup, and webhook endpoints.
What data we hold
- Your business profile, FAQs, imported website content, orders you sync, and settings.
- Chat transcripts (so the bot has context and you get analytics), captured leads, and thumbs-up/down feedback.
- Billing is handled by Stripe — we never see or store your card numbers.
We never sell your data or your customers' data, and we don't use your content to train shared models.
AI processing
When AI answers are enabled, conversation text is sent to the configured AI provider (an OpenAI-compatible API — either your own key or ChatbotReply's managed key) solely to generate the reply.
No training on your data: we never use your content to train shared models. When you bring your own API key, data goes only to your provider under your agreement with them. When you use ChatbotReply's managed key, requests go to our provider under their API platform terms, which exclude API data from model training. Nothing about this page is a substitute for your provider's own data policy — check it if you have specific compliance needs.
Your GDPR rights
If you're in the EU/UK, you can request access, correction, export, or deletion of personal data we hold about you. Store owners can delete conversations, leads, and documents from the admin dashboard at any time. For requests, email privacy@chatbotreply.com — we respond within 30 days.
Subprocessors
- Render — hosting & infrastructure (US)
- Neon — managed PostgreSQL database hosting (US)
- Stripe — payments & subscriptions
- Meta — WhatsApp, Messenger & Instagram messaging (only if you connect them)
- SendGrid / Resend — transactional email (only if you enable the email channel)
- Twilio — voice calls (only if you enable the voice channel)
- Shopify — order data you sync (only if you connect your store)
- hCaptcha — bot protection on signup and login
- OpenAI-compatible AI provider — reply generation (only when AI answers are enabled)
Our Data Processing Addendum governs how we handle personal data on your behalf.
Data retention
Chat transcripts and analytics are kept while your account is active so your reports keep working. Delete your account and we remove your business data within 30 days (backups age out within 90 days).
Responsible disclosure
Found a security issue? Email security@chatbotreply.com and we'll investigate promptly. Please don't probe other customers' data.
Incident response
If we discover a security incident affecting customer data, we will:
- Contain — revoke affected credentials, isolate the issue, and restore service from clean backups if needed.
- Notify — inform affected customers without undue delay and within 72 hours of becoming aware, with what happened, what data was involved, and what we're doing about it.
- Recover — our recovery targets are RTO ≤ 4 hours (stateless app redeploys in minutes; database restores from Neon's automated backups) and RPO ≤ 24 hours on current plans.
- Review — publish a post-incident summary to affected customers and fix the root cause.
Compliance roadmap
We are not SOC 2 certified and have not completed a formal penetration test yet. Security reviews are part of our roadmap as we grow into larger deals — this page will be updated as each milestone lands. Our Data Processing Addendum is available now for customers who need one.