Back to App

Privacy Policy

Last updated: March 3, 2026

1. Information We Collect

Account Information: When you create an account, we collect your email address and any profile information you choose to provide.

Usage Data: We collect information about how you use our service, including chatbots created, documents uploaded, and feature usage patterns.

Payment Information: Payment processing is handled by Polar (polar.sh). We do not store your payment card details. Polar retains transaction data as required by their terms and applicable law.

Chatbot Content: Documents and web content you upload to train your chatbots, as well as end-user queries submitted to your chatbots, are processed by our AI sub-processors (see Section 8).

Technical Data: We automatically collect certain technical information, including IP address, browser type, operating system, and device information.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and manage subscriptions
  • Generate chatbot responses using AI language models
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Analyze usage patterns to improve user experience
  • Enforce our terms and conditions
  • Comply with legal obligations

3. Information Sharing

We do not sell or trade your personal information. We share data only with the following categories of recipients:

  • Sub-processors: Third-party services we use to operate the platform (see Section 8 for the full list)
  • Legal Requirements: We may disclose information when required by law or court order, or to protect our legitimate rights
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred to the successor entity

4. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including encryption in transit (TLS) and at rest, access controls, and incident response procedures. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

5. Data Retention

We retain your personal information for the following periods:

  • Account data: Duration of service + 3 years for legal compliance
  • Chatbot & document content: Until account deletion or manual deletion by you
  • Usage analytics: 26 months
  • Payment records: 7 years for tax and legal requirements
  • Support communications: 3 years from last interaction

Upon account deletion, personal data and chatbot content are removed within 30 days. Backup copies are removed within 90 days. Some data may be anonymized and retained for statistical purposes.

6. Your Rights

Under GDPR you have the right to:

  • Access the personal information we hold about you
  • Correct any inaccurate personal information
  • Request deletion of your personal information
  • Object to or restrict processing of your information
  • Data portability (receive a copy of your data in a structured format)
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with the supervisory authority (ÚOOÚ in Czechia)

To exercise any of these rights, contact us at support@chatbotty.ai.

7. Cookies and Tracking

We use cookies and similar technologies necessary for authentication and session management. We may also use analytics cookies to understand usage patterns and improve the service. You can control cookie settings through your browser preferences; disabling essential cookies may affect service functionality.

8. Third-Party Services

We share data with the following categories of third-party providers to operate the service:

  • AI language model provider — Your uploaded documents and chatbot queries are sent to OpenAI (USA) to generate responses. This is the most significant data transfer in terms of content. Data is processed under OpenAI's Privacy Policy.
  • Database and authentication provider — Stores your account data, chatbot content, and documents.
  • Hosting and infrastructure providers — Serve the application and handle caching. IP addresses and session identifiers may be processed for rate-limiting and performance purposes.
  • Payment processor — Handles subscription billing and one-time purchases as Merchant of Record.
  • Authentication provider — Enables sign-in via Google OAuth.

All providers are contractually bound to process data only as instructed and to maintain appropriate security measures.

9. International Data Transfers

Some of our sub-processors (including OpenAI, Vercel, Upstash, and Polar) are based in the United States. Transfers of personal data to the US are carried out under Standard Contractual Clauses (SCCs) approved by the European Commission, or the EU-US Data Privacy Framework where applicable, providing an adequate level of protection for your personal data.

10. Children's Privacy

Our service is not intended for persons under 16 years of age, in accordance with GDPR requirements for digital services in the EU. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us at support@chatbotty.ai and we will delete it promptly.

11. Changes to This Policy

We may update this privacy policy from time to time. For material changes, we will notify you by email or a prominent notice within the service at least 30 days before the change takes effect. The "Last updated" date at the top of this page reflects the current version.

12. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us:

Email: support@chatbotty.ai

For privacy concerns, data access requests, and general support

13. GDPR Information

Data Controller

Puretech s.r.o., Company ID: 05503795, registered in Czechia
Email: support@chatbotty.ai

Supervisory Authority

Office for Personal Data Protection (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7, Czechia
Phone: +420 234 665 111
Email: posta@uoou.cz
Website: www.uoou.cz

Legal Basis for Processing

  • Contract performance: Art. 6(1)(b) GDPR — providing the service
  • Legitimate interests: Art. 6(1)(f) GDPR — analytics, security, fraud prevention
  • Consent: Art. 6(1)(a) GDPR — marketing communications (where applicable)
  • Legal obligation: Art. 6(1)(c) GDPR — tax and accounting records