Privacy Policy

Last updated: June 26, 2026

This Privacy Policy explains how aurochat collects, uses, stores, and deletes information when you use our website, dashboard, and embeddable chat widget.

1. Who we are

aurochat is a SaaS product that helps businesses create AI assistants trained on their own knowledge and embed those assistants on their websites.

For privacy questions, contact us at: support@aurochat.app.

2. Information we collect from account users

When you create an account, we may collect your name, email address, authentication information, workspace details, company name, website URL, billing status, plan information, and product usage data.

3. Knowledge sources

When you upload files, add URLs, or paste text, we process that content so your assistant can answer questions from it. Knowledge sources may include business documents, help content, policies, service descriptions, and other materials you choose to provide.

4. Chat widget data

When a visitor uses an aurochat widget on a customer website, we may process chat messages, timestamps, anonymous visitor identifiers, widget session information, origin domain, feedback, fallback events, and lead form submissions.

5. Lead information

If a visitor submits a contact form through the widget, we may collect name, email address, optional phone number, optional message, consent timestamp, and the related conversation context. This information is provided to the business that owns the assistant.

6. How we use information

We use information to provide the product, authenticate users, process knowledge sources, generate assistant answers, display conversations and leads, enforce plan limits, send transactional emails, prevent abuse, troubleshoot issues, improve reliability, and comply with legal obligations.

7. AI processing

aurochat uses Gemini for embeddings and answer generation. Knowledge sources and chat messages may be sent to AI services as required to provide assistant functionality.

8. Billing

Payments and subscriptions are handled through Stripe. aurochat does not store full payment card details. Stripe may process billing information according to its own terms and privacy policy.

9. Email

We use email services to send authentication emails, lead notifications, source failure notifications, quota alerts, and billing-related messages.

10. Storage and retention

Conversation retention depends on the active plan. Free workspaces retain conversations for 30 days. Starter workspaces retain conversations for 90 days. Pro is Coming soon and is expected to provide 365-day retention. Knowledge sources remain stored while the account is active unless deleted by the user.

11. Local storage and cookies

aurochat may use cookies and local storage for authentication, session management, security, and widget visitor continuity. The widget may store an anonymous visitor identifier so conversations can persist for a limited time.

12. Subprocessors

aurochat may use infrastructure, AI, payment, email, database, hosting, and storage providers to deliver the service. These may include Supabase, Google Gemini, Stripe, Resend, and Vercel, depending on the configured production environment.

13. Data sharing

We do not sell personal data to advertisers. We may share information with service providers that help operate aurochat, with the business that owns the assistant, when required by law, or to protect the safety and security of the product.

14. Data deletion

Account users may delete their account from the dashboard. Account deletion permanently removes or schedules deletion of workspace data, documents, embeddings, conversations, leads, and related records, except where retention is required for security, billing, legal, or operational reasons.

15. Your rights

Depending on your location, you may have rights to access, correct, export, or delete personal information. Contact support@aurochat.app to make a request.

16. Security

We use technical and organizational measures intended to protect information, including authentication, access controls, private storage for knowledge sources, server-side validation, and domain validation for widgets. No system can be guaranteed completely secure.

17. Voice and audio

Some assistants offer voice chat. When a visitor speaks, the audio is sent to our AI provider for speech-to-text, and the resulting transcript is processed by the same answer pipeline as text chat. Assistant replies may be converted to speech for playback. We always store the transcript, message metadata, duration, language, and input mode.

By default we do not store the original voice recording. A business can choose to enable storage of original visitor audio for quality review. When that is enabled, the visitor is shown a clear notice and must actively agree before voice chat starts; that consent is recorded. Stored audio is kept in private storage, is never made public, and is accessible only to the business that owns the assistant through controlled, expiring playback links.

Stored audio is deleted automatically when its retention period ends, when the related conversation is deleted, and when the account is deleted. Voice and audio are processed by third-party AI providers as described in “AI processing” and “Subprocessors”. Voice may also be available on additional messaging channels as those features are released; this policy will be updated accordingly. We do not claim any legal compliance certification.

18. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new “Last updated” date.