Privacy Policy
Effective 17 September 2026
In short
AI Chat for Website is a chat for business websites. A business (our customer) adds it to its site; it answers that site's visitors from what the site says, and hands chats to the customer's team. The AI model that writes the answers runs on our own servers. Conversations are not sent to a third-party AI provider.
This policy covers three groups, separately: people who visit our own website, our customers and the people on their teams, and the visitors of our customers' websites. For that last group the customer decides what is collected and why, and we handle the data on its behalf.
We use no advertising trackers and no third-party analytics, we do not sell personal information, and the chat widget sets no cookies.
This summary is here to help you read the document. The numbered sections below are the document.
1. Who we are and what this covers
AI Chat for Website is a product of Devsmooth Ltd., a company incorporated in British Columbia, Canada, with its registered office in Surrey, British Columbia ("Devsmooth", "we", "us"). This policy explains how we handle personal information across our website at www.aichatforwebsite.com, the customer portal at app.aichatforwebsite.com, and the chat widget that our customers install on their own websites (together, the "Service"). It is written with Canada's PIPEDA, British Columbia's PIPA and, where they apply, the EU and UK GDPR and United States state privacy laws in mind.
2. Three groups of people, two roles
Visitors to our own website. We decide how this information is handled, so we are the controller. See section 3.
Customers and portal users. The people who sign up, are invited to a customer's team, and sign in to the portal. We are the controller of their account information. See section 4.
Visitors to our customers' websites. When you use a chat on a website that is not ours and it is provided by AI Chat for Website, the business that runs that website (our customer) decides whether the chat is there, whether visits are recorded and what happens with the conversations. That business is the controller. We are its processor (a "service provider" under some laws): we handle the information on its instructions, under our Data Processing Addendum. Section 5 describes exactly what the widget does, so that you can see it for yourself, but questions and requests about that information go first to the business whose website you visited.
3. Visitors to our own website
Our website has no advertising trackers, no third-party analytics and no tracking pixels, and the site itself sets no cookies. Like any web server, ours receives your IP address and your browser's user agent in order to send you the page, and may keep them in short-lived server logs that we use only for security and troubleshooting.
The chat on our website is AI Chat for Website itself, and for that chat we are the controller. We run it in chat-only mode (section 5.2): nothing about you is recorded, and nothing is stored in your browser, unless you start a chat. If you do, we keep what section 5.3 lists, and we use it to answer you and to follow up if you leave contact details.
If you write to us by email, we keep the correspondence for as long as it is needed to deal with your request and for our records afterwards.
4. Customers and portal users
4.1 What we collect
- Account details: your name, your email address, your company name, the name shown to visitors when you join a chat, your role on the team (owner or agent), and a salted hash of your password (argon2id). We never store the password itself.
- Agreement record: the time you agreed to the Terms of Service and this policy, and which edition (its effective date).
- Sign-in records: the time of your last sign-in, and your
sign-in sessions. A session is a random token kept in a cookie named
wc_session; we store only its hash. The cookie is strictly necessary, is not readable by scripts, and lasts 30 days. - Codes and invitations: the six-digit codes we email to confirm an address or reset a password (stored hashed, valid 15 minutes), and team invitations (the invited address, the role, who invited, and a hashed single-use token, valid 7 days).
- Your website and settings: the address of the website you add, the text of its public pages as our crawler read them, the notes and instructions you type in, the widget's appearance and wording, the addresses you ask us to ignore, and the blocks you place.
- Usage: per website and per day, how many messages the assistant answered and how many AI tokens that took. These are counts, not content.
- Email we send you: codes, invitations, new leads, missed chats, "someone is waiting" notices and plan notices. We keep a delivery record of each message (recipient, subject, time, and what the receiving mail server said).
- Browser storage in the portal: the portal keeps small preferences in your browser's local storage, such as which of your websites you were last looking at. They are not sent to us.
4.2 Why we use it
To provide and secure the Service and to keep the record of our agreement with you (performance of the contract); to prevent abuse and defend our systems (legitimate interests); to send the operational email listed above (performance of the contract); to answer you when you write to us; and to meet legal obligations. We do not send marketing email without consent, and any such email has an unsubscribe link.
4.3 Payments
Paid plans are set up by email and paid by invoice. The Service itself collects no card details. For a paid account we keep the billing contact, the plan and the invoice records. When self-serve billing is added, card details will be handled by a dedicated payment processor and will not touch our servers, and we will update this policy and our list of sub-processors before we take the first card payment.
5. Visitors to our customers' websites
This section describes what the chat widget does on a customer's website. The customer chooses between two modes, and its own privacy notice should tell you which applies.
5.1 Normal mode: the chat, with visit recording
Each time a page with the widget loads, the widget tells us, and we record a visit for the customer. A visit holds:
- the address and title of each page viewed, without the query string (the part after the question mark, where websites sometimes put email addresses, tokens and order numbers), and the time of each view;
- the address of the page that referred you, also without its query string,
and the campaign tags
utm_source,utm_medium,utm_campaign,utm_termandutm_contentif the page address carried them; - your IP address, and the country we work out from it. The lookup uses a database on our own server (IP Geolocation by DB-IP); your address is not sent to anyone for it;
- your browser's user agent, and the device type, browser and operating system we read from it;
- your browser's language, time zone and screen size;
- when the visit started and when we last heard from the page, and roughly how long the tab was visible. For that last figure the widget sends a short signal every 15 seconds while the tab is in view.
To recognise a returning browser, the widget creates a random identifier and keeps it in your browser's local storage for that website. We store only a hash of it. The identifier is separate for every customer website, so it cannot be used to follow you from one website to another, and we do not try to identify you from your IP address or browser either. The widget sets no cookies. It may also keep in local storage the identifier of your open conversation (so the chat follows you from page to page), a flag that the chat has already offered its help once, and the size you chose for the chat window.
Visits by automated crawlers that identify themselves are not recorded.
5.2 Chat-only mode
A customer can switch visit recording off. Then the widget is a chat and nothing else: no visit, page view or time on site is recorded, no identifier is created, and nothing is stored in your browser, until you start a chat. Your IP address is still processed in memory to deliver the widget, to apply rate limits and blocks, and to keep abuse out, but it is not written to our database. The same applies on any website, whatever its setting, when a request comes from an address that the customer has asked us to ignore (for example its own office).
5.3 When you chat
In either mode, when you start a chat we keep: what you type; the assistant's answers and the pages of the website they were drawn from; any replies from the customer's team; whether you marked an answer as helpful; the address (without query string) of the page you started the chat on; your approximate country; and any name, email address or phone number you give, in the form or in the conversation. Contact details become a "lead" for the customer and are emailed to it, together with the conversation. If you give the same email address or phone number again later, the customer sees those conversations and visits together as one person. We never match people across different customers' websites.
The answers are written by an AI model from the text of the customer's public website. The model runs on hardware that Devsmooth owns and operates, in Canada. Your conversation is not sent to a third-party AI provider, and we do not use conversations to train AI models.
5.4 Who sees it
The customer's team sees visits, conversations, leads and people in the portal, for its own websites only. Your IP address is shown to the customer only in the detail view of a single visit, where it can be used to block abuse, and it is never sent to the widget or to other visitors. A customer can block an IP address or a browser identifier from its chat for a period it chooses. Devsmooth staff access this information only as needed to run, secure and support the Service.
6. Global Privacy Control and Do Not Track
We honour Global Privacy Control. When your browser sends
the GPC signal (the Sec-GPC: 1 request header, which browsers
also expose to pages as navigator.globalPrivacyControl), the
widget treats you exactly as in chat-only mode on every customer website,
whatever the customer's setting: no visit, page view, time on site or
identifier is recorded, and nothing is stored in your browser, unless you
start a chat. This is enforced twice, in the widget and on our server.
We do not act on the older Do Not Track (DNT) header. It has been deprecated, browsers are removing it, and it was never given a settled meaning. If you want to send us an opt-out signal, use Global Privacy Control.
7. What we do not do
- No advertising trackers and no third-party analytics, on our website, in the portal or in the widget.
- No sale or rental of personal information, and no sharing of it for cross-context behavioural advertising.
- No third-party AI provider: the model runs on our own servers.
- No use of conversations, visits or leads to train AI models.
- No cookies from the widget, and no identifier shared between one customer's website and another's.
8. Who we share it with
The companies that host parts of the Service, listed with their roles and locations in Annex 3 of the Data Processing Addendum: at present OVHcloud (the server that runs the application and its database) and Oracle (the server that runs our own mail system). Our domain's DNS is hosted at Cloudflare, as DNS only: requests to the Service do not pass through Cloudflare. When we email a lead or an invitation, the message is delivered to the recipient's email provider, as any email is. Beyond that: professional advisers under confidentiality, authorities when the law genuinely requires it, and a successor if the business is sold, under this same policy.
9. Where it lives
The application and its database run on a server in the United States. The AI model runs on our own hardware in Canada, reached from that server over an encrypted private tunnel. Our mail server runs on Oracle Cloud. Wherever the information is, it is protected by this policy, by the Data Processing Addendum and by our agreements with those providers. For personal data that is subject to the EU or UK GDPR we rely on the Standard Contractual Clauses for transfers, as the Addendum describes.
10. How long we keep it
| Information | Kept for |
|---|---|
| Conversations and their messages | 12 months after the last message, then deleted automatically |
| Visits and page views | 6 months after the visit's last activity, then deleted automatically. A browser identifier with no visits and no conversations left is deleted with them |
| Leads and people (contact details a visitor gave) | Until the customer deletes the website from its account, asks us to delete them, or closes its account |
| Blocks | A block stops applying when it expires. Its record is kept until the customer lifts it or deletes the website |
| Account details | For the life of the account, then deleted within 30 days of closure |
| Sign-in sessions | 30 days, or until you sign out |
| Emailed codes | 15 minutes; the record is deleted once it has expired |
| Invitations | 7 days; an expired invitation is deleted 30 days later |
| Email we sent | The text of a code or an invitation link is erased the moment it is sent; any other message text after 30 days; the delivery record after 90 days |
| Copies of the database taken before a software update | Up to 35 days, on the production server; restored only to recover the Service |
| Crawled website text | Replaced at each re-read of the website; deleted with the website |
The automatic deletions run several times a day. Records we must keep by law are kept only for that purpose and for as long as the law requires.
11. How we protect it
All traffic to the Service is encrypted in transit with TLS. Passwords are stored only as salted argon2id hashes, and session tokens, invitation tokens, emailed codes and visitor identifiers are stored only as hashes. Every portal request is scoped to the signed-in customer's own account. The widget's interface accepts requests only from the website it was set up for. Access to the production server is restricted to named administrators and is key-based. No system is perfectly secure; if a breach affects your personal information we will notify you, our customers and the authorities as the law requires.
12. Your rights
Depending on where you live, you can ask for a copy of your personal information, ask for it to be corrected or deleted, object to or restrict a use of it, and withdraw consent where consent is the basis. If you are a customer or portal user, write to privacy@aichatforwebsite.com and we will answer within 30 days. If you are a visitor to a customer's website, contact that business first: it is the controller and it can see your conversations in its portal. If you write to us instead, we will pass your request to that business and help it respond, as our Data Processing Addendum requires. You can also clear the widget's local storage for a website in your browser at any time, which removes the identifier from your side. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner for British Columbia, or your own national or state authority.
13. Children
The Service is a business tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 16 as a controller. Customers are responsible for where they place the chat.
14. Changes
If we change this policy materially we will announce it by email or in the portal before the change takes effect. This page always carries its effective date.
15. Contact
Privacy questions and requests: privacy@aichatforwebsite.com. Devsmooth Ltd., Surrey, British Columbia, Canada.