Privacy Policy

SummitBots provides an AI chat widget that businesses embed on their own websites. This policy explains what we collect, why, how long we keep it, and who we share it with.

The two roles we play

Which rules apply depends on whose data it is, so it is worth separating up front:

  • As a controller — for people who visit www.summitbots.io, sign up for an account, or email us. We decide how that data is used.
  • As a processor — for chat transcripts and leads collected by the widget on a customer's website. That data belongs to the customer who runs the site. We handle it on their instructions. If you chatted with a widget on someone else's site and want your data removed, contact that business first; we will support their request, and you can also reach us directly at the address below.

What we collect

From visitors who use a chat widget

  • The messages you type, and the assistant's replies
  • The page path where the conversation started (for example /pricing)
  • A randomly generated session identifier for the conversation
  • Contact details you choose to submit to a lead or handoff form — typically name, email, and optionally a phone number

The widget does not set cookies and does not track you across websites. It stores a single flag in your browser's sessionStorage to avoid re-showing the same greeting bubble, which your browser discards when you close the tab.

From customers who run an account

  • Account details: business name, owner email, and optionally an owner mobile number
  • Widget configuration, and any documents uploaded to inform the assistant's answers
  • A Stripe customer identifier for paid plans — we never see or store card numbers
  • Message counts per month, used to apply plan limits

Technical data

We use IP addresses for rate limiting and abuse prevention. An IP is used to build a short-lived counter key and is deleted within roughly two days. We do not build visitor profiles from it. Our hosting provider also keeps standard server logs.

This marketing site uses Google Analytics 4 to measure traffic. The app subdomain does not run analytics.

How we use it

  • To generate replies and operate the widget
  • To deliver captured leads to the business that collected them
  • To apply plan limits, bill paid accounts, and prevent abuse
  • To send transactional email — sign-in links and lead notifications

We do not sell personal information, and we do not use chat content to train our own models.

Who we share it with

We use a small number of subprocessors, each for one job:

  • Anthropic — generates assistant replies from conversation content
  • Vercel — hosting and server logs
  • Neon — the database where accounts, conversations, and leads are stored
  • Resend — transactional email delivery
  • Stripe — subscription payments
  • Twilio — SMS lead alerts, on plans where that feature is enabled
  • Voyage AI — converts uploaded documents into search embeddings
  • Google Analytics — traffic measurement on this marketing site only

We may also disclose information where the law requires it, or to protect our rights and the safety of our users.

How long we keep it

  • Chat transcripts are deleted after 90 days by an automated daily job. A conversation record is kept without its message content so usage history stays accurate.
  • Leads are kept until the customer deletes them or closes the account.
  • Sign-in sessions expire after 7 days; sign-in links after 15 minutes.
  • Rate-limit counters are pruned after about two days.
  • Unverified signups are deleted automatically after 14 days if the sign-in link is never used.

Security

Data is encrypted in transit. Passwords are stored as scrypt hashes, and session tokens are stored only as SHA-256 hashes — the raw token exists only in your browser cookie. Session cookies are httpOnly, which means page scripts cannot read them. Each account's data is scoped to its own widget key and checked on every request.

No system is perfectly secure. If you believe you have found a vulnerability, please email us rather than disclosing it publicly.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. If you are in the EEA or UK, you also have the right to complain to your local data protection authority. Californian residents may request disclosure of what we collect and ask us to delete it; we do not sell or share personal information as those terms are defined by the CCPA.

To exercise any of these, email support@summitbots.io. If the data was collected by a widget on another company's website, we will route your request to that company, since it is their data to act on.

International transfers

We are based in the United States and our subprocessors may process data there. Where data is transferred out of the EEA or UK, we rely on our subprocessors' standard contractual clauses.

Children

SummitBots is a business product and is not directed at children under 13. We do not knowingly collect their information. If you believe a child has submitted data through a widget, email us and we will delete it.

Changes

If we change this policy we will update the date at the top of this page. Material changes affecting account holders will also be sent by email.

Contact

Questions about this policy, or about data we hold: support@summitbots.io.