Privacy Policy
Last updated: 2026-07-06
This policy explains how Astroworld Chat handles personal data. It covers the business customers who use the dashboard and the website visitors who chat with a customer's bot.
Controller and processor
For visitor conversations, the business customer is the data controller and Astroworld is the data processor. We process that data only on the customer's instructions. A Data Processing Agreement is available at /dpa.
Data we collect
- Account data: name, email, company name, and billing identifiers from Stripe.
- Bot configuration and knowledge base: the content a business uploads for its bot.
- Visitor conversations: the messages a visitor sends and the bot's replies, plus a random visitor identifier stored in the visitor's browser.
- Remembered visitor profile (when the business enables memory): details a visitor states about themselves in the chat, such as their name, interests and preferences, so a returning visitor is recognized and does not have to repeat them. Sensitive details are not requested; visitors are asked not to share them and can erase everything remembered at any time.
- Conversational insights (when the business enables them): an automated read of the visitor to help the business's team respond, for example tone, mood, sentiment, urgency, buying stage, satisfaction, stated concern, goal or budget, and language. These are shown only to the business, never to the visitor.
- Lead score and visitor analytics: an automated lead score and behavioural signals such as pages viewed, device, browser, approximate location and session activity, shown to the business.
- Bookings, reminders, waitlist and rebooking (when the business enables booking): the visitor's name, email and chosen time, used to schedule the appointment and, if the business turns on reminders, to email a reminder beforehand with a one-tap reschedule or cancel link. If the business runs a waitlist and a slot is full, a visitor who opts in gives their name, email and desired day so the business can email them a time-limited link to claim a spot when one opens up. If the business turns on rebooking, a set time after an appointment it may email that customer a link to book their next visit (skipped if they have already booked again); you can opt out by replying to that email. If the business turns on intake, after booking you may be invited to answer a few questions it has set so it can prepare for your visit; only answer what you're comfortable sharing.
- Lead and quote-request forms (when the business enables them): the fields the business configures, which may include contact details and free-text such as the service requested, project scope or postcode. If the business enables review invitations, a visitor who leaves a positive rating may be invited to leave a review at the business's own review link.
- Usage and billing metrics (for businesses on per-seat, per-resolution plans): counts of the AI resolutions the business's bot handles, broken down by the model tier used to answer each one (Standard, Smart or Premium), together with the number of active team seats. These are aggregate counts about the business account, used to calculate the invoice; they are not used to profile individual visitors.
- Technical data: standard server logs needed to run and secure the service.
Some of the above (the remembered profile, conversational insights and lead score) is produced by automated analysis of the conversation. It is used by the business to provide and improve support, not to make decisions producing legal or similarly significant effects. Please do not share sensitive personal information in the chat.
How we use data
We use data to provide the chat service: answering visitor questions from the business knowledge base, remembering returning visitors, deriving conversational insights and a lead score for the business's team, showing analytics to the business, scheduling and reminding about appointments and inviting reviews after a positive rating where the business enables them, processing subscriptions, and sending service email. Memory, insights and lead scoring run only when the business turns them on and are visible only to that business (the data controller). We do not sell personal data, we do not use visitor conversations to train our own models, and we do not use this data for advertising.
For businesses on per-seat, per-resolution plans, we also use usage and billing metrics (per-tier counts of AI resolutions and the number of active team seats) to meter usage and bill the account: to apply the included monthly allowance, to charge for any additional seats, and to bill for resolutions above the allowance. These counts are about the business account, not individual visitors.
Sub-processors
We use these third parties to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Anthropic | AI model that generates chatbot answers | United States |
| Hetzner Online GmbH | Primary application and database hosting | Germany (EU) |
| Strato AG | Secondary hosting and backups | Germany (EU) |
| Stripe | Subscription billing and payment processing | United States / EU |
| Resend | Transactional email delivery | United States / EU |
| Google Ireland Ltd. (Google Analytics) | Website analytics via Google Consent Mode: full analytics (with cookies) only with your consent; without consent, only anonymous, cookieless, aggregated measurement signals (no personal data stored) | Ireland (EU) / United States (EU-US Data Privacy Framework) |
| Trustpilot | Review-collection widget shown in the account dashboard (receives page-load connection data such as IP and browser; sets no cookie on our own site) | Denmark (EU) |
Where data is hosted
All application and database data is hosted in the European Union (Germany), on Hetzner and Strato infrastructure. Some sub-processors (Anthropic, Stripe, Resend) may process limited data outside the EU under appropriate safeguards.
Cookies and analytics
On our own website (Astroworld Chat.com) we use only essential, functional cookies by default: the ones that keep you signed in (session and security), remember your language choice, and store your cookie choice itself. These are needed for the site to work, so we do not ask consent for them. For everything else, the choice is yours.
Data retention
Account and bot configuration data is kept while the account is active. Visitor conversations are retained for a configurable period and then deleted. When a business deletes its account, all associated data is removed.
One exception, called out because it survives deletion: the free trial is once per person. When you start a trial we keep an irreversible, salted hash of your email address and of the IP address you used, plus your address's domain. An address cannot be recovered from a hash, and we use it for nothing other than refusing a second free trial. If you delete your account your data is erased, but this hash remains for up to 24 months. Legal basis: our legitimate interest in preventing abuse of the free trial.
Security
All traffic is encrypted in transit with TLS (256-bit HTTPS). Access to production systems is restricted and key-based. Payments are handled by Stripe, which is PCI DSS compliant; we never receive or store card numbers.
Your rights
Businesses can exercise GDPR rights directly from the dashboard:
- Access and portability: export all your data as JSON from the dashboard.
- Erasure: delete your account and all associated data from the dashboard.
- Rectification, restriction, objection: contact us and we will action your request.
Visitors who want their conversation data removed should contact the business they chatted with (the data controller); we will assist that business with the request. A visitor can also erase everything the bot remembers about them at any time by typing "forget me" in the chat.
Cookies and widget storage
The chat widget stores a random visitor identifier in the visitor's browser so a conversation can continue across visits and returning visitors can be recognized. The widget can be configured to disable visitor tracking until a business has collected the consent it requires. The dashboard uses a single session cookie to keep you logged in. For the cookies and analytics on our own website, see Cookies and analytics.
Contact
Questions about privacy or data requests: [email protected].