Privacy Policy
Last updated: August 21, 2026
We do not sell your data. This policy explains, in plain terms, what ChatbotGen collects, why we collect it, who else sees it, and how long we keep it. We have written it against what the product actually does — not against a template.
When we say “Company”, “we”, “our”, or “us”, we mean ChatbotGen, operated by Toptive LLC. When we say “Services”, we mean our websites, including chatbotgen.com, and every product we maintain — the chatbot builder, the embeddable widget, the channel integrations, the MCP server, and any other service we provide. “You” means the person or organization that owns an account. “End user” means someone who chats with a chatbot that one of our customers built.
Two roles matter throughout this document. For your own account data, we are the controller. For the conversations your chatbots have with your visitors, you are the controller and we process that data on your behalf, under our Terms of Service.
We may update this policy. When we make a significant change, we will refresh the date at the top of this page and take appropriate steps to notify account holders.
What we collect from account holders
- Account details: your email address, first and last name, and a hashed password. If you sign up with Google, we store your Google account identifier and the OAuth tokens needed to keep you signed in — we never see or store your Google password.
- Consent evidence: the date and time you accepted these Terms and this Privacy Policy at signup.
- Onboarding answers: if you answer the optional “How did you find us?” question, we store the option you picked (for example search, YouTube, an AI assistant, or a friend) and, for some options, the short free-text detail you add.
- Content you create: chatbots, prompts, widget settings, lead-capture forms, and the training material you upload or point us at — documents, website URLs, questions and answers, and free text.
- Billing details: your Stripe customer and subscription identifiers, your plan, and your billing status. We never receive or store your full card number — Stripe collects and holds it on its own hosted checkout page.
- Integration credentials: the tokens and connection identifiers needed to run the channels and tools you enable, such as a Telegram bot token, a WhatsApp connection identifier, or an API key for a third-party tool you connect.
- MCP access keys: if you connect an AI assistant to your account through our MCP server, we store only a hash of the key plus its first characters, so the settings page can show you which key is in use. The key itself is displayed once, at creation, and we cannot recover it afterwards.
- Usage records: message counts per billing period, training activity, and technical logs (timestamps, request paths, error traces) that we keep to operate and debug the service.
- Support correspondence: anything you send us by email or through support channels.
Cookies and similar technologies
- We use a small number of first-party cookies. We do not run advertising cookies, and we do not embed third-party ad or social tracking pixels on our website.
- “_chatbotgen_key” is our session cookie. It is signed, HttpOnly, and required to keep you signed in. Without it the application cannot work.
- “_cbg_v” identifies your browser for our own website analytics. It contains a random identifier — no name, no email — is HttpOnly, and lasts two years.
- “_cbg_s” identifies a single browsing session for the same purpose. It contains a random identifier, is HttpOnly, and expires after 30 minutes of inactivity.
- Both analytics cookies are set by our server rather than by JavaScript. This is deliberate: browser privacy protections cap the lifetime of cookies written by JavaScript, which would break the returning-visitor measurement they exist for. It does not change what we store.
- PostHog, our product analytics provider, sets its own first-party cookies on our website. See the product analytics section below.
- Your browser also stores a “theme” value locally so the site remembers whether you prefer light or dark mode. That value never leaves your device.
- The chat widget you embed on your own website does not set any of these cookies. It is a separate surface, described in its own section below.
Website analytics we run ourselves
- We measure traffic on our own pages with first-party software we built and host. Nothing about it leaves our infrastructure, and there is no third-party analytics network involved.
- For each page you view on our website we record: the path and query string, the page title, the HTTP status, the language, the referring URL, any campaign parameters in the link (utm_source, utm_medium, utm_campaign, utm_term, utm_content, ref), your IP address, your user-agent string, the derived device type, operating system and browser, the network operator associated with your IP, and an approximate location.
- Approximate location means country, region, city, and the coordinates of that city — it is derived from your IP address, either from the location headers Cloudflare adds in front of our servers or from a local MaxMind GeoLite2 database. It is not GPS and it does not identify your street address.
- A small script on our pages adds what the server cannot see: how long a page was actually visible, how far you scrolled, and whether the interaction looked human. If that script is blocked or fails, we lose that detail and nothing else.
- That script does not run when your browser sends a Do Not Track signal. To be accurate about what this means: the server-side record of the page view is still written. Do Not Track suppresses the engagement measurement, not the page view itself.
- We use this to understand which pages, campaigns, and channels bring people to ChatbotGen, and to see the path from a first visit to a signup. Once you create an account, we link your account to the visitor record for your browser so that path can be measured end to end.
- We do not track your visitors on your website with any of this. It runs only on pages we own.
Product analytics (PostHog)
- We use PostHog Cloud (United States) to understand how the product itself is used. Its script runs on our own pages only.
- PostHog records page views, page leaves, and interactions such as clicks and form submissions on our site, together with standard technical properties (browser, device, referrer, approximate location derived from IP).
- Our servers also send PostHog a small set of product milestones: account created, chatbot created, training content added, email confirmed, WhatsApp connected, plan limit reached, trial started, subscription paid, trial expired, and chatbot embedded.
- Once you sign in, we identify you to PostHog by your email address, so those events are associated with your account rather than with an anonymous browser.
- We do not send the content of chatbot conversations or the content of your training material to PostHog.
- The embedded chat widget does not load PostHog. It reports four events back to us — widget loaded, widget opened, message sent, and a click on our “powered by” link — with the chatbot identifier and the website hostname it is running on. Those events are attributed to the chatbot owner's account, never to the person chatting.
Chatbot conversations and training content
- We store every conversation your chatbots have — the visitor's messages and the chatbot's replies — together with the channel it came from, a session identifier, timestamps, and any sources the answer was drawn from. The account that owns the chatbot can read all of it in the dashboard.
- On WhatsApp we also store the sender's phone number and WhatsApp display name; on Telegram, the Telegram sender identity. This is what makes a conversation attributable to one person across messages, and it is visible to the chatbot owner.
- Leads and forms are yours. If a chatbot collects a name, email address, or phone number — through a lead-capture form, the lead-capture tool, or an appointment booking — that data is stored against the conversation, shown to the chatbot owner in the dashboard, and exportable by them as a CSV file. Custom forms store whatever fields the chatbot owner chose to ask for. We do not use any of it for our own purposes.
- Training material you add — uploaded files, crawled pages, questions and answers, free text — is stored, split into chunks, and converted into numerical vectors so the chatbot can search it. Files are stored in object storage; the extracted text (and, for crawled pages, the page's HTML), the chunks, and the vectors are stored in our database.
- If a conversation is handed off to a human, we generate a short summary of it with an AI model and email that summary to the chatbot owner so they can pick up the thread.
- If you are a ChatbotGen customer, you are the controller of your visitors' conversation data and we act as your processor. You are responsible for telling your visitors that a chatbot is in use and for having a lawful basis to process what they send it.
- We do not sell conversation data, and we do not use your conversations or your training material to train our own models.
How AI processing works, and who sees your text
- Chatbot replies are generated by large language models operated by third parties. We reach them through OpenRouter (openrouter.ai), which routes each request to the model provider you have selected for that chatbot.
- This means the text involved in generating a reply — the chatbot's instructions, the relevant excerpts retrieved from your training material, recent conversation history, and the visitor's message — is transmitted to OpenRouter and to the model provider behind it.
- By default, chatbots use Google Gemini 2.5 Flash. A chatbot can be configured to use other models available through OpenRouter, including models from OpenAI and Anthropic. The provider that receives your text is the provider behind the model that chatbot is set to.
- Search vectors (embeddings) for your training material are generated through the same route, using an OpenAI embedding model. The text of the chunk is sent; the vector comes back and is stored in our database.
- When you add a website URL as training material, we fetch and extract that page's content through our content-extraction service (Agenteclaudio). The URL and the extracted content pass through it.
- If you enable an AI tool that calls an external API — for example a property-search tool — the parameters the model generates for that call are sent to that external service using the credentials you supplied. Enabling a tool is your decision and your disclosure to make.
- We do not control the retention practices of the model providers. If a specific model provider's policy matters to you, choose the model accordingly, or contact us before you deploy.
Messaging channels
- WhatsApp: connecting a chatbot links your WhatsApp number to our WhatsApp service infrastructure as a linked device. Incoming and outgoing messages pass through that infrastructure, which we operate for this purpose, before reaching our application. WhatsApp itself is operated by Meta Platforms, Inc. and is governed by its own terms and privacy policy.
- Telegram: messages are delivered to us by the Telegram Bot API using the bot token you provide, and our replies are sent back the same way. Telegram is operated by Telegram FZ-LLC and is governed by its own terms and privacy policy.
- We store the tokens and connection identifiers required to keep those channels working, along with the connection status of each channel.
- Disconnecting a channel stops new messages from flowing. It does not delete conversations already stored in your dashboard — you can delete those yourself, or ask us to.
Payments
- Payments are processed by Stripe. Checkout and the billing portal are hosted by Stripe, on Stripe's own pages.
- We never receive, see, or store your full card number, expiry date, or security code.
- What we store is what Stripe reports back to us: your Stripe customer identifier, subscription identifier, the price and plan you are on, trial and renewal dates, and payment status.
Emails we send
- Transactional email — account confirmation, password reset, invitations, billing notices, plan-limit warnings, and alerts such as a WhatsApp connection dropping — is sent from notification@chatbotgen.com through Postmark.
- We also send a small number of lifecycle emails: at most one nudge per account per topic, based on where an account has stopped in the setup flow (for example, a chatbot that was trained but never put live). Each of these is sent once and recorded so it is never repeated.
- You can opt out of lifecycle email by asking support. We cannot stop transactional email while your account is active — it is how we tell you about your own account.
- We do not sell or rent your email address, and we do not share it with advertisers.
Service providers we share data with
- DigitalOcean — application hosting, managed PostgreSQL database, and Spaces object storage for uploaded files and images. United States.
- Cloudflare — DNS, TLS termination, and CDN in front of our servers. Cloudflare sees request metadata, including your IP address, and supplies the approximate-location headers described above.
- OpenRouter — routing layer for large language model and embedding requests, and through it the model providers behind the models your chatbots use (including Google, OpenAI, and Anthropic).
- Agenteclaudio — the WhatsApp connection service and the web content-extraction service used when you train a chatbot on a URL.
- Telegram — the Bot API, when you connect a Telegram channel.
- Stripe — payment processing and subscription billing.
- Postmark — delivery of transactional and lifecycle email.
- PostHog — product analytics, as described above.
- Google — sign-in with Google, when you choose it.
- We share the minimum each of these needs to do its job. We do not sell personal data to anyone, and we do not share it for cross-context behavioural advertising.
Security
- Traffic between your browser and our servers is encrypted in transit. Traffic between our servers and the services listed above is encrypted in transit.
- Passwords are stored only as a salted hash. Access tokens for our MCP server are stored only as a hash — the plaintext key is shown to you once, at creation, and we cannot recover it afterwards.
- The credentials for channels and tools you connect — a Telegram bot token, for example — have to be stored in a usable form, because the integration cannot work without replaying them. Treat them as shared credentials: if you disconnect a channel, revoke the token on the platform that issued it.
- Access to production systems is limited to the small number of people who operate the service. Our staff can view account and usage information through internal administration pages when that is needed to run or support the service; those pages are excluded from our own analytics.
- No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected account holders without undue delay and describe what happened and what we are doing about it.
How long we keep things
- Account data, chatbots, training material, and conversations are kept for as long as your account is active.
- Raw page-view records from our own website analytics are deleted automatically after 365 days. The aggregate daily counts derived from them are kept.
- The visitor and session records behind those page views — including the IP address and approximate location — are currently kept indefinitely, because long-range attribution depends on them. If you want yours deleted, ask us and we will delete it.
- Demo chatbots created without an account are deleted automatically, along with everything crawled and stored for them: within 24 hours for demos created on our website, and within 8 days for demos created through our MCP server (so that the link to claim one stays valid while it lasts). A cleanup job runs every 15 minutes.
- Backups are retained on a rolling basis and may hold deleted data for a short period after deletion from our live systems.
Deleting your account and your data
- You can cancel your account from inside the application or through the billing portal.
- On cancellation, your content becomes inaccessible in the Services immediately, and within 30 days it is permanently deleted from our active systems and logs. Once it is permanently deleted we cannot recover it.
- If you want a specific chatbot, conversation, or training source deleted before then, you can delete it yourself from the dashboard.
- If you want us to delete something we hold outside your account — for example the visitor record for your browser — email support and tell us what to delete.
Your rights
- Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to object to or restrict how we use it, and to receive a copy in a portable format.
- You can exercise most of these yourself: your profile settings let you view and correct your details, and the dashboard lets you export and delete your content.
- For anything the application does not cover, email support@chatbotgen.com. We will respond within 30 days. We may need to verify that the request comes from you before we act on it.
- If you are an end user who chatted with a chatbot built on ChatbotGen, the business that operates that chatbot decides what happens to your conversation. Contact that business first. If you cannot reach them, contact us and we will help you find the right route.
- If you believe we have handled your data wrongly, you may also complain to your local data protection authority.
International transfers and children
- We are a United States company and our servers are in the United States. If you use ChatbotGen from outside the United States, your data is transferred to and processed there, and by the service providers listed above in the locations where they operate.
- ChatbotGen is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
If you are talking to a chatbot
You may have reached this page from a chat widget, a WhatsApp number, or a Telegram bot. If so, you are talking to a chatbot that a business built with ChatbotGen — not to ChatbotGen. What you type is stored and is visible to that business in its dashboard, exactly as an email to that business would be. Your message is also sent to a third-party AI model, through the providers listed above, so that a reply can be generated. On WhatsApp and Telegram, your phone number or account name is stored with the conversation so the business can reply to you.
Please do not send passwords, payment card details, government identifiers, or health information to a chatbot. If you want your conversation deleted, ask the business that operates the chatbot. We provide them with the tools to do it, and we will help if they cannot be reached.
Contact us
For any question about this policy, or to make a request about your data, email support@chatbotgen.com.
Toptive LLC
5005 Van Buren St, Hollywood, FL 33021
United States