1. Two different relationships
This page covers two things that are easy to confuse, so we will separate them at the start.
- You, our customer. We decide what to do with your account data — your name, your email, what you do in the dashboard, what you pay. For that data we are the controller, and this page is our policy.
- Your website’s visitors. When somebody chats on your site, you decide what the agent reads and what happens to the result. For their data you are the controller and we are your processor: we act on your instructions, and your privacy policy is the one that governs that relationship. You need to tell them a chat on your site is answered by an AI agent.
2. What we hold about you
- Your account. Name, email address, password (stored only as a hash we cannot reverse), and the one-time codes that prove the address is yours.
- Your configuration. The websites you add, the domains the widget may run on, your knowledge sources and their connection settings, your widget’s appearance, and your ticket endpoint.
- Your usage. Which model calls ran, their tokens and cost, and when. This is what lets you read your own spend.
- Your messages to us. What you send through the contact form or by email, with your network address, so we can answer you and see abuse of the form.
- Technical records. Server logs, including network addresses, kept for security and for working out what went wrong.
We ask for no more than that. There is no advertising on the service, no tracking for advertising, and we do not sell anything to anybody.
3. Why we hold it
- To run the service you asked for — the contract between us. Without your account and configuration there is nothing to run.
- To keep it secure and working — our legitimate interest, and yours: rate limits, abuse detection, logs.
- To bill you and keep the records tax law requires us to keep — a legal obligation.
- To answer you when you write to us.
We do not send marketing email you did not ask for, and we do not need your consent for anything above because none of it is advertising.
4. What the product does with data, precisely
These are statements about the code, not intentions. Each names the part of the system that implements it, so you or an auditor can ask us to show you.
- What a visitor types
- A visitor’s messages are stored against their conversation so they and your team can read the thread, and are sent to the model to be answered.
apps/chat - Masking in imported content
- For a database or JSON API source, and for crawled and pasted text, emails, phone numbers, card-shaped numbers and GSTINs are replaced with markers before the text is stored or sent to the model. It is a per-source setting, on by default, which you can turn off for a source where the detail is the point.
apps/knowledge/connectors/records.py - Reading your database
- A database source is read over a connection that only reads. The platform issues no writes of any kind against your data.
apps/knowledge/connectors - Identifying a visitor
- A visitor is recognised by their network address, so the same person keeps their history without signing in. Where you switch verification on, they prove an email with a one-time code and the ticket then carries the address they proved rather than whatever was typed.
apps/chat/services.py, apps/clients/verification.py - Files a visitor sends
- Kept in a private bucket. Nothing anyone uploads is executed or rendered by the platform, and a file is handed out only through a link that expires.
apps/common/storage.py - Tickets
- Posted to the endpoint in your own project that you configure. From that moment the ticket lives in your system, under your own privacy policy.
apps/clients - What each reply cost
- The tokens and cost of every model call are recorded against the conversation they ran for, so you can read your own usage.
apps/common/ai_usage.py
Two points worth drawing out, because they are easy to over-read. The masking in the second item applies to content the agent imports — from a database, a JSON API, a crawl, or text you paste — and it is a per-source setting you can switch off. It does not mask what a visitor types into the chat: to answer somebody about their order, the agent has to be told about their order.
6. Who else touches it
Only these, and only for what is listed. We add none without updating this page.
| Who | What they do | Where |
|---|---|---|
| OpenAI | Writes the agent’s replies. It is sent the visitor’s question and the passages of your own content that matched it. Used with the API key set on your own Settings page, so the account the calls are billed to is yours. |
United States |
| DigitalOcean Spaces | Stores files a visitor sends in the chat. They are private, and opened only through short-lived links. Where no bucket is configured the chat has no file upload at all. |
The region of the bucket configured for the platform |
| The Micronstars mail service | Sends the email the platform itself sends you: your sign-in codes and your welcome mail. The codes your own visitors receive are sent by your API, not by us. |
India |
Your own systems are not on this list because they are not ours: the endpoint your tickets are posted to, and the API that sends your visitors their verification codes, are yours. Once a ticket reaches your endpoint it is in your hands.
We may also have to disclose data where the law requires it. Where we are allowed to tell you that it happened, we will.
7. Data leaving the country
The model provider in the table above is in the United States, so a question asked of the agent, and the passages of your content that matched it, are processed there. Everything else stays with the services listed. If that is a problem for your own compliance, write to us before you build on it rather than after.
8. How long we keep it
- Your account and configuration: while your account is open. After it closes, 30 days, so a closure in error can be undone, then deleted.
- Conversations, tickets and knowledge content: until you delete them, or until the grace period above runs out. If you need a shorter retention period for your own policy, we will agree one with you.
- Files a visitor sent: with the conversation they belong to, in the private bucket.
- Billing records: as long as tax law requires, even after an account closes.
- Messages to our contact form: until the enquiry is finished with and no longer useful to keep.
9. Keeping it safe
Passwords are stored only as hashes. Traffic is served over HTTPS. A database source is read over a connection that only reads, so the platform cannot alter your data even in error. Files a visitor sends are private and handed out only through links that expire; nothing anybody uploads is executed or rendered by the platform. The widget runs only on the domains you list, and requests from anywhere else are refused.
No system is perfect. If personal data is exposed in a way that affects you, we will tell you within 72 hours of knowing, with what happened, what was affected, and what we are doing about it.
10. Your rights
You may ask us for a copy of what we hold about you, for a correction, for deletion, or for us to stop a particular use. Write to [email protected] from the address on the account and we will answer within 30 days. There is no charge.
If a visitor to your site asks you for their data or its deletion, come to us and we will help you do it — but the request is yours to answer, because for them you are the controller.
If we handle a request badly, tell us first; if that does not resolve it, you may complain to the data protection authority where you are.
11. Children
The service is for businesses, and is not meant for children. We do not knowingly hold data about a child. If you believe a visitor’s conversation on your site contains a child’s data that should not be there, tell us and we will remove it.
12. Changes to this policy
The date at the top says when this version took effect. Where a change matters to you — a new processor, a new purpose — we will email you rather than quietly change the page.
How to reach us
Write to [email protected] or call +91 63545 40630. A person reads it.
- Micronstars