Privacy Policy

Last updated: 9 July 2026

This Privacy Policy explains how AIBotLab ("AIBotLab", "we", "us"), operating aibotlab.ai, collects and processes personal data. It covers two audiences: our customers — the organizations and users who sign up for the Service — and the end visitors who chat with a customer's embedded chatbot.

1. Introduction — Our Two Roles

AIBotLab acts in two different roles depending on the data involved:

  • As a data controller for the account and organization data of our customers — we decide why and how it is processed.
  • As a data processor for the content our customers upload and for the conversations their embedded chatbots hold with end visitors — we process this data only on the customer's documented instructions, and the customer is the controller of that data.

This policy describes both roles.

2. Contacting Us About Data Protection

If you have any question about this policy or about how your data is handled, please reach us through our Contact page. We respond to privacy requests as described below.

3. Account & Organization Data We Collect

When you register and use the Service, we collect the data you provide: your name, email address, organization details and authentication data, together with the billing metadata needed to manage your subscription. Payments are handled by Paddle as our Merchant of Record, so we do not store your card details. We use this data to provide, secure, support and improve the Service and to communicate with you about your account.

4. Your OpenAI API Key

To operate your chatbots, you provide your own OpenAI API key. We store it encrypted at rest, never display it back to you or expose it to your frontend or widget, and never log it. It is used only to call OpenAI on your behalf. AIBotLab does not use your API key, uploaded content or conversation data to train AIBotLab or third-party AI models. OpenAI processes API requests according to its own terms, policies and data controls.

5. Knowledge-Base Content

The documents, FAQs and web pages you upload are stored and processed — including being split into chunks and converted into vector embeddings — solely to answer your own chatbots' questions. This content is isolated per organization and per chatbot. We act as a processor for it: it is handled on your instructions and is not used for any other purpose.

6. Widget Visitor Data

For end visitors who chat with a customer's embedded widget, we deliberately keep the data we hold to a minimum. We store an anonymous visitor identifier, basic page metadata such as the page where the chat took place, and the visitor's chat messages. We do not intentionally collect visitors' names or email addresses through the widget unless the customer configures the chatbot to ask for them. We do not use visitor IP addresses to identify individuals or track them across websites, although IP addresses may be processed temporarily in server, security or hosting logs. For this data, the customer who deployed the chatbot is the controller and AIBotLab is the processor.

7. Cookies and Similar Technologies

AIBotLab uses cookies and similar technologies to operate the Service, keep users signed in, maintain security, remember basic preferences, and keep chatbot conversations continuous.

The AIBotLab app uses cookies that are necessary for authentication, session management, security, fraud prevention and core service functionality.

The embedded chat widget uses first-party cookies or similar local storage to maintain an anonymous visitor identifier and keep a conversation continuous for a limited period. These technologies are used only to provide the chatbot experience and are not used for advertising, retargeting or cross-site tracking.

If we use analytics on our marketing site, we aim to use privacy-friendly analytics where possible. We do not use advertising or cross-site tracking cookies unless this is disclosed and, where required by law, consent is requested before those cookies are set.

8. How We Share Data: Service Providers and Payment Partners

We share personal data only with service providers that help us deliver the Service:

  • OpenAI — to generate chatbot responses, called with the customer's own API key;
  • our cloud hosting and object-storage provider, Amazon Web Services, primarily in the EU region in Frankfurt — to run the Service and store data; AWS CloudFront edge locations are used to serve public widget assets;
  • Paddle — to handle checkout, subscription billing, invoices, receipts, tax/VAT and payment-related support as our Merchant of Record. Paddle processes buyer and payment data under its own terms and privacy notice.

We do not sell personal data to anyone.

9. Data Retention

We keep account and organization data for as long as your account is active. Conversation data is automatically purged on a per-plan schedule — 30 days on Solo and 90 days on Team. When you close your account, we delete your data in line with these practices, except where we must retain limited records for legal, security, backup, tax, billing or dispute-resolution purposes.

10. Your Rights

Depending on your location, you have rights over your personal data, including the rights to access, rectify, erase, restrict or object to processing, and to data portability. Self-serve export and deletion tools are planned; until they are available, you can exercise these rights by contacting us via the Contact page. We respond within the time required by applicable law. If you are an end visitor of a customer's chatbot, we may need to refer your request to that customer, because the customer is the controller of your data and AIBotLab acts as processor.

11. International Transfers

Some of our service providers and sub-processors — notably OpenAI, Paddle and AWS CloudFront edge locations — may process data outside your country, including in the United States. Where personal data is transferred outside your country, we rely on appropriate safeguards, such as the standard contractual clauses, to protect it.

12. Contact & Complaints

To raise a privacy request or a complaint, please use our Contact page. If you are in the EEA or the UK and believe your data has been handled unlawfully, you also have the right to lodge a complaint with your local data-protection supervisory authority.