Privacy Policy
Last updated: July 16, 2026
Chat Cactus ("we", "us") provides a platform for building and deploying AI agents across chat, email, messaging, and phone channels. This policy explains what data we collect, why, and the choices you have. It applies to our website, dashboard, APIs, and the chat widgets and channel integrations our customers deploy.
1. Two kinds of people we handle data for
Customers — people who create a Chat Cactus account and build agents. We are the data controller for your account data.
End users / visitors — people who talk to a customer's agent (on their website widget, phone number, WhatsApp, Slack, and so on). For this data we act as a processor on behalf of our customer, who controls what their agent collects and how it is used. If you interacted with an AI agent on someone else's website, that business is your first point of contact for privacy requests.
2. Data we collect
Account data: name, email address, password (stored as a salted hash), workspace and team membership details.
Agent content: agent configurations, system prompts, and knowledge-base documents you upload. Documents are stored so your agents can answer from them (original file, extracted text, and text fragments with numerical embeddings).
Conversations: messages exchanged with agents, across every connected channel, including transcripts of voice interactions. Voice audio itself is transcribed and then discarded — we do not store recordings.
Visitor data collected by agents: whatever the deploying customer configures — typically name, email, phone (via lead forms), plus technical context such as page URL, referrer, browser language, and a widget identifier stored in the visitor's browser to remember returning conversations.
Integration credentials: OAuth tokens, API keys, and bot tokens you connect (Gmail, Twilio, Meta, Slack, Discord, Telegram). These are encrypted at rest with AES-256-GCM.
Billing data: handled by Stripe. We never see or store full card numbers — we keep subscription status, plan, and Stripe reference ids.
Usage data: message counts, token usage, model choice, latency, and cost per interaction, used for quotas, billing, and analytics dashboards.
3. How we use data
To provide the service: generating agent replies (your prompts, relevant knowledge fragments, and conversation history are sent to AI model providers), routing channel messages, enforcing plan limits, and showing you analytics.
To operate the business: billing through Stripe, support, abuse and fraud prevention, and service improvement using aggregated, de-identified usage statistics.
We do not sell personal data, and we do not allow AI providers to train their models on your content.
4. Who we share data with (subprocessors)
Only as needed to run the service:
- AI model providers — OpenAI and Anthropic (message content, prompts, relevant knowledge excerpts; and for voice features, audio for transcription and reply text for speech synthesis).
- Stripe — payments and subscriptions.
- Channel providers you connect — Twilio, Google (Gmail), Meta (WhatsApp/Messenger), Slack, Discord, Telegram — message delivery on the channels you enable.
- Hosting and infrastructure providers — servers, storage, and databases.
Each subprocessor receives only what its function requires.
5. Cookies and local storage
We use strictly necessary cookies for signing in (session cookies) and remembering your active workspace. The embedded chat widget stores a random identifier in the visitor's browser (localStorage) so returning visitors can continue their conversations.
We also use Google Analytics on our website to understand aggregate traffic and improve the product; it sets its own cookies and processes usage data according to Google's privacy policy. We do not use advertising or cross-site tracking cookies beyond this analytics tool, and you can block it with standard browser settings or extensions without affecting the service.
6. Retention and deletion
Account data, agent content, and conversations are kept while your account is active. Deleting an agent deletes its configuration; deleting a knowledge document deletes the stored file, extracted text, and embeddings; deleting your workspace or account removes the associated data from live systems, with residual copies clearing from backups on a rolling basis. Usage and billing records may be retained longer where required for tax and accounting.
7. Security
Encryption in transit (TLS) and at rest for integration credentials (AES-256-GCM), hashed passwords, signed and verified webhooks for every channel, per-agent domain allow-lists for the widget, rate limiting, and role-based workspace access. No method of transmission or storage is 100% secure, but we treat credential and conversation data as the most sensitive things we hold.
8. Your rights
Depending on where you live (e.g. GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Email us at [email protected] and we'll respond within 30 days. If you are an end user of a customer's agent, we'll route your request to that customer where appropriate.
9. Children
Chat Cactus is not directed at children under 16, and we do not knowingly collect their data.
10. Changes
We'll post any changes to this policy here and update the date above. For material changes we'll notify account owners by email.
Contact
Privacy questions: [email protected]