Privacy Policy
This policy describes what ChatAI CRM stores, who else it is sent to, and how long it is kept. Where a section names a retention period, a field or a provider, that is what the service does today, and we update this page when it changes.
Last updated:
1. Who is responsible for what
ChatAI CRM is operated by Victory TechNxt Private Limited, a private limited company
incorporated in India on 5 February 2026, CIN U62090MH2026PTC467479, with its registered office at
Office No 906, Plot No 47, Sector 15, Navi Mumbai, Kharghar, Raigarh (MH), Panvel, Maharashtra, India, 410210 ("we", "us"). In this policy, customer means the business or
agency that holds an account, and visitor means someone who chats with a customer's
assistant on the customer's website.
The split matters, because it decides who you should write to:
- Account data — the names, emails and billing details of the people who hold ChatAI CRM accounts. We decide how this is handled, so we are the controller.
- Conversations, and the contact details a visitor leaves — this belongs to the customer whose website the assistant is embedded on. They choose what their assistant knows, what it asks for, and how long to keep it. We process it on their instructions. If you are a visitor asking for a transcript to be corrected or erased, ask that business first: they decide what happens to it. If you write to us instead we will pass the request on and support them in carrying it out, and we will act on it ourselves where the law requires us to.
2. What we store
Account and workspace
- Name, work email, company, and role. Accounts require a verified business email.
- Passwords are stored only as an argon2id hash. We never hold the plaintext and cannot recover it for you.
- The country your workspace was created from, and the currency pinned from it. This is worked out once, at signup, from the network-level country your request arrived with — we do not re-check it later, so a customer who travels does not see a different price list.
- Billing records: plan, invoices, invoice line items, payments, and usage counts. Card numbers are handled by the payment gateway and never reach our servers.
Content you add
The website URLs we crawl for you, the documents and text you upload, and the extracted passages ("chunks") those are split into so the assistant can retrieve them. Whatever you put in there is what the assistant can quote to a visitor, so treat the knowledge base as public-facing.
Conversations and messages
Each conversation stores the assistant it belongs to, an opaque session token for the browser, the channel, a message count, status, the detected language, and any name, email or phone the visitor supplied. Each message stores the role, which is the visitor, the assistant, or a member of your team who has taken the conversation over, the full text, the citations shown beneath an answer, the AI disclosure wording the visitor was shown, any thumbs up or down, and — for assistant messages — the model that produced it and its token and cost figures.
Transcripts are kept because the customer needs them: to check what their assistant told a visitor, to investigate a disputed answer, and to see which questions it could not answer. None of that is possible from a deleted record.
Leads
When a visitor leaves their details, a lead record stores the name, email, phone and language, a status, and — importantly — the exact consent wording shown and the time consent was given. We store the wording rather than a tick, so that "what was this person actually agreeing to" is answerable later.
Technical and audit
- IP address and request metadata, used for rate limiting and abuse prevention.
- An audit log of significant actions in the dashboard: who did it, what they did, the target, their IP, and whether they were acting through support impersonation.
3. AI providers
Answers are generated by third-party AI providers. This section names them and sets out what each one receives.
To answer a question, we send the visitor's message, the recent turns of that conversation, and the passages retrieved from your own knowledge base to one of a small set of providers: OpenAI, Anthropic, Google and xAI. Which one answers a given message depends on which providers are configured and available at that moment; the provider and model that produced each answer are recorded against the message. We hold the provider accounts under their business terms — you do not supply a key, and your content is sent under our contract with them, not yours.
Two things follow from how the product is built. Answers are composed only from the material you added: where nothing in your knowledge base clears the similarity floor, the model is called with no excerpts at all and told so, and the prompt forbids it inventing one, so it declines and offers to take the visitor's contact details instead. And every conversation opens by telling the visitor they are talking to an AI assistant. You can reword that notice; you cannot switch it off.
4. Voice
Voice is off by default and is enabled per assistant, on plans that include it. When a visitor speaks to an assistant that has it switched on:
- The recording is sent to OpenAI for transcription. We do not store the audio. It is held in memory for the length of the request and then discarded.
- The transcript is stored as an ordinary visitor message, and is answered by the same grounded pipeline as typed questions, with the same floor and the same citations.
- The spoken reply is synthesised by OpenAI and returned to the browser to play. That audio is not stored either.
- The duration of the recording is metered in ChatAI Tokens against your plan's monthly allowance, at the rate the transcription provider charges per minute, so a long clip costs more of it than a short one.
5. Diagnostics and error reports
Answer diagnostics
For each answered message we keep a diagnostic record: the question, which passages retrieval found and what they scored, the similarity floor in force, and which models were asked. It exists so that "it gave a wrong answer last Tuesday" is an answerable question. Two limits are worth stating:
- The text of the retrieved passages is not copied into it — only enough to identify the passage and its score.
- It is purged 45 days after it is written. The purge runs in small batches during ordinary request traffic rather than as a scheduled job, so on a quiet workspace a record may outlive 45 days by a little, until the next pass reaches it.
These records are visible to platform staff only. They are not exposed to customers or agencies, because a score reveals how retrieval is tuned and a model name plus token counts reveals an agency's resale margin.
Crash reports
Error reporting is optional and off unless a report destination is configured. When it is on, every report is scrubbed before it leaves our servers:
- Request bodies, cookies, environment and query strings are dropped whole, not trimmed — that is where a visitor's message text would otherwise sit.
- Local variables are stripped from every stack frame, because that is where the visitor's question, a decrypted provider key and a lead's email all sit at the moment something fails.
- Authorization and cookie headers are replaced.
- Remaining free text is rewritten by pattern: API keys, bearer tokens, JSON web tokens, email addresses and phone numbers.
- User identity is removed from the report entirely.
The scrubbing is deliberately blunt and over-redacts. Over-redacting an innocent string costs a support engineer a question; under-redacting sends somebody's phone number to a third party.
6. Cookies, analytics and advertising
This section is about our marketing site and dashboard, not about the assistant running on a customer's website. It is separate because the data is different in kind: everything above is data you or your visitors give the product, and this is data about people browsing our own site — including people who never become customers.
We run one third-party measurement tool: the Meta Pixel, from Meta Platforms, on
chataicrm.com and on the dashboard at /app/. It loads on those hostnames and
nowhere else, so a copy of this site running on a staging domain does not load it. We do not
currently run Google Analytics, Microsoft Clarity or any other analytics product on these pages. If
that changes, this section changes with it.
What is recorded
Page views, and a small number of specific steps: submitting a website address to be previewed, being shown that preview, submitting contact details, completing a registration, and starting a subscription. Each carries the page it happened on and, where the step involves one, the website address that was submitted.
What is sent to Meta
- A random identifier we generate for your browser. It is not derived from anything about you and means nothing outside this site. It exists so that a visit and a later signup can be recognised as the same browser rather than as two strangers.
- Your email address and phone number, hashed, if you give them to us on this site. The hashing is done by Meta’s script inside your browser before anything is sent, so the plain values do not leave the page. Meta uses the result to work out whether the person who signed up is someone who was shown an advertisement. We pass only the address and the number you typed into a form on this site. Meta’s own script may additionally read fields you complete here; the forms on this site ask for nothing but an email address and a phone number. Nothing anyone types into an assistant is ever sent to Meta.
- The technical data any web request carries: IP address, browser, and the address of the page.
Cookies and local storage
We set no cookies of our own on these pages. Meta’s script sets its own — _fbp, and
_fbc if you arrived from one of our advertisements — which identify a browser to Meta.
Separately, we keep a few values in your browser’s local storage, which are never sent anywhere:
the random identifier above, and small markers recording that a form has already been sent or a
prompt already shown, so that you are not asked the same thing twice. If you submit contact details
while your connection is down, they are held in your own browser until the send succeeds, and then
cleared.
Turning it off
Blocking third-party scripts or cookies in your browser stops the pixel, and nothing on this site depends on it working. How Meta uses what it collects across sites is governed by your own Meta advertising settings rather than by us. The rights described in section 11 apply to this data as they do to the rest, and the contact address given there is the one to use.
7. Other subprocessors
We do not sell personal data. Besides the AI providers named above, data is handled by:
| Purpose | Provider | What it sees |
|---|---|---|
| Hosting and database | Cloud infrastructure provider (named on request) | All stored data |
| Transactional email | Transactional email provider (named on request) | Recipient address and message content |
| Payments (India) | Razorpay | Billing identity and payment details |
| Payments (elsewhere) | Stripe | Billing identity and payment details |
| Answer generation | OpenAI, Anthropic, Google, xAI | The question, recent turns, and retrieved passages |
| Voice transcription and speech | OpenAI | The recording, and the reply text to be spoken |
| Advertising measurement on our own site | Meta Platforms | A hashed email address and phone number where given, a random browser identifier, and page and step data |
Access inside the product is scoped by tenant: an agency reaches only its own clients' data, and a client reaches only its own. We also disclose data where the law requires it.
We will name our hosting and transactional email providers, and the region your data is stored in, to any customer or data principal who asks at [email protected].
8. Retention, export and deletion
Account data, knowledge bases and transcripts are kept for as long as the account is active, except for the diagnostic records described above, which expire after 45 days, and rate-limit counters, which hold a key derived from an IP address for the length of their window: a few minutes for chat, up to an hour for signup, password-reset and similar attempts.
Cancelling does not by itself delete anything. When a subscription ends your access stops, but the workspace, its knowledge bases and its transcripts stay as they are until the workspace is deleted: by you from the dashboard, or by us on your written request. If you want your data gone when you leave, delete the workspace or write to us.
Export
A workspace can export its own data from the dashboard, or from the API: the account record, every assistant, every conversation with its full message history, and every knowledge document with its extracted passages, as JSON. Because that export is every visitor conversation the workspace has ever had, verbatim, it requires the same records-deletion permission an erasure needs. It is not guarded by the password prompt that workspace deletion is, so treat that permission as the one that matters. Each export is written to the audit log with the IP it came from.
Deletion
A workspace can erase itself from the dashboard. It is guarded three ways: the permission to do it, the acting user's own password, and typing the word DELETE. There is no undo.
What that action destroys: every assistant in the workspace, every conversation and message in it, every knowledge document and extracted passage, the crawl jobs behind them, and any support tickets the workspace has raised with us together with the messages on them.
What it does not destroy, and you should ask us if you need it gone: lead records captured from your conversations, invoices and billing records that we are required to retain for accounting and tax, and audit log entries. Write to [email protected], with "Deletion request" in the subject line, and we will complete deletion within 7 days, except where the law requires us to keep a record.
9. Children
ChatAI CRM is a business product; account holders must be adults. But our customers include schools, whose website visitors may be children.
An assistant can be marked child-facing. In that mode it will not collect a name, email or phone number from a visitor — the request is refused by the API, not merely hidden in the widget. India's DPDP Rules require verifiable parental consent before a child's personal data is processed, and a tick-box asking someone to declare their age is not verification. So we do not try to verify: a child-facing assistant answers questions and keeps no name, email or phone number. An email address or phone number is refused outright by the API rather than merely hidden in the widget, and a name sent on its own is discarded rather than stored. It does still record the conversation itself, as described in section 2.
10. Security
- Passwords hashed with argon2id; provider credentials encrypted at rest.
- TLS in transit.
- Per-tenant scoping on every query, so one customer's data is not reachable from another's session.
- Rate limiting on public chat endpoints, an allow-list of the origins a widget may be embedded on, and an audit trail of privileged actions.
No system is perfectly secure, and we would rather say that than imply otherwise.
11. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to some processing. Use the export and delete tools in the dashboard, or write to [email protected].
Under India's Digital Personal Data Protection Act you may ask us for a summary of the personal data we process about you, ask for correction or erasure, nominate someone to exercise these rights on your behalf, and raise a grievance. Grievances go to our Grievance Officer at [email protected], with "DPDP grievance" in the subject line so it is routed as a grievance rather than as ordinary support. We will acknowledge within 7 days.
If you are a visitor to a customer's website rather than an account holder, see section 1 — that business decides what happens to your conversation, and asking them is usually faster.
12. India: GST and pricing
- Prices are charged in INR for customers in India and in USD elsewhere. The currency is decided once at signup, from the network-level country your request arrived with, and pinned to the workspace, so a customer who travels does not see a different price list. Detection is best effort: where we cannot establish a country the workspace defaults to India and INR, and you can ask us to correct it at [email protected].
- Indian invoices carry 18% GST, along with your GSTIN if you have given us one, the place of supply, and the SAC code for the service. Exports of service are zero-rated under LUT, and the invoice states that reason rather than showing an unexplained zero.
- Billing identity is frozen onto each invoice at the moment it is issued, so a later change to your registered name does not silently restate last year's invoices.
- We are registered for GST in India. Our GSTIN and our registered company number
(CIN
U62090MH2026PTC467479) appear on every invoice we issue.
13. Changes and contact
We may update this policy. Material changes will be notified by email or in the dashboard, and the date at the top of this page will change.
Questions about this policy, or a request to exercise your rights: [email protected].