Log in

Security and data handling

This page answers the questions security reviewers and customers ask most often about Chat Thing. The legal detail is in our Privacy Policy, Data Processing Agreement, GDPR page and sub-processor list. If this page and those documents ever differ, the legal documents apply.

Summary

QuestionAnswer
Who runs Chat Thing?Chat Thing Ltd, a company registered in England and Wales and registered with the UK Information Commissioner's Office (ICO)
Where is data stored?In the United States: database, file storage and sign-in on Supabase, application servers on Railway
Which AI providers process chat data?OpenRouter, which routes each request to the provider of the model your bot uses (for example OpenAI, Anthropic or Google). Speech features use OpenAI directly
Is my data used to train AI models?Chat Thing never uses your data to train AI models
Is there a DPA?Yes. See the Data Processing Agreement
Is Chat Thing SOC 2 certified?No
Can I delete my data?Yes, from the dashboard. Deleting bots, data sources, conversations or your account removes the data

Where your data is stored

Chat Thing stores your account, bots, knowledge and conversations in the United States:

  • Supabase hosts the database, file storage and sign-in. The searchable index of your knowledge (the embeddings created when you sync) is stored in the same database. Files you upload to data sources are kept in private storage.
  • Railway runs the application servers and background jobs.
  • Cloudflare provides content delivery, DNS, DDoS protection and SSL certificates.

The full list of sub-processors, what each does and where it processes data, is on the sub-processor list.

Which AI providers process your data

When someone chats with your bot, the message, your bot's instructions, relevant content from your knowledge and the conversation so far are sent to an AI model to write the reply.

  • Chat replies go through OpenRouter, which sends each request to a provider serving the model you choose for that bot, such as OpenAI, Anthropic or Google.
  • Knowledge indexing and search use an OpenAI embedding model, also through OpenRouter.
  • Speech features (speech-to-text and text-to-speech in the web chat) send audio and reply text to OpenAI directly, and only when a bot has them turned on.
  • Your own OpenAI key (Enterprise): if you add one, requests made with it go directly to OpenAI under your own OpenAI account.

Each provider handles data under its own terms, linked from the sub-processor list.

Training on your data

Chat Thing never uses your data to train AI models. This is stated in our Privacy Policy.

Encryption

All traffic to Chat Thing's app and website is served over HTTPS, and browsers are told to use HTTPS only. Communication with Chat Thing is encrypted in transit.

Access control

  • Team roles. Each team member has a role (Owner, Admin, Responder or Viewer) that limits what they can see and change. Only the owner can manage billing. See Teams and roles.
  • Separate teams. Bots, conversations and usage belong to one team. Members of one team can't see another team's data.
  • Widget access. You can password-protect a bot. See Website access and security.
  • API. The Chat API uses a secret key for each bot's API channel. See API overview.
  • AI assistants (MCP). Connections use OAuth sign-in or a personal key that you can revoke, and are limited by your team role. See MCP authentication.

Data retention and deletion

Chat Thing keeps your data for as long as your account exists. There's no automatic time limit on conversations; you decide what to delete.

What you deleteWhat's removed
A conversationThe conversation, its messages and any files uploaded in it
A data sourceIts content, its searchable index and any uploaded files
A botThe bot and everything in it: conversations, data sources and their index, channels, power-ups, webhooks and tests
A teamIts bots and all their data. Its subscription is cancelled
Your accountYour personal team and any team where you're the only member, with all their data, then your login. See Delete your account

Deletion is permanent. Our Privacy Policy explains how we handle your personal information after account deletion, and the legal and financial records we're required to keep.

You can export conversations as CSV from the Conversations page.

GDPR and data processing

  • For the conversations your bots have, you're the data controller and Chat Thing is the data processor. You're responsible for the data your bots collect from your customers.
  • Chat Thing's Data Processing Agreement covers our processing on your behalf. For a signed copy, email support@chatthing.ai.
  • Data is stored in the US. Our GDPR page and Privacy Policy explain how transfers outside the UK and EU are protected.
  • To exercise data protection rights or ask a privacy question, see the contact details in the Privacy Policy.

Frequently asked questions

Is Chat Thing SOC 2 certified?

No. Chat Thing is not SOC 2 certified. For how we handle your data, see this page and our Data Processing Agreement.

Can I choose which country my data is stored in?

No. Your bots, knowledge and conversations are stored in the United States.

Can I control which AI provider my bot uses?

Each bot uses one model, and that model's provider handles its replies. On plans with model choice (Standard and above), pick a model from a provider you're comfortable with in your bot's model settings.

Can I use my own AI provider account?

On the Enterprise plan, you can add your own OpenAI API key. It's used once your plan's included message tokens run out. See Message tokens.

Who in my team can see conversations?

Every member of your team can read your bots' customer conversations in Conversations. What else they can see and change depends on their role.

  • Manage your team and roles

    Create a team, invite members, choose the right role (Owner, Admin, Responder or Viewer), remove people, and move bots between teams.

  • Sign in and manage your account

    Sign up, confirm your email, reset a forgotten password, change your email address, manage email preferences and delete your Chat Thing account.

  • Control who can use your web chat

    Password-protect your bot, turn on spam protection, understand where the widget can be embedded and when to allow advanced SDK features.

Last updated