---
title: "Security and data handling"
description: "Where Chat Thing stores your data, which AI providers process it, whether it's used for training, how access and deletion work, GDPR, DPA and SOC 2."
canonical_url: "https://chatthing.ai/docs/account/security-and-data"
last_updated: "2026-09-25"
---

# Security and data handling

This page answers the questions security reviewers and customers ask most often about Chat Thing. The legal detail is in our [Privacy Policy](https://chatthing.ai/legal/privacy), [Data Processing Agreement](https://chatthing.ai/legal/dpa), [GDPR page](https://chatthing.ai/legal/gdpr) and [sub-processor list](https://chatthing.ai/legal/sub-processors). If this page and those documents ever differ, the legal documents apply.

## Summary

| Question | Answer |
| --- | --- |
| Who runs Chat Thing? | Chat Thing Ltd, a company registered in England and Wales and registered with the UK Information Commissioner's Office (ICO) |
| Where is data stored? | In the United States: database, file storage and sign-in on Supabase, application servers on Railway |
| Which AI providers process chat data? | OpenRouter, which routes each request to the provider of the model your bot uses (for example OpenAI, Anthropic or Google). Speech features use OpenAI directly |
| Is my data used to train AI models? | Chat Thing never uses your data to train AI models |
| Is there a DPA? | Yes. See the [Data Processing Agreement](https://chatthing.ai/legal/dpa) |
| Is Chat Thing SOC 2 certified? | No |
| Can I delete my data? | Yes, from the dashboard. Deleting bots, data sources, conversations or your account removes the data |

## Where your data is stored

Chat Thing stores your account, bots, knowledge and conversations in the United States:

- **Supabase** hosts the database, file storage and sign-in. The searchable index of your knowledge (the embeddings created when you sync) is stored in the same database. Files you upload to data sources are kept in private storage.
- **Railway** runs the application servers and background jobs.
- **Cloudflare** provides content delivery, DNS, DDoS protection and SSL certificates.

The full list of sub-processors, what each does and where it processes data, is on the [sub-processor list](https://chatthing.ai/legal/sub-processors).

## Which AI providers process your data

When someone chats with your bot, the message, your bot's instructions, relevant content from your knowledge and the conversation so far are sent to an AI model to write the reply.

- **Chat replies** go through **OpenRouter**, which sends each request to a provider serving the [model you choose](https://chatthing.ai/docs/bot-settings/models) for that bot, such as OpenAI, Anthropic or Google.
- **Knowledge indexing and search** use an OpenAI embedding model, also through OpenRouter.
- **Speech features** (speech-to-text and text-to-speech in the web chat) send audio and reply text to **OpenAI** directly, and only when a bot has them turned on.
- **Your own OpenAI key (Enterprise):** if you add one, requests made with it go directly to OpenAI under your own OpenAI account.

Each provider handles data under its own terms, linked from the [sub-processor list](https://chatthing.ai/legal/sub-processors).

## Training on your data

Chat Thing never uses your data to train AI models. This is stated in our [Privacy Policy](https://chatthing.ai/legal/privacy).

## Encryption

All traffic to Chat Thing's app and website is served over HTTPS, and browsers are told to use HTTPS only. Communication with Chat Thing is encrypted in transit.

## Access control

- **Team roles.** Each team member has a role (Owner, Admin, Responder or Viewer) that limits what they can see and change. Only the owner can manage billing. See [Teams and roles](https://chatthing.ai/docs/account/teams#roles).
- **Separate teams.** Bots, conversations and usage belong to one team. Members of one team can't see another team's data.
- **Widget access.** You can password-protect a bot. See [Website access and security](https://chatthing.ai/docs/channels/website/access-and-security).
- **API.** The Chat API uses a secret key for each bot's API channel. See [API overview](https://chatthing.ai/docs/developers/api-overview).
- **AI assistants (MCP).** Connections use OAuth sign-in or a personal key that you can revoke, and are limited by your team role. See [MCP authentication](https://chatthing.ai/docs/mcp/authentication).

## Data retention and deletion

Chat Thing keeps your data for as long as your account exists. There's no automatic time limit on conversations; you decide what to delete.

| What you delete | What's removed |
| --- | --- |
| A conversation | The conversation, its messages and any files uploaded in it |
| A data source | Its content, its searchable index and any uploaded files |
| A bot | The bot and everything in it: conversations, data sources and their index, channels, power-ups, webhooks and tests |
| A team | Its bots and all their data. Its subscription is cancelled |
| Your account | Your personal team and any team where you're the only member, with all their data, then your login. See [Delete your account](https://chatthing.ai/docs/account/sign-in-and-account#delete-your-account) |

Deletion is permanent. Our [Privacy Policy](https://chatthing.ai/legal/privacy) explains how we handle your personal information after account deletion, and the legal and financial records we're required to keep.

You can export conversations as CSV from the [Conversations](https://chatthing.ai/docs/manage/conversations#download-conversations) page.

## GDPR and data processing

- For the conversations your bots have, you're the **data controller** and Chat Thing is the **data processor**. You're responsible for the data your bots collect from your customers.
- Chat Thing's [Data Processing Agreement](https://chatthing.ai/legal/dpa) covers our processing on your behalf. For a signed copy, email [support@chatthing.ai](mailto:support@chatthing.ai).
- Data is stored in the US. Our [GDPR page](https://chatthing.ai/legal/gdpr) and [Privacy Policy](https://chatthing.ai/legal/privacy) explain how transfers outside the UK and EU are protected.
- To exercise data protection rights or ask a privacy question, see the contact details in the [Privacy Policy](https://chatthing.ai/legal/privacy).

## Frequently asked questions

### Is Chat Thing SOC 2 certified?

No. Chat Thing is not SOC 2 certified. For how we handle your data, see this page and our [Data Processing Agreement](https://chatthing.ai/legal/dpa).

### Can I choose which country my data is stored in?

No. Your bots, knowledge and conversations are stored in the United States.

### Can I control which AI provider my bot uses?

Each bot uses one model, and that model's provider handles its replies. On plans with model choice (Standard and above), pick a model from a provider you're comfortable with in your bot's [model settings](https://chatthing.ai/docs/bot-settings/models).

### Can I use my own AI provider account?

On the Enterprise plan, you can add your own OpenAI API key. It's used once your plan's included message tokens run out. See [Message tokens](https://chatthing.ai/docs/account/message-tokens#what-happens-when-you-run-out).

### Who in my team can see conversations?

Every member of your team can read your bots' customer conversations in [Conversations](https://chatthing.ai/docs/manage/conversations). What else they can see and change depends on their [role](https://chatthing.ai/docs/account/teams#roles).

## Related

- [Manage your team and roles](https://chatthing.ai/docs/account/teams): Create a team, invite members, choose the right role (Owner, Admin, Responder or Viewer), remove people, and move bots between teams.
- [Sign in and manage your account](https://chatthing.ai/docs/account/sign-in-and-account): Sign up, confirm your email, reset a forgotten password, change your email address, manage email preferences and delete your Chat Thing account.
- [Control who can use your web chat](https://chatthing.ai/docs/channels/website/access-and-security): Password-protect your bot, turn on spam protection, understand where the widget can be embedded and when to allow advanced SDK features.
