Privacy & security

Account

Privacy & security

What data the Chatisto widget collects, how credentials are protected, the Data Processing Agreement and how to delete visitor data.

What the widget collects

DataWhen
Messages the visitor sendsAlways.
A random visitor ID (in a cookie)Always. Used to continue the conversation on the next page.
Country, browser and deviceAlways. Detected from the request.
IP addressAlways.
Pages visitedOnly if Track Page Visits is on (Settings → Client Settings).
Email, name and other propertiesOnly if the visitor provides them, or your website sends them via the JavaScript API.

Mention Chatisto in your website's privacy policy, and add the widget to your cookie banner if you use one.

Data Processing Agreement

Download our DPA in Settings → General → Privacy → Download DPA.

AI and your data

Visitor messages and your knowledge base content are sent to the AI provider of the model you choose (Anthropic or OpenAI) to generate answers, and to an evaluation model for answer quality scoring.

Security

  • Passwords and tokens for connected services (email accounts, HubSpot, Slack) are stored encrypted.
  • Sign in with email and password or Google.
  • The MCP server uses OAuth, so AI assistants never see your password.
  • Data is backed up daily.

Deleting data

  • One contact: open it in Contacts and delete it.
  • A whole workspace: on your workspace list, click delete on the workspace card and type its name to confirm. This can't be undone.
  • Account deletion or a data request: email support@chatisto.com.

Read the full Privacy Policy.

Stuck or missing something in the docs? support@chatisto.com