Privacy Policy
Last updated 30 September 2026
ChatCraft ("ChatCraft", "we", "us") runs chatcraft.in, a service that lets businesses build AI support chatbots trained on their own content and deploy them on their website and on messaging channels such as WhatsApp. This policy explains what personal data we collect, how we use and store it, who we share it with, and how you can ask us to delete it.
1. Who this policy covers
- Customers: people and businesses who sign up for a ChatCraft account and build chatbots. For their account data, ChatCraft decides how the data is used.
- End users: people who chat with a customer's chatbot, through the website widget, a shared chat link, or a connected messaging channel such as WhatsApp, Instagram or Threads. We process their messages on behalf of the customer who runs the chatbot. That customer is responsible for telling their own users how their data is handled.
2. Data we collect
Account data
- Name, email address and a hashed password (we never store the password itself).
- Email verification status, plan, and billing status.
- Payments are handled by our payment provider, Polar. We receive a customer and subscription reference from them. We never see or store your card details.
Content you add to a chatbot
- Files you upload, text you paste, Q&A pairs you write, and pages we crawl from URLs you give us.
- Chatbot settings such as its name, instructions, welcome message and theme.
Conversations
- The messages end users send to a chatbot and the answers it gives, with timestamps, sources cited, and technical measurements (response time, token counts).
- For the website widget and chat link: the visitor's IP address, browser user agent and the page the chat was opened from. The IP address is also used for rate limiting to stop abuse.
Data from Meta platforms (WhatsApp, Instagram, Threads)
When a customer connects a Meta product to a chatbot, we receive data from Meta through its official APIs, only for the accounts the customer connects and only for the permissions they grant:
- WhatsApp Business: the sender's WhatsApp phone number (WhatsApp ID) and profile name, the content and IDs of messages sent to the business number, and message delivery events. About the connected business account: its phone number ID, WhatsApp Business Account ID, display phone number and verified business name.
- Instagram: the connected professional account's ID, username and basic profile information; direct messages and comments sent to that account, with the sender's Instagram-scoped ID and username; and posts or media that the customer asks ChatCraft to read or publish.
- Threads: the connected profile's ID, username and basic profile information; posts and replies that the customer asks ChatCraft to read, answer or publish; and related reply and mention data.
- Access credentials: the access tokens, and where needed the app secret and webhook verify token, that let ChatCraft act for the connected account. These are encrypted before they are stored.
We do not request access to data we do not need to run the chatbot, and we do not use Meta data for any purpose other than the ones described below.
Data stored in your browser
The dashboard keeps your sign-in token and your light or dark theme choice in your browser's local storage. We do not use advertising cookies or third-party tracking or analytics scripts.
3. How we use data
- To provide the service: index your content, answer end users' questions, and send replies back on the channel the question came from.
- To show customers their conversation history and analytics for their own chatbots.
- To run accounts, billing and plan limits, and to send service emails such as verification and password resets.
- To keep the service secure, prevent abuse and fix problems.
- To meet legal obligations.
We do not sell personal data, use it for advertising, or use customers' content or conversations to train AI models.
4. AI processing
To write an answer, ChatCraft sends the end user's question, recent messages from the same conversation, and the most relevant passages from the chatbot's content to an AI model. We use OpenAI models hosted in Microsoft Azure, with Groq as a backup. These providers process the data only to return the answer and, under their API terms, do not use it to train their models. Searching and ranking your content runs on ChatCraft's own servers.
5. How Meta platform data is handled
- It is used only to provide the chatbot features the customer turned on for that account.
- It is never sold, licensed, or shared with data brokers or advertising networks.
- It is not used to build profiles of users or for any kind of surveillance.
- It is shared only with the service providers in section 6, and only as needed to answer the message.
- It is deleted when the customer disconnects the account, deletes the chatbot or their ChatCraft account, when the retention period below ends, or when a user asks us to delete it.
We follow Meta's Platform Terms and Developer Policies for all data received from Meta.
6. Who we share data with
We share data only with providers that help us run ChatCraft, and only what each one needs:
- Cloud hosting for our servers, database and backups.
- Cloudflare for network delivery and protection against attacks.
- Microsoft Azure OpenAI and Groq to generate answers.
- Meta to receive and send messages on WhatsApp, Instagram and Threads.
- Resend to deliver account emails.
- Polar to process payments.
We may also disclose data if the law requires it, to protect the rights and safety of our users or the public, or as part of a merger or sale of the business, in which case this policy continues to apply to the data.
7. How long we keep data
- Conversations are deleted automatically after the retention period of the customer's plan: 7 days on Free, 90 days on Pro and 365 days on Business. Customers can delete individual conversations sooner from the dashboard.
- Chatbot content is kept until the customer removes it or deletes the chatbot.
- Channel credentials are kept until the customer disconnects the channel or deletes the chatbot.
- Account data is kept until the account is deleted.
- Backups are kept for 14 days, so deleted data leaves our backups within 14 days.
8. Security
All traffic is encrypted with HTTPS. Passwords are hashed, and third-party access tokens and secrets are encrypted at rest. Each chatbot's content and conversations are kept separate, so one customer's data never appears in another customer's answers. Access to production systems is limited to the people who run the service.
9. Your rights and deleting your data
You can ask us to access, correct, export or delete your personal data, or object to how we use it. Customers can edit or delete chatbots, content and conversations from the dashboard at any time. For anything else, including deleting a whole account or data we received through WhatsApp, Instagram or Threads, follow the steps on our data deletion page or email [email protected]. We respond within 30 days.
If you chatted with a business's chatbot, you can also contact that business directly, since it controls the conversation data.
10. International transfers
Our service providers may process data in countries other than your own. Where they do, we rely on their contractual safeguards to protect it.
11. Children
ChatCraft is a business service and is not meant for children under 13, or the minimum age for digital consent where you live. We do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. The date at the top shows the latest version. If a change is significant, we will tell customers by email or in the dashboard before it takes effect.
13. Contact
For any privacy question or request, email [email protected].