BotChata

LEGAL

Privacy Policy

Last updated: August 2026

Who we are

BotChata ("we", "us", "our") provides an AI chatbot platform that allows website owners to create chatbots trained on their own content. Our service is available at botchata.net. Contact for inquiries: support@botchata.net.

Pricing

The current pricing for the BotChata platform is published on our website in the Pricing section. For users located in Ukraine, prices are shown and charged in Ukrainian hryvnia (UAH) via the WayForPay payment gateway. For international users, prices are shown and charged in US dollars (USD) or euro (EUR) depending on the payer's country, via Paddle.

Intellectual property

BotChata is the exclusive owner of the BotChata software and holds all lawful rights to use, distribute, and grant access to this intellectual property. Content that users provide to train their chatbots remains the intellectual property of the respective users/website owners.

What data we collect

We collect: (1) Account data — your email address and encrypted password when you register. (2) Website content — pages crawled from URLs you provide, stored as vector embeddings to power your chatbot. (3) Chat logs — messages exchanged between your website visitors and your chatbot, associated with your account. (4) Usage data — basic analytics such as message count, error logs, and feature usage to improve the service. (5) Billing data — your payment details are processed and stored by our payment providers Paddle (international payments) or WayForPay (payments within Ukraine). We do not store full card numbers. (6) Google account data — if you sign in with Google, we receive your email address and the fact that it is verified. If you connect Google Calendar or Google Sheets to a chatbot, we store an encrypted OAuth refresh token and the identifier of the calendar or spreadsheet you connected. See "Google user data" below.

How we use your data

Your data is used to: deliver and operate the chatbot service; process payments; send transactional emails (account creation, weekly digest) via Resend; improve the platform based on aggregate usage patterns. We do not sell, rent, or share your personal data with third parties except as described below.

Data sharing

We share data only with: (1) Paddle / WayForPay — payment processing. (2) OpenAI — chat messages are sent to OpenAI's API to generate responses. OpenAI processes data in accordance with their Data Processing Addendum, available at openai.com/policies/data-processing-addendum. (3) Resend — email delivery. (4) Hetzner — infrastructure hosting (servers located in Germany, EU). (5) Google — only if you choose to sign in with Google or to connect Google Calendar / Google Sheets to a chatbot, and only for the purposes described in "Google user data" below. We require all sub-processors to implement appropriate data security measures.

Google user data

Google Calendar and Google Sheets are optional integrations. Nothing is accessed unless you explicitly connect them from your dashboard, and each connection applies to a single chatbot. What we access and why: (1) Google Calendar (scope auth/calendar.events) — we create an event on the calendar you selected for every booking your visitors make, and we read events in the requested day window so the chatbot does not offer a slot already taken by a booking BotChata itself created. Events you created yourself are ignored and never block a slot. We do not read event contents for any other purpose and we do not copy your calendar into our database. (2) Google Sheets (scope auth/drive.file) — when you connect Sheets, BotChata creates one new spreadsheet in your Google Drive and appends one row per booking to it. This scope gives us access only to files our app itself created; we cannot see any other file in your Drive. What we store: an OAuth refresh token, encrypted at rest with Fernet, plus the identifier of the connected calendar or spreadsheet. What we do not do: we never sell Google user data, never use it for advertising or profiling, never use it to train AI models, and no human reads it except where required to resolve a support request you raised or where required by law. BotChata's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time by clicking Disconnect in your dashboard, or from your Google Account at myaccount.google.com/permissions. Revoking deletes our stored token; bookings already created in your calendar or spreadsheet remain yours and are unaffected.

Data retention

Account data is retained for as long as your account is active. If you delete your account, we delete all associated data within 30 days. Chat logs and indexed content are deleted immediately when you delete a chatbot. You can request deletion of your data at any time by contacting us.

Your rights

You have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data; object to or restrict processing; receive a machine-readable copy of your data (data portability). To exercise these rights, contact us at support@botchata.net.

Cookies

We use a session cookie to keep you logged in and a preference cookie for theme (light/dark); both are strictly necessary and set without consent. We also use Google Analytics 4 to measure aggregate traffic. Google Consent Mode v2 is enabled and every consent category — analytics and advertising alike — defaults to "denied" before Analytics loads: no analytics cookie is set until you accept in the cookie banner, and advertising storage and personalisation stay denied at all times. You can change or withdraw your choice at any time in the banner. We do not use advertising cookies and we do not sell data to advertisers.

Security

We use HTTPS for all data in transit. Passwords are hashed using bcrypt. API keys and OAuth tokens are encrypted at rest using Fernet symmetric encryption. We regularly review our security practices.

Changes to this policy

We may update this policy from time to time. We will notify registered users by email of any material changes. The date at the top of this page indicates when it was last updated.

Contact

If you have questions about this privacy policy or how we handle your data, email us at support@botchata.net.