Legal
Privacy Policy
Last updated: August 2026
Conversation content is encrypted at rest
Message content is encrypted with AES-256-GCM before it is written to our database, using a key unique to each chatbot. This protects the message table against exposure on its own. A leaked export of conversations is not readable without the key. The key itself is stored in your chatbot's configuration and is accessible to our servers, since the assistant needs it to read and continue the conversation. Access to production data is restricted to authorised personnel.
1. Who We Are
BotChap is a SaaS chatbot widget builder operated by Otonomi Technologies and Consulting FZCO, registered in the Dubai Silicon Oasis Free Zone, Dubai, UAE ("Otonomi", "we", "us", "our"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use BotChap ("the Service").
By using BotChap you agree to the practices described in this policy. If you do not agree, please stop using the Service.
2. Data We Collect
2.1 Account Data
When you sign in with Google we receive your name, email address, and profile photo from Google's OAuth service. We store this to identify your account and personalise the Service.
2.2 Profile Data
You may optionally provide your phone number and postal address from your Profile page. This information is stored in your account record in our database, is private to you, and is used only for billing and support purposes. You can update or delete it at any time from your Profile page.
2.3 Billing & Payment Data
Payments are processed by Stripe on behalf of Otonomi Technologies and Consulting FZCO. We never store your full card number, CVV, or raw payment details on our servers. We retain your Stripe customer ID, subscription plan, billing interval, and subscription renewal date to manage your account.
2.4 Chatbot Configuration Data
All widget settings you create, including backend URLs, appearance settings, API keys, and authentication tokens, are stored in our PostgreSQL database and are accessible only to your account. Sensitive credentials, including calendar OAuth tokens (Google/Outlook), messaging-channel access tokens (WhatsApp/Messenger/Instagram), and API keys/auth tokens you supply for AI backends and custom integrations (OpenAI, Flowise, Dify, LangChain, Shopify, and custom webhook credentials), are encrypted at rest with AES-256-GCM. By default these credentials are used server-side only and are never sent to end-user browsers. If you explicitly enable client-side authentication for a chatbot, an advanced, non-default setting we no longer offer to new accounts, that chatbot's credentials are sent to the widget's browser context so it can call your backend directly.
2.5 Conversation Data
When end-users interact with your deployed BotChap widgets, basic session metadata (chatbot ID, message count, timestamp, browser user-agent) is always recorded to power your analytics dashboard. Full message content is only stored if you have explicitly enabled the Log Full Messages setting.
When message logging is enabled, message text is encrypted with AES-256-GCM before it is written to our database. A unique 256-bit key is generated per chatbot and stored within your chatbot configuration. Stored messages appear only as ciphertext and are meaningless without that key.
Where that encryption happens depends on the surface. For the website widget, messages are encrypted in the visitor's browser before they reach us, so our servers never hold the plaintext. For messaging channels, WhatsApp, Facebook Messenger and Instagram, that is not possible: Meta delivers the message to our server in plain text, so the encryption is applied by our server on arrival, and the plaintext exists in memory for as long as it takes to answer and store it. In both cases what is written to disk is ciphertext.
You are responsible for informing your end-users that their messages may be logged and for obtaining any consent required by the laws of your jurisdiction.
2.6 Usage & Technical Data
We may collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for security monitoring, debugging, and service improvement only. We do not sell this data.
3. How We Use Your Data
- To create and manage your BotChap account
- To process payments and manage your subscription via Stripe
- To deliver the Service features included in your plan
- To send transactional emails (subscription confirmations, renewal reminders, cancellation notices, support replies)
- To power your analytics dashboard (session counts, message counts, conversation timelines)
- To investigate and resolve technical issues or abuse reports
- To comply with legal obligations under UAE law
We do not use your data for advertising and we do not sell or share your personal data with third parties for their own purposes.
4. Legal Basis for Processing
We process your personal data on the following grounds:
- Contract performance, to provide the Service you have signed up for
- Legitimate interests, to keep the Service secure, operational, and improving
- Legal obligation, to comply with applicable laws and financial regulations
- Consent, where you have explicitly opted in (e.g. enabling conversation logging)
5. Encryption Architecture
This section explains how BotChap protects conversation content, and where that protection begins on each surface.
- Key generation, when you create a chatbot a unique random AES-256-GCM key is generated using the Web Crypto API and stored in your chatbot's configuration. That configuration lives in our database and is readable by our servers, which is what allows an assistant to continue a conversation it did not just receive.
- Website widget, messages are encrypted in the visitor's browser using that key before they are sent to us, so our servers never hold the plaintext of a widget conversation.
- Messaging channels, WhatsApp, Messenger and Instagram deliver messages to our server in plain text. This is how Meta's platform works and we cannot change it. Our server encrypts the message on arrival, before storing it. The plaintext exists in server memory only for as long as it takes to generate a reply and store the turn.
- Decryption on demand, when you view conversation logs in your dashboard, messages are decrypted in your browser using the key from your chatbot config.
- What we store, only encrypted ciphertext (e.g.
aGVsbG8=:dGhpcyBpcyBl…). Without the key, this is unreadable.
6. Third-Party Services
We use the following third-party processors. Each operates under its own privacy policy. If you use BotChap to process your own end-users' personal data, our Data Processing Addendum sets out the terms of that processing.
Google LLC (Gemini API)
Generating assistant replies. Message content is sent to Google to produce an answer. Google does not use it to train their models under the paid API terms.
OpenAI, L.L.C.
An alternative model provider, selectable per chatbot. Where a chatbot is configured to use an OpenAI model, message content is sent to OpenAI instead of Google to produce the reply. OpenAI does not train on data submitted through their API.
Hostinger International Ltd
Server and database hosting (Manchester, United Kingdom). All stored data resides on infrastructure rented from Hostinger.
Google Firebase Authentication
Account sign-in only. No conversation data is stored in Firebase.
Stripe
Payment processing and subscription management
Google OAuth
Sign-in authentication (Google accounts)
Apple Inc.
Sign-in authentication (Sign in with Apple, iOS app only). We receive your name and the email address you choose to share, which may be an Apple-generated private relay address.
Hostinger (SMTP)
Transactional email delivery
Meta Platforms
Where you connect a WhatsApp number, Facebook Page or Instagram account, messages are exchanged through Meta and are also subject to Meta’s own policies.
RevenueCat
In-app purchase management for the mobile apps
When you configure your own AI backends, webhooks, or third-party integrations inside BotChap widgets, user messages are forwarded to those external endpoints. You are solely responsible for the privacy practices of those services.
6a. Messaging Channels (WhatsApp, Messenger, Instagram)
A BotChap account holder may connect their own WhatsApp number, Facebook Page or Instagram professional account so that their assistant can answer people who message that business. This section describes what we receive from Meta when they do.
What we receive. When someone messages a connected business, Meta delivers us the message text, the platform-assigned identifier for that conversation (a page-scoped or Instagram-scoped id), a timestamp, and, on WhatsApp, the display name the sender has set. We also store the access token the business granted us, encrypted, so we can reply on their behalf.
What we do with it. We generate a reply using the business's own configured instructions and knowledge base, send it back through Meta, and store the exchange so the assistant has context for the rest of the conversation. Message content is sent to our model provider, Google or OpenAI, depending on which model that chatbot is configured to use, for that purpose. Nothing is used for advertising, profiling, or training our own models, and nothing is sold.
What we never do. We do not message anyone who has not messaged the business first, we send no bulk or promotional messages, and we do not combine data from one business's conversations with another's.
Deleting it. Email support@botchap.com saying which business you messaged and roughly when, and we delete the conversation and its messages. Removing BotChap from the apps connected to your Facebook or Instagram account stops further messages reaching us, but please send the email as well rather than relying on that alone. Full instructions are on our Data Deletion page.
7. Data Retention
- Account & profile data, retained while your account is active. Deleted within 90 days of a verified account deletion request.
- Billing records, retained for 7 years to comply with UAE financial regulation.
- Conversation logs, retained while the associated chatbot exists. Permanently deleted when you delete the chatbot or your account.
- BotChap AI Assistant data (Knowledge Base documents, calendar connection, survey questions and responses), preserved indefinitely while you hold an active paid plan. If your account goes 45 consecutive days without one, this data is permanently deleted for any chatbot that has it — you're notified in-app and by email about a week beforehand. Upgrading at any point before the 45 days elapse keeps everything intact.
- Analytics, computed from your conversation records rather than stored separately, so they exist for exactly as long as those conversations do.
- Server logs, size-capped and rotated automatically, which in practice is a few weeks.
8. Data Security
We apply multiple layers of security to protect your data:
- Encryption in transit, all data is transmitted over HTTPS/TLS
- Conversation encryption at rest, message content is encrypted with AES-256-GCM before storage, so an exposed copy of the message table on its own is not readable (see Section 5). This protects against exposure of a raw database or backup copy. It does not protect against someone who has the decryption key, which is available to our servers and to your embedded widget by design, since the widget needs it to encrypt and decrypt messages in the visitor's browser
- Restricted production access, access to production systems is limited to the company director. There is no session-replay, analytics or third-party support tool with a view of customer conversations
- Per-user isolation. Every read and write is scoped to the authenticated account at the application layer, and ownership is checked on each request
- Server-side credential proxy, by default your API keys and auth tokens are stored server-side and proxied to backends, not exposed in end-user browsers. An advanced, non-default setting (client-side authentication, no longer offered to new accounts) sends that chatbot's credentials to the browser instead. See Section 2.4
- Payment security, card data is handled entirely by Stripe and never touches our servers
Despite these controls, no system is completely secure. Please use a strong, unique password for your Google account and notify us immediately at support@botchap.com if you suspect unauthorised access.
9. Cookies
BotChap uses only functional cookies required to maintain your authenticated session (managed by Firebase Authentication). We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. You can clear cookies at any time through your browser settings, which will log you out of the Service.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access, request a copy of the personal data we hold about you
- Rectification, correct inaccurate data (name, phone, address can be updated directly from your Profile page)
- Erasure, request deletion of your account and associated data
- Portability, receive a copy of your data in a structured, machine-readable format. This is currently fulfilled manually on request rather than through a self-service export tool
- Objection, object to processing based on legitimate interests
- Restriction, request that we limit how we use your data pending a dispute
- Withdraw consent, disable conversation logging at any time from your chatbot settings
To exercise any of these rights, email support@botchap.com. We will respond within 30 days.
11. International Data Transfers
Your data is stored on servers rented from Hostinger International Ltd, physically located in Manchester, United Kingdom. The United Kingdom is not part of the European Union and maintains its own data protection framework (the UK GDPR). Message content is additionally transmitted to Google LLC for the sole purpose of generating an assistant reply, and sign-in is handled by Google Firebase Authentication; both operate data centres globally and may process data outside the UK, EU, and UAE. Google maintains Standard Contractual Clauses and other safeguards for its own international transfers. We are working with legal counsel to confirm and document the appropriate transfer mechanism for our own hosting arrangement as it applies to personal data originating in the EU, Türkiye, and elsewhere; this section will be updated as that work concludes. By using BotChap you acknowledge these data flows.
12. Children's Privacy
BotChap is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, contact us at support@botchap.com and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
14. Contact
For any privacy-related questions, data requests, or security concerns, please contact us at:
Otonomi Technologies and Consulting FZCO
Dubai Silicon Oasis, Dubai, UAE
support@botchap.com