Privacy Policy
Last updated September 11, 2026
1. Overview
This policy explains what personal data CYBIBOT collects, why, and the choices you have about it. It covers two groups of people: the businesses (“Customers”) who sign up to use the Service, and the end customers who contact a Customer’s AI receptionist through their website chat, phone number, WhatsApp, SMS or email inbox (and any additional channels we make available).
2. Information we collect
- Account information — name, work email, business name, and password (stored as a salted hash, never in plain text) or the identifier from an OAuth provider if you sign in with Google or Microsoft.
- Business content — documents, FAQs, business rules and other material a Customer uploads to ground their AI receptionist’s answers.
- Conversation data — messages exchanged between a Customer’s end customers and the Service, including the transcript of a phone call and the phone number or email address a message arrives from, so the Customer can review them, reply, and the Service can maintain context within a conversation. Where a Customer connects a calendar or CRM, the details needed to book an appointment or create a contact are passed to that provider on their behalf.
- Usage data — log data such as IP address, browser, and actions taken in the product, used for security and reliability.
3. How we use information
- To provide and operate the Service, including generating AI responses.
- To secure accounts — rate limiting, fraud and abuse detection, and session management.
- To communicate with you about your account, such as verification codes and password resets.
- To improve the Service’s reliability and quality.
- To comply with legal obligations.
4. AI processing and subprocessors
Generating a response can involve sending relevant parts of a conversation to a third-party AI model provider. We select subprocessors that contractually commit not to use Customer Data to train their own models, and we limit what’s sent to what the model needs to answer well. A current list of subprocessors is available on request through our contact page.
5. Data sharing
We don’t sell personal data. We share it with service providers who help us run the Service (hosting, email delivery, AI model providers) under contracts that limit their use of it to that purpose, and we may disclose it if required by law or to protect the rights, safety or property of CYBIBOT or others.
6. Data retention
We keep account and conversation data for as long as the workspace is active. Short-lived security records are purged automatically: one-time codes (email verification, password reset) expire within minutes, and expired sign-in tokens and invitations are deleted on a scheduled job. Both are stored only as hashes in the meantime.
We don’t yet offer self-serve export or deletion, and we won’t claim otherwise: automated retention windows and self-serve erasure are on our roadmap. In the meantime, ask us through our contact page and we will tell you what we hold about you and action a deletion request manually.
7. Your rights
Depending on where you’re located, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. Customers can manage most of this directly in their workspace; for anything else, or if you’re an end customer contacting a business that uses CYBIBOT, reach us through our contact page and we’ll route the request appropriately.
8. Security
Passwords are hashed, never stored in plain text. Sessions use short-lived access tokens with rotating, revocable refresh tokens, and we rate-limit authentication endpoints against abuse. No method of transmission or storage is perfectly secure, but we design the Service to fail safely and to limit what any single compromised credential can reach.
9. Cookies
We use strictly necessary cookies/local storage to keep you signed in and remember your workspace, and a limited set of analytics to understand how the marketing site is used. We don’t use third-party advertising cookies.
10. International transfers
Data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
11. Children
The Service is intended for business use and isn’t directed at children. We don’t knowingly collect personal data from children.
12. Changes to this policy
We’ll post any changes here with an updated date, and notify account owners directly for material changes.
13. Contact
Questions about this policy or a request regarding your data? Reach us through our contact page.