Privacy Policy
Last updated: September 2026
This Privacy Policy explains how Privas Intelligence Ltd, a company registered in England and Wales under company number 17195166 and trading as Privas AI, handles personal data.
We have written this policy to describe what our software actually does. Where a capability is not yet built, we say so rather than implying otherwise.
1. Who this policy is for
Privas AI handles two separate groups of people, and our legal role differs for each. Read the part that applies to you.
| You are | Read | Our role |
|---|---|---|
| A business or individual with a Privas AI account | Part A | We are the controller of your data |
| Someone who chatted with an AI assistant on another company's website | Part B | We are a processor. That company is the controller |
If you chatted with an assistant on a company's website and want your data deleted, that company decides; see section B.9 for how to reach them and how we help.
Part A: If you have a Privas AI account
A.1 What we collect
Account information. Your name and email address. Your email is held both by our authentication provider, Clerk, and in our own database, where it is refreshed from Clerk each time you sign in and shared with Stripe for billing.
Billing information. Your subscription plan, billing period, usage counters, and Stripe customer and subscription identifiers. We never receive or store your card details: those are collected and held by Stripe.
Content you upload. Documents, web pages, and other knowledge sources you add to train your assistant, plus images such as assistant avatars and domain icons.
Configuration you provide. This may include credentials for services you connect: your own mail server password, and authentication tokens for external tool servers you register. These are encrypted before storage (see section A.5).
Google Calendar, if you connect it. The Google account email address you connected, encrypted access credentials issued by Google, the identifier of the bookings calendar we create for you, and the identifiers of the booking events we place on it. Section A.8 explains exactly what we can and cannot see in your Google account.
Team and access data. Collaborator roles, and the email addresses of people you invite, including invitations that are never accepted.
Enquiry data. If you join a waiting list or submit a contact or demo request, we keep the name, email, phone number, company, and any notes you provide.
A.2 Why we use it
To operate your account and your assistants; to process payments and enforce plan limits; to send service messages such as usage warnings and billing notifications; to provide support; to keep the platform secure; and to meet legal obligations.
Our lawful bases are performance of a contract for operating the service and billing, legitimate interests for security, abuse prevention and service communications, and consent where you have given it, such as joining a waiting list.
A.3 How long we keep it
Account and content data is kept for as long as your account is open. Closing your account deletes it; section A.6 sets out exactly what goes and the two operational records that stay.
Billing records are kept for seven years after the transaction to meet UK accounting and tax requirements.
Waiting list, enquiry, and unaccepted invitation records are currently kept indefinitely. We are introducing a retention limit for these; until then you can have yours removed at any time by emailing us.
A.4 Who we share it with
The providers listed on our Sub-processors page, which forms part of this policy. In summary: Clerk for sign-in, Stripe for payments, Uploadcare for images, Spacemail for outbound email, Contabo for hosting in Singapore, Google Analytics for website usage, and Anthropic and OpenAI for processing the knowledge sources you upload.
We do not sell your personal data, and we do not share it for advertising.
A.5 How we protect it
Credentials you entrust to us (mail server passwords, external tool tokens, and the database credentials we generate for your assistant) are encrypted with AES-GCM using a unique nonce per operation before being written to storage. The encryption component validates its key at start-up and refuses to run if the key is invalid.
Each of your domains gets its own separate database for its knowledge and conversations, rather than sharing storage with other customers. Administrative access requires authentication and a role check on the specific domain.
The full technical and organisational measures we apply, together with their current limitations, are set out in our Data Processing Agreement, which customers who process personal data can request. Those measures apply to your data too.
A.6 Deleting your account
You can delete your account from your dashboard settings, and doing so deletes your data. Specifically, it destroys, for every domain you own:
- the database holding that domain's knowledge base and all of its conversations;
- the separate database holding what the assistant remembered about returning visitors across sessions (section B.4);
- every record in our main database: your profile, your chatbots, your settings, your billing record, your collaborators and invitations, message logs, queued emails, and analytics events;
- the domain icon and assistant avatar you uploaded.
Deleting an individual domain does the same for that domain alone.
Two things survive:
- An operational record that the deletion happened: its date, who requested it, and the domain's name. We keep this to demonstrate that we did what we say we do. It contains no conversation content.
- Anonymous daily counters: how many conversations a domain handled on a given day, with no session or visitor identifier attached (section B.5).
If any step fails, nothing is deleted. Rather than leave a half-erased account behind, the operation stops and tells you so, with your account still intact, so you can try again. If it keeps failing, email [email protected].
Your subscription is cancelled as part of the deletion. You will not be charged again.
Before 29 August 2026 this was not true: account deletion removed your login and your records but left the conversation databases in place, and neither operation removed the cross-session memory database. If you deleted an account or a domain before that date and want the leftover data destroyed, email [email protected] and we will do it and confirm.
A.7 Your rights
If you are in the UK or EEA you have the right to access, correct, delete, restrict, or object to our processing of your data, and to receive it in a portable format. If you are in Indonesia, equivalent rights apply under Law No. 27 of 2022.
Email [email protected]. We will respond within 30 days. You may also complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority.
A.8 Google Calendar
Connecting Google Calendar is optional. It exists for one purpose: so that visitors booking an appointment through your booking page are never offered a time you are already busy, and so that each booking appears in your Google Calendar.
What you allow when you connect. Google asks you to grant these permissions, and we request nothing more:
| Permission | What we do with it |
|---|---|
See your availability (calendar.freebusy) | We ask Google which blocks of time are busy on your main calendar, so those times are not offered on your booking page. Google answers with start and end times only. We never receive the title, description, location, or attendees of any of your events. |
Create a secondary calendar and manage its events (calendar.app.created) | When you connect, we create one new calendar in your Google account, named after your domain (for example "acme.com bookings (Privas)"). When a visitor books, reschedules, or cancels, we add, move, or remove that booking on that calendar. This permission reaches only calendars Privas AI created. We cannot read, change, or delete your main calendar or any other calendar you own or that is shared with you. |
Your email address and basic sign-in identity (openid, email) | Shown in your dashboard so you can see which Google account is connected. |
What we write to your calendar. For each booking: the meeting title, the visitor's name and email address, the note they left, if any, the meeting location, and the start and end time. We do not add the visitor as a guest on the event, so Google does not send them an invitation. We never put the visitor's link for managing their booking on your calendar.
What we store. Your Google account email address; the credentials Google issued, encrypted with AES-GCM before they are written to our database; the identifier of the calendar we created; the identifier of each booking event; and the time and result of the last sync. Busy times are held in memory for at most one minute to avoid asking Google repeatedly, and are never written to storage.
What we never do with Google user data. We do not sell it; we do not use it for advertising; we do not use it to train, fine-tune, or improve any AI or machine-learning model, and we do not send it to our AI providers; we do not transfer it to anyone except as needed to provide the booking feature you turned on, to comply with law, or as part of a merger or acquisition with notice to you; and our staff do not read it unless you ask us to for support, it is needed for security, or the law requires it.
Privas AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. Press Disconnect under Settings, Appointments. We delete the stored credentials immediately and ask Google to revoke them. You can also remove Privas AI's access at any time from your Google Account at myaccount.google.com/permissions; we detect this and stop syncing. Deleting your domain or your account removes the connection as well (section A.6).
Disconnecting does not delete the bookings calendar or the events already on it, because they are in your Google account and belong to you. Remove the calendar in Google Calendar if you no longer want it.
Part B: If you chatted with an assistant on a website
When you chat with an assistant powered by Privas AI on another organisation's website, that organisation decides what is collected and why. They are the controller. We store and process the conversation on their behalf, under a contract with them.
This part tells you what we hold, because you are entitled to know even though your rights are exercised against them.
B.1 What is stored when you chat
Each exchange is stored as a record containing:
- Your message, exactly as you typed it
- The assistant's reply
- A rewritten version of your question, which the AI produces internally to search the knowledge base more effectively
- Which passages of the organisation's knowledge base were used to answer
- Results returned by any external tool the assistant called, for example a calculated insurance premium or an exchange rate
- Technical information about why the assistant behaved as it did
If you provide your email address (because the assistant asked for it, because you requested a follow-up, or because you asked for the conversation by email), it is stored against your chat session, against a contact record, and in our outgoing email queue, where it remains alongside the message body.
Please treat a chat window as you would any web form: do not enter passwords, payment card numbers, national identity numbers, or health information.
B.2 What we do not collect
Notably:
- We do not record your IP address.
- We do not collect geolocation data.
- We do not record your browser's user-agent string, and we do not fingerprint your device.
None of these are collected anywhere in the visitor-facing product. This is a deliberate design choice, not an oversight.
B.3 What is stored in your browser
We do not use tracking cookies in the chat widget. We use your browser's local storage:
- A session identifier: a random value that groups your messages into one conversation. It expires after 12 hours.
- A visitor identifier: a random value used to count returning visitors in aggregate analytics. It has no expiry.
- A copy of your conversation, so the chat survives a page refresh.
These are random values. They are not linked to your name or identity unless you provide it. Clearing your browser's site data removes them.
On privas.ai the visitor identifier is not written until you accept it. Until then, and if you decline, your visit is counted using a temporary value held only in the page, which disappears when you close the tab, and any earlier copy is deleted. You can change your answer at any time through Cookie Settings in the site footer.
One boundary to be clear about: when you meet the assistant embedded on another company's website, our banner is not shown and cannot ask on their behalf, so the identifier is written there. What governs that is the cookie notice of the company whose site you are on.
Where this does not reach: the assistant embedded on another company's website is governed by that company's cookie notice, not ours. Our banner is not shown there and cannot ask on their behalf.
B.4 Memory across conversations
This feature is currently active.
The assistant can remember information across your separate visits. When you chat, an AI model reads your messages and extracts entities (things you mentioned, such as a product, a company, or a place) and preferences it infers from what you said. These are stored in a memory database belonging to the organisation whose assistant you used, linked to your browser's session identifier, and may be used to give more relevant answers when you return.
Staff at that organisation can view what has been remembered for a session, and the reasoning the assistant used, through their dashboard.
Two things you should know:
- The memory database is shared by all visitors to that organisation's assistant. Your data is kept separate from other visitors' by a filter applied in our software, not by giving each person their own database.
- Memory is keyed to your browser. Clearing your browser's local storage breaks the link.
B.5 Analytics
We record a small set of events so the organisation can see how their assistant performs, for example that a chat was opened, that a question was answered, or that a link was clicked. We store the event name, the page address, and a few non-identifying parameters.
Before storage, parameters are stripped of anything resembling personal data. Both field names and values are checked, so an email address or phone number is removed even if it arrives under an innocuous label.
Analytics events are deleted after approximately 90 days. Because they are removed in monthly blocks, an individual event may persist for up to about four months. Aggregate daily totals, which contain no session or visitor identifier, are kept permanently.
Google Analytics no longer loads in the chat surfaces. Because the chat window is served from privas.ai, it used to inherit the site-wide tag, so Google was told that a chat surface had been opened, never the content of your messages. That tag has been removed from the chat window and the share-link chat pages, and elsewhere on privas.ai it loads only if you accept it.
B.6 How your conversation is protected
What protects it. Each organisation's conversations are held in its own separate database with its own credentials, so one organisation's assistant cannot reach another's data. We apply technical controls designed to keep the data of one organisation separate from another's and to restrict access to it. Staff access requires authentication and a role check, and stored credentials are encrypted.
A chat window is not a secure channel for sensitive information. Do not enter passwords, payment card numbers, authentication credentials, national identity numbers, or health information into a chat widget, ours or anyone else's, unless the organisation operating it has specifically asked you to.
B.7 Where your conversation goes
Your message is stored on our servers in Singapore.
To generate a reply, your message, the recent conversation, and the relevant parts of the organisation's knowledge base are sent to Anthropic in the United States. Your message is also sent to OpenAI in the United States to be converted into a numerical form used for searching the knowledge base.
If the organisation has connected an external tool, information the assistant extracts from your message may be sent to a server that organisation chose and controls. We do not control that server. Ask them about it.
If the assistant emails you, your address and the message pass through our email provider.
We do not train AI models on your conversations, and we do not sell or share your conversation for advertising.
B.8 How long your conversation is kept
Conversations are currently kept for as long as the organisation keeps their assistant. There is no automatic expiry today.
We are introducing a configurable retention limit so organisations can have conversations deleted after a defined period. Until that ships, we will not state a retention period we do not enforce.
Analytics events are removed on the schedule in section B.5.
B.9 Getting your data deleted
Start with the organisation whose assistant you used. They are the controller and the decision is theirs. Their privacy notice should tell you how to reach them; the assistant itself can usually tell you who operates it.
We will help. Contact us at [email protected] with the website and roughly when you chatted. We will identify the organisation, pass your request on, and act on their instruction.
How this works today: there is no self-service button for you, and none for them that is narrower than deleting the whole assistant. The organisation can destroy everything at once (deleting their domain erases the conversation database and the memory database with it), but erasing one visitor's data inside a live assistant is done by hand, by our team, on the controller's instruction. In the meantime the outcome is the same (your data is deleted), but it takes a person, so please allow up to 30 days.
B.10 If you booked an appointment
Some organisations let you book a meeting through a Privas AI booking page or from inside a chat. As with conversations, the organisation is the controller and we process the booking on its behalf.
What is stored. Your name, your email address, the note you left, if any, the time you booked, the time zone you booked in, and whether the booking came from a booking page or a chat (in which case it is linked to that chat session). We also keep a history of what happened to the booking: when it was made, moved, cancelled, or a reminder was sent.
Abuse protection. To stop automated abuse, the booking page uses your IP address, held in memory for about a minute, to limit how many requests one address can make. It is not written to storage or to logs, which is why section B.2 remains accurate.
Your booking link. Your confirmation email contains a private link for rescheduling or cancelling without an account. Anyone who has that link can change or cancel your booking, so do not forward it. We never write that link into logs, analytics, or the organisation's calendar.
Emails you receive. A confirmation, a message when the booking is moved or cancelled, and, where the organisation's booking page sends them, a reminder before the meeting. These carry a calendar file (.ics) you can add to your own calendar. They are sent through the email service described in section B.7, or through the organisation's own mail server if it has set one up, and the organisation may receive a copy.
Google Calendar. If the organisation has connected Google Calendar (section A.8), your name, email address, note, and booking time are also placed on a calendar in that organisation's Google account. You are not added as a guest, and Google does not contact you.
What is not done with it. Your booking is not sent to our AI providers and is not used to train any model. We count that a booking was completed, for the organisation's analytics, without your name or email address.
How long it is kept, and deletion. Bookings are kept for as long as the organisation keeps its assistant, and deleting the organisation's domain deletes them. To have your booking data erased, follow section B.9.
Part C: Applies to everyone
C.1 International transfers
Privas AI is registered in England and Wales, operates from Jakarta, Indonesia, and hosts its infrastructure in Singapore. AI processing takes place in the United States. Personal data therefore crosses borders as a normal part of the service.
For UK and EEA data we rely on the UK International Data Transfer Addendum or Standard Contractual Clauses, together with each provider's own transfer terms. For Indonesian data subjects we rely on the cross-border provisions of Law No. 27 of 2022 on Personal Data Protection.
C.2 AI models and your data
What we do. Privas AI does not train, fine-tune, or otherwise use customer content or visitor conversations to build machine-learning models. We operate no training pipeline. Our AI providers are called only to answer requests as they arrive.
What we can say about them. We use Anthropic and OpenAI through their standard published API terms. We have not negotiated a private agreement, a zero-retention arrangement, or an enterprise addendum with either of them, and we have no commitments from them beyond what they publish and apply to every API customer.
Many privacy policies state that "our AI providers do not train on your data" as though it were a promise the company had secured. In our case it would be a description of the providers' own published default, not something we have contracted for, and they can change their published terms without asking us. You can read their terms yourself; we will point you to the current versions if you ask.
One practical consequence you should know: under standard API terms a provider may hold submitted content for a limited period for safety and abuse-monitoring purposes, even where it does not use that content for training. We cannot switch that off.
The one place the platform learns from usage is a feature that records procedural patterns for a single organisation: which kind of tool tends to suit which kind of question, and which pieces of information are usually needed. It never stores the content of an answer or anything a visitor said, it is never shared between organisations, and a pattern is only retained once it has occurred across multiple independent sessions.
C.3 Children
Privas AI is a business product and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, email [email protected] and we will delete it.
C.4 Security incidents
We maintain safeguards to protect the personal data we hold, and we investigate and respond to suspected security incidents. If personal data we hold is compromised, we will notify affected customers without undue delay and within 72 hours of becoming aware, and regulators where required.
C.5 Changes to this policy
We will update the date at the top when this policy changes and, for material changes affecting visitor data, update the Sub-processors page beforehand. Customers with a Data Processing Agreement receive notice as set out in that agreement.
C.6 Contact
Privas Intelligence Ltd Email: [email protected] Website: https://privas.ai Registered in England and Wales, company number 17195166 Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Operations: Jakarta, Indonesia
We have not appointed a Data Protection Officer, as we are not required to. Privacy enquiries go to the address above.
About Privas AI
Privas AI is a privacy-first AI assistant platform designed to help organizations deploy conversational AI representatives on their websites.
The platform uses domain-scoped knowledge retrieval to ensure that AI responses are generated only from authorized knowledge sources.
Learn more about Privas AI:
- Sub-processors: https://privas.ai/sub-processors
- Terms of Service: https://privas.ai/terms
- Cookie Policy: https://privas.ai/cookies
- Documentation: https://privas.ai/documentation