Data Privacy & Security

Effective date: July 16, 2026

This page summarizes how CrawlChat handles customer knowledge base content, conversations, and related operational data. It is intended to complement our Privacy Policy, which explains our broader privacy practices.

Our role

CrawlChat provides tools for customers to create AI agents from documentation, website pages, uploaded files, and connected services. For most knowledge base content and end-user conversations, CrawlChat acts as a processor or service provider for the customer that configured the assistant.

Customers decide what sources to connect, who may access each collection, which channels are enabled, and what instructions the assistant follows. Customers are responsible for ensuring they have the rights and permissions needed to add data to CrawlChat.

Data stored in CrawlChat

CrawlChat may store:

  • knowledge base content, such as crawled pages, uploaded files, imported documentation, repository content, tickets, issues, transcripts, and connected-source records;
  • metadata needed to manage that content, such as URLs, titles, source identifiers, update status, timestamps, and source configuration;
  • embeddings, search indexes, and source-citation metadata used to find relevant context;
  • chat messages, generated answers, ratings, corrections, tickets, attachments, and related conversation details;
  • collection settings, prompts, widget customization, access settings, channel settings, and integration configuration; and
  • operational logs, diagnostics, usage events, and security signals needed to run and protect the service.

Use of customer data

CrawlChat uses customer data to provide the service requested by the customer. This includes indexing content, updating knowledge bases, searching relevant sources, generating responses, citing sources, routing messages through enabled channels, supporting tickets, monitoring reliability, preventing abuse, and troubleshooting issues.

We do not sell customer knowledge base content or end-user conversations. We do not use a customer's private knowledge base content to train models for other customers.

AI processing

When CrawlChat generates an answer or performs an AI-powered feature, it sends the relevant parts of the request to the selected model provider. This may include the user's question, customer instructions, conversation context, retrieved knowledge base snippets, source metadata, and formatting instructions.

CrawlChat is designed to send only the information needed for the requested feature. Customers can reduce exposure by limiting connected sources, keeping collections private, reviewing assistant prompts, and choosing appropriate model and channel settings.

Third-party services

CrawlChat uses third-party services to operate the platform. These may include providers for cloud hosting, databases, vector search, payments, email, analytics, error monitoring, abuse prevention, connected integrations, and AI model processing.

When customers enable integrations, data may be exchanged with the connected service, such as Slack, Discord, GitHub, Google Chat, Notion, Confluence, Linear, or similar services. The customer controls which integrations are enabled and is responsible for configuring them appropriately.

Access control

CrawlChat provides collection visibility settings and team roles to help customers control access. We recommend setting sensitive collections to Private and granting access only to trusted users and approved channels.

Customers should keep API keys, integration tokens, webhooks, and account credentials confidential. Customers should promptly remove users or integrations that no longer need access.

Retention and deletion

Customers can delete collections, knowledge groups, and related content in the product. When a collection or knowledge group is deleted, associated knowledge base information is removed from CrawlChat-managed databases.

Stored messages older than 30 days are automatically purged annually, unless retention is required for legal, security, abuse prevention, backup, or operational reasons. Backups, logs, and derived operational records may take additional time to expire through normal retention cycles.

Security measures

CrawlChat uses technical and organizational measures designed to protect customer data, including access controls, authentication, monitoring, operational safeguards, and separation of customer workspaces and collections.

No system is perfectly secure. Customers should avoid adding data they are not authorized to process and should configure visibility, integrations, and access controls with the sensitivity of their content in mind.

Incident handling

If we discover a security incident that affects customer data, we will investigate, take appropriate containment and remediation steps, and notify affected customers when required by law or contract.

Contact

For questions about data privacy or security, contact us at support@crawlchat.com.