Privacy Policy
Last updated 3 September 2026
The short version
If you chat with a business using whiz.chat, we store what you type and any contact details you choose to share, so that business can reply to you. Your messages are sent to OpenAI to generate a response. We don't store your IP address, we don't use tracking cookies in the chat widget, and we don't sell anything to anyone. The business you were talking to controls that conversation — we only hold it for them.
1. Who this covers
whiz.chat is operated by [LEGAL ENTITY NAME, ABN] of [REGISTERED ADDRESS] (“we”, “us”). You can reach us at [PRIVACY CONTACT EMAIL].
We provide a chat agent that businesses embed on their own websites. That means two different groups of people are involved, and we hold a different responsibility to each. This policy covers both — find the section that describes you.
- Business owners who sign up for an account. For your information, we are the controller: we decide how it's used, and this policy is the whole agreement.
- Visitors who chat on a business's website. For your information, we are a processor acting on that business's instructions. They decide why your conversation is collected and what happens to it; we store and process it on their behalf. Their own privacy policy applies alongside this one.
2. If you chatted with a business
What is collected
- What you type. The full conversation, including anything you mention in passing.
- Contact details you share. If you give a name, email address or phone number in the conversation, it's saved as a contact record so the business can follow up. This happens automatically from what you write — there's no form to submit, and no separate step where you opt in. That's why we tell you before you start typing.
- Your country. Our hosting provider derives a two-letter country code from your IP address. Only that code is stored. We do not store, log, or have access to your IP address itself.
- A random visitor ID. A random identifier is generated and kept in your browser's local storage so that if you come back, your conversation is still there. It is not a cookie, it is not shared between different businesses' sites, and it isn't linked to anything about you unless you provide it yourself. Clearing your browser storage removes it and starts a new conversation.
- Timestamps for each message.
What is not collected
We don't place advertising or tracking cookies through the chat widget. We don't build a profile of you, follow you across sites, or sell or rent your information to anyone. Our own product analytics deliberately excludes the chat widget entirely, so opening a chat on a business's website does not register you as a visitor to ours.
Who sees your conversation
- The business you contacted. They can read the whole conversation in their dashboard and reply as a human at any point.
- OpenAI. Your messages are sent to OpenAI to generate the agent's replies and to detect contact details. See the sub-processor table below.
- Our infrastructure providers, to the extent needed to host and store the data. Also in the table below.
3. If you have a whiz.chat account
- Account details — your email address and password. Passwords are hashed by our authentication provider; we never see them.
- Business details — your business name, website address, and a logo if you upload one. Uploaded logos are stored in a publicly-readable location — anyone with the file's URL can view it, so don't upload anything you wouldn't publish.
- Your knowledge base — text read from your website during an import, plus anything you write or edit yourself.
- Notification settings — the email address you want lead alerts sent to, and a record of each browser or device you turn push notifications on for.
- Usage analytics on our marketing site and dashboard — cookieless page and event counts, used to understand which pages work.
4. Reading your website
When you point whiz.chat at your website, we fetch its public pages the way any visitor or search engine would, extract the text, and store it so the agent can answer from it. We only do this when you ask us to — at setup, or when you press re-read. There are no scheduled or background crawls. We only fetch pages that are publicly reachable; we do not log in, submit forms, or attempt to reach anything behind a password.
5. How the AI works
When a visitor sends a message, we search your stored website content for relevant passages and send those, your knowledge base, and the recent conversation to OpenAI, which generates the reply. Replies are checked before they're shown: if one contains a phone number or link that doesn't match your business's own details, it is replaced rather than sent.
We access OpenAI through its API, and OpenAI's API terms state that data submitted this way is not used to train its models — you should read their terms directly if this matters to you. For our part: we do not train any model on your conversations or your website content, and we never use one customer's data to improve another customer's agent.
6. Who else processes your data
We use the following sub-processors. Each is bound to handle the data only as needed to provide their service to us.
| Provider | What for | What they receive |
|---|---|---|
| Vercel | Hosting and delivery | Requests to the site, including IP addresses in transit (not stored by us); cookieless usage analytics, excluding the chat widget |
| Supabase | Database, accounts, file storage | Everything stored: accounts, conversations, contacts, knowledge base, logos |
| OpenAI | Generating replies, reading your website content | Conversation messages, your knowledge base and website text |
| Resend | Sending lead notification emails | Your notification email address and the contact details of the lead |
| Push services (Apple, Google, Mozilla, depending on your browser) | Delivering push notifications to account holders | An encrypted notification payload. Only ever for account holders — never for visitors |
Data is stored in [DATA REGION — confirm your Supabase project region], and some of these providers process data in the United States and elsewhere. Where information is transferred overseas, we take reasonable steps to ensure it's handled consistently with this policy and applicable law.
7. Cookies and local storage
- The chat widget sets no cookies. It stores a random visitor ID and conversation ID in your browser's local storage so your conversation persists if you return.
- The dashboard uses essential cookies to keep you signed in. Without them, you can't log in.
- Our marketing site uses cookieless analytics. If you enter your website address before signing up, it's held in a short-lived cookie (24 hours) purely so it survives the signup step and we don't have to ask you twice.
- There are no advertising or cross-site tracking cookies anywhere in the product.
8. How long we keep things
We currently keep conversations and contact records indefinitely — until the business deletes them or closes its account. Closing an account deletes its business, conversations, contacts and knowledge base. Push notification records are removed automatically when a device stops accepting them.
[DECISION NEEDED: set a retention period — e.g. conversations deleted after 24 months — and describe it here. “Indefinitely” is honest but is a weak position under the Australian Privacy Principles and the GDPR, both of which expect data to be kept no longer than necessary.]
9. Your rights
You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it.
- If you have an account, contact us at [PRIVACY CONTACT EMAIL]. Much of it you can also edit or delete yourself from your settings.
- If you chatted with a business, contact that business first — the conversation is theirs, and they can delete it. If you can't reach them, contact us and we'll help, though we may need to refer your request to them.
Depending on where you live you may have additional rights, including to object to processing, to request a portable copy, or to complain to a regulator. In Australia that is the Office of the Australian Information Commissioner (OAIC); in the EU or UK, your local data protection authority. We'd rather you came to us first.
10. Security
Data is encrypted in transit. Access to the database is restricted by row-level security so a business can only reach its own records, and the chat widget never talks to the database directly. Uploaded logos are the exception noted in section 3 — those are deliberately public.
No system is perfectly secure. If we become aware of a data breach likely to result in serious harm, we'll notify affected people and the relevant regulator as required by law.
11. Children
whiz.chat isn't directed at children, and accounts are for businesses. We don't knowingly collect information from children. If you believe a child has provided information through a chat widget, contact us and we'll delete it.
12. Changes
We'll update this page when the product changes, and update the date at the top. If a change materially affects how we handle your information, we'll tell account holders by email before it takes effect.
13. Contact
Questions, requests or complaints: [PRIVACY CONTACT EMAIL]. We'll acknowledge within a reasonable time and aim to resolve complaints within 30 days.
See also our Terms of Service.