Skip to content
Data and privacy

Know which data the chat needs and who can access it

Chtio separates projects by owner and role, checks allowed domains and protects important actions. The website owner remains responsible for the privacy notice and lawful collection of visitor data.

Quick answer

Quick answer

Chtio separates projects by owner and role, checks allowed domains and protects important actions. The website owner remains responsible for the privacy notice and lawful collection of visitor data.

What matters
  • Role-based access
  • Allowed domains
  • Protected credentials
How it works

From preview to working chat

Three clear steps without hidden settings or a required payment.

01
Preview the chat

Enter a domain and inspect the standard Free appearance before signup.

02
Create the project

Activate the account, confirm the domain, and receive the working code.

03
Start replying

Connect AI, agents, and the channels available on the selected plan.

Preview chat on my website

What you get

01

Role-based access

The owner assigns team members and decides which projects and sections they may use.

02

Allowed domains

A working widget runs only for an approved project and an allowed website.

03

Protected credentials

Passwords are stored as secure hashes, and important forms use CSRF protection.

04

Attachment controls

Uploads are limited by type and size and stay associated with a specific project.

Data created during normal support work

01

Owner account

Name, email, interface language and verification data are used for sign-in and project management.

02

Visitor messages

Conversation text, technical context and selected form fields are stored so the team can continue the request.

03

Attachments

Files and images stay within the project and count toward its storage allowance.

04

Connected channels

Telegram and operator apps use linked identifiers so replies remain in one conversation history.

05

Public funnel events

When first-party analytics is enabled, Chtio stores the event name, language, page key, path without query parameters, referrer domain and an HMAC hash of a random first-party journey identifier. After sign-up, only completed milestones may be recorded: registration, activation, project creation and project submission. Email addresses, project domains, message text, form values, full IP addresses and the raw identifier are not stored.

How it works

01

Define the minimum data

Do not ask for information that is not needed to resolve the request.

02

Update the notice on your website

Explain what is collected, why it is needed and how visitors can ask privacy questions.

03

Limit team access

Grant only the required project access and review team members regularly.

Division of responsibility

Chtio helps control

  • team access to projects
  • allowed domains and working tokens
  • conversation history and attachments

The website owner must define

  • !the lawful basis for processing visitor data
  • !retention and deletion rules required by the business
  • !privacy and consent wording for the applicable country

Questions about this use case

Are passwords stored in plain text?+

No. The project uses standard secure password hashing and verifies the hash during sign-in.

Can the chat be used for sensitive data?+

Collect the minimum and do not request passwords, payment credentials or documents without a separate protected process and a lawful basis.

Is this page a legal privacy policy?+

No. It is a product transparency overview. Formal policies must include the service owner, applicable law and the actual processing operations.

What is stored during Telegram activation?+

The normalized number is stored encrypted when encryption support and the storage field are available. A protected hash and the last four digits are also kept for uniqueness checks and display.

How does the public funnel identifier work?+

The browser receives a random HttpOnly chtio_journey cookie for up to 90 days. Only its HMAC hash is stored so preview activity can be linked to registration and project creation without keeping an email address or domain. Events are deleted after 180 days by default.

Start with a safe basic workflow

Enter the domain, save the language and create the project with the standard Free appearance. Team access and additional features are configured in the dashboard.

Preview chat on my website
Preview chat on my websitePreview before signup Preview chat on my website