Enter a domain and inspect the standard Free appearance before signup.
Know which data the chat needs and who can access it
Chtio separates projects by owner and role, checks allowed domains and protects important actions. The website owner remains responsible for the privacy notice and lawful collection of visitor data.
Quick answer
Chtio separates projects by owner and role, checks allowed domains and protects important actions. The website owner remains responsible for the privacy notice and lawful collection of visitor data.
- ✓Role-based access
- ✓Allowed domains
- ✓Protected credentials
From preview to working chat
Three clear steps without hidden settings or a required payment.
Activate the account, confirm the domain, and receive the working code.
Connect AI, agents, and the channels available on the selected plan.
What you get
Role-based access
The owner assigns team members and decides which projects and sections they may use.
Allowed domains
A working widget runs only for an approved project and an allowed website.
Protected credentials
Passwords are stored as secure hashes, and important forms use CSRF protection.
Attachment controls
Uploads are limited by type and size and stay associated with a specific project.
Data created during normal support work
Owner account
Name, email, interface language and verification data are used for sign-in and project management.
Visitor messages
Conversation text, technical context and selected form fields are stored so the team can continue the request.
Attachments
Files and images stay within the project and count toward its storage allowance.
Connected channels
Telegram and operator apps use linked identifiers so replies remain in one conversation history.
Public funnel events
When first-party analytics is enabled, Chtio stores the event name, language, page key, path without query parameters, referrer domain and an HMAC hash of a random first-party journey identifier. After sign-up, only completed milestones may be recorded: registration, activation, project creation and project submission. Email addresses, project domains, message text, form values, full IP addresses and the raw identifier are not stored.
How it works
Define the minimum data
Do not ask for information that is not needed to resolve the request.
Update the notice on your website
Explain what is collected, why it is needed and how visitors can ask privacy questions.
Limit team access
Grant only the required project access and review team members regularly.
Division of responsibility
Chtio helps control
- ✓team access to projects
- ✓allowed domains and working tokens
- ✓conversation history and attachments
The website owner must define
- !the lawful basis for processing visitor data
- !retention and deletion rules required by the business
- !privacy and consent wording for the applicable country
Questions about this use case
Are passwords stored in plain text?+
No. The project uses standard secure password hashing and verifies the hash during sign-in.
Can the chat be used for sensitive data?+
Collect the minimum and do not request passwords, payment credentials or documents without a separate protected process and a lawful basis.
Is this page a legal privacy policy?+
No. It is a product transparency overview. Formal policies must include the service owner, applicable law and the actual processing operations.
What is stored during Telegram activation?+
The normalized number is stored encrypted when encryption support and the storage field are available. A protected hash and the last four digits are also kept for uniqueness checks and display.
How does the public funnel identifier work?+
The browser receives a random HttpOnly chtio_journey cookie for up to 90 days. Only its HMAC hash is stored so preview activity can be linked to registration and project creation without keeping an email address or domain. Events are deleted after 180 days by default.
Start with a safe basic workflow
Enter the domain, save the language and create the project with the standard Free appearance. Team access and additional features are configured in the dashboard.
