How we handle your data
Chatevo processes customer content, conversation data, and credentials to deliver AI assistant functionality. This page summarizes what we collect, how we use it, and how long we keep it.
Data categories
Section titled “Data categories”| Category | Examples | Purpose |
|---|---|---|
| Account data | Email, name, organization, billing | Authentication, support, invoicing |
| Configuration | Assistants, prompts, KB metadata, tools | Operating your assistants |
| Knowledge content | Uploaded PDFs, crawled pages, embeddings | Retrieval-augmented answers |
| Conversations | Visitor messages, assistant replies, citations | Chat functionality, analytics |
| Credentials | API keys, OAuth tokens for your tools | Server-side tool calls only |
| Telemetry | API logs, error reports, usage metrics | Reliability and billing |
Data use
Section titled “Data use”We use your data to:
- Index and search knowledge bases for accurate answers
- Execute tool calls against your configured APIs
- Stream widget and Direct API responses
- Generate usage and audit reports in your dashboard
- Improve platform reliability (aggregated, non-content metrics)
We do not use your knowledge base content or conversations to train foundation models shared across customers.
Multi-tenant isolation
Section titled “Multi-tenant isolation”Every organization’s data is logically isolated:
| Layer | Isolation |
|---|---|
| Storage | Organization-scoped namespaces and row-level access |
| Search indexes | Per-organization vector and keyword indexes |
| Compute | Requests tagged with organization ID; cross-tenant access blocked |
| Credentials | Encrypted blobs scoped to creating organization |
Retention
Section titled “Retention”| Data type | Default retention | Configurable |
|---|---|---|
| Conversations | 90 days | Pro+ custom retention |
| Knowledge documents | Until deleted by you | — |
| Audit logs | 1 year | Enterprise extended |
| Backups | 30 days encrypted | Enterprise options |
Delete resources in the dashboard or via API to remove them from active storage. Backup purging follows the backup retention window.
Subprocessors
Section titled “Subprocessors”Chatevo uses vetted cloud providers for hosting, model inference, and email. Enterprise customers receive a subprocessor list with the DPA.
Your responsibilities
Section titled “Your responsibilities”- Only upload content you have rights to use
- Configure allowed domains on widget deployments
- Rotate API keys and tool credentials regularly