Skip to content

How we handle your data

Chatevo processes customer content, conversation data, and credentials to deliver AI assistant functionality. This page summarizes what we collect, how we use it, and how long we keep it.

CategoryExamplesPurpose
Account dataEmail, name, organization, billingAuthentication, support, invoicing
ConfigurationAssistants, prompts, KB metadata, toolsOperating your assistants
Knowledge contentUploaded PDFs, crawled pages, embeddingsRetrieval-augmented answers
ConversationsVisitor messages, assistant replies, citationsChat functionality, analytics
CredentialsAPI keys, OAuth tokens for your toolsServer-side tool calls only
TelemetryAPI logs, error reports, usage metricsReliability and billing

We use your data to:

  1. Index and search knowledge bases for accurate answers
  2. Execute tool calls against your configured APIs
  3. Stream widget and Direct API responses
  4. Generate usage and audit reports in your dashboard
  5. Improve platform reliability (aggregated, non-content metrics)

We do not use your knowledge base content or conversations to train foundation models shared across customers.

Every organization’s data is logically isolated:

LayerIsolation
StorageOrganization-scoped namespaces and row-level access
Search indexesPer-organization vector and keyword indexes
ComputeRequests tagged with organization ID; cross-tenant access blocked
CredentialsEncrypted blobs scoped to creating organization
Data typeDefault retentionConfigurable
Conversations90 daysPro+ custom retention
Knowledge documentsUntil deleted by you
Audit logs1 yearEnterprise extended
Backups30 days encryptedEnterprise options

Delete resources in the dashboard or via API to remove them from active storage. Backup purging follows the backup retention window.

Chatevo uses vetted cloud providers for hosting, model inference, and email. Enterprise customers receive a subprocessor list with the DPA.

  • Only upload content you have rights to use
  • Configure allowed domains on widget deployments
  • Rotate API keys and tool credentials regularly