Privacy Policy

Last updated: July 11, 2026

1. Overview

This policy explains how KeyChat ("we", "us") collects, uses, and shares information when you use our customer-messaging platform (the "Service"). It covers both the business users who operate KeyChat workspaces and, where we act on a workspace's behalf, the end customers who message those businesses.

2. Information we collect

  • Account information — name, email address, password (stored as a hash), and workspace details you provide at signup.
  • Workspace content — messages exchanged with your customers on connected channels, contact details of those customers, knowledge-base documents, message templates, appointment details, and agent configuration.
  • Connection credentials — API keys and tokens for the channels and AI providers you connect. These are encrypted at rest.
  • Billing information — subscription plan and status. Payment card details are collected and stored by Stripe, our payment processor; we never see full card numbers.
  • Usage and log data — technical logs (such as IP addresses, timestamps, and request metadata) used for security, rate limiting, and troubleshooting.

3. How we use information

  • To provide the Service: routing messages between channels, generating AI responses, booking appointments, sending campaigns, and powering the team inbox.
  • To operate accounts and billing, send service emails (such as password resets and billing notices), and provide support.
  • To secure the Service: authentication, abuse prevention, rate limiting, and audit logging.
  • To understand aggregate product usage and improve the Service. We do not sell personal information or use your workspace content for advertising.

4. AI processing

When an AI employee responds to a conversation, relevant message content and knowledge-base excerpts are sent to the AI provider configured by the workspace (such as Anthropic or OpenAI) using the workspace's own API key. That processing is governed by the provider's terms and data policies applicable to the workspace's provider account. We do not use your conversations to train AI models.

5. When we share information

We share information only as needed to run the Service:

  • Messaging platforms you connect (for example Meta for WhatsApp, Messenger, and Instagram, or Telegram) — to deliver and receive your messages.
  • AI providers you configure — to generate responses, as described above.
  • Service providers — hosting and infrastructure, Stripe for payments, and our email delivery provider for transactional email.
  • Legal reasons — when required by law, or to protect the rights, safety, and security of KeyChat, our users, or the public.
  • Business transfers — if we are involved in a merger, acquisition, or asset sale, information may transfer subject to this policy.

6. Data on behalf of workspaces

For messages and contact data belonging to a business's end customers, we act as a processor/service provider on that business's instructions. If you are an end customer of a business using KeyChat, contact that business directly for privacy requests about your conversation data; we will support the business in fulfilling them.

7. Security

  • Channel credentials, provider API keys, and other secrets are encrypted at rest (AES-256-GCM).
  • Passwords are stored only as salted hashes; sessions use signed tokens.
  • Traffic to and from the Service is encrypted in transit (TLS).
  • Workspace data is isolated per tenant; access within a workspace is role-based.

No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.

8. Data retention and deletion

We retain workspace data for as long as the workspace is active. When a workspace is deleted, its content — conversations, contacts, knowledge documents, credentials — is deleted from our production systems within a reasonable period, subject to limited retention in backups and logs that expire on a rolling basis, and to records we must keep for legal or accounting purposes.

9. Your rights

Depending on your location, you may have rights to access, correct, export, restrict, or delete your personal information. Workspace owners can edit most account and workspace data directly in the app. For anything else, contact us at support@keychat.app and we will respond within the timeframes required by applicable law.

10. Cookies and local storage

The web app uses browser local storage for essentials only: your session token and interface preferences (such as theme). We do not use advertising cookies or third-party tracking on the Service.

11. Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children; if you believe a child has provided us information, contact us and we will delete it.

12. International transfers

Our infrastructure and service providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.

13. Changes and contact

We may update this policy from time to time; material changes will be announced by email or in the app before they take effect. Questions or requests: support@keychat.app. See also our Terms of Service.