Agent AI Chat
Terms of ServicePrivacy PolicyData Processing AddendumDocumentation

Privacy Policy

Last updated: 12 August 2026

Draft — pending legal review. This document was prepared to reflect the actual data flows in the product and has not yet been reviewed by a lawyer. Do not treat it as final until reviewed by qualified counsel, particularly regarding GDPR representative/DPO requirements if EU visitor volume becomes significant.

1. Who this policy covers

This policy explains how Agent AI Chat, operated by Zihad Hosan (Bangladesh), handles personal data. It covers two groups differently:

  • Customers — the businesses and individuals who sign up for an account to configure and embed the chat widget. For Customer account data, we act as the data controller.
  • End visitors — people who chat with a widget embedded on a Customer's website. For the messages they send through the widget, the Customer is the data controller and we act as their data processor, under the terms of our Data Processing Addendum.

2. Data we collect from Customers

  • Account data: email address, hashed password, workspace/tenant name
  • Content you configure: business information, FAQs, widget settings
  • Billing data: handled by Lemon Squeezy (our billing partner and Merchant of Record) — we receive subscription status and renewal dates, not full card details
  • Usage data: session and chat volume, for the analytics shown on your dashboard and for abuse prevention

3. Data we process on behalf of Customers (end-visitor chat data)

When someone chats with an embedded widget, we process the messages they send and the AI-generated replies in order to run the conversation and generate grounded answers. This includes sending message content to our LLM provider (see Section 6) to generate a response. We do not knowingly use end-visitor chat content to train models, and we do not sell it.

4. How we use data

  • To provide, maintain, and secure the Service
  • To generate AI responses grounded in a Customer's configured content
  • To process payments and manage subscriptions
  • To respond to support requests
  • To meet legal obligations

We do not sell personal data, and we do not use it for third-party advertising.

5. Where data is stored

Application data (accounts, content, chat sessions and messages) is stored in a managed Postgres database hosted in the AWS eu-west-2 (London) region. Application hosting runs on Vercel's global infrastructure.

6. Sub-processors

We use the following sub-processors to operate the Service:

  • Neon — managed Postgres database hosting (AWS eu-west-2, London)
  • Vercel — application hosting and deployment
  • OpenRouter — LLM API provider; receives chat message content and Customer-configured content to generate AI responses
  • Lemon Squeezy — billing, payment processing, and tax compliance (Merchant of Record)

The full list with roles is in the Data Processing Addendum. We'll update this list if sub-processors change.

7. Data retention

  • Customer account data: retained while the account is active, deleted within 30 days of account deletion
  • End-visitor chat sessions and messages: retained while the Customer's account is active; deleted when the Customer deletes the content, the chat session, or their account
  • Billing records: retained as required by applicable tax and accounting law, independent of account deletion

8. Your rights

Depending on where you're located, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Customers can exercise these rights for their own account data via their dashboard or by contacting us. End visitors should direct data requests about their chat data to the website operator (the Customer) they chatted with, who can in turn request deletion or export from us as their processor. You can also contact us directly at hello@zihadhosan.dev and we will route the request appropriately.

9. Account and data deletion

Deleting a Customer account triggers erasure of that tenant's data — content, FAQs, chat sessions and messages, and account records — from our production database. This is a manual, verified process today pending fuller self-service tooling.

10. Security

Passwords are hashed, not stored in plain text. Access to production data is limited to the operator. Data in transit is encrypted (HTTPS/TLS). No method of storage or transmission is 100% secure, and we can't guarantee absolute security.

11. Children's data

The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If a Customer configures a widget for a website directed at children, they are responsible for ensuring that use complies with applicable law (e.g. COPPA, GDPR-K).

12. International transfers

Data may be processed in Bangladesh (by the operator) and in the hosting regions of our sub-processors (primarily the EU/UK for database storage, and the US for some sub-processors). Where required, we rely on our sub-processors' own transfer safeguards (e.g. Standard Contractual Clauses).

13. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app notice before taking effect.

14. Contact

Questions or data requests: hello@zihadhosan.dev.