How secure is My Chatbot?

Green Gradient Image
blue gradient

We prioritize the safety of your data and are committed to ensuring that your data remains yours, and not used by us or anyone else.

Is LiveChatAI secure? (TLDR)


Yes, to ensure data security and address the main queries we usually receive:


* We automatically delete your files after they’ve been added to your LiveChatAI (uploaded to OpenAI), unless you explicitly instruct us not to
* Your uploaded (embedded) content (vectors) and reference content (text, author, links, etc.) are stored and encrypted on Pinecone, which is hosted on Google Cloud Platform (GCP) and located in * The Dalles, Oregon, USA (us-west1-gcp). More details are available here: https://www.pinecone.io/security/.


Do you store my documents?


We automatically delete your files after they’ve been ‘embedded’ (uploaded to OpenAI), but the content from them is retained so we can return references to your LiveChatAI answers, unless you explicitly permit us to store your document for reference purposes.
This content is encrypted and stored in an isolated container.


Who sees my documents?


No one else can see your documents or anything you’ve uploaded. The only way others can see your content is if you share access to your LiveChatAI via the share URL, embedding on a website, or providing access through our API.
If you request us to investigate an issue with your LiveChatAI, then we’ll be able to see your content and settings. We’ll only do this if you ask us to.


Where is information stored?


Content you upload is securely stored with Pinecone after it’s been processed by OpenAI (who don’t store it or anything shared via API with them - see here for more: https://openai.com/policies/api-data-usage-policies). We only store the text from your documents and webpages and not the actual file itself.


Who owns the data that is uploaded?


The content and data you upload to the site is exclusively yours. We do not use it for any other purpose apart from providing you with the LiveChatAI service or assisting with any customer support queries you may have. Furthermore, it is deleted when you remove it in the UI.


Who can access my LiveChatAI?


Only individuals with whom you share your LiveChatAI account will have access to your LiveChatAI.
LiveChatAIs are not discoverable unless someone has your link.


Does OpenAI use my model to train its model?


No. OpenAI no longer uses data from others for their training via the API (and hasn’t since 1 March). You can learn more about their data retention policy here: https://openai.com/policies/api-data-usage-policies.


Do I need to add an OpenAI key?


No, unless you are on a Beast plan and choose to use your own key.



Is LiveChatAI GDPR compliant?


We adhere to the following core principles of GDPR as outlined here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/:
We process your data in a transparent, fair, and lawful manner. We outline how we process your content, where it’s stored, and who has access to it. We abide by local laws on personal data storage as well.


We only collect data required for our service and that’s necessary for you to use LiveChatAI. We don’t share your data with any 3rd party that isn’t core to our service, e.g. Pinecone (Secure data storage for your uploads), OpenAI (AI models used to process your uploads and answer questions on your content), Google Analytics (allows us to improve our services). We only keep this data for as long as you want us to and we anonymize it wherever possible.


We make every effort to keep all your data up to date and to make it as easy as possible for you to update, amend or remove any data we hold about you or your account.
We store information about you and your account until you ask us to delete it. We’ll only keep this information for as long as you’re a customer and using our service. If you’d like us to export or delete any data about you, you can always email us.


We use the latest security standards both when your data is in transit (through an API call, for instance) and at rest (when it’s stored in our database). We use bank-grade encryption for all data storage. We also use access and authorization controls to ensure only you can access your data and you have control over who else can access it.


Do you have a SOC-2?


We currently do not have a SOC-2 report, but if this is a requirement for you, let us know ([email protected]) and we may be able to assist.


Are you HIPAA compliant?


We currently cannot prove HIPAA compliance, but if this is a concern for you, let us know ([email protected]) and we may be able to assist.
Can I use LiveChatAI ‘on-premise’ or self-host