Version 2026-09-17 · Published September 17, 2026

Privacy notice

Download this version

Conversation contact profile — September 22, 2026 supplement

This update replaces the September 21 form behavior described below. Before the first message in each new conversation, the chatbot asks for your name and email address. Phone number and organization are optional. You may provide an international phone number, such as +61 for Australia. Previously supplied details may be offered for review, but a new conversation requires your confirmation and consent.

With your consent, the chatbot operator and its configured AI service receive the supplied profile to personalize responses in this conversation. The AI can refer to your name, email, phone or organization while you chat. These details are self-reported, not instructions to the AI or proof of identity. The AI is not given another conversation’s profile in place of your confirmation.

Contact collection is required even when OTP is off. Submitting the form does not send a verification code. When OTP is enabled, the separate verification step may request a code after four accepted messages. Only an email address or phone number with a matching completed code check is marked verified; name and organization remain self-reported. Consent is not marketing permission. CAPTCHA and message limits keep their separate settings.

Newten records the conversation profile, consent version and time. Authorized workspace owners and admins can view, export or erase these records in Visitor contacts. Contact records expire after 90 days, subject to the existing cleanup process described below. Profile erasure stops the form details from being supplied to future AI responses; it does not remove details already present in conversation messages or generated replies, or erase separately saved leads, exports, provider records or backups.

You can choose “Not now” without sending your pending message. For access, correction or erasure requests, contact [email protected] and identify the chatbot or workspace; do not send verification codes. The downloadable September 17 notice remains unchanged.

Previous visitor contact collection — September 21, 2026 supplement

The September 22 conversation-profile supplement above supersedes this earlier form behavior, including when details are collected and their use by the AI.

This section explains contact collection when a chatbot administrator turns off one-time-code (OTP) verification. It supplements the in-chat contact section below. The downloadable September 17 notice remains available unchanged.

After four accepted messages, participating chatbots request your name, email address and consent. You may also provide a phone number in international format, such as +61 for Australia. With OTP off, no verification code is sent and no contact method is marked verified. Your details are self-reported and are not proof of identity or marketing consent.

The chatbot operator uses these details to associate contact information with your chat. Newten records your consent version and time. The form keeps these details separate from the model prompt; details you type into ordinary chat become part of the conversation. You may choose “Not now” without sending the pending message.

Authorized workspace owners and admins can view, export or erase these records through Visitor contacts. Unverified contact records expire 90 days after collection; verified records expire 90 days after verification. Expired records are excluded from the contact list. Cleanup runs in batches every 15 minutes while the service runs, so outages or a backlog may delay physical removal.

Unverified addresses and numbers do not link different visitors together. Erasure of an unverified record clears that visitor’s collected form details. It does not erase conversations, separately saved leads, exports, provider records or backups, and does not reset message limits. If OTP is later required, the visitor must verify an offered method before continuing beyond the initial allowance.

CAPTCHA is controlled separately. When enabled, Cloudflare processes the technical data needed for its bot check. Turning off OTP does not turn off CAPTCHA or message limits. For access, correction or erasure requests, contact [email protected] and identify the chatbot or workspace; do not send verification codes.

Who operates Chyt.ai

Chyt.ai is a product developed by Thompson Consulting.

Service operator: THOMPSON CONSULTING (OPC) PRIVATE LIMITED.

Registered office: A5, S. No. 16/2, First Floor, Swapnamandir Society, Deccan Gymkhana, Pune, Maharashtra 411004, India. CIN: U62010PN2026OPC251118.

For privacy questions, access, correction, withdrawal or deletion requests, contact [email protected]. Include the chatbot URL or workspace name and what you want us to handle. Do not send passwords, verification codes or identity documents in your initial request.

For a chatbot run by another organization, that organization decides its chatbot’s purpose and is responsible for its own privacy notice. Chyt processes its chatbot data to provide the service. Contact that operator first; we can help route requests. This notice does not authorize that operator to use your details for unrelated purposes.

Information used to provide the service

We process account and workspace details, authentication records, uploaded documents and connected knowledge sources, chatbot conversations and attachments, and operational, billing and usage records. These support account access, chatbot answers, configured integrations, security, support and plan limits.

Relevant conversation messages and source excerpts are sent to the configured AI provider to generate answers. Voice features process audio and transcripts through configured voice services. Avoid submitting information you do not want the chatbot operator or its service providers to process.

Cloudflare provides bot protection and receives technical data needed for that check. Our hosting, database and configured messaging providers process information needed for their services. External processing may occur outside India; we do not promise that every provider keeps all data in India. Provider contracts and settings affect their handling and retention.

Account terms and privacy acknowledgements

When you affirmatively accept the account terms, we record your account identifier (or verified demo identifier), the Terms of Service and Privacy Notice versions, fingerprints of those documents, the server-recorded acceptance time and the account-entry method. We use this record to establish which documents you accepted, administer access, handle disputes and meet legal obligations. The acknowledgement is separate from chatbot visitor contact consent and does not opt you into marketing.

Acceptance records are append-only through the application and access is restricted. No earlier account is marked as having accepted a newer version without a fresh affirmative action. We do not collect an additional IP address or browser user-agent in this acceptance receipt. Other security and operational systems may separately process technical data as described in this notice.

Agreement records are retained separately from chatbot and contact content. There is currently no automatic deletion deadline for these records. Contact us for a copy, correction or erasure request; we will assess the request, any applicable legal retention or dispute needs, and the appropriate handling. Deleting a chatbot or workspace does not automatically erase agreement records.

Billing and tax records

Billing name, email, address, State, recipient type and optional GSTIN are used to prepare invoices and tax records. Issued invoice details are preserved, and tax records are retained as required by applicable law; deleting a workspace does not automatically erase them.

In-chat contact verification

This feature is being rolled out. The following applies when a chatbot asks you to complete its verification form; not every chatbot has enforcement enabled yet.

The form collects your name, email address, chosen verification method, and affirmative consent with its version and time. WhatsApp and SMS verification also require your phone number; email verification does not collect a phone number. These details support contact verification, abuse prevention and visitor message limits. Only the method you choose for the code is verified. A verified code does not establish your legal identity or verify the other contact method.

If you choose WhatsApp, your phone number and verification message are sent through Meta’s WhatsApp service. SMS fallback, when available, uses MSG91 to send and verify a code to your phone number. Email verification, when available, sends the code through Amazon SES. Only the method you select is verified; verifying a phone number does not verify your email address. Form details and codes are handled separately from the model prompt; if you type those details into ordinary chat, they become part of that conversation.

Authorized workspace owners and admins can view and export verified contact records. The form is not marketing consent. You may choose “Not now” without sending the pending chat message. Where verification is required, continuing beyond the initial four accepted messages requires completion of the form.

Active contact records expire 90 days after verification and are excluded from the admin contact list at expiry. Automated cleanup runs in batches every 15 minutes while the service is running, and expired records are also cleared when their visitor state is checked. Outages or a cleanup backlog may delay physical removal. Erasure also clears linked records for the same verified contact within that chatbot.

Pending verification details expire after 10 minutes. Abuse-prevention counters are short-lived. Erasure clears the form’s name, email, phone and consent fields but does not replenish the daily allowance. A keyed, pseudonymous contact link remains effective only until the next UTC day and is then eligible for cleanup. Visitor identifiers and message-admission records remain to enforce usage limits; they are not anonymous data.

Export, erasure and contact-retention events record the acting administrator where applicable, record identifiers, time and affected count—not copies of the contact fields. These audit events are eligible for cleanup after 365 days.

Your choices, correction and erasure

You can decline the contact form, ask the chatbot operator to export or erase your verified contact record, or contact us using the address above. We may need proportionate verification before disclosing or changing records. Correcting a verified contact requires erasure and fresh verification; erasure does not reset message limits or grant marketing permission.

Erasing a verified contact is not the same as erasing conversation history, source documents, AI-extracted leads, downloaded exports, provider records or backups. Copies of the same details can remain in those separate stores. Ask explicitly if your request covers them too. Automated permanent deletion across all stores is not yet available; we will explain the scope, any lawful retention and expected handling before claiming completion.

Contact verification is not designed to obtain parental or guardian consent. Operators must not use this form as a substitute for a lawful children’s-data or guardian-consent process.

Browser storage and security

The chat uses browser storage for session continuity and a signed visitor identifier scoped to the chatbot and deployment. Visitor continuity tokens expire after 30 days unless renewed. The token is not a workspace login or permission to retrieve private conversation history. Clearing storage or using another browser may require verification again.

Workspace permissions and server-side checks restrict contact access. No online service can guarantee absolute security. Removing a source or chatbot in the dashboard is not a promise of immediate permanent removal from every store or backup.

Other account, content, conversation and backup retention schedules are not covered by the contact-record schedule above. If you require a fixed deletion deadline or data-processing agreement, confirm it with us before uploading the affected data. This notice does not waive rights that applicable law gives you.

Service and security information · Terms of Service