Privacy Policy

Last updated: September 27, 2026

This Privacy Policy explains what personal data Feedbot collects, why, how long we keep it, who we share it with and what your rights are.

Feedbot is operated by Aleksei Khaliapin, an individual entrepreneur registered in Georgia, Lermontovi St. 12, Batumi, Adjara, Georgia (“Feedbot”, “we”, “us”). Contact for all privacy questions: support@feedbotai.com.

1. Who this policy covers

  • Customers: people and companies who create a Feedbot account. For customer data, we are the controller.
  • Visitors: people who chat with a customer’s chatbot on the customer’s website, app or chat link. For visitor data, the customer is the controller and Feedbot is the processor (see section 6).
  • Website visitors: people who visit feedbotai.com.

2. Data we collect about customers

  • Account data: name, email address, password (stored as a hash), organization name, language and settings.
  • Billing data: plan, subscription status and invoices. Payments are handled by Creem, our Merchant of Record; we don’t receive or store your full card details.
  • Content you add: knowledge base texts, FAQ, imported website pages and uploaded documents, chatbot instructions and settings, action and integration settings. Secrets for actions and integrations are stored encrypted.
  • Usage and technical data: log-ins, API and MCP usage, error logs, IP address and browser information for security and abuse prevention.
  • Communications: emails and messages you send us.

3. Why we use customer data

  • To provide the Service: run your chatbots, process conversations, send notifications and reports (performance of our contract with you).
  • To bill you through Creem and keep accounting records (contract and legal obligations).
  • To keep the Service secure, prevent abuse and fix problems (legitimate interests).
  • To send important service emails (for example about security, billing or changes to terms). Product news only if you agree; you can unsubscribe at any time.

We don’t sell personal data, and we don’t use customer or visitor data to train AI models.

4. Data on feedbotai.com

Our marketing website uses Plausible Analytics (self-hosted), which does not use cookies and does not collect personal data. It counts page views and clicks in aggregate. The demo chatbot on our website works like any customer chatbot (see section 6), with Feedbot as the controller.

5. Cookies and local storage

  • The dashboard uses essential cookies to keep you signed in.
  • The chat widget stores a random visitor ID and the current conversation ID in the browser’s localStorage, so a returning visitor sees their conversation. It doesn’t set tracking cookies and isn’t used for advertising. Visitors can clear it in their browser at any time.

6. Visitor data (Feedbot as processor)

When a visitor uses a customer’s chatbot, we process on the customer’s behalf and on their instructions:

  • chat messages and attachments the visitor sends, and the chatbot’s replies;
  • contact details the visitor chooses to give (such as name, email, phone);
  • identity data the customer passes with identify (such as user ID, email, name and custom metadata);
  • the page URL and title where the chat took place, and the referrer;
  • a hashed IP address (used for rate limiting and abuse protection, not stored in plain form), approximate country, browser language and device type;
  • conversation analysis we generate for the customer (summary, category, priority, lead score, product issues).

The customer decides why and how this data is used and is responsible for informing visitors and having a legal basis. Visitors who want to access or delete their data should contact the company that runs the chatbot; we will help that customer respond. If a visitor contacts us directly, we will forward the request to the customer.

7. Email follow-ups

If a customer turns on email follow-ups and a visitor leaves their email, Feedbot may send that visitor a follow-up email on the customer’s behalf (for example, “we fixed the issue you reported”). Every follow-up email includes an unsubscribe link, and the visitor can also reply STOP to stop further emails. We honor unsubscribes for that customer’s chatbot right away.

8. Sub-processors

We use these providers to run the Service:

Provider Purpose Location
OpenRouter and the AI model providers it routes requests to (such as Google, Anthropic, OpenAI) Generating chatbot answers and conversation analysis USA and other countries
Cloudflare Website and widget hosting (CDN), DNS, security, email routing Global
Hetzner Application servers and databases Germany and Finland (EU)
Email delivery provider (Cloudflare Email or an SMTP provider) Sending account, notification and follow-up emails EU / USA
Creem Payments, taxes and invoices (Merchant of Record) EU / USA
Telegram, Slack, Discord Notifications, only if the customer turns them on Varies
GitHub, Linear and webhooks Issue export and integrations, only if the customer turns them on Varies

We send AI providers only the data needed to generate an answer, such as the conversation, relevant knowledge snippets and instructions. Where providers are outside the EU, transfers rely on standard contractual clauses or equivalent safeguards offered by the provider.

9. How long we keep data

  • Conversations and visitor data are kept while the customer’s account is active, unless the customer deletes them sooner or sets a shorter retention period.
  • After an account is deleted, we delete its data, including knowledge base content and conversations, within 30 days.
  • Backups are rotated automatically; deleted data disappears from backups when they rotate, usually within another 30 days.
  • Billing records are kept as long as tax and accounting laws require.
  • Security logs are kept for a limited time, usually up to 90 days.

10. Security

We protect data with encryption in transit (HTTPS/TLS), encryption of stored secrets, access control and least-privilege access for staff, hashed passwords and API keys, rate limits and abuse filtering, origin allowlists for the widget, HMAC-signed identity and webhooks, and regular backups. No system is perfectly secure; if a breach affects your personal data, we will notify you and, where required, the authorities without undue delay.

11. Your rights

Depending on where you live (for example under the GDPR), you have the right to access, correct, delete or export your personal data, to restrict or object to processing, and to withdraw consent at any time. You can also complain to your local data protection authority.

To use these rights, email support@feedbotai.com. We will reply within 30 days. Customers can also export or delete most data themselves in the dashboard.

12. Children

The Service is not intended for children under 16. Customers must not configure chatbots to target children or collect their data without the required consent.

13. Changes

We may update this policy. We will post the new version here and change the “Last updated” date; for material changes we will notify customers by email or in the dashboard.

14. Contact

support@feedbotai.com. Aleksei Khaliapin, Lermontovi St. 12, Batumi, Adjara, Georgia.