Legal

Privacy Policy

Last updated: 25 August 2026

What we collect, why we have it, who else touches it, and how long we keep it. It is longer than a paragraph because the honest version is, but it is written to be read.

The short version. We read the public pages of your website so your chatbot can answer from them. We now also store the questions your visitors ask and the answers your chatbot gave, so you can read them back — that is what section 3 describes, and we said we would tell you here on the day it started.

We do not sell anything to anyone. We do not run ads. We do not build a profile of anyone across websites. We never store a visitor's IP address, only a scrambled version that cannot be turned back. We name every outside company that touches your data, further down this page.

The chat widget that runs on your website contains no analytics and no trackers.

The rest of this page is the same thing said carefully.

1. Who we are

SiteEcho is a product of Nandhakumar Software Labs, an Indian sole proprietorship owned and operated by Nandhakumar S. In this policy, “we”, “us” and “SiteEcho” mean that business. A sole proprietorship is not a separate legal entity from its proprietor.

Email us about anything on this page: support@getsiteecho.com.

Grievance Officer, as required of us under India's IT Rules and the Digital Personal Data Protection Act, 2023: Nandhakumar S, reachable at support@getsiteecho.com. We answer within 30 days.

SiteEcho is one product of that business. Nandhakumar Software Labs publishes umbrella policies covering all of its products at nandhakumar.me/privacy-policy and nandhakumar.me/terms-of-service. This page is the product-specific one for SiteEcho, and where it is more specific than the umbrella policy, this page is the one that describes what actually happens to your data.

2. There are two kinds of people here

This is the most important thing on the page, so it goes first.

If you are a SiteEcho customer — you signed up, you added your website — then we decide what to do with your account data and we answer to you for it. The legal word is that we are the controller.

If you are a visitor to a website that uses SiteEcho — you saw a chat bubble on someone's site and asked it a question — then we are only holding that conversation on behalf of the business whose website you were on. They chose to install us. They decide how long conversations are kept. The legal word is that we are the processor, and they are the controller.

In practice: if you are a visitor and you want your conversation deleted, the business that owns the website is the right place to ask. You can still write to us and we will help — but we will normally need to check with them first, because it is their data, not ours to give away.

If you are a customer, that also means something about you: you are responsible for telling your own visitors that a chatbot is there and that conversations are recorded. Section 11 gives you wording you can copy.

3. What we collect, and why

If you have an account with us

WhatWhy we have it
Your name and email addressTo create your account, sign you in, and email you about it
How you sign inSign-in is handled by Supabase Auth. Your password never reaches our servers — we only ever see a signed token saying it is you
Your workspace and chatbot settingsIt is the product

If you are on a paid plan or a trial, payment is handled by Stripe. Your card number never reaches our servers — the payment form belongs to Stripe, and the card, your billing name and address, and any tax ID you enter are held by them, not by us. We could not show you your own card number if you asked.

What we store is a short record of which plan you are on: an identifier for you at Stripe, an identifier for the subscription, the plan name, whether it is trialing, active, past due or cancelled, when the current period ends, and whether you have asked it to stop renewing. That is the whole of it — there is no card, no billing address and no tax ID in our database. Stripe is named in the table below.

The pages of your website

When you add a website we fetch its public pages and keep the text of each page with its address and title, plus a numeric fingerprint of each chunk of that text. The fingerprint is what makes searching work. It is a long list of numbers, not readable as text — but it was derived from your text, so we treat it as your content.

We only fetch pages that are publicly reachable. We check your site's robots.txt before fetching a page and skip anything it tells us not to fetch. We do not log into anything, we do not fill in forms, and we do not follow links behind a password.

What your visitors say to your chatbot

  • the question, and the answer we gave
  • which of your pages the answer came from
  • the time, and which chatbot it was
  • the website address the widget was loaded on

This is stored now. Until recently a question was answered and forgotten the moment the answer finished streaming. It is now kept, so you can read your conversations back, see what people ask, and see what your website failed to answer — which is the useful part. The list above is exhaustive: we do not record a visitor's location, device, browser, or which page they were on.

Your visitors can mark an answer helpful or unhelpful. That is a single up or down against one answer, visible to you and to us. It is not linked to anything about the person who gave it.

Visitors should not type personal or sensitive information into a chat box, and your chatbot should never ask for any. If a visitor types their email address into a message, it gets stored inside the message like any other text. We cannot detect that in advance.

The technical bits

IP addresses. We need some way to stop one person sending ten thousand messages and running up your bill. So before an IP address is written anywhere — to our rate-limit store, to a log line, to disk — we run it through a keyed one-way function (HMAC-SHA-256) and keep only the scrambled result. That is enough to recognise the same visitor twice within a few minutes. It cannot be reversed into an IP address, and changing the key makes every old value meaningless. We do not store raw IP addresses.

Session tokens. The widget gets a short-lived token so a conversation can continue across messages. We store only a hash of it, and it expires after 4 hours. It is not an advertising identifier and does not follow anyone to another website.

Server logs. Ordinary web-server logs — request path, status code, timing, scrambled IP. Held briefly by our hosting provider and then discarded on their schedule; we do not archive them ourselves.

The free preview on our homepage

Anyone can paste a web address into our homepage and get a working chatbot without signing up. When that happens we temporarily keep the address you typed, the text of the few pages we read, and the messages you sent to the preview.

All of it is deleted automatically 30 minutes after the preview starts. It is not attached to any account, because there is no account. We do keep a record that some address was previewed so we can count how many people try the tool — so treat the address itself as recorded, and do not paste a private or unlisted URL into the preview.

The waitlist

Before plans open, our pricing buttons collect an email address. We store the email, which plan you clicked, and the date. We use it for one thing: to email you when plans open. Every email has an unsubscribe link.

Our marketing website

getsiteecho.com uses Vercel Web Analytics. It counts page views and where they came from. It sets no cookies and does not identify individual people.

It is not in the widget. The widget script that runs on your website contains no analytics of any kind. Loading a third-party tracker into someone else's website would contradict the entire product, so we do not do it — and we would tell you loudly if that ever changed.

4. What we do not do

  • We do not sell personal data. There is no version of this where we sell it.
  • We do not run advertising, and we do not let anyone advertise through us.
  • We do not track anyone across different websites.
  • We do not use your website content, or your visitors' conversations, to train any AI model — not ours, and not anyone else's.
  • We do not read your conversations out of curiosity. Our staff can technically reach the database, and will only look at your data when you ask us for support, or when something is broken and we cannot fix it otherwise.

5. The other companies involved

Running this needs other people's infrastructure. Every company that stores or handles data for us is listed here. We think naming them is the minimum honest thing to do.

CompanyWhat they do for usWhereWhat they see
OpenAITurns your page text into searchable fingerprints, and writes the answersUnited StatesChunks of your page text, and the visitor's question
SupabaseOur database, and sign-inUnited States (us-east-1)Everything stored: accounts, page content, and your visitors' conversations. Also your password, which we never see
RenderRuns our application serversVirginia, United StatesData while it is being processed
VercelHosts our website and dashboardGlobal edge networkMarketing-site page views
Render Key ValueShort-term queue and rate-limit countersVirginia, United StatesScrambled IPs and job references. No conversation content
CloudflareStores our weekly encrypted database backup (R2)United StatesA copy of everything in the database, including your account details and page content
StripeTakes payments and holds our billing recordsUnited StatesYour card details, billing name and address, tax ID if you enter one, and your invoices. We never see the card number

About OpenAI specifically, because it is the one people ask about: under OpenAI's API terms, content sent through their API is not used to train their models. They keep it for up to 30 days to check for abuse, then delete it. We use their API, not ChatGPT.

We will not add a new company to this list without updating this page. If you are on a paid plan we will email you at least 30 days before a new one starts handling your data, so you have time to object or leave.

6. Where your data lives

Our business is in India. Our servers and our database are in the United States. So wherever you are, your data crosses a border to reach us.

We rely on Standard Contractual Clauses in our agreements with the companies in Section 5 to cover those transfers. If you need a copy for your own records, ask us.

7. How long we keep things

WhatHow long
Your account and settingsWhile your account is open
Your website content and its fingerprintsUntil you delete the chatbot, or delete your account — either removes them immediately
Conversations with your chatbotWhile the chatbot exists. Deleting the chatbot deletes them immediately
A visitor's helpful/unhelpful ratingWith the answer it belongs to
Preview conversations30 minutes, with the preview that holds them
Preview sessions30 minutes, then deleted automatically
Waitlist emailsUntil you unsubscribe or ask us to remove it
Scrambled IPs in the rate limiterMinutes. They expire with the counter
Server logsOur hosting provider's retention period; not archived by us
Weekly database backup (Cloudflare R2)90 days, then deleted automatically by a bucket rule
Invoices and payment recordsAs long as Indian tax law requires. Held by Stripe. These are the one thing we cannot delete on request

When you close your account — the Delete account button on your account page — your chatbots stop answering immediately and everything under them is deleted straight away: the pages they read, the fingerprints, and every conversation your visitors had with them. There is no waiting period and nothing for you to ask us for. Two honest limits: a copy may persist in the weekly backup above until it ages out, and your sign-in itself is not deleted, so the same email can sign up again and get a new, empty account.

If you were paying, your subscription is cancelled at Stripe before anything is deleted, so closing your account stops the billing. If we cannot reach Stripe to cancel it, we stop and delete nothing rather than leave a subscription charging a card for an account that no longer exists. Your invoices stay with Stripe, as the row above says.

8. Keeping it safe

What we actually do, rather than adjectives:

  • Everything travels over HTTPS.
  • Your widget only answers on the exact web addresses you list. Not a pattern, not a wildcard — the exact address. Someone who copies your widget code onto their own site gets nothing.
  • Session tokens are stored as hashes, never in the clear.
  • IP addresses are scrambled before storage, as described above.
  • Rate limits sit on every path that costs money, at several levels at once. If our rate-limit store is unreachable, requests are refused rather than let through.
  • We never handle your password at all. Sign-in goes through Supabase Auth, which stores it hashed on our behalf. We could not tell you your password if we wanted to, because we have never had it.

No system is perfectly safe, and it would be dishonest to claim otherwise. If your data is ever exposed in a breach, we will email you within 72 hours of finding out, and tell you what happened and what we are doing about it — even when it makes us look bad.

9. What you can ask us to do

Wherever you are, you can ask us to:

  • show you everything we hold about you
  • correct anything wrong
  • delete it
  • hand it over in a portable file
  • stop using it for a particular purpose
  • withdraw consent you gave earlier
  • complain if you think we handled it badly

Write to support@getsiteecho.com. We reply within 30 days, free. If we need to check it is really you, we will ask — that is a protection, not an obstruction.

In India, the Digital Personal Data Protection Act, 2023 also lets you nominate someone to exercise these rights if you die or become incapacitated, and lets you complain to the Data Protection Board of India if our answer does not satisfy you.

In the EU or UK, our legal grounds are: performing our contract with you, legitimate interests (keeping the service secure and stopping abuse), consent (marketing email, which you can withdraw at any time), and legal obligation (tax records). You can complain to your national data protection authority.

In California, we do not sell or share personal information as those words are defined there, so there is nothing to opt out of.

10. Children

SiteEcho is for businesses. You must be 18 or over to hold an account. We do not knowingly collect data from children.

If you are a customer and your website is aimed at children, you are responsible for the rules that come with that — including India's DPDP Act, which requires verifiable parental consent for anyone under 18, and COPPA in the United States. We do not have a mechanism for parental consent, so a chatbot on a site aimed at children is not something we can currently support.

11. If you are a customer, put this in your own policy

You installed a chatbot that records conversations. Your visitors need to be told. You are welcome to use this wording:

This website uses a chat assistant provided by SiteEcho. Questions you ask it and the answers it gives are stored so we can improve the information on this site. A scrambled version of your IP address is used to prevent abuse; your actual IP address is not stored. Please do not enter personal or sensitive information into the chat. SiteEcho's privacy policy: getsiteecho.com/privacy

If you are in the EU or UK you need a data processing agreement with us. It is included on the Growth plan and available on request on Starter — just email us.

12. Changes

If we change something small, we update the date at the top. If we change something that actually affects you, we email every customer at least 30 days before it takes effect and say plainly what changed. We do not quietly rewrite this page.

13. Contact

support@getsiteecho.com — privacy questions, data requests, complaints, and the Grievance Officer all arrive at the same inbox, because there is one of us and pretending otherwise would be theatre.

Nandhakumar Software Labs, India.