Legal
Privacy Policy
Last updated: July 18, 2026
Introduction and scope
Zorachat ("Zorachat," "we," "us," or "our") provides an AI-powered customer-support platform with hosted assistants, chat widgets, knowledge tools, AI-provider routing, lead capture, conversation management, live-agent features, cloud services, and integrations (collectively, the "Service").
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our website, create or use an account, configure or deploy an assistant, connect a website or external service, interact with a Zorachat-enabled assistant, use cloud-connected features, or otherwise use the Service.
Our privacy roles
Zorachat acts as a controller for personal information used for our own website, account administration, billing, security, legal compliance, support, and direct customer relationships.
When an organization uses Zorachat to process conversations, leads, knowledge content, or other information on its instructions, that organization is generally the controller or business and Zorachat generally acts as its processor or service provider. The organization decides why the information is processed, what the assistant collects, which integrations are enabled, and how the information is used.
The exact legal roles may vary by jurisdiction and use case.
Information we collect and process
Depending on how the Service is used and configured, we may collect or process:
- Account and contact information: name, email address, company name, job or team information, account identifiers, authentication information, communication preferences, and support correspondence.
- Billing and plan information: subscription details, credit purchases and usage, plan limits, transaction records, invoices, billing contact information, and payment status. Payment providers process payment-card information; we do not intentionally store full payment-card numbers on our servers.
- Workspace and assistant configuration: assistant names, instructions, prompts, branding, widget settings, supported channels, team permissions, provider selection, handoff rules, and other configuration choices.
- Knowledge and business content: website content, URLs, FAQs, custom text, documents, uploaded PDFs, extracted document text, product or service information, policies, and other materials selected for use by an assistant.
- Conversation and lead information: visitor messages, generated responses, conversation identifiers and status, enabled attachments, lead details, available contact information, handoff summaries, agent messages, notes, and actions.
- Connected-site and integration information: website URL, site name, company name, administrator or account email, platform and software versions, API or REST endpoints, connection identifiers, status information, and configuration metadata.
- Provider and integration credentials: API credentials, tokens, channel identifiers, or authentication material supplied for an AI provider, messaging platform, cloud connection, or other enabled integration.
- Widget and request information: IP address, browser or device information, referring page, timestamps, standard HTTP request information, delivery metadata, and security information generated when a browser requests or uses a widget or related asset.
- Usage, diagnostic, and security information: feature usage, event timestamps, request and response status, error details, log information, IP address, device and browser details, and information used to authenticate users, maintain performance, investigate incidents, and prevent abuse.
- Cookies and similar technologies: identifiers and preference information used on our website and dashboard as described below.
Sensitive information
Please do not submit sensitive personal information, special-category data, confidential credentials, or regulated information in conversations or knowledge content unless you have determined that doing so is lawful and appropriate.
Sources of information
We receive information:
- directly from customers, account holders, administrators, agents, visitors, and support requesters;
- automatically from browsers, devices, servers, APIs, widgets, and connected platforms;
- from websites, documents, systems, and channels that an administrator chooses to connect or synchronize; and
- from AI providers, payment providers, messaging platforms, and other services used to operate enabled features.
How we use information
We use information to:
- provide, configure, operate, maintain, and support the Service;
- create and manage accounts, workspaces, assistants, teams, plans, and permissions;
- deliver widgets and respond to visitor requests;
- route AI requests to a selected provider and return generated responses;
- ingest, index, retrieve, and synchronize selected knowledge content;
- provide Zora credits, managed AI replies, cloud monitoring, mobile live-agent functions, push notifications, and human handoff;
- operate integrations selected by an administrator;
- store and present conversations, leads, account information, and usage information to authorized users;
- process subscriptions, credits, invoices, and account communications;
- authenticate requests, enforce usage limits, prevent fraud and abuse, protect security, and investigate incidents;
- diagnose errors, maintain performance, and improve the reliability and functionality of the Service;
- respond to support requests and send important service notices;
- comply with legal obligations and enforce our Terms; and
- send marketing communications where permitted, subject to available choices and opt-out rights.
AI processing and automated output
The Service uses automated systems, including large language models, to generate responses based on a visitor's message, assistant instructions, selected knowledge, conversation context, and administrator configuration.
AI output may be inaccurate or inappropriate. Zorachat is intended to support customer communication and human handoff, not to make decisions producing legal or similarly significant effects without appropriate human review.
When an administrator selects an external AI provider and supplies its credential, supported requests are routed first through api.zorachat.ai and then forwarded to the selected provider. Zorachat processes the selected credential and request information as necessary to authenticate and relay the request. Third-party AI providers process information under their own terms and privacy policies.
Zorachat Cloud Services
When an administrator connects Zorachat Cloud Services for Zora credits or another cloud-connected feature, we may process account and site information, assistant configuration, visitor messages, knowledge context, generated replies, lead information, enabled attachments, conversation metadata, usage and credit information, and data needed for monitoring, notifications, human handoff, abuse prevention, billing, and account management.
Cloud-connected features may include managed AI replies, hosted knowledge processing, mobile live-agent support, push notifications, account and plan management, and other features presented at the time of configuration.
External providers and integrations
Depending on an administrator's configuration, information may be processed by:
- Zorachat API relay and cloud services: https://zorachat.ai/privacy-policy
- OpenAI API: https://openai.com/policies/privacy-policy/
- Google Gemini API: https://policies.google.com/privacy
- Anthropic Claude API: https://www.anthropic.com/legal/privacy
- Slack: https://slack.com/trust/privacy/privacy-policy
- Telegram: https://telegram.org/privacy
Integration authorization
We may also use hosting, content-delivery, security, analytics, communications, payment, email, and push-notification providers to operate the Service.
Enabling an optional provider or integration authorizes the exchange of information reasonably necessary to operate it. This may include conversation content, identifiers, lead details, available contact details, handoff summaries, attachments, credentials, and notification metadata. Administrators are responsible for reviewing the terms and privacy practices of the providers they select.
Legal bases
Where applicable law requires a legal basis, we rely on one or more of the following depending on the context:
- performance of a contract, including providing accounts, subscriptions, support, AI routing, and configured cloud features;
- legitimate interests, including securing and improving the Service, preventing abuse, communicating with customers, and operating our business, where those interests are not overridden by individual rights;
- consent, where required for optional communications, cookies, or a particular processing activity;
- compliance with legal obligations; and
- protection of vital interests or establishment, exercise, or defence of legal claims where applicable.
Customer legal bases
For personal information processed on behalf of a customer, that customer determines the applicable legal basis and is responsible for providing notices and obtaining consent where required.
Customers, visitors, and data requests
Customers determine what information their assistants collect, which knowledge sources are connected, which providers and integrations are enabled, and how locally controlled records are retained. Customers are responsible for:
- providing accurate privacy notices to their visitors and users;
- establishing an appropriate lawful basis and obtaining consent where required;
- limiting collection to information necessary for the configured purpose;
- configuring suitable access and retention controls;
- responding to requests concerning information under their control; and
- reviewing the terms and privacy practices of enabled external providers.
Visitor data requests
If you interacted with Zorachat through another organization's website, application, or channel, direct requests concerning that interaction to the organization first. We will provide reasonable assistance to that organization where required and technically feasible.
CMS and website integrations
Zorachat may connect to websites, commerce platforms, content-management systems, messaging channels, and other services through plugins, scripts, APIs, or connectors. Each integration may transmit platform-specific identifiers, configuration, content, and technical information. The administrator decides which integration to install and which supported features to enable.
WordPress-specific information
The Zorachat plugin for WordPress may store plugin settings, conversation records, and captured lead records in the connected website's WordPress database. Enabled attachments or temporary files may also be stored in the site's WordPress uploads environment. The website owner controls access to and retention of those local records.
Depending on configuration, the plugin may process the site URL, site name, company name, administrator email address, public REST URL, WordPress version, PHP version, plugin version, site or bot identifiers, site authentication material, connection status, and configuration metadata.
An administrator may submit or synchronize WordPress pages, posts, FAQs, custom text, uploaded PDFs, extracted document content, and WooCommerce product information for use by the assistant. Local WordPress storage does not mean local-only processing: AI generation, knowledge ingestion, cloud monitoring, mobile support, push notifications, Zora credits, and handoff integrations require selected information to be transmitted to external services.
When the widget is enabled, a visitor's browser requests the widget asset from widget.zorachat.ai. Standard network and HTTP information may be transmitted or transiently processed, including IP address, browser or device information, referring page, request time, and delivery or security metadata.
All supported AI requests from the WordPress Plugin are sent first to api.zorachat.ai. If the administrator selects OpenAI, Google Gemini, or Anthropic Claude and supplies its API credential, Zorachat processes the selected provider credential and request information as a relay and forwards them to the selected provider. Request information may include the visitor's message, assistant instructions, relevant website or knowledge content, FAQ or WooCommerce context, enabled attachments, conversation metadata, and request metadata.
If the administrator enables Slack, Telegram, mobile monitoring, push notifications, or another handoff destination, conversation content, identifiers, lead details, available contact details, summaries, attachments, and notification metadata may be sent to that destination.
The WordPress website owner is responsible for adding an appropriate notice to the site's own privacy policy, establishing a lawful basis, obtaining consent where required, configuring retention, and responding to requests concerning locally stored WordPress data. Disconnecting a cloud service does not necessarily delete local WordPress records.
Data retention
We retain hosted account and service information while an account is active and for as long as reasonably necessary to provide the Service, maintain security and business records, comply with law, resolve disputes, and enforce agreements. Retention periods vary by data type and purpose.
Information may remain in backups, security logs, fraud-prevention records, or legally required records for a limited period after deletion from active systems. External providers retain information according to their own policies and the administrator's account settings with those providers.
Information held locally by a customer's website, application, CMS, or other connected platform is retained according to that customer's configuration, deletion actions, hosting practices, and legal obligations. Customers should establish and apply an appropriate retention schedule for conversations, leads, attachments, logs, and knowledge content.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and access controls. No method of transmission or storage is completely secure.
Customers remain responsible for securing their websites, hosting environments, devices, administrator accounts, integration credentials, and authorized agent access. If you believe Zorachat account information or a connected credential has been compromised, contact support@zorachat.ai and revoke or rotate the affected credential with its provider.
International transfers
Zorachat, its service providers, and administrator-selected providers may process information in countries other than the country where the account holder or visitor is located. Where required, we use appropriate contractual or other safeguards for international transfers. Administrators are responsible for assessing transfers caused by providers and integrations they choose to enable.
Your rights and choices
Depending on your location and subject to applicable exceptions, you may have rights to access, correct, delete, restrict, or port personal information; object to certain processing; withdraw consent; opt out of certain marketing; and complain to a data-protection authority.
You may update account information through available dashboard controls or contact support@zorachat.ai. We may need to verify your identity and authority before completing a request. Withdrawing consent does not affect processing that occurred lawfully before withdrawal.
For information controlled by another organization or held in that organization's website or application, contact that organization. Zorachat may not have direct access to locally stored records.
Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information directly from children. Customers must not configure the Service to collect children's information without all notices, consents, and safeguards required by applicable law. Contact us if you believe information from a child has been submitted improperly.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised version and update the "Last updated" date. Material changes may also be communicated by email or in-product notice where appropriate.
Contact us
If you have questions about this Privacy Policy or our privacy practices, contact us at support@zorachat.ai.
Questions? support@zorachat.ai