Skip to main content
This page explains what SiteGPT does with the data in your account, which controls you have over it, and where to find documents for a security review. The public legal pages describe the standard terms. If you signed a DPA with SiteGPT, your signed DPA controls. This page links to the public pages.

Certifications and public commitments

SiteGPT’s public security questionnaire states:
  • SOC 2 Type II: SiteGPT completed a SOC 2 Type II examination. It covers security, availability, and confidentiality. Enterprise customers can request the report through the trust portal.
  • GDPR: SiteGPT is GDPR certified by DPLMC International.
  • HIPAA: SiteGPT was assessed for HIPAA compliance by DPLMC International. A Business Associate Agreement (BAA) is available on the Enterprise plan. See HIPAA.
  • ISO 27001: SiteGPT does not hold an ISO 27001 certification.
  • Encryption: all data is encrypted in transit with TLS 1.2 or higher, and at rest.
  • Hosting region: data is stored with the vendors on the subprocessor list, mostly in the United States. SiteGPT does not offer EU-only hosting.

Who controls the data

For the content your chatbots learn from, the conversations they have, and the leads they collect, you are the controller. SiteGPT processes that data for you, on your instructions. This is stated in the privacy policy.

How your data is kept apart

  • Each chatbot has its own content. When a chatbot looks for an answer, it searches only the content added to that chatbot. Content is not shared between chatbots or between customers.
  • Access is per chatbot. People see a chatbot only if they own it or are a member of it. Each member has a role: Agent, Manager, Admin, or Super Admin. The role controls who can see conversations, change content and settings, and manage members. See Team members.
  • Billing is per person. Members do not see the owner’s plan or billing.

How AI providers use your data

SiteGPT uses outside AI services to read content and write answers. The subprocessor list names them. It includes OpenAI for language model processing, Cohere for embeddings, Pinecone for vector search, and Context.dev for parsing uploaded files. Requests to OpenAI go through the Portkey gateway.
  • SiteGPT does not use your content or conversations to train AI models. SiteGPT’s AI providers process this data under their data processing terms, which also set how long they keep it.
In HIPAA workspaces, OpenAI processing uses zero-data-retention endpoints. SiteGPT still stores conversations and other records under its own retention rules. See HIPAA.

How long SiteGPT keeps your data

On standard accounts with an active subscription, SiteGPT does not delete your chatbots or their data on a schedule. Chatbot content, conversations, and leads stay until you delete them, or until you delete the chatbot or your account. If you cancel your subscription and it ends, SiteGPT schedules your chatbots and their data (conversations, documents, and leads) for deletion no earlier than 30 days after the subscription ends. At least seven days before the deletion date, SiteGPT emails the account owner that date. To keep your chatbots, subscribe again before that date. Billing records stay after account deletion, as tax and accounting law requires. HIPAA workspaces are different: conversation content is redacted automatically. See HIPAA.

What you can delete

Each deletion is permanent. You cannot undo it. Before you delete, you can export conversations and leads to CSV. See Export conversations to CSV and Export leads to CSV. For a deletion or export that you cannot do in the dashboard, email support@sitegpt.ai.

Sign-in and access keys

  • Sign-in has no passwords. You sign in with a link that SiteGPT sends to your email. The link works for 1 hour. There is no Google or other social sign-in. Anyone who can read your inbox can sign in as you, so protect your email account. See Sign in and profile.
  • API tokens are shown only once, when you create them. SiteGPT stores only a hash of each token. Give each token only the scopes it needs. You can rotate or revoke a token at any time. See Authentication.
  • Webhook tokens are secrets that SiteGPT sends with each webhook delivery, so your endpoint can check the sender. They stay visible in Settings > Webhooks. If a token leaks, change it there. See Webhooks.

What the widget collects from visitors

  • The widget stores the messages in each conversation.
  • It collects contact details only when you turn on a lead form.
  • Tracking events that go to your analytics tools contain IDs and event names. They contain no name, email, phone number, or message text.
  • To ask visitors to accept your terms, or to show a notice below the chat, see Add a disclaimer and consent.

Documents for a security review

If your review needs signed documents, more detail, or a call, email support@sitegpt.ai. For data protection questions, email privacy@sitegpt.ai.