Certifications and regulations
- SOC 2 Type II: SiteGPT is audited against SOC 2 Type II. Reports are available through the trust portal.
- GDPR: SiteGPT operates as a processor for the visitor data your chatbot handles, with GDPR-aligned processes for data subject requests and deletion.
- HIPAA: SiteGPT maintains a HIPAA compliance program. If your use case involves protected health information, contact support@sitegpt.ai to discuss requirements and agreements before going live.
How your data is handled
- Your content stays yours. Trained content is used to answer your chatbot’s questions, and is not shared across customers.
- Conversations and leads are stored for your dashboard and are exportable and deletable by you: delete individual content, leads, and conversations in the dashboard, or the whole chatbot at once.
- API tokens are shown once at creation and stored hashed; scope them narrowly and rotate them from the Agents page.
- Webhook tokens are shared secrets that SiteGPT sends with every delivery so your endpoint can verify the sender. They stay visible in Settings → Webhooks; treat them like passwords and change them there if one leaks.
- Sign-in is passwordless. Email links avoid password reuse; access to your inbox is access to your account, so protect the inbox accordingly.
For your visitors
- The widget collects what you configure it to collect: conversation messages, and contact details when you enable lead collection or pre-chat details.
- Tracking events sent to your analytics carry ids and event names, not message content or contact details.
- Add your own terms in front of the chat with Disclaimer Text in Appearance.