Convo

Privacy Policy

Last updated August 16, 2026

1. Overview

Convo (“Convo,” “we,” “us,” or “our”) is a chat widget built and operated by Amrex Systems. This policy explains what data we collect when a business (“Customer,” “you”) purchases and embeds Convo on its website, and what data we collect from the people who chat with that widget (“Visitors” or “End Users”).

Because Convo sits on Customer websites and talks to Customer visitors, this policy covers two relationships at once: our relationship with the Customer who buys Convo, and our role as a data processor handling conversation data on that Customer’s behalf. Section 6 explains that distinction in more detail.

2. Information We Collect

a. Customer account information

When you sign up for Convo, we collect:

  • Name, email address, and password (handled via our authentication provider)
  • Billing details, processed by our payment processor (we do not store full card numbers)
  • Your website URL and the site(s) you embed the widget on
  • Optional profile details, such as a profile picture
  • If you connect help center content, docs, or PDFs for training, the content of those materials
  • If you provide your own AI provider API key (BYO-key), that key, stored encrypted

b. Visitor / end-user conversation data

When someone chats with a Convo widget on a Customer’s site, we collect:

  • The messages they send and receive during the conversation
  • Name and email, if they share it or it’s captured during the conversation
  • Conversation metadata, including timestamps, status (open, claimed, resolved), and which page the chat started on
  • Presence and connection information needed to keep the chat session live

c. Automatically collected information

Like most web services, our infrastructure providers log standard technical data automatically: IP address, browser type, device type, and general usage timestamps, used for security, abuse prevention, and keeping the service running.

3. How We Use Information

  • To operate the chat widget: deliver messages in real time, route conversations, and hand off to a human teammate when needed
  • To generate AI responses to Visitor questions, grounded in the Customer’s connected docs and help content
  • To extract and save a Visitor’s name and email when they provide it in conversation, so a Customer can follow up
  • To provide the Customer dashboard: conversation history, transcripts, and analytics
  • To bill Customers for their one-time purchase and provide support
  • To maintain security, prevent abuse, and debug issues with the service
  • To improve Convo’s reliability and response quality

4. AI Processing & Third-Party Model Providers

To generate replies, Convo sends the relevant parts of a conversation, along with any connected docs or help content, to a large language model provider (such as Google, OpenAI, or Anthropic). If a Customer supplies their own API key, that traffic is processed under the Customer’s own agreement with that provider. Otherwise it is processed under our agreement with our default provider.

We do not permit these providers to use Customer or Visitor conversation data to train their general-purpose models outside of what is needed to generate the response itself, where the provider offers that setting.

5. Data Sharing & Subprocessors

We don’t sell personal data. We share it only with:

  • Infrastructure & database providers (e.g. Google Firebase, Supabase), to store account data, conversations, and files
  • AI model providers, to generate chat responses, as described above
  • Payment processors, to handle the one-time purchase
  • Law enforcement or regulators, only when required by valid legal process
  • A successor entity, in the event of a merger, acquisition, or asset sale, with notice to affected Customers

6. Our Role: Controller vs. Processor

For Customer account data (billing, login, dashboard usage), Amrex Systems acts as the data controller. For Visitor conversation data collected through a Customer’s embedded widget, the Customer is the controller and we act as a processor on their behalf. The Customer decides what their widget is used for and is responsible for telling their own visitors how that data is used, including through their own privacy policy.

7. Data Retention

We retain conversation transcripts and account data for as long as a Customer’s account is active, so dashboards, analytics, and transcripts keep working. If a Customer deletes their account, we delete or anonymize associated data within a reasonable period, except where we’re required to keep it for legal, security, or billing-record purposes.

8. Security

We use industry-standard safeguards, including encryption in transit, access controls, and restricted internal access to production data, to protect the information we hold. No method of transmission or storage is completely secure, and we can’t guarantee absolute security, but we work to keep this policy’s promises in practice, not just on paper.

9. Your Rights

Depending on where you’re located, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing.

  • Customers can manage most of this directly from the dashboard, or by contacting us.
  • Visitors who want their conversation data corrected or deleted should contact the Customer whose website they chatted on, since that Customer controls the data. If that’s not possible, contact us and we’ll route the request.

10. Cookies & Local Storage

The Convo widget uses cookies or local storage to keep a Visitor’s conversation connected across page loads on the same site. The Customer dashboard uses cookies to keep you signed in. We don’t use these for cross-site advertising tracking.

11. Children's Privacy

Convo is not directed at children, and we don’t knowingly collect personal data from children under 13 (or the relevant age of digital consent in a Visitor’s region). If you believe a child has provided us with personal data, contact us and we’ll remove it.

12. International Data Transfers

Our infrastructure and subprocessors may store and process data in countries other than your own. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to cover these transfers.

13. Changes to This Policy

We may update this policy as Convo changes. If we make material changes, we’ll update the “last updated” date above and, for significant changes, notify Customers by email.

14. Contact Us

Questions about this policy or a data request? Reach us at privacy@useconvo.com.

Also see our Terms of Service and Data Processing Agreement.