Legal

Privacy policy.

What Chatkit collects, why, who it goes to, and how to get rid of it. Written to be read, not to be survived.

Last updated 1 September 2026

Who we are

Chatkit is operated by Montigate LLC (“we”, “us”). Chatkit is drop-in chat support software: our customers embed it in their own web and mobile apps so they can talk to their users.

This policy covers the Chatkit website at chatkit.cc, the Chatkit dashboard, and the chat widget and SDKs we provide. For anything in it, write to info@chatkit.cc.

Two kinds of people appear in this policy, and it matters which one you are. Customers sign up for a Chatkit account and we decide how their account data is handled. End users are the people who chat inside a customer's app — for that data the customer decides what is collected and why, and we only process it on their instructions. If you are an end user, contact the app you were chatting in first; we will help them answer you.

What we collect

Account data. Your email address, a securely hashed password, and the name of the workspace you create. If you sign in with Google we receive your name, email address and profile picture instead of a password.

Workspace data. Your workspace name and identifier, your API keys, your plan, and any webhook URL or sender address you configure.

Conversation data. The messages, files and images sent through Chatkit, plus the end-user details a customer's app passes to us — an opaque user id, and optionally a display name and email address so replies can be routed and notified. Customers choose what to send us here; we ask them not to send more than they need.

Technical data. Standard server logs — IP address, browser user agent, timestamps and the URL requested — kept to keep the service running, debug faults and block abuse.

We do not collect special-category data, we do not run advertising or third-party tracking on chatkit.cc, and we never sell personal data to anyone.

If you sign in with Google

Signing in with Google is optional — email and password works just as well. When you do use it, Google asks your permission and then gives us three things from your Google account: your name, your email address, and your profile picture (the standard openid, email and profile scopes).

We use them for exactly one purpose: to create your Chatkit account and sign you into it, and to show your name and picture to you and your teammates inside the dashboard. We do not use Google account data for advertising, we do not sell or transfer it, and we do not use it to train any AI or machine-learning model. It is not shared with anyone beyond the infrastructure providers listed below, who store it on our behalf.

Chatkit's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

You can revoke our access at any time at myaccount.google.com/permissions. Revoking stops future sign-ins; to delete the data we already hold, delete your account or email us.

How we use it

To run the service you asked for: authenticate you, deliver and store messages, send notification emails, and show your inbox. To keep it working and safe: rate limiting, abuse prevention, backups, debugging. To bill you, where a paid plan applies. And to reply when you contact support.

Our legal bases under the GDPR are performance of our contract with you, our legitimate interest in a secure and functioning service, and consent where the law requires it.

Who we share it with

Only the processors that make Chatkit run, each bound to use the data solely for us:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting and content delivery.
  • Google — only if you choose to sign in with Google.

We also disclose data when the law compels us, and we would transfer it to an acquirer if the business were sold — in which case this policy travels with it. That is the whole list.

Cookies

Chatkit sets cookies for one thing: keeping you signed in. They are strictly necessary, they are not used to profile you, and there are no advertising or analytics cookies on chatkit.cc. Clearing them signs you out.

How long we keep it

Account and workspace data lives as long as your account does. Conversation data is kept until the customer who owns it deletes it or closes their workspace. Server logs roll off within 30 days. When you delete your account we delete your data and the conversations belonging to it, save for anything we must keep for legal or accounting reasons; backups age out on their own cycle within 30 days.

Security

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production data is limited to the people who need it. Tenants are isolated at the database level with row-level security, so one workspace cannot read another's conversations. No system is perfect; if a breach affects you, we will tell you and the relevant regulator within the deadlines the law sets.

Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. You can also complain to your local data protection authority. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

Email info@chatkit.cc and we will respond within 30 days.

International transfers

Our providers may process data outside your country, including in the United States. Where that involves personal data from the EEA or the UK, the transfer relies on the European Commission's Standard Contractual Clauses.

Children

Chatkit is a business tool and is not directed at children under 13 (or under 16 where local law sets that bar). We do not knowingly collect their data; if we learn we have, we delete it.

Changes to this policy

If we change this policy we update the date at the top, and for anything material we email account holders before it takes effect.

Contact

Montigate LLC — info@chatkit.cc. A real person reads it.