What to tell visitors about AI chat and data
A policy page is for the record. The disclosure next to the input is what people actually read.
Almost every site with an AI assistant has a privacy policy that covers it somewhere. Almost none have anything useful at the moment of interaction, which is the only moment the visitor is thinking about it.
What belongs at the point of interaction
Four facts, in as few words as they can honestly be expressed:
- This is an AI assistant, not a person.
- The conversation is stored.
- Roughly what it is stored for.
- How to reach a human instead.
That is it. Not the full data flow, not the provider list, not the retention schedule. Those belong on the policy page and linking to it from here is enough.
Why the AI disclosure matters even when it is obvious
Some teams skip it because they think it is evident. It usually is, and stating it anyway does two things. It removes any argument that a visitor was misled, and it sets expectations so that a limited answer reads as a known limitation rather than a person being unhelpful.
There is also a direction of travel worth noting: disclosure requirements for automated systems are tightening in several jurisdictions. Stating it plainly is cheap now and avoids a retrofit later.
Writing it without a legal tone
The failure mode is writing three sentences that read like a contract. Compare:
Interactions with this automated service may be recorded and processed by third party service providers in accordance with our privacy policy.
You are chatting with an AI assistant. We save these conversations so we can improve our website. Ask for a person any time.
Both are accurate. The second gets read. The first is a legal reflex that produces no comprehension and no goodwill.
Where to put it
Below the input field, in small but readable text, visible when the chat is open. Not in a tooltip, not behind an info icon, and not only in the first message where it will scroll away.
Small text still has to meet contrast requirements. This is a place where sites routinely fail their own accessibility standard because the text is considered incidental. It is not incidental. It is the disclosure.
What to do if a visitor types something sensitive
They will. People paste order numbers, email addresses, and occasionally things far more sensitive into chat boxes. Two things follow.
Decide in advance whether the assistant should acknowledge and redirect when it detects something like a card number, and have a deletion path so that when someone asks you to remove what they typed, there is a real process rather than an improvised one.
Our own position
Applying this to Creobot: it is in development, its provider and retention details are not final, and we would rather publish that than a confident placeholder. When those details are settled they will be published before general availability.
About the author
Sachin, Founder, Creoglyph. Writes about the website owner view: product, conversion, buyer questions and website operations.