Privacy

What happens to your content and your visitors' questions, including what we have not decided yet.

Launch draft. Creobot is in development. This page is a launch draft, last updated 15 August 2026, and is subject to change before general availability. It is not legal advice. Items marked as not finalised are genuinely undecided rather than withheld, and they will be published before general availability.

What this page is

A plain description of how Creobot is intended to handle data. Creobot is in development. Where a detail is not settled, this page says so rather than stating a placeholder, because a specific claim about data handling is a claim that will eventually be checked.

The two kinds of data

There are two distinct data subjects here and they carry different weight.

Your content. The pages and files you choose to index. On a public marketing site this is content you already published. If you upload internal documents, you are moving private content into a pipeline that includes third party providers, and that should be a deliberate choice.

Your visitors' questions. These come from people who did not choose our vendors. They can contain personal information, because people type things into chat boxes that they would not put in a form. The sensitivity here is higher and it is not ours to be relaxed about.

Where data goes

When an assistant answers a question, data crosses out of our infrastructure at three points: when content is converted to embeddings, when a visitor's question is converted to an embedding, and when the question and the retrieved passages are sent to a language model. That third crossing carries the most.

What is not finalised

The following are genuinely undecided and will be published before general availability:

  • Model providers
  • Whether provider training on submitted data is disabled
  • Retention period for conversations
  • Retention period for indexed content
  • Full subprocessor list
  • Data residency and processing region
  • Deletion workflow and timescale
  • Whether a DPA will be offered and on what terms
  • Cookie consent mechanism and vendor
  • Analytics provider
  • Support tooling provider
  • Payment provider
  • Governing law and jurisdiction
  • Refund and cancellation terms

What we are not claiming

We hold no security certification. We are not claiming SOC 2, HIPAA, ISO 27001, PCI DSS, or compliance with any named framework. We are not claiming zero retention, that data is never used for model training, or a specific processing region. Other products in this category do make some of these claims. We are not mirroring a claim we cannot evidence.

Your rights

Depending on where you are, you may have rights over personal data including access, correction, deletion and portability. Once Creobot is generally available there will be a documented route to exercise them. In the meantime, contact us and we will handle requests manually.

Contact

Questions about this page can go through our contact page. If something here is unclear or appears wrong, we would rather hear it than have it stand.