Privacy Policy
Last updated: 15 August 2026
alChatBot (“we”, “the service”) lets businesses connect their messaging channels and calendar to AI agents that reply to customers on their behalf. This policy explains what data we hold, why we hold it, who else sees it, and how to get rid of it. It applies to chatbot.tural.ai and everything served from it.
1. Information we collect
Account data. Your name, email address and password hash when you register, and your workspace and plan.
Connected messaging channels. When you connect WhatsApp, Instagram or Facebook, we store the account identifiers, session or access tokens needed to send and receive on your behalf, and the conversations that pass through those channels — messages, contact names and phone numbers or platform identifiers, and any media exchanged.
Google account data. Only if you choose to connect Google Calendar or sign in with Google. Described in full in section 2.
Usage data. Server logs, request metadata and AI usage records used for billing and for diagnosing faults.
2. Google user data
Connecting Google Calendar is optional and always initiated by you. When you do, Google asks for your consent to the following scopes, and we request no others:
openid,email,profile— to identify which Google account the connection belongs to, so the right calendar is used and you can see which account is connected.calendar.readonly— to list the calendars on your account so you can choose which one the agent should use, and to read existing events when checking whether a proposed time is free.calendar.events— to create a booking when a customer agrees a time, and to cancel it if they change their mind.
What we store. Per workspace: the Google account email, the refresh token, the id of the calendar you selected, and the list of granted scopes. We do not copy your calendar into our database — events are read from Google at the moment they are needed and are not retained afterwards.
What we do with it. Google Calendar data is used for one purpose: letting the AI agent you configured answer scheduling questions and book, move or cancel appointments during a customer conversation. Nothing else.
Where it goes. To produce a reply, the agent sends the relevant part of the conversation — which may include event titles, times and attendee email addresses returned by Google — to the AI provider powering that agent (OpenAI, Anthropic or Google, as selected in your workspace). These providers process the request and return a reply; under their API terms they do not use this data to train their models. We use no other subprocessors for Google data, and we never sell it, share it for advertising, or use it to build profiles.
Human access. No member of our team reads your Google Calendar data. Access is limited to what an automated system needs; in the rare case where a named engineer must inspect stored data to fix a fault you have reported, it happens with your knowledge and only for as long as the investigation takes.
AI training.Google user data is never used to train, retrain or fine-tune any AI or machine-learning model, ours or anybody else’s.
Limited Use
alChatBot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access. Disconnect Google Calendar from Settings in your dashboard: the stored refresh token and connection record are deleted immediately, and the agent loses calendar access at once. You can also revoke access from your Google account at myaccount.google.com/permissions, which has the same effect from Google’s side.
3. How AI processing works
Messages, contact details and any tool results the agent needs are sent to the AI provider selected for that agent in order to produce a reply. Providers act as processors on our instruction and, under their API terms, do not train on this data. Which provider handles your workspace is visible and configurable in the dashboard.
Agent activity — the message, the reply, and which tools ran — is retained for 15 days so you can audit what an agent did, then deleted automatically.
4. Messaging platforms
WhatsApp, Instagram and Facebook data is used solely to receive and send messages on the accounts you connect, and to show those conversations in your dashboard. Tokens are used only for API communication with Meta’s platforms. We do not sell this data or share it with third parties beyond the AI provider described above.
5. Storage and security
Data is held on servers we operate, on infrastructure rented from a commercial hosting provider. Access is restricted to the systems that need it, and traffic between you and the service is encrypted in transit.
6. Retention and deletion
Connection tokens are kept until you disconnect the channel. Conversations and CRM records are kept while your account is open, because they are the working record your agents rely on. Agent activity logs are kept for 15 days.
You can delete a connection at any time from the dashboard. To delete your account and everything in it, write to the address below; we action deletion requests within 30 days and confirm when it is done.
7. Sharing
We do not sell personal data. We share it only with the AI provider chosen for your workspace (to produce replies), with the messaging platform the conversation belongs to (to deliver messages), with our payment processor Stripe (to take payment — we never see or store card numbers), and where the law compels us.
8. Your rights
You can ask what we hold about you, ask for a copy, ask for corrections, and ask for deletion. Write to the address below and we will answer within 30 days.
9. Children
The service is for businesses and is not directed at anyone under 16. We do not knowingly collect data from children.
10. Changes
If we change this policy we update the date at the top. Material changes — a new category of data, a new recipient — are announced in the dashboard before they take effect.
11. Contact
Questions about privacy, or a deletion request: gttural@gmail.com