Privacy Policy

Last updated: September 04, 2026

Radioactive Labs ("we", "us", or "our") operates Universal Chatbot (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

1. Information We Collect

1.1 Account Information

When you create an account or use the Service, we may collect:

  • Contact information - Email address, name, phone number
  • Password - Stored as a cryptographic hash (never in plain text)
  • Profile information - Any additional information you choose to provide
  • Billing information - Payment details and billing address (processed securely by Stripe; we do not store full card numbers)

1.2 Organization Data

If you create or join an organization (team account), we store:

  • Organization name
  • Membership relationships and roles

1.3 Conversation Data

When end users interact with chatbots you deploy, we collect:

  • Messages - Full conversation history between users and your chatbot
  • Session data - Conversation state and flow progress
  • Technical data - IP address, browser user agent, timestamps
  • Platform identifiers - User IDs from connected platforms (e.g., Intercom contact IDs, Telegram user IDs, the scoped Messenger or Instagram id Meta assigns a customer for your account, or the phone number a customer messages you from on WhatsApp)
  • Attachments - Files, images, audio and video an end user sends to your chatbot, along with any location or contact card they choose to share

Not all of this reaches us through a chatbot. Where a platform lets you connect a number or account you were already using, you may choose to share the conversations that took place on it before you connected it, including messages your own staff sent. We receive that history only if you approve the sharing at the point of connection, and we store it alongside your other conversations so your team can see the full thread. See the platform sections below for what each one shares.

1.4 Knowledge Base Content

When you upload documents or provide URLs for your knowledge base, we store:

  • Document content and metadata
  • Processed text chunks for search
  • Vector embeddings for semantic search

1.5 Analytics Data

We collect analytics to improve our Service:

  • Visit information - Pages visited, referrer, landing page
  • Device information - Browser type, operating system, device type
  • Location data - Approximate location derived from IP address (city/region/country level)
  • UTM parameters - Campaign tracking data from URLs

1.6 Cookies and Browser Storage

We use cookies for:

  • Authentication - Session cookies to keep you logged in
  • Analytics - Visit and visitor tokens for usage analytics

The chat widget sets no cookies. It stores one anonymous identifier in your browser's local storage so a conversation continues if you reload or return to the page. The identifier expires after 9 months, is readable only by the site you are visiting, and holds nothing about you beyond itself. Clearing your browser storage for that site removes it and starts a new conversation.

1.7 Stored Table Data

When your flows save information to tables you create, we store:

  • Table contents - Information your flows save, which may include names, email addresses and phone numbers your customers provide
  • Field-level encryption - Any column you mark as encrypted is stored encrypted at rest

2. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Process and respond to chatbot conversations
  • Generate AI-powered responses using your knowledge base
  • Provide analytics and insights about chatbot performance
  • Send service-related communications (account verification, security alerts)
  • Improve and optimize the Service
  • Detect and prevent fraud or abuse

3. Third-Party Services

We use the following third-party services to provide our Service:

3.1 AI/Language Model Providers

We use Google Gemini to power AI features including intent recognition, content generation, and knowledge base queries. When AI features are used:

  • Conversation messages and context are sent to Google's API
  • Relevant knowledge base content may be included for context
  • AI responses are stored in our database

Google's use of this data is governed by their Privacy Policy and Data Processing Terms.

3.2 Platform Integrations

When you connect third-party platforms, we access data according to the permissions you grant:

Intercom

When connected, we access:

  • Conversation messages and metadata
  • Contact information (name, email)
  • Admin and team information for routing
  • Tags for categorization

We send bot responses and perform actions (tagging, assignment) on your behalf.

Telegram

For Telegram deployments, we receive messages sent to your bot and user metadata (user ID, name). We send bot responses via the Telegram Bot API.

WhatsApp

For WhatsApp deployments we use Meta's WhatsApp Business Platform (Cloud API). When a customer messages your business number, we receive:

  • The message content, which may be text, a button or list selection, a location, an image, document, audio clip, video or sticker, or a contact the customer chose to share
  • The customer's WhatsApp phone number and the profile name they have set on WhatsApp
  • Your business phone number and its Meta phone number identifier
  • The message identifier and timestamp Meta assigns

Media a customer sends is downloaded from Meta and stored on our infrastructure so it can be shown in your conversation history and inbox. We send bot replies and your agents' replies back through the Cloud API. The access credentials you provide for your WhatsApp Business account are encrypted at rest and used only to receive and send messages for your deployments.

You can connect a number you already use in the WhatsApp Business app and keep using both. When you do, Meta asks whether to share that number's existing chat history, covering up to the previous six months. If you approve, we receive those past conversations, including messages your staff sent from the app, and store them with your other conversations so your team sees an unbroken thread. Meta asks you this question during connection, and your answer to Meta governs: we add no separate consent step and cannot request the history if you decline.

While that number stays connected to both, Meta also tells us when your staff reply from the WhatsApp Business app and when contacts are added or changed in it. We use those notices to keep your inbox from talking over a colleague and do not retain their contents.

If you connect through Meta's guided setup rather than by supplying your own credentials, we also record which Meta user authorised the connection, so that Meta can tell us to undo it. Removing our app from your Meta business settings, or asking Meta to delete your data, withdraws our access to every number that authorisation covered. Instructions are at universalchatbot.com/data-deletion. This removes our access and the credentials behind it; it does not delete the conversations your business has already had, which remain yours to keep or delete.

Meta's handling of these messages is governed by the WhatsApp Business Data Transfer Addendum and Meta's Privacy Policy.

Facebook Messenger and Instagram

For Messenger and Instagram deployments we use Meta's Messenger Platform and Instagram messaging API. When a customer messages your Page or your Instagram account, we receive:

  • The message content, which may be text, a button or quick reply selection, or an image, audio clip, video, file or sticker they attached
  • An identifier Meta assigns that customer, scoped to your account: it does not identify them anywhere else and cannot be matched to their profile on another business's Page
  • The name and profile picture on their account, where Meta makes them available to us
  • Your Page or Instagram account identifier, and the message identifier and timestamp Meta assigns

Media a customer sends is downloaded from Meta and stored on our infrastructure so it can be shown in your conversation history and inbox. We send bot replies and your agents' replies back through the same API. Meta also tells us when someone on your team replies from Meta's own inbox, which we use to keep your agents from talking over a colleague.

Instagram replies to your stories and mentions of your account in other people's stories reach us only if you switch them on for that account. While they are off, Meta's notice about them is discarded as it arrives and nothing is stored.

Connecting either channel goes through Meta, so we record which Meta or Instagram account authorised it. Removing our app from your Meta business settings or your Instagram account settings, or asking Meta to delete your data, withdraws our access to everything that authorisation covered.

Future Integrations

We plan to support additional platforms including Slack. Similar data access patterns will apply, and this policy will be updated accordingly.

3.3 Document Processing

We use a self-hosted document processing service to convert uploaded documents to searchable text. Documents are processed on our infrastructure and are not shared with external services.

3.4 Payment Processing

We use Stripe to process payments. When you make a payment:

  • Payment card details are collected and processed directly by Stripe
  • We do not store full card numbers on our servers
  • We receive transaction confirmations and billing information necessary to provide the Service

Stripe's use of your data is governed by their Privacy Policy.

3.5 Geolocation

We use a locally-hosted MaxMind GeoLite2 database for IP-based geolocation. No data is sent to external geolocation services.

4. Data Retention

We retain different types of data for different periods:

  • Account data - Retained until you delete your account, plus 90 days to allow for recovery and resolve any pending matters
  • Conversation data - Retained for 24 months from the conversation date, then automatically deleted. You may delete conversations earlier through the Service.
  • Knowledge base content - Retained until you delete the documents or your account
  • Stored table data - Retained until you delete the rows, the table, or your account. This data is deliberately kept beyond the conversation that created it.
  • Analytics data - Retained for 24 months, then anonymized or deleted
  • Billing and financial records - Retained for 6 years as required by law
  • Cookies and browser storage - Session cookies expire when you close your browser; the chat widget's identifier expires after 9 months

When you delete your account, we will delete or anonymize your personal data within 90 days, except for billing records we are legally required to retain.

5. Data Security

We implement security measures including:

  • Encryption in transit - All data transmitted over HTTPS
  • Credential encryption - OAuth tokens, API keys, and user-provided credentials encrypted at rest
  • Password hashing - Passwords stored using bcrypt cryptographic hashing
  • Multi-tenant isolation - Organization data strictly isolated between accounts
  • Secure cookies - HttpOnly and Secure flags on sensitive cookies

6. Data Sharing

We do not sell your personal information. We share data only:

  • With your consent - When you connect third-party integrations
  • With service providers - Third-party AI providers as described above
  • For legal compliance - When required by law or to protect our rights
  • In business transfers - If we merge with or are acquired by another company

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access - Request a copy of your personal data
  • Correction - Request correction of inaccurate data
  • Deletion - Request deletion of your data
  • Portability - Request your data in a portable format
  • Objection - Object to certain processing activities
  • Withdraw consent - Withdraw consent for optional processing

To exercise these rights, contact us at the address below.

If you connected a platform account through Meta, you can also withdraw that access yourself, either from your Meta business settings or by asking Meta to delete your data. universalchatbot.com/data-deletion explains what happens and lets you check the status of a request.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

9. Children's Privacy

Our Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:

Radioactive Labs
Email: [email protected]

Request a demo
This form is running on UniversalChatbot.