Last updated: September 04, 2026
Radioactive Labs ("we", "us", or "our") operates Universal Chatbot (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
When you create an account or use the Service, we may collect:
If you create or join an organization (team account), we store:
When end users interact with chatbots you deploy, we collect:
Not all of this reaches us through a chatbot. Where a platform lets you connect a number or account you were already using, you may choose to share the conversations that took place on it before you connected it, including messages your own staff sent. We receive that history only if you approve the sharing at the point of connection, and we store it alongside your other conversations so your team can see the full thread. See the platform sections below for what each one shares.
When you upload documents or provide URLs for your knowledge base, we store:
We collect analytics to improve our Service:
We use cookies for:
The chat widget sets no cookies. It stores one anonymous identifier in your browser's local storage so a conversation continues if you reload or return to the page. The identifier expires after 9 months, is readable only by the site you are visiting, and holds nothing about you beyond itself. Clearing your browser storage for that site removes it and starts a new conversation.
When your flows save information to tables you create, we store:
We use collected information to:
We use the following third-party services to provide our Service:
We use Google Gemini to power AI features including intent recognition, content generation, and knowledge base queries. When AI features are used:
Google's use of this data is governed by their Privacy Policy and Data Processing Terms.
When you connect third-party platforms, we access data according to the permissions you grant:
When connected, we access:
We send bot responses and perform actions (tagging, assignment) on your behalf.
For Telegram deployments, we receive messages sent to your bot and user metadata (user ID, name). We send bot responses via the Telegram Bot API.
For WhatsApp deployments we use Meta's WhatsApp Business Platform (Cloud API). When a customer messages your business number, we receive:
Media a customer sends is downloaded from Meta and stored on our infrastructure so it can be shown in your conversation history and inbox. We send bot replies and your agents' replies back through the Cloud API. The access credentials you provide for your WhatsApp Business account are encrypted at rest and used only to receive and send messages for your deployments.
You can connect a number you already use in the WhatsApp Business app and keep using both. When you do, Meta asks whether to share that number's existing chat history, covering up to the previous six months. If you approve, we receive those past conversations, including messages your staff sent from the app, and store them with your other conversations so your team sees an unbroken thread. Meta asks you this question during connection, and your answer to Meta governs: we add no separate consent step and cannot request the history if you decline.
While that number stays connected to both, Meta also tells us when your staff reply from the WhatsApp Business app and when contacts are added or changed in it. We use those notices to keep your inbox from talking over a colleague and do not retain their contents.
If you connect through Meta's guided setup rather than by supplying your own credentials, we also record which Meta user authorised the connection, so that Meta can tell us to undo it. Removing our app from your Meta business settings, or asking Meta to delete your data, withdraws our access to every number that authorisation covered. Instructions are at universalchatbot.com/data-deletion. This removes our access and the credentials behind it; it does not delete the conversations your business has already had, which remain yours to keep or delete.
Meta's handling of these messages is governed by the WhatsApp Business Data Transfer Addendum and Meta's Privacy Policy.
For Messenger and Instagram deployments we use Meta's Messenger Platform and Instagram messaging API. When a customer messages your Page or your Instagram account, we receive:
Media a customer sends is downloaded from Meta and stored on our infrastructure so it can be shown in your conversation history and inbox. We send bot replies and your agents' replies back through the same API. Meta also tells us when someone on your team replies from Meta's own inbox, which we use to keep your agents from talking over a colleague.
Instagram replies to your stories and mentions of your account in other people's stories reach us only if you switch them on for that account. While they are off, Meta's notice about them is discarded as it arrives and nothing is stored.
Connecting either channel goes through Meta, so we record which Meta or Instagram account authorised it. Removing our app from your Meta business settings or your Instagram account settings, or asking Meta to delete your data, withdraws our access to everything that authorisation covered.
We plan to support additional platforms including Slack. Similar data access patterns will apply, and this policy will be updated accordingly.
We use a self-hosted document processing service to convert uploaded documents to searchable text. Documents are processed on our infrastructure and are not shared with external services.
We use Stripe to process payments. When you make a payment:
Stripe's use of your data is governed by their Privacy Policy.
We use a locally-hosted MaxMind GeoLite2 database for IP-based geolocation. No data is sent to external geolocation services.
We retain different types of data for different periods:
When you delete your account, we will delete or anonymize your personal data within 90 days, except for billing records we are legally required to retain.
We implement security measures including:
We do not sell your personal information. We share data only:
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us at the address below.
If you connected a platform account through Meta, you can also withdraw that access yourself, either from your Meta business settings or by asking Meta to delete your data. universalchatbot.com/data-deletion explains what happens and lets you check the status of a request.
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
Our Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
Radioactive Labs
Email: [email protected]