Chattler.ai
  • Հարթակ
  • Գներ
  • Կոնտակտներ
  • Սցենարներ
am am
ru Русский en English tj Тоҷикӣ am Հայերեն tt Татарча ar العربية
Մուտք

Գաղտնիության քաղաքականություն

Թարմացման ամսաթիվը՝ 26.08.2026

This document is a translation. The Russian version prevails in case of discrepancy.

This Privacy Policy describes what data is processed when you use the Chattler platform, on what grounds, who it is shared with, how long it is kept, and how to have it deleted.

The Policy covers the whole Platform: the chattler.ai website, the app.chattler.ai web application, the chat widget for a customer website, the public chat page, AI agents, the knowledge base, integrations with external platforms, and extensions.

1. The Operator

The data controller is Chattler Limited Liability Company:

  • OGRN 1256900007440, INN 6900024213, KPP 690001001
  • Address: office 40, 1 Moskovskaya street, Tver, Tver region, 170100, Russian Federation
  • Email for data protection requests: support@chattler.ai

Processing is carried out under Federal Law No. 152-FZ of 27 July 2006 On Personal Data.

2. The Operator acts in two capacities

The Platform processes data belonging to two different groups of people, and the Operator role differs between them.

With respect to User data, the Operator acts as the data controller. With respect to the data of people who contact the User through connected channels, the Operator acts on the instructions of the User, who independently determines the purposes and scope of processing.

What this means in practice: if you messaged a business and want to know what data about you is processed, or want it deleted, contact that business — it determines the purposes of processing. The Operator will act on that business instructions. The Data Deletion document explains the procedure.

3. What data is processed

User data:

  • registration details: name, email address, interface language, time zone;
  • authentication data: a salted password hash, or an external account identifier where Google sign-in is used;
  • sign-in and device journal: IP address, browser and device information, browser identifier, date and outcome of the sign-in attempt;
  • AI agent configuration, including system prompt texts and model parameters;
  • knowledge base materials uploaded by the User;
  • balance, payments, charges, and token consumption records;
  • support requests and correspondence with the Operator.

Contact data, processed on the User instructions:

  • identifier and profile in the channel concerned: name, username, profile image, and for WhatsApp the phone number;
  • the content of the conversation, including text, images, video, audio, files, and location data where the Contact sent it;
  • channel metadata: conversation and integration identifiers and, for group chats, the chat identifier.

Website technical data: cookies, browser information, and visit statistics.

4. Annex: data received through each integration

An integration is connected by the User voluntarily and can be disconnected at any time. Before an integration is connected, no data from that platform is processed.

ChannelData received
InstagramBusiness account details, inbound and outbound messages, comments, attachments, post metrics
ThreadsProfile details, posts, replies, mentions, metrics
TelegramContact profile, messages, attachments; for groups, the chat identifier
WhatsAppContact phone number, messages, attachments
VKContact identifier and profile, messages
AvitoListing and chat identifiers, messages
Chat widget and chat pageMessages, attachments, browser identifier
Google CalendarAccess and refresh tokens, busy or free status, calendar events
Extensions and external servicesData the User themselves sends to the connected service through an AI agent

Instagram. The following permissions are requested at connection time:

  • instagram_business_basic — to read basic details of the connected business account, so the User can see which account is connected and conversations can be linked to it.
  • instagram_business_manage_messages — to receive inbound messages and send replies on the User behalf. This is the core function of the integration.
  • instagram_business_manage_comments — to read comments on posts and reply to them, where the User has enabled that.
  • instagram_business_manage_insights — to read account and post statistics for display to the User.
  • instagram_business_content_publish — to publish material prepared by the User or their AI agent, on the User explicit instruction.

Threads. The following permissions are requested at connection time: threads_basic, threads_content_publish, threads_delete, threads_keyword_search, threads_location_tagging, threads_manage_insights, threads_manage_mentions, threads_manage_replies, threads_profile_discovery, threads_read_replies, threads_share_to_instagram. They are used to read profile details, to publish material and delete it on the User instruction, to search for and discover posts on a topic, to add a location tag, to read statistics, and to read mentions and replies so that the AI agent can respond to them.

Data received through Instagram and Threads is used solely to operate the User AI agent in those channels and to display it to the User in the Platform interface. The restrictions in section 10 apply to it in full.

5. Purposes and legal grounds

  • Providing access to the Platform and performing the Terms of Use — ground: performance of a contract to which the data subject is a party.
  • Operating the AI agent in connected channels, including composing and sending replies — ground: performance of the contract with the User, and, for Contact data, the instructions of the User.
  • Taking payments and maintaining balances — ground: performance of the contract and accounting law requirements.
  • Security, prevention of unauthorised access and abuse — ground: the Operator legitimate interest and legal requirements.
  • Supporting the User and answering requests — ground: performance of the contract.
  • Improving the Platform on the basis of anonymised statistics — ground: the Operator legitimate interest.
  • Sending service notifications — ground: performance of the contract. Marketing messages are sent only with separate consent, which can be withdrawn at any time.

6. Who data is shared with

The Operator engages the following processors, each only to the extent that the relevant function requires:

WhoWhy
OpenRouter and the language model providers reached through itProducing AI agent answers
Google Cloud StorageStoring files and attachments
Payment providerTaking payments. Bank card details are not passed to the Operator
PostHogProduct analytics for the web application
Cloudflare TurnstileProtecting forms against automated submissions
Email service providerSending mail from no-reply@chattler.ai

Data may also be disclosed to competent state authorities in the cases and in the manner prescribed by the law of the Russian Federation.

Separately: by connecting a channel or an extension, the User initiates an exchange of data with the external platform or service concerned. That transfer happens on the User instruction, and processing on the platform side is governed by that platform own documents.

7. Cross-border transfer

Some of the processors listed in section 6 are located outside the Russian Federation, so personal data is transferred across borders under article 12 of Federal Law No. 152-FZ.

Transfers are limited to what is needed to provide the service and go only to the parties listed in section 6. The Operator takes measures to protect data in transfer, including encryption in transit.

By registering on the Platform and connecting integrations, the User consents to such transfers. The Platform cannot operate without them, because the language models that produce answers are hosted outside the Russian Federation.

8. Retention periods

DataPeriod
Conversations12 months from the last activity in the conversation, then deleted automatically
Individual messages12 months from when the message was sent, then deleted automatically
Attachments received from Contacts90 days, then deleted automatically
Links to files sent to a Contact7 days
Sign-in journal12 months
Account and AI agent configurationFor the life of the account; deleted on the User request
Knowledge base materialsUntil the User deletes the material or the agent
Access tokens for connected channelsUntil the integration is disconnected
Unconfirmed registrations3 hours
Payment and accounting records5 years under article 29 of Federal Law No. 402-FZ On Accounting

Where consent to processing is withdrawn, or the purposes of processing have been achieved, data is destroyed within thirty days, except for records whose retention period is fixed by law.

9. Rights of the data subject

A data subject may obtain information about the processing of their data, require it to be corrected, blocked, or destroyed, and withdraw consent to processing.

Requests go to support@chattler.ai. The Operator responds within the time limits set by law. Where a demand to stop processing personal data is received, the Operator stops processing within ten working days of receiving it.

The deletion procedure is set out separately in Data Deletion.

Where a request comes from a Contact rather than a User, section 2 of this Policy applies: the User determines the purposes of processing, and the request is passed to them.

10. What the Operator does not do

  • does not sell personal data;
  • does not use data obtained from the platforms to build advertising audiences or for targeting;
  • does not combine it with other data sets;
  • does not use conversations to train machine learning models;
  • does not disclose it to third parties beyond those listed in section 6 and the cases prescribed by law.

11. Security measures

  • Passwords are stored as a hash with an individual salt; the Operator does not know the original password.
  • Credentials for connected services are held in a database with restricted access; for the Instagram, Threads, and Avito integrations, and for extensions, an additional layer of encryption with key rotation applies.
  • Attachments received from Contacts are placed in private storage and served only through a signed link with a limited lifetime.
  • Administrator sessions store a hash of the token rather than the token itself.
  • Actions taken by Platform administrators are written to an audit log.
  • Data in transit between the User, the Platform, and the processors is encrypted.

12. Cookies and local storage

The website and the web application use cookies and browser local storage for authentication, device recognition, security, and interface preferences. The Platform cannot work correctly without them.

Analytics cookies are used to understand how the Platform is used. A User may restrict them in the browser; core functionality is not affected.

13. Age limit

The Platform is intended for business use and is not directed at people under 16. The Operator does not knowingly collect their data. If it emerges that a minor data was obtained without proper consent, it will be deleted.

14. Changes and contacts

The Operator may amend this Policy. The current version is published on the website with its date. Material changes are notified to the User at the email address given on registration, or in the Platform interface.

Questions and requests: support@chattler.ai, or by post to office 40, 1 Moskovskaya street, Tver, Tver region, 170100, Russian Federation.

Related documents: Terms of Use and Data Deletion.

← Գլխավոր էջ
Chattler.ai Հարթակ, որը օգնում է գործարկել AI գործակալներ ծանոթ հաղորդակցման ինտեգրացիաների միջոցով
support@chattler.ai @chattler_ai
Գաղտնիության քաղաքականություն Օգտագործման պայմաններ Տվյալների ջնջում

Մենք օգտագործում ենք cookie ֆայլեր, որպեսզի կայքը ճիշտ աշխատի և հասկանանք, թե ինչպես է այն օգտագործվում։ Շարունակելով օգտվել կայքից՝ դուք համաձայնում եք դրան։ Մանրամասները՝ Գաղտնիության քաղաքականություն