AI Agent Privacy Policy
This policy covers the LetsTok AI Agent service only — the agent on your website, the shared inbox, the CRM and the follow-up board. LetsTok's video and social publishing products are covered by a separate policy.
Version 1.0 · 2026-08-27
Este documento está disponível apenas em inglês. A versão inglesa é a que prevalece.
1. Who we are
The LetsTok AI Agent is operated by Letstok. In this policy "we" and "Letstok" mean the operator of the service; "you" or "the business" means the business that subscribes; and "visitor" means a person who uses the agent on that business's website.
2. Our role: you control, we process
This distinction determines everything below. For conversations between a business and its website visitors, the business is the data controller and Letstok is a data processor acting on the business's documented instructions. We do not decide why those conversations happen or what is said in them.
For the business's own account data — the people who sign in, billing records, support requests — Letstok is the controller.
The agent answers as the business, under a name and appearance the business chooses. Visitors are talking to that business, not to Letstok.
3. What we process
- Business account data: the email address used to sign in (through LetsTok's existing Firebase authentication), name, role, team members, and audit records of actions taken in the inbox and CRM.
- Knowledge base content: the pages, product listings, price lists, policies and files the business asks us to read, plus the extracted text and the numerical embeddings derived from it.
- Conversation data: every message exchanged with the agent, in both directions, including what the visitor typed, what the agent answered, which knowledge-base passages grounded the answer, and any images or product cards shown.
- Visitor data: an anonymous visitor identifier stored in the widget, the page the conversation began on, referrer, coarse device and browser information, IP address, and any contact details the visitor volunteers — typically a name and a phone number or email.
- CRM data: contacts created from conversations, their status, notes your team writes, and tasks.
- Configuration data: the agent's name, greeting, tone, opening hours, escalation rules and the things you tell it never to say.
- Usage and cost data: how many answers the agent generated, token counts and the cost of each, used for billing and for our own margin reporting.
- Technical data: server logs, error traces and rate-limit counters, used to operate and secure the service.
4. What we ask visitors for — and what we refuse
The agent is instructed never to ask a visitor for a payment card number, a national identity number or a password, and to refuse if one is offered. Free-text notes are scanned before storage and long digit sequences that look like card or identity numbers are replaced with a redaction marker.
This is a safeguard, not a guarantee. A visitor can type anything. If sensitive data does reach a conversation, the business can delete that conversation from its inbox and the deletion propagates as described in section 8.
5. Artificial intelligence, and who sees the text
Answers are generated by a large language model. To produce an answer we send the model: the agent's instructions, the business profile, the relevant passages retrieved from the knowledge base, the recent conversation history, and the visitor's message.
We use OpenAI as our model and embedding provider, under their API terms. Data submitted through the OpenAI API is not used to train their models. We do not use conversation content to train any model of our own, and we do not use one business's data to improve another business's agent.
- The model sees conversation text and knowledge-base passages. It does not receive your billing data, your team's account credentials, or data belonging to any other business.
- Embeddings — numerical representations of your knowledge base — are generated once at ingestion and stored in our database, not by the model provider.
- You can turn the AI off at any time from your workspace settings, which leaves the widget capturing contact details without generating answers.
6. Why we process it
- To answer your visitors' questions from your own content — the service you subscribed to.
- To route conversations to your team and notify the right person.
- To create and maintain your contacts and tasks.
- To meter usage and bill you accurately.
- To detect abuse, prevent fraud and keep the service available.
- To report to you which questions your agent could not answer, so you can improve it.
7. What we do not do
- We do not sell personal data, and we never have.
- We do not use your conversations, your knowledge base or your contacts to train models.
- We do not use one customer's data to answer another customer's visitors. Every record carries a workspace identifier and every query is scoped to it.
- We do not send marketing to your visitors. Contact details captured by the agent belong to you and are used for the purposes you determine.
- We do not let the agent claim to be human. If a visitor asks, it says it is an AI assistant and offers a person.
8. How long we keep it
Deleting a conversation from your inbox removes its messages and any embeddings derived from them. Backups are overwritten on a rolling 30-day cycle.
| Data | Retention |
|---|---|
| Conversations and messages | For as long as your workspace is active. Deleted 30 days after account closure. |
| Contacts, notes and tasks | Same as above. Exportable at any time before closure. |
| Knowledge base and embeddings | Until you remove the source, or 30 days after account closure. |
| Usage and cost records | 7 years, as accounting records. |
| Server and security logs | 90 days. |
| Anonymous visitor identifier | 30 days from the visitor's last message. |
9. Subprocessors
We will give notice before adding a subprocessor that processes conversation content, so you can object.
| Provider | Purpose |
|---|---|
| OpenAI | Generating answers and embeddings. API data is not used to train their models. |
| Google Cloud (europe/us regions) | Hosting, database and file storage. |
| Google Firebase | Authentication for the people who sign in to your workspace. |
| Stripe | Subscription billing. Card details are handled by Stripe and never stored by us. |
| SendGrid | Transactional email — escalation alerts, invitations, weekly reports. |
| Meta (WhatsApp Business Platform) | Only if you connect WhatsApp, and only for messages on that channel. |
10. Security
- Data is encrypted in transit and at rest.
- Each workspace's data is separated at the database layer and every query is scoped to a workspace identifier, enforced in code rather than by convention.
- Access to production data is limited to staff who need it, and is logged.
- The widget only runs on the domains you list, and its session tokens are cryptographically signed.
11. Rights of your visitors
Your visitors' rights are exercised against you, because you are the controller of those conversations. If a visitor contacts us directly we will tell them to contact you, and let you know.
We will help you respond: you can search, export and delete any conversation or contact from your workspace, and we will assist with anything the interface does not cover.
12. Your rights as a business
You can access, correct, export or delete your account data at any time, object to processing, or ask us to restrict it. Write to us at the address below.
You can export your contacts and conversations before closing your account. After closure the deletion timetable in section 8 applies.
13. International transfers
Data is hosted in Google Cloud regions. Some subprocessors — notably our model provider — process data in the United States. Those transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.
14. Israeli and European law
Where Israeli law applies, we process personal data in accordance with the Protection of Privacy Law, 5741-1981 and its regulations, including the amendments in force. Where the GDPR applies, we act as processor under Article 28 and will enter into a data processing agreement on request.
15. Changes to this policy
We will post any change here with a new version number and effective date. Material changes are notified by email to workspace owners before they take effect.
Contact
Questions about this policy, or a data request: contact@letstok.com. Letstok Technologies Ltd., Haoman 10, Hadera, Israel, 388501.