Privacy Policy

Last updated: July 2026

This Privacy Policy describes how IaHaI ("we", "us", or "our") collects, uses, and protects information when you use IaHaI (the "Service"), including when your customers interact with an AI-powered chat widget powered by our platform. By using the Service, you agree to the practices described in this policy.

1. Data We Collect

When a visitor interacts with a IaHaI chat widget, the following data is collected:

  • Chat conversation text — the full content of messages sent by the visitor and replies generated by the AI assistant.
  • Bot response corrections — when a business owner uses the Bot Teaching feature to correct a bot answer, the original answer, the corrected answer, and the associated question are stored per-bot and in anonymised form in a cross-bot global teaching store.
  • Timestamps — the date and time each conversation begins.
  • Detected language — the language of the visitor's messages (e.g. English, Hebrew, Arabic, French), detected automatically from message content.
  • Message count — the number of messages exchanged within a session.
  • Widget interaction events — whether the widget was opened or closed, device type (mobile / desktop), and session duration. No IP address or personally identifiable information is captured from these events.
  • Monthly message count per bot — a running total of messages processed by each bot in the current billing month. This counter contains no personal data; it is used solely to enforce plan limits and reset automatically at the start of each new billing month.
  • Anonymised conversation archive — widget conversations (excluding test-chat sessions) are retained in a permanent, anonymised archive for service-improvement purposes. Before archiving, all emails, phone numbers, and URLs embedded in message text are automatically replaced with placeholder tokens ([email], [phone], [url]). This data is used solely to improve the quality of AI responses and to build fine-tuning datasets for future model versions. It is never sold or shared with third parties. You may request deletion of archived data attributed to your business by contacting support@iahia.net.

We do not collect names, email addresses, IP addresses, or any other personally identifiable information from end-users of chat widgets unless a visitor voluntarily includes such information in their chat messages. Any such data incidentally included is scrubbed before archiving. The one deliberate exception is appointment booking (Section 18): when a visitor chooses to book an appointment through the chat, they provide their name, phone number, and optionally an email address so the business can honour and confirm the booking.

Service limits are enforced based on your subscription plan. Conversation counts reset on your monthly billing cycle. Conversation count data is stored per bot and deleted after 365 days.

2. How We Use This Data

Collected data is used for the following purposes:

  • Generating AI responses to visitor questions in real time.
  • Providing the business operator (our customer) with analytics — most-asked questions, language breakdown, session counts, and engagement trends.
  • Improving the quality of AI responses across the platform through aggregated, de-identified pattern analysis (cross-bot learning).
  • Where the operator has enabled AI training and the widget has displayed a consent banner — using conversation data to improve AI model behaviour. This only applies when both conditions are met simultaneously.
  • Service operation — authorised IaHaI personnel may access conversation and configuration data as needed to operate the platform, provide customer support, and monitor response quality.

3. Sub-Processor: Anthropic Claude API

All AI responses are generated by Anthropic's Claude API. Conversation messages are transmitted to Anthropic's servers for processing. Anthropic is a named sub-processor under this policy.

Anthropic's use of data submitted through its API is governed by Anthropic's own privacy policy and API usage policies. We have a Data Processing Agreement (DPA) in place with Anthropic for business use of the API.

By interacting with a chat widget powered by IaHaI, users acknowledge that their messages are processed by the Anthropic Claude API.

4. AI Training and Consent

Conversations may be used to improve the AI model only when both of the following conditions are met:

  • The widget operator has enabled the AI Training setting in their bot configuration.
  • The widget has displayed a consent notice banner to the visitor before the conversation begins, and the visitor has actively dismissed it by clicking "I understand — start chatting".

If the consent banner has not been shown, no conversation data will be used for AI training purposes, regardless of the operator's settings. This is enforced at the API level.

5. Data Retention

Conversation logs are retained for 365 days from the date of the conversation. After this period, conversations are automatically deleted from our servers. Aggregated, de-identified analytics (question counts, topic trends, language distribution) may be retained indefinitely as they contain no conversation-level data.

Website scan cache (used to provide the AI with business context) is retained for up to 24 hours per domain, then automatically purged.

6. Your Rights — Deletion and Data Access

You have the right to request a copy of, or the permanent deletion of, any conversation data associated with your use of a IaHaI widget. To exercise these rights, contact us at:

support@iahia.net

We will respond to deletion and access requests within 30 days. Because conversation logs do not include names or email addresses by default, requests must include enough context (approximate date, business widget used, and a sample of what was discussed) to locate the relevant records.

7. GDPR — Users in the European Union

The Service is operated from Israel and may serve users located in the European Union. Where EU data protection law (GDPR — Regulation (EU) 2016/679) applies, we rely on the following legal bases for processing:

  • Legitimate interests (Article 6(1)(f)) — for processing conversation data to generate AI responses and provide analytics to the operator. Our interest is providing the contracted service; this interest is not overridden by user rights because no sensitive personal data is collected and users can opt out by not using the widget.
  • Consent (Article 6(1)(a)) — for any AI training use, obtained through the explicit consent banner described in Section 4.

EU users have the right to access, rectify, erase, restrict, and port their personal data, and to object to processing. To exercise these rights, contact us at support@iahia.net.

Israel has been recognised by the European Commission as providing an adequate level of data protection for personal data transfers from the EU.

8. Israeli Privacy Law

Users located in Israel are covered under the Privacy Protection Law 5741–1981 and its regulations, including the Privacy Protection Regulations (Data Security) 5777–2017.

We maintain appropriate technical and organisational security measures as required under these regulations. The database of conversation logs constitutes a "database" under the law and is operated in compliance with its requirements.

Israeli users may exercise rights of access and correction under the law by contacting us at support@iahia.net.

9. Data Security

Conversation data is stored on Vercel's infrastructure. Access to raw conversation logs is restricted to the platform administrator account. Data in transit is protected by TLS. We do not sell, rent, or share conversation data with third parties other than Anthropic (sub-processor) and Vercel (infrastructure provider).

10. Cookies and Tracking

IaHaI does not use advertising cookies or third-party tracking pixels. The chat widget does not set any cookies. Anonymous session analytics (widget open/close events) are collected via a first-party API endpoint and do not involve any third-party analytics service.

11. Automated System Improvement

To improve response quality over time, the Service may analyse anonymised conversation Q&A pairs and automated test results using the Anthropic Claude API. This process generates candidate style-rule updates; a rule is only applied automatically when its confidence score reaches 0.85 or higher as assessed by the model.

No personally identifiable information is retained during this analysis. All conversation data used for improvement purposes is anonymised before being passed to the Anthropic API, and raw conversation files are subject to the retention limits described in Section 5.

A log of every improvement run — including which rules were applied or rejected and the confidence scores — is stored in data/improvement-log.json and is accessible to the platform administrator.

12. Automated Quality Testing

The Service runs an automated quality test suite before each production deployment. Tests include static file analysis (navigation, legal compliance, API security) and live bot-response evaluations that call the Anthropic API with sample questions.

Test results are recorded in data/test-scores.json with a timestamp, per-category scores, and a list of failed test IDs. No end-user data is used in quality tests; all evaluation prompts are synthetic and authored by IaHaI.

13. Sub-Processors

We use the following third-party sub-processors to deliver the Service. Each sub-processor is bound by a data processing agreement or equivalent contractual protections.

  • Anthropic, PBC — AI language model inference (conversation responses and quality improvement analysis). Data is processed under Anthropic's usage policies and data processing addendum.
  • Paddle (Paddle.com Market Ltd) — payment processing and subscription management, acting as merchant of record. Payment method data (card numbers, billing address) is processed and stored exclusively by Paddle; IaHaI does not receive, store, or have access to your payment method details. Billing data (invoices, subscription status) is held by Paddle and subject to their privacy policy.
  • Vercel Inc. — cloud infrastructure, hosting, and serverless compute. All Service data at rest resides on Vercel's infrastructure and is subject to their data processing addendum.

If we add, replace, or remove a sub-processor we will update this section and the "Last updated" date.

16. Bot Teaching Data

The Bot Teaching feature allows business owners to correct bot answers by submitting a preferred response. This data is handled as follows:

  • Per-bot store — corrections are saved to the business owner's individual teaching file and are used to improve responses for that bot only. This data is accessible only to the account owner and the platform administrator.
  • Global (anonymised) teaching store — corrections are also contributed anonymously to a cross-bot teaching store. The original question pattern and corrected answer are stored; no business name, bot ID, or user identity is retained in the global store.
  • Usage — global teaching entries with a confidence score of 0.6 or higher are injected as style-reference context into all bots on the platform to improve overall answer quality.
  • Deletion — business owners may delete any of their own teaching entries at any time via the Bot Teachings tab in their dashboard. Deletion of a per-bot entry does not retroactively remove anonymised data already contributed to the global store.

Teaching data is not used to train or fine-tune any AI foundation model. It is used solely to steer existing model responses via prompt injection.

17. Account Information & Marketing Emails

When you create an account or sign in (via Google, GitHub, Apple, or an email magic link), we retain your email address and basic account metadata (sign-in method, first and last sign-in dates, and your plan) for as long as your account is active. This is necessary to operate the Service — authenticate you, apply your plan, and provide support — and is covered by this policy. We always send essential account and service emails (such as sign-in links and billing notices) regardless of any marketing preference.

Separately, you may opt in to receive occasional product and marketing updates from the IaHaI team. This is entirely optional and requires your explicit consent — the opt-in checkbox at sign-in is unticked by default, and we never add you to a marketing list by implication. We record the date of your consent.

You can withdraw consent at any time: toggle "Product & marketing updates" off in your dashboard, or click the unsubscribe link included in every marketing email. Withdrawing consent removes you from the marketing list immediately and does not affect essential account emails. To request deletion of your account email entirely, contact us at support@iahia.net.

18. Appointment Booking Data

Businesses on eligible plans can take appointment bookings through their dashboard and their chat widget. When a visitor books (or requests) an appointment, we store the details they submit — name, phone number, optional email address, the chosen service and time, and any note they add — solely to provide the scheduling service for the business they booked with. That business sees these details in its dashboard calendar and uses them to confirm, decline, or manage the appointment; where the business enables it, we send the visitor confirmation and status messages on the business's behalf.

Booking details are not used for AI training. Where booking details (such as a phone number) also appear inside chat message text, the standard scrubbing in Section 1 applies before any archiving and before any cross-business pattern aggregation (Section 11). Booking records can be deleted on request: use the cancellation link in your confirmation, contact the business you booked with directly, or email support@iahia.net.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date above. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy. If you do not agree to the updated policy, you must stop using the Service.

15. Contact Us

For privacy-related questions, data requests, or to report a concern:

support@iahia.net

General support: support@iahia.net

© 2026 IaHaI · Terms · Home