What we collect, why, and where it goes.
Plain English. No legalese to obscure what's happening with your information. If something here is unclear, write to us and we'll fix the wording.
Last updated · May 4, 2026
Who we are
TheChattyAI is operated by Richard Gallagher, based in Henderson, Nevada. We provide AI voice receptionists and operations software to home-service and small-business owners. When this policy says "we" or "us," it refers to TheChattyAI.
What we collect
We collect different information depending on whether you visit our website, request a demo, or sign up as a customer.
From every website visitor
- Pages visited and time on site. Standard server logs.
- IP address and User-Agent. Used for rate limiting and basic abuse prevention.
- Session ID. A random identifier so the demo flow can connect across pages without an account.
When you ask Luna to call your phone
- Configurator selections. Industry, tone, and language preferences you choose to shape the demo.
- Phone number you provide for the callback, plus the affirmative consent flag.
- Audio of the demo call. The same recording infrastructure we use for paying customers. Stored encrypted, not used to train third-party models.
- Transcript of the demo conversation. Stored so you can review the call and so we can improve quality.
When you fill in a contact form, request a callback, or book a demo
- Name.
- Email or phone number (whichever you give).
- Business name and any details you choose to share.
- Consent flag (we record that you affirmatively asked us to contact you).
What we do not collect
- We do not buy or rent contact lists. Every record originates from someone who came to our site.
- We do not run advertising trackers, fingerprinting scripts, or third-party analytics on this site.
- We do not collect government IDs, payment card numbers, or banking details on the marketing site. Payments are handled by a PCI-Level-1-compliant payment processor on a separate page.
How we use it
- To run the demo you asked for. Microphone audio and transcripts power the live conversation and the post-call summary.
- To follow up when you've asked us to. If you give us a phone or email and ask us to contact you, we will, until you ask us to stop.
- To improve the product. Aggregate, de-identified usage informs which features need work. We don't sell or share this data.
- To meet legal obligations. Tax records, fraud investigations, and lawful requests, narrowly scoped.
Service providers
Some parts of TheChattyAI are powered by third-party service providers. They process your data only to provide their part of the service, under contracts that bind their use. We maintain a current list of subprocessors by category. If you need the named, line-by-line subprocessor list (for an enterprise procurement review, a HIPAA / BAA review, or a privacy-impact assessment), email hello@thechattyai.com and we will share it under NDA.
- Telephony. Receives your phone number when you book a callback or run the live phone demo. Call audio in transit. PSTN-grade carrier with HIPAA BAA available.
- Voice orchestration. Receives audio frames in real time during a call. Holds nothing once the call ends.
- Language model provider. Receives turn-by-turn audio and transcripts during a call to power Luna and Lucy. Does not retain or train on this data.
- Recording storage. Durable encrypted storage of call recordings. Per-tenant folder isolation.
- Booking handoff. When you click "Book a demo," your contact details transfer to a third-party scheduling tool to confirm the slot.
- Payment processor. PCI-Level-1-compliant provider for paying customers and customer-facing invoices. We do not see card numbers.
- Hosting + edge. Backend on a HIPAA-capable PaaS, frontend on an edge CDN.
- Typography CDN. Loads the display, body, and mono typefaces. Sends your IP and User-Agent only.
- Observability. Agent traces and call analytics, retained three years, covered by a Business Associate Agreement for medical workloads.
How your data stays yours
TheChattyAI is multi-tenant: every customer is logically isolated from every other customer. We enforce this at the database level using PostgreSQL row-level security with a per-request tenant context. A connection cannot read another tenant's data even if a query forgets to filter by tenant. We've written internal lint gates that fail the build if anyone tries to bypass the rule.
Customer-facing actions (calls, SMS, bookings) are written to an append-only event ledger. The ledger cannot be edited or deleted without a database admin, which gives you and us a tamper-evident record of what your AI agents actually did.
Retention
- Demo session data: retained while we use the insights to improve the product. You can ask us to delete a specific session at any time.
- Customer call data: retained for the life of your account. You can request export and deletion when you cancel.
- Observability traces: three years.
- Audio recordings: stored encrypted by our recording-storage provider; retention configurable per tenant.
- Tax and legal records: retained for the periods required by US law.
Your rights
If you live in California, the EU/UK, or another jurisdiction with privacy laws, you have rights regarding your personal information: typically to access, correct, port, or delete it. Email us and we'll honor a valid request within 30 days. We don't make this hard.
- To stop demo follow-ups: reply STOP to any SMS, or email hello@thechattyai.com.
- To delete your data: email us. We'll confirm what we held and what we removed.
- To get a copy of your data: email us. We export to JSON or CSV.
Security incidents
If we ever discover unauthorized access to your data, we will tell you within 72 hours of confirmation, with a plain description of what we know, what we don't, and what we're doing about it. We will not soft-pedal a real incident.
Changes to this policy
We update this policy as the product evolves. The "Last updated" date at the top reflects the most recent change. Significant changes will be announced by email to customers.
Contact
Email hello@thechattyai.com or call +1 (877) 839-6798. We're a small team. You'll usually hear back from Richard directly.
Questions about anything on this page? Write to us. We read every email.
hello@thechattyai.com