Privacy Policy

Last updated: [Effective date]

Draft, pending legal review. This is a plain-English draft. It isn’t final and may change before HopChat launches. Text in brackets is still to be filled in.

The short version

  • We store what HopChat needs to work: your account, your company’s messages, and the files you share.
  • AI providers see messages only when an agent or a search answer is used, and only from the chats involved.
  • AI provider keys stay on our servers. They’re never sent to your devices.
  • We don’t sell your data, show ads, or use your messages to train AI models.
  • Backups are kept for 30 days. You can ask us to export or delete your data at any time.

This policy explains how [Company legal name] (“we” or “us”) handles information in the HopChat apps for iPhone, iPad, and Mac, the HopChat service, and this website. If something here is unclear, email us at [contact email].

Who is responsible for your data

HopChat is a workplace tool. Your company decides who joins, which chats exist, and which agents are added. For the content your company puts into HopChat, such as messages and files, your company is in charge and we process it on its behalf. For account details, billing, and how we run our own service, we are responsible.

What we collect

Account information

Content

Calls

Voice and video travel through our real-time media servers to connect the people on the call. We keep a record that a call happened, who joined, and how long it lasted. We don’t record the audio or video of calls.

Device and usage information

Billing

If your company pays for a plan, we keep the plan, seat count, and billing contact. Payments are handled by [payment processor]. We don’t store full card numbers.

How we use it

AI agents and AI providers

Agents in HopChat are powered by AI providers, currently OpenAI and Anthropic. Here’s exactly when they see your data:

We send this data through the providers’ business APIs and keep the API keys on our servers. [Confirm each provider’s current API terms on training and data retention, and summarize them here.] We don’t use your content to train AI models.

On the Business plan, your company can use its own OpenAI or Anthropic key. Requests made with your key are also covered by your own agreement with that provider.

Who we share it with

We don’t sell personal data, and we don’t share it for advertising. We share it only with:

A current list of our service providers is available at [link to subprocessor list].

How long we keep it

Your choices and rights

We’ll respond to requests within 30 days.

Security

We encrypt data in transit with TLS, limit access to production systems to the people who need it, and keep AI provider keys on our servers rather than on devices. [Describe encryption at rest and any other safeguards.] No system is perfectly secure, so if we learn of a breach that affects your data, we’ll tell your company promptly.

Where your data is stored

HopChat is hosted in [region or country]. If data moves across borders, we use the safeguards the law requires, such as standard contractual clauses.

This website

This website doesn’t use advertising or analytics cookies. Our servers keep standard request logs, such as IP address and pages visited, to keep the site running and secure.

Children

HopChat is for work and isn’t meant for anyone under 16. If you think a child has given us personal data, contact us and we’ll delete it.

Changes to this policy

If we make a significant change, we’ll tell you in the app or by email before it takes effect. The date at the top shows when this policy last changed.

Contact

[Company legal name]
Email: [contact email]