Adding a chatbot to your website means visitors will type questions into it, and sometimes more than questions: names, e-mail addresses, account details. As the site owner, you’re responsible for how that information is handled on your site. This guide explains what a chatbot typically collects, where it goes, and the settings and habits that keep privacy in mind.
We use GoChatterBot as the example throughout. This is practical guidance, not legal advice; for your specific obligations, speak to someone qualified where you operate.
What a website chatbot collects
Any chatbot needs the question to answer it. Beyond that, products differ. Ask any vendor exactly what they receive and keep. For GoChatterBot:
What the service receives to answer
To answer a question, the service receives the question, the earlier messages in the same conversation, the address of the page it was asked on and the visitor’s IP address. Our Privacy Policy explains what we keep, for how long, and the providers that help us run the service.
What your WordPress site keeps
The plugin stores each conversation in your own WordPress database: the questions and answers, the sources used, the page where it started, the time, any rating the visitor gave, and, only if you choose, the visitor’s IP address and approximate location. You control that copy.
The settings that matter
All of these are in GoChatterBot → Settings → Access and privacy. The Access and privacy guide covers them in detail.
Keep conversations for
Set a number of days and older conversations are deleted automatically once a day. Leaving it at 0 keeps them until you delete them. Keeping records only as long as you need them is a good default: pick a period that covers how long you’d realistically look back.
Visitor addresses
This decides whether each visitor’s IP address and approximate location are stored with the conversation. If you don’t use that information, leave it off.
Who sees the chat
Choose everyone, or only signed-in users with the roles you tick. Limiting the chat to logged-in members makes sense for a members’ area or an intranet.
When the plugin is deleted
Decide whether deleting the plugin also deletes every conversation and setting. Leaving this off keeps your records if you reinstall; turning it on means removing the plugin removes the data too.
Protection that’s built in
- Sensitive number masking. Numbers that look like payment card or Social Security numbers are replaced before a message is saved.
- Only published content is read. The chatbot never reads drafts, private posts or password-protected pages, so it can’t repeat them to visitors.
- Answers stay on your site’s subject and come from your published content, not from other conversations.
Habits worth building
Tell visitors what they’re talking to
Use the AI notice (General settings) to say, before the first question, that visitors are talking to an automated assistant. It’s honest, and it sets the right expectations.
Ask visitors not to share personal details
The Note under the message box stays visible while visitors type. A line such as “Please don’t enter personal or payment details” helps. Masking catches common number formats, but it can’t catch everything a visitor might type.
Mention the chatbot in your privacy policy
You run the website, so your privacy policy should cover the chatbot: that visitors can chat with an automated assistant, what your site keeps and for how long, and how to ask for a conversation to be deleted.
Know how to find and delete a conversation
If a visitor asks for their conversation to be removed, you can search Conversations by what was said or by date, open the transcript and delete it. If you need to provide records, Export downloads the conversations you’ve filtered as a CSV file. See Conversations.
Review who has admin access
Conversations can be read by site administrators. Make sure the people with that access are the people who should have it.
A starting point for your privacy policy
Every organization’s wording will differ, and your policy should reflect your own settings and obligations. As a starting point, many sites add a short paragraph along these lines, adjusted to match what they actually do:
Our website has a chat assistant that answers questions using the information published on this site. It is an automated service, not a person. When you use it, we keep a record of the conversation for [number] days to improve our website and respond to feedback, after which it is deleted automatically. Please don’t enter personal, financial or health information in the chat. To ask us to delete a conversation, contact [contact details] with the date and approximate time of your conversation.
Fill in the retention period you set under Keep conversations for, mention IP addresses only if you turned on Visitor addresses, and link to our Privacy Policy for the service itself.
Privacy questions to ask any chatbot vendor
Privacy checklist
- What does the service receive with each question, and what does it keep?
- Where are conversations stored, and who can read them?
- Can I set how long conversations are kept?
- Can I switch off storing IP addresses?
- Can I export and delete individual conversations?
- Can the chatbot see unpublished or private content?
- Which other companies help run the service?
Privacy and trust go together
Visitors trust a chatbot that is clear about being automated, honest when it doesn’t know, and careful with what they type. The same settings that protect privacy also make the chatbot more trustworthy. For the accuracy side, see our article on grounded answers, and for how everything fits together, the Conversations & Privacy feature page.
