What we process, and where it sits.
Written as specifics rather than reassurance. If a claim here cannot be checked, it should not be here.
Version 1 / 4 September 2026
What AnswerHatch processes
- Your published pages
- We crawl the public pages of the domain you nominate, with your approval and after you have proved control of the domain. Each document is stored with the URL it came from, the date it was fetched and its hash. AnswerHatch is built for public content: pages behind a login, case files and internal systems are out of scope.
- Your visitors' questions
- The text of the question, and the page it was asked from. Nothing else about the visitor is required for the widget to answer.
- Your account details
- The contact email on the account, the domains on the subscription, and the usage counts that the plan caps are measured against.
- Operational logs
- Request records used to run the service, enforce rate limits and diagnose faults.
How long questions are kept
Visitor questions are retained for 30 days and then deleted. The retention window is there so a fault can be diagnosed and a refusal can be reviewed. After it elapses the question is gone.
Where it is processed
On AnswerHatch-operated infrastructure. We run the machines. Questions are not sent to a hosted model provider, and no third-party model API is in the path of an answer. The literal claim: your data does not leave our platform, it stays on our own machines, it is retained 30 days, and it never transits a third-party model API.
We do not fine-tune models on your content or on your visitors' questions.
Sub-processors
- Cloudflare
- Network in front of the platform: DNS, the tunnel and the edge that customer traffic passes through. This is our only sub-processor today.
- Stripe (not yet in the path)
- When self-serve billing opens, Stripe will process card payments and hold the billing details that go with them. Self-serve billing is not open yet, so no payment data is being processed today. This page will be updated on the day that changes.
Voice, and who hears the audio
AnswerHatch never receives audio. When a visitor uses the Ask by voice button, the speech is turned into text by their own browser and only the text reaches us. Which service does that transcription depends on the browser: Chrome and Edge send the audio to their own vendor's speech service, and Safari transcribes on the device. That step is between the visitor and their browser vendor, and it happens before AnswerHatch is involved.
Consent at the start of a chat
The widget shows a consent and disclosure line when a chat starts, by default, on every tier. It is a product decision rather than a customer setting, so it cannot be switched off by accident.
If you are the site owner
Your visitors' questions are processed by us on your behalf. You are welcome to name AnswerHatch as a sub-processor in your own privacy policy, and we will send you wording you can paste in. Ask at [email protected].
Questions, corrections and deletions
Write to [email protected]. Tell us the domain and roughly when the question was asked, and we will find it, tell you what is held and delete it on request.
What this page does not say: it claims no certifications and no audits, because we hold none today. See the security page for the architecture facts we offer in their place.