Privacy

Privacy Policy

Last updated: October 4, 2026

1. Introduction

Cognice LLC, a Texas limited liability company doing business as Wisdone AI ("we", "us", "our"), operates the Wisdone.ai platform. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service, in compliance with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

By using our Service, you acknowledge that you have read and understood this Privacy Policy.

2. Data We Collect

2.1 Business Users (Account Holders)

  • Account data: email address, hashed password, website domain
  • Billing data: managed by Stripe; we store only a Stripe customer ID
  • Configuration data: widget preferences, agent settings, knowledge base content, CTA definitions, suggested questions
  • Usage data: message counts, daily usage statistics

2.2 End Users (Chat Widget Visitors)

  • Chat messages: questions and AI-generated responses
  • IP address: used for rate limiting and lead deduplication
  • Session ID: randomly generated per conversation
  • Lead information: only if voluntarily provided (e.g. name, email, phone)
  • User agent and referrer: collected with lead captures

2.3 Visitors to Wisdone.ai

When you browse our own website we collect usage analytics to understand which pages are useful and where sign-up gets stuck. Our product analytics store nothing on your device. If you visit from outside the EU/EEA, the UK and Switzerland, we also use Google Analytics, which sets first-party cookies to count visits (see section 6). Visitors from those regions get no analytics cookies.

  • Page and interaction data: pages viewed, buttons clicked, sign-up and onboarding steps completed
  • Visit source: referring website and campaign tags (e.g. utm_source) in the link you arrived from
  • Device data: browser, operating system, screen size, and approximate location derived from your IP address
  • Session recordings: a replay of page interactions, with everything typed into form fields masked, so we can fix confusing screens

Once you sign in, this usage data is linked to your account so we can see how the product is used. The embedded chat widget never loads these analytics tools on our customers' websites.

2.4 Data We Do Not Collect

  • The chat widget does not use cookies or browser fingerprinting
  • We do not track end users across websites
  • We do not collect payment card details (handled entirely by Stripe)

3. Legal Basis for Processing (GDPR)

DataLegal Basis
Business user account dataContract performance (Art. 6(1)(b))
End-user chat messagesLegitimate interest of the business user (Art. 6(1)(f))
Lead capture dataConsent of the end user (Art. 6(1)(a))
IP addresses for rate limitingLegitimate interest (Art. 6(1)(f))
Website usage analyticsLegitimate interest in improving our website (Art. 6(1)(f))
Payment data (via Stripe)Contract performance (Art. 6(1)(b))

4. How We Use Your Data

  • Provide and operate the chatbot service
  • Process chat messages through AI language models to generate responses
  • Create vector embeddings of knowledge base content for semantic search
  • Display conversation analytics to business users
  • Deliver lead capture data to business users
  • Send transactional emails (verification, notifications, usage alerts)
  • Process payments and manage subscriptions
  • Prevent abuse and enforce rate limits
  • Understand how our website and dashboard are used, and improve them

5. Sub-Processors and Third Parties

We share data with the following third-party services as necessary to provide the Service:

ProviderPurposeData Shared
OpenAIAI language models (chat responses, embeddings)Chat messages, knowledge base content
AnthropicAI language models (chat responses, when a Claude model is selected)Chat messages, knowledge base context
StripePayment processingBilling information
GoogleSSO authenticationEmail address (during sign-in)
Google AnalyticsWebsite traffic measurement (visitors outside the EU/EEA, UK and Switzerland)Website usage data (section 2.3); account ID once signed in
PostHogProduct analytics and session recordingsWebsite usage data (section 2.3); account ID once signed in
ShopifyStore integration (only if you connect a Shopify store)Store products and order lookups requested by your shoppers
ResendTransactional email deliveryEmail addresses, email content
DigitalOceanCloud hosting infrastructureAll data (encrypted at rest)

We do not sell, rent, or trade your personal information to any third party.

6. Cookies and Browser Storage

We do not use advertising cookies. Our product analytics (PostHog) run in cookieless mode and store nothing on your device. Google Analytics sets first-party cookies only for visitors outside the EU/EEA, the UK and Switzerland, and never for advertising. You can block them in your browser settings or with Google's opt-out add-on. Everything else we store is what the Service needs to work:

NameTypePurposeDuration
auth_tokenCookie (HTTP-only)Keeps you signed in to the dashboard7 days, or until sign-out
auth_claimsCookieLets the dashboard show the right pages for your role7 days, or until sign-out
_ga, _ga_*Cookie (Google Analytics)Counts visits and returning visitors. Not set for visitors from the EU/EEA, UK or SwitzerlandUp to 2 years
wisdone_attributionSession storageRemembers which link or campaign brought you here, for the rest of this visitUntil the browser tab is closed
darkModeLocal storageRemembers your light/dark theme choiceUntil cleared
Demo customizationLocal storageCarries the look you chose in the demo into your new accountRemoved after sign-up
wisdone_session_*Local storage (chat widget)Keeps an ongoing chat open across page reloads on websites using our widget24 hours

7. Data Retention

We retain data for the duration of your account, subject to the following policies:

Data TypeRetention Period
Account dataUntil account deletion
Conversation analyticsBased on plan tier: 7 / 30 / 90 / 180 days, or unlimited
Conversation checkpointsAutomatically cleaned up after 30 days
LeadsBased on plan tier retention period
Knowledge base contentUntil manually deleted or account deletion
Website usage analyticsUp to 14 months
Session recordingsUp to 30 days

Upon account deletion, all associated data is permanently removed from our systems, including vector embeddings, conversation data, leads, and configuration.

8. Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights:

  • Right of access: Request a copy of your personal data (available via the Export Data feature in your dashboard)
  • Right to rectification: Update inaccurate personal data through your account settings
  • Right to erasure: Delete your account and all associated data (available via the Delete Account feature in your dashboard)
  • Right to data portability: Export your data in a structured, machine-readable JSON format
  • Right to restriction: Request restriction of processing by contacting us
  • Right to object: Object to processing based on legitimate interest by contacting us

To exercise any of these rights, use the self-service tools in your dashboard or contact us at support@wisdone.ai.

9. California Privacy Rights (CCPA)

If you are a California resident, you have the following additional rights:

  • Right to know: Request disclosure of what personal information we collect, use, and share
  • Right to delete: Request deletion of your personal information
  • Right to opt-out of sale: We do not sell personal information to third parties
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights

We do not sell, share, or use your personal information for cross-context behavioral advertising.

10. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Passwords are salted and hashed using bcrypt
  • All data in transit is encrypted via TLS/HTTPS
  • JWT-based authentication with HTTP-only cookies
  • Widget-to-server communication is encrypted with AES
  • Database access is restricted and credentials are stored as environment variables
  • Content Security Policy (CSP) headers restrict widget embedding to authorized domains

11. Children's Privacy

Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related inquiries, data requests, or complaints, please contact us: