Legal

Privacy Policy

Last updated: July 4, 2026

We believe privacy is a right, not a feature. This policy explains plainly what data Chatterfly collects, why, and how you can control it.

1. Introduction

Chatterfly Technologies Private Limited ("Chatterfly", "we", "us", or "our") operates the Chatterfly agentic workflow platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, when we share it, and the choices you have. By using the Service you agree to this Policy.

2. Information We Collect

2.1 Account & Identity Data

When you create an account we collect your name, email address, and (if you use OAuth) the profile information returned by your identity provider (GitHub or Google). Passwords are hashed with bcrypt and never stored in plaintext.

2.2 Workflow & Configuration Data

We store the workflow definitions, agent configurations, prompt templates, and knowledge-base content you create on the platform. This data is stored per-tenant and is logically isolated from other tenants.

2.3 Integration Credentials

If you connect third-party services (LLM providers, telephony, messaging channels, etc.) we store the credentials you provide. All credentials are encrypted at rest using AES-256-GCM with per-tenant key derivation (HKDF-SHA256) and are never returned in API responses.

2.4 Conversation & Run Data

The platform records the inputs, outputs, and timeline events of each workflow run. This includes messages exchanged with end-users of your workflows. You are responsible for ensuring your end-users have been informed of and consented to any recording or processing.

2.5 Usage & Technical Data

We automatically collect IP addresses, browser/device type, pages visited, and other standard server-log data to operate, secure, and improve the Service. API keys are stored as SHA-256 hashes with a visible prefix only.

2.6 Communications

If you contact us by email or submit a support request we retain the content of that communication.

3. How We Use Your Information

  • Provide, operate, and maintain the Service.
  • Authenticate you and enforce role-based access control.
  • Execute workflow runs on your behalf, including calling third-party LLMs and APIs you have configured.
  • Send transactional emails (e.g. email verification, password reset).
  • Monitor platform health, investigate security incidents, and enforce our Terms of Service.
  • Comply with applicable legal obligations.
  • Improve the platform through aggregated, anonymised usage analytics.

4. Sharing of Information

4.1 Sub-processors

We engage infrastructure and service providers (cloud hosting, database, email delivery) to operate the platform. These sub-processors process data only on our instructions and under confidentiality obligations.

4.2 LLM & Third-party API Calls

When you configure a workflow to use an external LLM (e.g. OpenAI, Google Gemini) or any other third-party API, the inputs and outputs of those calls pass through that third party. Their own privacy policies apply. You are responsible for reviewing those policies and obtaining any necessary consents from your end-users.

4.3 Legal Disclosure

We may disclose information if required by law, court order, or to protect the rights, property, or safety of Chatterfly, its users, or others.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service.

4.5 No Sale of Personal Data

We do not sell, rent, or trade your personal information to any third party for their own marketing purposes.

5. Data Retention

We retain your account data and workflow data for as long as your account is active. Run-timeline and audit-log records are retained for at least 90 days and may be retained longer for compliance purposes. You may request deletion of your account and associated data by contacting us at info@chatterfly.in. Some data may be retained in backups for a limited period after deletion.

6. Security

We implement technical and organisational measures appropriate to the risks involved, including AES-256-GCM encryption for credentials, short-lived signed JWTs, append-only audit logs with SHA-256 hash chains, and per-tenant query isolation. No method of transmission or storage is 100% secure; please use a strong, unique password and report suspected vulnerabilities to info@chatterfly.in.

7. Your Rights

Depending on applicable law you may have the right to access, correct, or delete your personal data, to object to or restrict certain processing, and to data portability. To exercise these rights please email info@chatterfly.in. We will respond within the timeframe required by applicable law.

8. Cookies & Similar Technologies

We use session cookies necessary for authentication and platform functionality. We do not currently use third-party advertising or tracking cookies. You can configure your browser to reject cookies, but some features of the Service may not function correctly if you do.

9. Children's Privacy

The Service is not directed at children under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information please contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date at the top of this page and, where required, notify you by email or in-app notice. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

11. Contact Us

For privacy-related enquiries, requests, or complaints please contact: Chatterfly Technologies Private Limited Email: info@chatterfly.in