Saytu
Legal

Privacy Policy

How Saytu collects, stores, shares, and deletes data connected to your store's AI character widget.

Last updated 2026-07-09. Under legal review.

Data controller

Saytu is a product of Bot and Life Co., Ltd. (company registration 0105547132674), 100 J.Press Tower A, Floor 12, Nanglinchee Rd., Chong Nonsee, Yannawa, Bangkok 10120, Thailand. It is the data controller for the processing described below. Privacy requests and questions go to info@botnlife.co.

What we process

Operating the assistant involves three kinds of data: the product catalog and store policies you connect, the text of visitor conversations with the character, and — only when order lookup is enabled — order-lookup inputs such as an order number or email needed to check order status.

Redaction before storage

Order-lookup inputs are passed through a redaction step before a conversation is ever written to the database. Messages produced this way are tagged as redacted at the point of storage, not redacted after the fact.

Contact identifiers

We don't store shopper email or phone numbers in plaintext. We store a one-way hash of the identifier (plus a short masked preview for support screens), which cannot be reversed back into the original email or phone number.

Retention

Contact identifiers expire automatically about 90 days after last activity, after which a scheduled job anonymizes them. Live chat session records have a 24-hour lifetime and are removed automatically after that. Conversation transcripts otherwise remain until deleted through a merchant request or app uninstall.

Uninstalling the Shopify app

When a merchant uninstalls Saytu on Shopify, Shopify sends a shop/redact webhook roughly 48 hours later. On receiving it, we hard-delete everything tied to that shop: conversations, messages, contacts, knowledge sources, and the shop record itself.

Shopify customer GDPR webhooks

We honor Shopify's mandatory customer privacy webhooks: customers/redact (erase a specific customer's data on request) and customers/data_request (report what we hold about a customer).

Subprocessors

We use the following service providers to operate Saytu. Conversation content is sent to the AI, speech-to-text, and text-to-speech providers below solely to produce a reply — it is not used to train their public models.

  • OpenAI and/or OpenRouter — generating chat replies
  • Groq — speech-to-text
  • Cartesia — text-to-speech
  • AWS S3 — asset and uploaded character model storage
  • MongoDB Atlas — database
  • Shopify — billing for Shopify installs
  • Stripe — billing for web installs
  • Clerk — authentication for web installs

International transfer

Most of the subprocessors above are US-hosted. Using Saytu means conversation and account data may be transferred to, and processed in, the United States and other countries outside Thailand.

Your choices

Merchants can request anonymization or deletion of their shop's data from Settings or by contacting info@botnlife.co. Shoppers who want their data deleted or reported on should ask the merchant's store to submit that request — see the Shopify customer GDPR webhooks above for how that's handled.

Changes to this policy

We may update this policy as the product changes. The date at the top of this page reflects the last update.

Contact

Privacy questions can be sent to info@botnlife.co.