Privacy, data retention and GDPR
This article explains what Svellyo stores, for how long, and how to honour data requests from your customers.
Updated September 8, 2026
What the widget stores in the visitor's browser
The widget does not set cookies. It keeps a single random visitor token in localStorage so the same browser sees its previous conversations. No third-party trackers or advertising scripts are loaded. The token is scoped to your workspace and can be cleared with window.Svellyo("reset").
What Svellyo stores about visitors
Messages and attachments in their conversations.
The page URL and referrer when the chat started, browser and operating system, approximate country from the IP address, and the widget language.
Anything you pass through
identify: user id, email, name, avatar and attributes.Satisfaction ratings and comments.
Attachments are stored in private object storage and served through short-lived links.
Retention
Under Settings → Retention the owner chooses how long conversations are kept: Forever, 90 days or 1 year. A daily job permanently deletes conversations whose last message is older than the limit, including their attachments. Analytics keep aggregate counts only.
Set this to match your own privacy policy. Support conversations often contain personal data, and shorter retention is a simple way to reduce risk.
Requests from your customers
Export a person's data
Open Contacts, find the person, and click Export. You get a JSON file with their profile, attributes and every message in their conversations. Send it to them for access or portability requests.
Delete a person
On the same contact page, click Delete. This removes the contact record, their identity and attributes, and unlinks their conversations so they show as an anonymous visitor. Tick Also delete their conversations to remove the messages too. Deletion is permanent.
Export a whole workspace
Owners can download a complete export from Settings → Retention: contacts, conversations, messages, knowledge base articles and settings as JSON. Use it for backups or when moving away from Svellyo.
Deleting a workspace or your account
Deleting a workspace (Settings → Danger zone) hides it immediately and purges its data after a short grace period. Deleting your account (Account → Danger zone) does the same for every workspace you own and removes your profile. Transfer ownership first if teammates need to keep a workspace.
AI processing
Visitor messages and the relevant parts of your knowledge base are sent to the AI model provider to generate replies. Svellyo uses providers that do not train on this data. You can turn the AI off per workspace under Settings → AI, in which case no message content leaves Svellyo's infrastructure for AI processing.
Security
All traffic is encrypted in transit. Data is stored in encrypted databases and object storage.
Integration webhook URLs and identity secrets are encrypted at rest.
Widget requests are limited to the domains you allow and rate-limited per visitor.
Team sign-in supports Google and email with verification; sessions can be revoked from Account → Security.
Your privacy policy
Mention Svellyo as a processor for live chat and support in your privacy policy, and link to Svellyo's privacy page. If you need a data processing agreement, contact us from the widget on svellyo.com.