embent

Privacy Policy

Last updated August 2026.

Draft — pending legal review. This page describes our actual data practices but has not been reviewed by a lawyer. It is not legal advice.

What this policy covers

Embent (embent.com) is an AI agent platform: businesses point Embent at their website, our crawler reads and indexes that content, and an embeddable chat widget answers the business's visitors using that content. This policy covers what we store about (a) the business owners who sign up for an Embent account ("customers") and (b) the visitors who chat with a customer's widget on the customer's own site.

Information we store about customers

  • Account details: name and email address, used for sign-in and notices.
  • Workspace and billing data: workspace name, plan, and subscription status (payments themselves are handled by Polar — see Subprocessors below; we do not store your card number).
  • Session data: sign-in sessions include an IP address and user-agent string, used only for authentication security (detecting suspicious sign-ins), never for tracking or advertising.
  • Content you give us: the pages, documents, and Q&A text you submit for your bot to crawl and index, and any settings you configure (bot name, appearance, welcome message, domain allowlist).

Information we store about a customer's website visitors

When someone chats with a customer's Embent widget, we store the conversation on behalf of that customer, so the customer can review it in their dashboard:

  • The messages exchanged (visitor questions and bot answers, with citations).
  • If the visitor voluntarily submits a lead form: the name, email, phone number, and stated intent they typed in. Lead capture never blocks chatting and is always visitor-initiated.
  • We do not require visitors to sign in, and the widget itself sets no advertising or tracking cookies (see Cookies below).

This visitor data belongs to, and is controlled by, the Embent customer running that bot — we process it as a processor on their behalf, not as an independent controller.

Cookies

Our dashboard (app.embent.com) sets a single authentication session cookie so you stay signed in. The embeddable chat widget sets no cookies of its own. We do not use advertising, analytics, or cross-site tracking cookies anywhere in the product today.

Subprocessors

We rely on the following subprocessors to run Embent:

  • Cloudflare — hosting, AI Search (content indexing and retrieval), and the AI Gateway our chat requests route through.
  • Railway — hosting for our API and database.
  • OpenAI — the language model that generates chat answers, called only through Cloudflare's AI Gateway, never directly.
  • Polar — our merchant of record for billing; Polar handles payment details directly, we never see or store your card number.
  • Brevo — transactional email (sign-up verification, password reset, and account notifications).

How long we keep data

We keep customer account and bot data for as long as the account is active. Conversation and lead data is kept for as long as the bot exists so the customer can review it; deleting a bot or closing an account removes it. Downgrading a plan never deletes data.

Your choices

Customers can export their leads, delete sources, pause or delete a bot, and close their account at any time from the dashboard. Website visitors who want data removed should contact the business running the widget they chatted with — as the controller of that conversation data, they are best placed to act on the request, and can reach us to relay it if needed.

Contact

Questions about this policy: [email protected].