⚡ New: free forever plan — 1 AI receptionist, 50 chats/mo · no card needed
Legal

Privacy Policy

Effective date: July 30, 2026

Who we are

Mazingi ("Mazingi", "we", "us") provides an AI receptionist service that businesses embed on their websites to answer visitor questions and capture leads. This policy explains what we collect, why, and the choices you have. Questions? Email [email protected].

Two kinds of people use Mazingi

  • Customers — businesses that create a Mazingi account and run a receptionist on their website. For customer account data, we are the data controller.
  • Visitors — people who chat with a receptionist on a customer's website. We process visitor data on behalf of that customer, who controls it. If you chatted with a business's assistant and have questions about your data, contact that business first.

What we collect

  • Account information: name, email address, and a securely hashed password — or your basic Google profile (name, email) if you sign in with Google. We never see or store your Google password.
  • Workspace content: the chatbot settings, website pages, documents, and FAQs a customer adds to train their receptionist.
  • Conversations and leads: messages visitors exchange with a receptionist, and details a visitor chooses to share when requesting a quote (such as name, phone, email, ZIP code, and project description). These are stored in the customer's workspace.
  • Technical data: a session cookie to keep you signed in, IP addresses used for rate limiting and spam prevention, and basic request logs.

How we use it

  • To operate the service: answering visitor questions from the customer's own content, capturing and delivering leads, and running the dashboard.
  • To generate AI responses: conversation messages and trained content are sent to our AI provider (OpenAI) to produce replies and search embeddings. Per OpenAI's API terms, this data is not used to train their models.
  • To send transactional email via Resend: account verification, password resets, lead notifications, and conversation copies a visitor requests.
  • To prevent abuse: Cloudflare Turnstile protects our forms from bots; rate limits protect the service.
  • We do not sell personal data, and we do not use your content or your visitors' conversations for advertising.

Who we share it with

Only the service providers needed to run Mazingi, each bound by their own privacy commitments:

  • OpenAI — AI response generation and content embeddings
  • Resend — transactional email delivery
  • Cloudflare — bot protection (Turnstile)
  • Our hosting and database providers — running the application and storing data

We may also disclose information if required by law or to protect the rights, safety, or security of Mazingi, our customers, or others.

Retention and deletion

  • Account and workspace data is kept while your account is active.
  • Customers can delete chatbots, knowledge sources, conversations, and leads from their dashboard at any time; deletion removes the underlying data, including search embeddings.
  • To delete your entire account and workspace, email [email protected] and we will complete it within 30 days.
  • The homepage "try it on your website" preview is ephemeral: it reads one public page, keeps it in memory for up to 20 minutes, and stores nothing.

Security

All traffic is encrypted in transit (HTTPS). Passwords are hashed, sessions are cookie-based with industry-standard protections, and every workspace's data is isolated — each request is checked against your identity, workspace membership, and role before any data is touched. No method of storage is 100% secure, but we treat your leads and conversations as the business-critical data they are.

A small number of named Mazingi staff can open a customer workspace to investigate a support request or a fault. Every such access is written to an audit log recording who opened which workspace and when, and staff cannot change your subscription this way. We do not access your workspace for any other purpose.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email [email protected] and we will respond within 30 days. If you are a visitor whose data lives in a customer's workspace, we will refer your request to that customer and assist them in fulfilling it.

Cookies

We use a single first-party session cookie to keep you signed in, plus Cloudflare Turnstile's cookie for bot protection on our forms. We do not use advertising or cross-site tracking cookies.

Children

Mazingi is a business tool and is not directed at children under 16. We do not knowingly collect their data.

Changes

If we make material changes to this policy we will update the date above and, for significant changes, notify customers by email. Continued use after changes means you accept the updated policy.