GatewayAI Privacy Policy
Version 1.5 — Effective July 27, 2026
GatewayAI, LLC ("GatewayAI," "we," "us") builds and operates AI assistants that run on our customers' websites. This policy explains what we do with personal information, where it actually lives, and what we don't hold at all.
1. Two different situations
This policy covers two distinct relationships, and the rules differ between them.
If you are visiting gatewayai.tech, or you are a GatewayAI customer, Section 3 applies. We decide how that information is used.
If you are a visitor to one of our customers' websites and you chatted with an assistant there, Section 4 applies. In that situation we are a service provider to that business. The business — not GatewayAI — decides what is collected, how long it is kept, and what it is used for. Your rights run against that business, and its privacy notice governs. We help them operate the assistant; we do not own the data.
2. The short version
- We do not sell or share personal information, and never have.
- We do not use customer or visitor data to train any AI model. Our AI provider does not train on it either.
- A live customer site stores its data in that customer's own accounts, not ours. Dedicated database, never shared, never copied into our storage.
- We do not log the content of conversations anywhere in our own systems. We record counts, sizes, and timestamps for billing.
- We retain administrative access to our customers' systems to support them, which means we are able to read what is in them. We say so plainly rather than claiming otherwise.
- We never see or store payment card numbers. Stripe handles that.
- No tracking cookies. No advertising. No analytics on visitors.
3. Our own website and our customers
What we collect.
From visitors to gatewayai.tech: our marketing site loads nothing from any third party — no analytics, no tag manager, no external fonts or scripts. The hosting platform records standard request logs (IP address, page requested, status, timestamp, user agent) for thirty (30) days.
From customers: business contact details, billing contact and name, business address, notes we keep about the account, and the configuration and credentials needed to run the service. Payment card details go directly to Stripe and are never transmitted to or stored by us; we receive a token, the card brand, and the last four digits. While we are building a site, we store its initial administrative password in encrypted form that we can read; we clear it when the site is handed over (see Section 7).
From our own emails to customers: when we send an operational email such as a checkout link, we record the recipient address, subject line, and delivery outcome (delivered, bounced, spam-flagged) so a payment link does not silently fail. We do not store the body.
From operating the service: usage metadata for each customer — conversation identifiers, token counts, payload byte sizes, model used, latency, computed cost, and timestamps. This is what we bill from. It is metadata about activity, never the content of a conversation.
Why we use it. To provide and operate the services; to bill and collect payment; to communicate about the account; to monitor security, abuse, and reliability; to comply with tax and legal obligations; and to improve our own service. Where the GDPR applies, our legal bases are performance of a contract, our legitimate interests in operating and securing the service, and compliance with legal obligations.
How long we keep it. Account and billing records for seven (7) years, as required for tax and financial recordkeeping. Usage metadata and email delivery records for the life of the account. Hosting platform request logs for the period set by the platform.
Backups. We back up our own usage and billing ledger nightly to cloud storage in the United States. That process runs on third-party continuous-integration infrastructure, and the resulting file contains customer business names, contact addresses, and the usage ledger without additional encryption; stored provider credentials inside it stay individually encrypted. We never back up a customer's site database into our storage. Because the ledger holds no conversation content, neither do the backups.
Cookies on gatewayai.tech. Only what is strictly necessary to operate the site. We set no advertising, analytics, or cross-site tracking cookies.
4. Visitors to our customers' websites
When you use an AI assistant on a business's website, that business is the controller — the "business" under California law and the "controller" under Utah, Colorado, and EU law. GatewayAI is its processor and service provider.
What is collected. The full text of your chat conversation, including anything you volunteer in it. Anything you submit through a contact or lead form: first and last name, email address, phone number, and your message. A conversation identifier generated in your browser. An AI-generated topic, summary, and outcome classification for each conversation, and a judgment of whether it represents a sales lead.
Information about children. Where a business offers services for children, the assistant's lead capture is designed to record details a visitor volunteers about who the service is for — which can include a child's first name and age, and sometimes a street address. That information is stored with the lead, included in the notification email sent to the business, and included in any export the business runs. If you would rather not have those details recorded, do not enter them into the chat. Direct questions about a business's handling of children's information to that business.
What is not collected. The application does not store your IP address, user agent, page URL, referrer, or location. Your IP address is used in memory for rate limiting and is never written to a database or an application log. Separately, the cloud platform hosting the website records standard request logs that include connecting IP addresses, in the cloud project belonging to that business.
Where it is stored. In a database instance dedicated to that business, in an account the business owns, running on our database provider's infrastructure in Oregon, United States. It is never shared with another customer, and GatewayAI does not host it, hold a copy of it, or back it up into our own storage at any point. Databases used during the build phase, before a site is public, run in accounts we control; those are destroyed when the site goes live.
How long it is kept. The business chooses a retention period for chat conversations in its administrative settings — 30, 60, or 90 days, or no automatic deletion. The default is 30 days, and a scheduled job performs the deletion. Two exceptions: a conversation attached to a lead the business hasn't closed is kept while that lead stays open, and lead and contact-form records are not covered by the retention setting and are kept until the business deletes them. The business can delete an individual lead or conversation at any time; deleting a lead also deletes its transcript. We do not set the retention period and cannot answer for the business's choice.
What passes through us. Your messages and excerpts of the business's own content are routed through our gateway to reach the AI model. Separately, after a conversation goes idle, the transcript is sent to the AI model again on a recurring schedule so it can be classified and any lead details extracted — this happens after you have stopped chatting. We do not store message content at any point. We record counts, byte sizes, timing, and cost for billing.
Storage in your own browser. The chat widget uses your browser's per-tab session storage to hold the conversation transcript, whether the chat panel is open, two conversation identifiers, a cached eligibility check, and whether you have dismissed the AI notice. All of it is discarded when you close the tab. There is no cookie, no localStorage entry, no persistent identifier, and no fingerprinting. The conversation identifier does become a record key on the server side.
Automated processing. Responses are generated by an AI model without human review. They can be wrong. Nothing an assistant says is a binding statement by the business unless the business confirms it. The assistant does not make decisions producing legal or similarly significant effects about you.
Your rights. Direct requests to access, delete, correct, or port your information to the business whose website you used — they hold and control it, and they have export and single-record deletion tools for exactly this purpose. If you contact us instead, we will forward your request to that business. We cannot act on a request independently, and the business, not GatewayAI, is responsible for responding to you.
5. Who else is involved
Every third party that receives customer or visitor information:
| Provider | What it receives | Location |
|---|---|---|
| Anthropic, PBC | Conversation content, to generate responses and to classify idle conversations | United States |
| Turso | Hosts each customer's dedicated site database — chat transcripts and lead records | AWS us-west-2 (Oregon) |
| Neon | Hosts our usage and billing database — usage metadata, customer contact details, encrypted credentials | AWS us-west-2 (Oregon) |
| Google Cloud Platform | Compute for the gateway and customer sites; platform logs; secret storage; backup storage | GCP us-west1 (Oregon) |
| Stripe, Inc. | Customer billing identity, payment processing, usage unit counts | United States |
| Resend | Outbound email delivery, including recipient addresses and full message content | United States |
| GitHub | Source code, deployment, and scheduled backup jobs; holds infrastructure credentials | United States |
| Google Workspace | Our own business email | United States |
Our AI provider does not use API inputs or outputs to train its models under the standard commercial terms applicable to our account, and deletes them on a rolling basis, currently within roughly thirty days. During that window the provider may access inputs and outputs for safety and security purposes under its own terms. We do not hold a zero-retention arrangement with that provider, and we do not claim your data is deleted immediately on transmission.
We use no analytics service, error-tracking service, session replay, advertising network, or content delivery network.
Individual customer sites may embed third-party content at that customer's request — a map or a scheduling widget, for example. Those are the customer's own site content, may set their own cookies, and belong in that business's privacy notice rather than this table.
6. Security
Data is encrypted in transit on every hop. Provider credentials are encrypted at rest with AES-256-GCM. Authentication tokens are stored only as cryptographic hashes. Each customer is provisioned a dedicated AI provider workspace with its own credential and a dedicated database instance, so one customer's activity and data cannot reach another's; if a customer's credential cannot be used, the service returns an error rather than falling back to a shared one.
Access to customer systems is limited to performing the service, responding to a customer request, addressing a security incident, or complying with law.
No system is perfectly secure. We do not guarantee that unauthorized access will never occur.
7. Administrative access to customer systems
We retain administrative credentials to our customers' code repositories, cloud projects, and databases so we can diagnose and fix problems without waiting for access to be provisioned. This means we are able to read the conversations and lead records stored in a customer's system. While we are building a site, our operator console holds its initial administrative password in a form we can read. We clear that record when the site is handed over to the business and do not keep it afterward.
We do not currently keep an audit log attributing that access to a particular person, and we do not claim our access is logged or reviewable. We consider it more honest to state this than to imply either that the data is beyond our reach or that our use of it is tracked.
Customers may revoke this access at any time. Doing so limits what we can diagnose and repair but does not affect their ownership of anything.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of your personal information, to opt out of sale or targeted advertising (we do neither), and to appeal a denied request. Utah, California, Colorado, Connecticut, Virginia, and other states provide such rights, as does the GDPR.
For information we control under Section 3, email privacy@gatewayai.tech. We will verify your identity by a reasonable method and respond within the period required by applicable law — generally 45 days, extendable once. We will not discriminate against you for exercising a right.
For information described in Section 4, contact the business whose website you used.
If we deny a request, you may appeal by replying to our decision. In Utah you may also contact the Utah Division of Consumer Protection; in other states, your attorney general's office.
9. Children
Our services are not directed to children under thirteen (13), and our customer terms prohibit deploying an assistant on a website directed to children under thirteen. We do not knowingly collect information from children under thirteen. If you believe a child has provided information, contact us and we will work with the relevant business to have it deleted.
10. International transfers
We are located in the United States and process information here. If you contact us from outside the United States, your information will be transferred to and processed in the United States, which may not provide the same level of protection as your home jurisdiction. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism.
11. Changes
We may update this policy. The version number and effective date at the top will change, and material changes will be announced by email to customers at least thirty (30) days in advance. Prior versions are available on request.
12. Contact
GatewayAI, LLC
A Utah limited liability company, Entity No. 14715107-0160
Privacy requests and questions: privacy@gatewayai.tech
Legal notices: legal@gatewayai.tech
Everything else: colton@gatewayai.tech
Our registered agent and principal business address are on public record with the Utah Division of Corporations and Commercial Code, searchable by entity name or number.
gatewayai.tech