Privacy Policy
Effective: 2026-09-13
This policy explains what personal data the RobiFox service processes, for how long, for what purpose, and with whom it is shared. In short: as little as possible, for as short a time as possible.
1. Who the controller is
The service is operated by the company below. You can ask about data processing at the contact details given here, and exercise your rights through them.
| Company name | Kovács Csaba egyéni vállalkozó |
|---|---|
| Registered address | 1191 Budapest, Báthory utca 23. |
| Company registration number | Nem alkalmazható / N/A (egyéni vállalkozó / sole trader) |
| Tax number | 73074962-1-43 |
| EU VAT number | HU73074962 |
| kcsdworks@gmail.com | |
| Hosting provider | Tárhely.Eu Szolgáltató Kft. |
2. Three different roles — the most important section
Three kinds of people's data occur in the service, and our role differs for each. Every other rule follows from this.
a) Visitors to the Customer's website
People who talk to the embedded assistant on the Customer's website. For their data the CONTROLLER is the Customer (the website operator) and we are a PROCESSOR: we store and process on their instruction. Information for those visitors therefore belongs in the Customer's own privacy policy. This also covers live chat with a human agent: there too the Client is the controller, and we provide the console and the storage.
b) The Customer's staff (our users)
People who sign in to the control panel. For their data WE are the controller.
c) People who write to us on the public site
For data submitted through the contact form WE are the controller.
d) People who request a preview of their own website on the public site
People who submit a website address without signing up, so that we can show what our assistant would know about it. For that address and the preview built from it WE are the controller — there is no Customer whose instruction we act on. The detailed rules for this group are in section 9, because this is our only case in which we contact ANOTHER server at your request.
3. What we process, and why
| Data | Purpose | Retention |
|---|---|---|
| Registration data (name, email, hashed password) | Creating the account and signing in; performance of the contract | Until the account is closed, then for the statutory retention period |
| Billing data | Invoicing the fee; legal obligation | As required by accounting law (typically 8 years) |
| The TEXT of visitor conversations (question, answer) | Providing the service, troubleshooting, improving answer quality | 90 days in the conversation log, after which the question and answer automatically expire. If a lead is created, the full conversation copy attached to it follows the separate rule below |
| LIVE HUMAN CHAT messages (what the visitor and the responding agent wrote), the agent’s name, and a record of when and with what wording the visitor was informed | Human support: when the visitor asks for a person, or the assistant hands the case over | The MESSAGE TEXT expires after 90 days (it is emptied). What does NOT expire: the responding agent’s NAME (our staff member, not the visitor’s data — without it the thread would be unreadable), and the RECORD of the notice given (version, language, wording), because that is exactly what we must be able to show. The clock runs from when the message was written, not from when the conversation closed |
| The NUMBERS from conversations (how many questions, whether it knew, how long it took, what it cost) | Billing and reporting towards the Customer | Does not expire. The statistics row itself contains no name, e-mail address or IP address. Its technical conversation identifier remains; if a lead was created, it can be linked to that lead until the Customer deletes it |
| Visitor lead (name, email, phone, message) | The Customer contacting their own prospect | Until the Customer deletes it — it is their business data. The conversation copied onto it expires 90 days after the lead is closed |
| Original text of an unanswered question (“missing knowledge") | Showing the Customer which questions are worth writing an answer for | Until the project or account is deleted, or until a data-subject deletion request is carried out. Closing the work item does not itself delete the question text |
| Contact form data | Answering your enquiry | 90 days after it is closed, and at most 730 days from arrival |
| The website address submitted on the public site and the preview built from it (the question asked, the answer given, and the addresses of the source pages used) | Producing and showing the preview, and serving the same domain — submitted by anyone — from the result we already have, for 6 hours (see section 9) | 30 days, after which the whole record is deleted automatically |
| The email address given for the chattable trial and its non-reversible fingerprint, the submitted website address, the state of the trial, plus the knowledge extracted from the website and — if one is made — a snapshot of its front page | Building and serving the trial, sending the confirmation message and the message linking to the completed trial, and the anti-abuse limit (one address may start one trial a day, three in total) | An unconfirmed request is deleted in full after 3 days; the plain email address of a started trial is erased after 30 days; the trial itself (knowledge, snapshot, conversation) is deleted after 30 days; the fingerprint goes after 365 days |
| Newsletter subscription: the email address, the text, version and language of the consent, its two timestamps (when you ticked it and when you confirmed it), and the unsubscribe identifier | Sending the newsletter, and being able to prove the consent — without that the subscription cannot be taken on legally | Until you withdraw it; after unsubscribing the proof of consent is kept for a further 3 years (legitimate interest in being able to prove it), and the address so that you do not receive mail again |
4. What we deliberately do NOT process
These are not accidental gaps but design decisions:
- The embedded assistant uses NO cookies and stores no message content in the browser. It stores two short entries bound to the browser tab (sessionStorage). The first is the identifier of the conversation in progress and its ticket, for at most 30 minutes — without it the visitor would start over on every page change. The second is a single marker recording that the greeting has already happened in this browser tab: it prevents the assistant from approaching the visitor again within the same session, and it contains no identifier, no message and no other data. Both entries are removed when the tab closes, the first one also after 30 minutes, and neither contains the text of any message. This fact alone does not settle whether the Customer's own website needs a cookie banner — that has to be judged together with everything else embedded there.
- We do not store IP addresses in the database. An IP is used only as the key of the anti-abuse rate limiter — and not in raw form even there, but as an irreversible fingerprint — expiring within minutes up to at most one day, and cannot be queried back.
- We do not fingerprint visitors and we do not build profiles.
- We do not store microphone audio: speech recognition runs on our own server and the audio is discarded after recognition. Only the transcribed text remains.
- We do not sell data and do not share it for advertising.
5. Who else receives data (processors)
We use the following providers to deliver the service. Of these, only the language model receives the text of visitor conversations:
Language model: router and model provider
To produce an answer, the visitor's question, the earlier turns of the conversation and the relevant excerpt of the knowledge base reach the model. The call does not go directly to the company that builds the model: it passes through a routing provider, which forwards the request to the model provider configured on our side. There are therefore two processors in the chain, and the text of the conversation passes through both.
| Routing provider | OpenRouter (openrouter.ai) |
|---|---|
| Model provider | OpenAI (openai.com) |
Every single call carries the flag that forbids data collection, and failover to a substitute provider is switched off — so a request cannot end up at a provider we did not select in advance. We do not hand over conversation content for training, and we do not train a model on it ourselves either.
If the provider named above is established outside the European Economic Area, the transfer takes place under the data protection terms of our contract with them. The provider in force at any time is the one named above; we announce a change of provider by updating this policy.
Speech synthesis (premium voice tier only)
Receives the text of the ANSWER in order to read it aloud. The standard voice tier runs on our own server, where nothing leaves the system.
Payment provider
The Customer's billing data. Visitor data is NOT shared with them. We neither see nor store card details.
HERE THE PAYMENT PROVIDER DOES NOT ACT ON OUR INSTRUCTIONS ALONE. Because it handles the sale as reseller, it also processes billing data — name, address, tax number — in its OWN right, in order to meet the invoicing and tax rules that apply to it. In that respect it is an independent controller rather than a processor, and its own privacy policy applies. We do not hand this data over: you enter it yourself on its checkout page.
Hosting provider
Operating the server. Data is stored in the European Union.
6. Your rights
You have the following rights in relation to this processing. We accept requests at the email address above and respond without undue delay, within one month at the latest.
- Access: you can find out what data we hold about you.
- Rectification: you can ask us to correct inaccurate data.
- Erasure: you can ask us to delete your data where no legal obligation prevents it.
- Restriction: you can ask us to store the data but not use it.
- Portability: you can request your data in a machine-readable format.
- Objection: you can object to processing based on legitimate interest.
- Complaint: you may lodge a complaint with the Hungarian data protection authority (NAIH) or with a court.
7. If you are a visitor requesting deletion
If you talked to our assistant on someone's website and want your data deleted, there are two routes: tell the operator of that website (they are the controller), or write to us directly. When the deletion is carried out, your lead record is deleted, the text of your conversation is deleted, and so is your unanswered question. If a human agent also took part in the conversation, the text of those live-chat messages is deleted as well.
Why is there no "delete my data" button in the widget?
Because a visitor cannot be identified: they have no sign-in and no account. Such a button would let anyone delete SOMEONE ELSE'S data. The request is therefore initiated by a human after identification.
If you requested a preview and want it deleted before the deadline
A preview record is deleted on its own (see section 9), but you do not have to wait. Write to the email address above and include the link to the preview — the random token in it is exactly why it is random: whoever knows it is the one who received the result. On deletion the submitted address and the entire preview built from it are removed, and the link stops serving anyone. We also release the 6-hour lock on the domain when we delete (ElonezetKapu::elenged), so a new crawl can be started immediately afterwards.
8. Security
- Encrypted connection (HTTPS) for all traffic.
- Passwords are stored only as one-way hashes; two-factor secrets are encrypted separately.
- Two-factor authentication (TOTP) can be enabled on every account.
- Role-based permissions: a read-only user cannot start an operation that incurs cost.
- Customer data is isolated with account- and project-level scoping; one customer cannot see another's.
9. The pre-signup preview
On our public site you can enter the address of your website and, without signing up, see what our assistant would know about it. This is our only feature in which we contact another server at your request — so here is exactly what happens.
- WE STORE THE WEBSITE ADDRESS YOU SUBMIT. Without it we could not hand the result back to you, and we would re-crawl the same site on every page refresh.
- WE ALSO STORE THE PREVIEW MADE FROM IT, in full: the question the system asked, the answer it gave, the addresses and page titles of the sub-pages used, and the crawl accounting — that is, how many sub-pages we skipped and why (with a few example addresses), and where any redirect led. All of this comes from your own public website. For the chattable trial we additionally store the knowledge extracted from the text of your website and its search indexes, plus your page title and main colour — without these the trial could not answer questions about your own site.
- ALL OF IT IS DELETED AFTER 30 DAYS. Not anonymised — deleted: every field of the record comes from your submission, so not even a "statistics row" is left behind. A scheduled task does this every day (elonezet:takaritas). There is one exception, and we say it plainly: if the run fails, the submitted domain and the preview token are written to our operational error log so that we can investigate. That log is not public, and you can ask us to delete that entry too at the email address above.
- WE DO ASK FOR YOUR EMAIL ADDRESS, AND WE SEND ONE SINGLE MESSAGE TO IT. The form has three fields: your email address, a newsletter checkbox that is not pre-ticked, and your website address. The message contains a link; opening that link starts NOTHING — you get a page where you start the trial yourself with a button. Without this, mail filters that pre-fetch links would start the work on your behalf. You still need no account.
- WE KEEP A FINGERPRINT OF YOUR ADDRESS AGAINST ABUSE. We erase the plain address from the record after 30 days; a non-reversible fingerprint stays for 365 days, solely so that one address cannot start unlimited trials (at most one per day, 3 in total). The address cannot be reconstructed from the fingerprint.
- IF YOU DO NOT CONFIRM, WE DELETE EVERYTHING AFTER 3 DAYS. If you never open the message, we keep nothing: not your address, not its fingerprint, not the website address you submitted.
- WE DO NOT STORE IP ADDRESSES. An IP is used solely as the KEY of the anti-abuse rate limiter, and not even in raw form there: what goes into the cache is an irreversible fingerprint keyed with our application secret, expiring within minutes up to at most one day (the daily counter's key lives until the end of the calendar day). In practice this means we can tell that "this machine has already submitted ten times today", but not which machine — and after expiry even that is gone by itself. It never reaches the database, never appears on any screen, and cannot be queried back.
- WE DOWNLOAD YOUR WEBSITE. On your server this looks like one or a few ordinary visits coming from our address. In your access log the user agent STARTS WITH this name: RobiFox-Elonezet — the full line is longer, because the name is followed by a version and a contact address. Search for that prefix. It is deliberately different from the crawler that builds our paying customers' knowledge bases, so that you can tell the two apart.
- WE LOOK AT AT MOST 8 PAGES, no deeper than 1 click(s) from the address you gave, once. We do not map the whole site, we do not come back, and the crawl does not restart by itself.
- Only submit a website you are entitled to operate, or one whose owner has given you permission. The crawl runs at your request.
- FOR 6 HOURS THE RESULT IS NOT ONLY YOURS. If someone else submits the same domain within 6 hours, we do not start a new crawl: we send them to exactly the link you were given. The token in the link is random and unguessable, but for 6 hours knowing the domain substitutes for it — anyone who knows which address you submitted can read your preview: the question, the answer and the sources. This is deliberate, so that several people at one company can look at the same report without another pointless crawl — but you need to know it BEFORE you submit. If that is not acceptable to you, do not submit an address whose preview you cannot share.
- AND THE OTHER WAY ROUND: WHAT YOU SEE MAY NOT BE YOUR OWN SUBMISSION. If we already crawled the domain in the last 6 hours for somebody else, you receive that finished preview — which may be up to 6 hours old and does not reflect the site as it was when you submitted. We do not hide this: the result page states that it comes from an earlier run, and when that run was made. You can get a fresher one for the same domain once the 6 hours have passed.
10. Changes
We update this policy from time to time. We will notify you of material changes at sign-in or by email. The current text is always available on this page, with its effective date.