Privacy Policy
Last updated: 8 July 2026 · Written to be readable, not defensive.
What this covers
This describes how HeyWilder handles personal data. It applies to two groups of people:
- Operators — you, our customer, using the dashboard.
- Visitors — people who chat with a bot embedded on your website.
What we collect from operators
- Your name, email, and password (hashed — we never see the plaintext)
- Your business info: name, hours, FAQs, welcome messages — whatever you type into Settings
- Your operator email address for alerts
- Basic activity logs (which pages you visit, when you log in) for troubleshooting
We don't collect payment info during beta because there's no payment.
What we collect from your customers
- The messages they send to your bot
- The bot's replies
- Contact info they voluntarily provide (name, email, phone) if they request human handoff or fill in a pre-chat form
- An anonymous session ID so their conversation stays continuous across page reloads
How we use it
Operator data runs your dashboard and configures your bot. Visitor messages get sent to Anthropic to generate a reply, then stored so you can review the conversation in your dashboard. We don't build advertising profiles, we don't share data with data brokers, and we don't use it to train any AI models.
Who else sees the data
We work with a small number of trusted service providers who help us run the product. Data is shared with them only to the extent needed for their specific role:
If we add a new subprocessor we'll email you before we start using them and you'll have the right to object.
- Anthropic (Claude API) Generates bot replies. Sees the current message + relevant context. Anthropic doesn't train models on our API traffic and is certified under the EU–US Data Privacy Framework.
- Render Hosts the HeyWilder servers and database. Data is stored in Render's EU region.
- Sentry Captures error logs when something breaks so we can fix it. Errors may include small snippets of the offending request.
- Twilio Sends SMS handoffs if you enable that feature. Only sees the SMS content and phone number.
- Google Workspace Delivers transactional email (handoff alerts, password resets) via Gmail.
How long we keep it
Chat conversations are kept for as long as your account is active, or until you or your visitor asks us to delete them — whichever comes first. If you close your account we delete everything within 30 days. Backups are retained for 30 days after deletion, then permanently removed.
You're the controller for your customers' data, so you can also ask us to apply a shorter retention period (for example, "delete conversations after 90 days") — email us and we'll set it up.
Legal bases for processing
For your operator account data, we rely on contract (running HeyWilder for you) and legitimate interest (keeping the service secure and functional).
For your customers' chat data, we act only on your documented instructions as the data controller — you're responsible for having the right legal basis to run the chatbot on your website.
Your rights (and your customers' rights)
Under GDPR you and your customers can:
- Ask for a copy of the personal data we hold
- Ask us to correct anything that's wrong
- Ask us to delete it
- Object to specific uses
- Take your data to another service (portability)
Email support@heywilder.co for any of these — we respond within a few business days.
Data controller / processor
For your operator account data, HeyWilder is the data controller. For your customers' chat data, you are the data controller (you decide what to collect and why) and HeyWilder is the processor (we run it on your behalf). If you need a formal Data Processing Agreement, email us and we'll send you one.
Cookies and local storage
The chat widget on your customers' site does not set any cookies. It uses a small piece of temporary local storage in the visitor's browser to keep a random session ID so the conversation stays continuous across page reloads — this is strictly functional and doesn't need a cookie banner under EU ePrivacy rules.
The HeyWilder dashboard uses a single essential cookie to keep operators logged in.
Data breaches
If we ever have a personal data breach that affects your data — yours as an operator or your customers' — we'll tell you without undue delay after we become aware of it, along with the facts we have and what we're doing about it.
Children
HeyWilder is a business tool for hospitality and venue operators. Our service isn't directed at children under 16, and you shouldn't configure your bot to knowingly collect data from them. If you become aware that a customer under 16 has used your bot, contact us and we'll help you delete their data.
Where data is stored
All data is stored in the European Union (Render's EU region). Some subprocessors (Anthropic, Sentry, Google) may process data outside the EU under standard contractual clauses.
Changes
If we change how we handle data in a way that meaningfully affects you, we'll email you 14 days ahead.
Data questions? Email support@heywilder.co — we always reply. See also our Terms of Service.