Legal
Privacy Policy
Last updated: August 30, 2026
Applies to wordpress.zorachat.ai and the Zorachat WordPress plugin.
Introduction and scope
Zorachat ("Zorachat," "we," "us," or "our") operates this website (wordpress.zorachat.ai) and the Zorachat plugin for WordPress (the "WordPress Plugin"). Together with Zorachat Cloud Services, the Zorachat API relay, the public chat widget, and related tools, these make up the "Service."
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit this website, download or install the WordPress Plugin, configure an assistant, connect Zorachat Cloud, bring your own AI provider key, or when a visitor chats with a Zorachat-enabled WordPress site.
The WordPress Plugin is open-source software licensed under GPLv2 or later. Using the plugin on your site does not by itself send visitor conversations to Zorachat until an administrator enables an AI provider or connects Zorachat Cloud.
Our privacy roles
Zorachat acts as a controller for personal information used for this website, plugin-directory communications, account administration, Cloud billing and credits, security, legal compliance, support, and our direct customer relationships.
When a WordPress site owner uses the plugin to process conversations, leads, knowledge content, or other information on their instructions, that site owner is generally the controller or business and Zorachat generally acts as its processor or service provider. The site owner decides what the assistant collects, which knowledge is trained, which provider is selected, and whether Cloud is connected.
The exact legal roles may vary by jurisdiction and use case.
Information we collect and process
Depending on how the Service is used and configured, we may collect or process:
- Website and contact information: name, email address, company name, and messages you send to support@zorachat.ai.
- WordPress site and administrator information: site URL, site name, company name, administrator email, public REST URL, WordPress version, PHP version, plugin version, site or assistant identifiers, connection status, and configuration metadata — especially when connecting Zorachat Cloud.
- Assistant configuration: assistant name, instructions, widget appearance, provider selection (OpenAI, Google Gemini, Anthropic Claude, or Zorachat Cloud), and related settings.
- Knowledge and business content: WordPress pages, posts, FAQs, custom knowledge, uploaded PDFs (text extracted locally using Smalot PDF Parser), and WooCommerce product information selected by the administrator.
- Conversation and lead information: visitor messages, generated replies, lead names and emails collected in chat, attachments when image-aware chat is enabled, timestamps, conversation status, and agent takeover actions.
- Provider credentials: API keys you supply for OpenAI, Gemini, or Anthropic. These are used to authenticate relayed requests and should be stored and rotated under your control.
- Cloud and credit information: connection status, Cloud credit balances and usage, plan details, expiration, and billing status when Cloud is connected.
- Widget and request information: IP address, browser or device information, referring page, timestamps, and standard HTTP metadata when a visitor loads the widget from widget.zorachat.ai.
- Usage, diagnostic, and security information: feature usage, errors, logs, and information used to authenticate requests, enforce limits, and prevent abuse.
Sensitive information
Please do not submit sensitive personal information, special-category data, confidential credentials, or regulated information in conversations or knowledge content unless you have determined that doing so is lawful and appropriate.
Sources of information
We receive information:
- directly from site owners, administrators, agents, visitors, and people who contact support;
- automatically from browsers, devices, servers, APIs, and the chat widget;
- from WordPress content, PDFs, FAQs, and WooCommerce products an administrator chooses to train;
- from AI providers and Cloud services used to operate enabled features.
Where WordPress stores data locally
Conversation records, captured leads, and plugin settings created by the WordPress Plugin are stored in the site owner's WordPress database. Enabled attachments or temporary files may be stored in the site's WordPress uploads environment. The website owner controls access to and retention of those local records.
Local storage does not mean local-only processing. To generate a reply or ingest knowledge, the plugin sends the visitor's message and relevant instructions or knowledge context to the AI service the administrator selected.
How we use information
We use information to:
- provide, configure, operate, maintain, and support the Service;
- deliver the chat widget and respond to visitor requests;
- route AI requests to a selected provider and return generated responses;
- ingest, index, and retrieve selected knowledge, including WooCommerce product context;
- provide Zorachat Cloud credits, managed AI replies, realtime mobile live-agent monitoring, push notifications, and human handoff;
- store and present conversations, leads, and analytics to authorized WordPress users;
- authenticate requests, enforce usage limits, prevent fraud and abuse, and investigate incidents;
- diagnose errors and improve reliability;
- respond to support requests and send important service notices;
- comply with legal obligations and enforce our Terms.
AI processing and the API relay
The Service uses automated systems, including large language models, to generate responses based on a visitor's message, assistant instructions, selected knowledge, conversation context, and administrator configuration.
AI output may be inaccurate or inappropriate. Zorachat is intended to support customer communication and human handoff, not to make decisions producing legal or similarly significant effects without human review.
All supported AI requests from the WordPress Plugin are sent first to api.zorachat.ai. If the administrator selects OpenAI, Google Gemini, or Anthropic Claude and supplies that provider's API key, Zorachat processes the credential and request as a relay and forwards them to the selected provider. Both Zorachat and that provider therefore process the request data.
Request information may include the visitor's message, assistant instructions, relevant website, FAQ, knowledge-base, or WooCommerce context, enabled attachments, conversation metadata, and request metadata.
Zorachat Cloud Services
Zorachat Cloud is optional. Local Inbox, agent replies, takeover, return-to-AI, Leads, and Analytics remain available in WordPress without a Cloud connection.
This service is used only when an administrator chooses to connect. When connecting or managing Cloud, we may process the site URL, site name, company name, and administrator email address.
During use we may process visitor messages, assistant instructions, website and knowledge-base context, WooCommerce context if enabled, generated replies, lead information entered in chat, enabled attachments, conversation metadata, credit balances, and data needed for mobile monitoring, push notifications, abuse prevention, and billing.
Connecting Cloud may grant 5,000 Cloud credits instantly, as presented at the time of connection. Credits are used for managed AI replies and related Cloud features.
External services
Zorachat uses external services only for features an administrator enables. Depending on configuration, information may be processed by:
- Zorachat API relay and Cloud Services — https://api.zorachat.ai/
- OpenAI API — https://openai.com/policies/privacy-policy/
- Google Gemini API — https://policies.google.com/privacy
- Anthropic Claude API — https://www.anthropic.com/legal/privacy
- Hosting, content-delivery, security, email, and push-notification providers used to operate the Service.
Administrator responsibility for providers
Enabling a provider or Cloud authorizes the exchange of information reasonably necessary to operate it. Site administrators are responsible for reviewing the terms and privacy practices of every enabled external service and for adding an appropriate notice to their own site privacy policy.
Legal bases
Where applicable law requires a legal basis, we rely on one or more of the following depending on the context: performance of a contract; legitimate interests (including securing and improving the Service and preventing abuse) where those interests are not overridden; consent where required; compliance with legal obligations; and establishment or defence of legal claims.
For personal information processed on behalf of a WordPress site owner, that site owner determines the applicable legal basis and is responsible for providing notices and obtaining consent where required.
Site owners, visitors, and data requests
WordPress site owners determine what their assistant collects, which knowledge is trained, which provider is used, and whether Cloud is connected. They are responsible for:
- providing an appropriate privacy notice to visitors;
- establishing a lawful basis and obtaining consent where required;
- responding to requests to access, correct, export, or erase personal data stored in WordPress;
- configuring suitable access and retention controls; and
- reviewing the terms and privacy practices of enabled external services.
If you chatted on someone else's site
If you interacted with Zorachat through another organization's WordPress site, send requests about that chat to that organization first. We will provide reasonable assistance where required and technically feasible. Disconnecting Cloud does not necessarily delete local WordPress records.
Chat widget
When the public widget is enabled, a visitor's browser may request the widget asset from widget.zorachat.ai. Standard network and HTTP information may be transmitted, including IP address, browser or device information, referring page, request time, and delivery or security metadata. Site owners should disclose this and obtain consent before loading the widget where applicable law requires that approach.
This website (wordpress.zorachat.ai)
This marketing site may use cookies or similar technologies to operate pages, remember preferences, and understand traffic. We may process the contact details you send to support@zorachat.ai. We do not require an account to browse this site.
Data retention
We retain hosted account and Cloud information while a connection or account is active and for as long as reasonably necessary to provide the Service, maintain security, comply with law, and resolve disputes.
Information held in a customer's WordPress database is retained according to that customer's configuration, deletion actions, hosting practices, and legal obligations. Site owners should apply an appropriate retention schedule for conversations, leads, attachments, and knowledge content.
External providers retain information according to their own policies and the administrator's settings with those providers.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and access controls. No method of transmission or storage is completely secure.
Site owners remain responsible for securing their WordPress sites, hosting, administrator accounts, and API keys. If a credential may have been compromised, contact support@zorachat.ai and revoke or rotate it with the provider.
International transfers
Zorachat, its service providers, and administrator-selected AI providers may process information in countries other than where the site owner or visitor is located. Where required, we use appropriate safeguards for international transfers. Administrators are responsible for assessing transfers caused by providers they choose to enable.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal information; object to certain processing; withdraw consent; and complain to a data-protection authority.
Contact support@zorachat.ai. We may need to verify your identity and authority. For information stored only in another organization's WordPress site, contact that organization. Zorachat may not have direct access to locally stored records.
Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information directly from children. Site owners must not configure the Service to collect children's information without all notices, consents, and safeguards required by law.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised version on this website and update the "Last updated" date. Material changes may also be communicated by email or in-product notice where appropriate.
Contact us
Questions about this Privacy Policy: support@zorachat.ai. Platform policy (hosted SaaS, including features not available in the WordPress Plugin): https://zorachat.ai/privacy-policy.
Questions? support@zorachat.ai · Terms and Conditions
