/プライバシー

ほとんど何も知りません。
わざとです。

Spookatが知るのは、訪問者が自分で入力したことだけです。Cookieバナーに足すものも、開示すべきトラッキングも、売るものもありません。何が起きるのかを、順番に正確に説明します。

ある訪問者の1日、ログ付き。

  1. ページ読み込み0当社APIへのリクエスト数。届くのはcdn.spookat.comの静的なランチャーファイル1つだけです。
  2. スクロール、閲覧、離脱0来たことすら分かりません。ピクセルもビーコンもなし。
  3. ランチャーをクリック1チャットを読み込むリクエスト。まだ何も保存しません。
  4. メッセージ送信✉ここで初めて保存します。チームが返信できるように。
  5. 履歴の期限切れ∅Spookatから自動で消えます。期間はプランにより30/90/365日。その30日後にはバックアップからも消えます。

保存するもの

  • メッセージ。チームが読んで返信するため
  • 名前やメールアドレス。訪問者が入力した場合のみ
  • チャットがどのサイトから来たか、送信時のページ、ブラウザ、国
  • タイムスタンプと、返信したメンバー
  • cool guyでは、アプリから渡されたログインユーザーのID

決して触れないもの

  • Cookieとフィンガープリント。ブラウザのストレージに置くのはチャットトークン1つだけで、それもメッセージを書いた後のみ
  • 閲覧履歴、セッション、チャット前の行動
  • IPアドレス。配信とレート制限には使いますが、記録はしません
  • アナリティクス、ヒートマップ、セッションリプレイ
  • 広告、データ販売、チャットを使ったAIの学習

spookat.comはセルフホストのUmamiを使っています。Cookieなし、生のIPは保存しません。あなたのサイトのウィジェットは、アナリティクスを一切実行しません。

データの行き先。
正直に。

メッセージは、あなたが接続した場所に届きます。届いた後は、私たちではなくその場所のルールが適用されます。そうでないふりをするより、はっきり言っておきます。

ボットは
名札をつける。

AIエージェントを接続すると、訪問者には必ずそれが分かります。オフにできる設定ではありません。

  1. AIのメッセージには、どのスタイルでも必ずAIラベルが付きます。
  2. エージェントは人間の名前で投稿できません。当社のAPIが拒否します。
  3. チームはすべての会話を見られます。エージェントの発言も一語残らず。
  4. 当社が自らあなたの会話でAIを動かすことはありません。例外はcool guy以上の任意機能である意図タグだけです。

あなたのデータ、あなたのボタン。

以下のプライバシーポリシーは英語で記載されており、英語版を正本とします。

privacy policy

Draft, effective [EFFECTIVE DATE]. The plain-words version is everything above this line. This part says the same thing the way the law wants it said.

1. who we are

Spookat is run by [COMPANY NAME], a sole trader registered in Poland (jednoosobowa działalność gospodarcza), NIP [NIP], [ADDRESS] (“Spookat”, “we”). Write to us at hello@spookat.com. We have not appointed a data protection officer; we are not required to.

2. two roles

3. what we collect, why, and for how long

what why legal basis how long
visits to spookat.com, counted by our self-hosted Umami: page, referrer, browser, device type, country to see which pages work legitimate interest, Art. 6(1)(f) GDPR aggregated statistics, no profile of you
waitlist: your email and, if the link had one, the utm_source you came from to send you an invite consent, Art. 6(1)(a) until you sign up or ask us to delete it, and at most 12 months
account: email, name, and, if you sign in with GitHub, Google or Discord, your account id there and its sign-in tokens, encrypted to run your account contract, Art. 6(1)(b) while the account exists, then deleted within 30 days; backups age out 30 days after that
billing: plan, country, invoice data we get back from Paddle to know what you paid for and keep tax records contract and legal obligation, Art. 6(1)(b) and (c) as long as Polish tax and accounting law requires (generally 5 years after the end of the year)
support: what you send to hello@spookat.com to help you contract or legitimate interest as long as the conversation needs, and at most 24 months

Umami on spookat.com sets no cookies and stores no IP address. It counts visits with a salted hash that rotates, so it can’t recognise you over time. It runs on our own server under spookat.com/u/, so no third party sees your visit.

We use IP addresses only in memory, to deliver pages and to rate-limit abuse. We never write them to a database, a log or an error report. Cloudflare (below) carries all traffic to our sites, the widget’s included, as our network proxy and CDN, so it sees IP addresses in transit.

Card and payment details never reach us. Paddle (see below) sells the subscription as merchant of record and handles payment as an independent controller, under Paddle’s privacy policy.

4. who else gets data

We share data only with the services we need to run Spookat, each under a contract that binds them to protect it:

who what for where
Paddle.com Market Limited billing, merchant of record United Kingdom
Postmark (ActiveCampaign, LLC) transactional email: sign-in links, notices, reply follow-ups United States
Backblaze, Inc. encrypted backups EU region
[VPS PROVIDER] hosting [REGION], EU
Cloudflare, Inc. network proxy and CDN in front of our sites, IP addresses in transit United States, global network
OpenRouter, Inc. intent tags, only if a customer turns them on United States

Slack and Discord get chat messages only when a customer connects their own workspace or server to Spookat. That is the customer’s choice, and Slack’s or Discord’s terms and retention settings apply there.

Signing in with GitHub, Google or Discord is optional; an emailed link always works. If you choose one, that provider sends us your account email, whether it verified it, your name and your profile picture link, and sees that you signed in to Spookat. Its own privacy policy applies on its side. Discord is also the one a customer connects their server with, above.

Transfers outside the EEA rely on an adequacy decision (United Kingdom) or on the European Commission’s Standard Contractual Clauses (United States).

5. cookies

spookat.com sets no cookies. The Spookat widget sets no cookies either: after a visitor sends a first message, it keeps one chat token in that browser’s storage so the conversation survives a reload. The dashboard at app.spookat.com uses one strictly necessary cookie to keep you signed in.

6. your rights

You can ask us for access to your data, a copy of it (portability), to correct it, to delete it, to restrict or object to how we use it, and you can withdraw consent at any time without affecting what happened before. Write to hello@spookat.com; we answer within one month.

You can also complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

7. country lookup

We turn an IP address into a country with an offline database that runs on our own server. The IP address is never sent anywhere and never stored. IP to country data by DB-IP.com, licensed under CC BY 4.0.

8. changes

If this policy changes in a way that matters, we update this page and email customers before the change applies.

デフォルトで静か。

先行登録