Trust
Trust and security
How AnswerTide handles your content and your customers' conversations. Last updated 1 October 2026. Service health is on the status page.
What we read
- Public pages on the site you point us at, and its help subdomains (such as docs. or help.). We honor robots.txt and never sign in, send cookies or get past a login wall.
- Files you upload, and questions and answers you add yourself.
What we store
- Your content: the text of imported pages and uploaded files, split into passages for search. We keep the extracted text of an upload, not the original file.
- Conversations: visitors' questions, the answers, the sources cited and any feedback.
- Corrections: answers you fix or approve, with their edit history.
- Contact details visitors leave: for example the email a visitor gives when they ask for a person, and the handoff transcript sent to your team.
- Your account: team members' email addresses. Card details are handled by our payment processor; we keep only its reference IDs.
Visitors get a random ID in a cookie, not a profile. We don't store visitors' IP addresses in our database; where we limit requests by IP, we keep only a one-way hash.
Where it's stored
In the United States. Our application servers run in the US East region, and our database is hosted in the United States.
Retention and deletion
- Your workspace: kept while your account exists, including after a subscription ends, so you can come back. Nothing in it is deleted automatically.
- Deleting a workspace: email privacy@answertide.com from an owner's address. Deleting a workspace removes its content, conversations, corrections and visitor contact details from our database, and we reply when it's done. Database backups may hold a copy until they are replaced.
- Single conversations: deleting one conversation isn't in the dashboard yet. Email us and we'll delete it.
- Corrections and uploads: delete a correction, or remove an uploaded file and the text imported from it, in the dashboard at any time.
- Export: download your conversations as CSV or JSON from the dashboard.
- Demos: a demo built from your public site is deleted automatically 7 days after it's created, or right away with its “Delete this demo” button.
Encryption
- In transit: the site, the dashboard, the widget and our API are served only over HTTPS. Plain HTTP requests are redirected to HTTPS.
- At rest: API keys you give us for actions are encrypted in our database with a separate key that is not stored in the database.
Access control
- Each workspace has an owner, admins and members. Owners and admins manage the team, billing and domains; members work in the dashboard.
- Every workspace's data is fenced off in the database itself (row-level security), so one workspace's requests can't read another's.
- The widget on your site uses its own restricted database role. It can't read your dashboard data.
- Our internal admin tools are limited to named AnswerTide staff accounts.
How we use AI
- Answers come only from your content. Each answer links the page it came from, and every link is checked against the pages we imported for you.
- When no source supports an answer, the assistant says it isn't sure and offers to reach your team instead of guessing.
- To write an answer, we send the visitor's question, the recent conversation and the relevant passages of your content to our AI provider.
- We don't train AI models on your content or your customers' conversations. Corrections you approve are used only for your own workspace's answers.
Subprocessors and DPA
The providers we use, what each one does and where, are listed on Subprocessors. Our Data Processing Addendum covers the processing we do on your behalf.
Certifications
AnswerTide doesn't hold third-party security certifications such as SOC 2 or ISO 27001. We answer security questionnaires honestly.
Report a security issue
Email security@answertide.com. Include steps to reproduce, and give us a reasonable chance to fix the issue before you share it publicly.