Skip to content

What Sairo processes, why, and for how long.

This policy covers the Sairo service, the sairo.app website, the embedded assistant, Sairo for Mac and Windows, and the Sairo mobile apps. It names the providers involved, gives the retention period for each kind of record, and explains how to request access, correction or deletion. If you chatted with Sairo on another business’s website, that business decides how it uses your conversation; this policy describes Sairo’s role as its service provider.

The short version.

Sairo processes account details, website content, visitor conversations and workspace records to run an AI website assistant and live chat service for businesses. It sends relevant text to AI providers to generate replies, search embeddings and dictation transcripts, and it uses hosting, email, payment and backup providers to operate. Sairo does not sell personal information, does not use it for advertising, and does not place third-party analytics or tracking in its website or apps.

Records are kept for as long as the account or workspace that owns them exists, plus the fixed periods listed on this page. You can ask for access, correction or deletion at any time. A verified deletion request disables the account immediately and removes personal data within 30 days, apart from records the law requires Sairo to keep.

Account and workspace information.

Sairo stores account details such as name and email address, a password hash, workspace memberships, roles, invitations and sign-in sessions. These records support access to the service and administration of a workspace. For paid plans, Sairo keeps the customer, subscription and invoice identifiers and status returned by Dodo Payments; card numbers are entered with Dodo Payments and are never stored by Sairo.

A contact form submission stores the details you enter so Sairo staff can review and respond. Do not include passwords, API keys or sensitive personal information in a general enquiry.

Website content and conversations.

The service stores indexed website content, extracted business details and saved answers. It also records visitor messages, assistant replies, live specialist replies, conversation outcomes, appointment requests and any contact details a visitor chooses to provide.

On a website whose owner has switched live chat on, the widget reports that someone is reading a page so a specialist can offer help. Sairo records the page path, its title and how long the visit has lasted, against a hash of the widget token that browser already holds. It does not record the query string, a network address or a location, and the record is removed shortly after the visitor stops reading. Websites without live chat enabled do not report this at all.

A visitor can attach a photo or a PDF to a conversation, and a specialist can send one back. Sairo stores the file with that conversation, decides its type by reading the file itself rather than trusting its name, and always serves it as a download rather than displaying it as part of a page. A workspace can also upload its own reference documents, which become indexed knowledge like any other source. Do not send information through either route that the agreed service is not meant to handle.

If a specialist blocks an abusive visitor, Sairo stores the reason, who blocked them, and hashes of that browser’s widget token and network address, so the block can be enforced and lifted. Workspace members may use conversation notes, assignments, lead follow-up records and live chat presence timestamps. Access depends on their role, project scope and site specialist assignment. The website operator decides what content to connect, who may read conversations and how its team follows up with visitors.

Ask Sairo history and change records.

Ask Sairo stores your requests, assistant replies, relevant tool results and proposed or completed changes. A change record includes the affected website, previous and proposed values, status and timing so you can review or undo a supported update.

History is owned by your account within the workspace. Applied updates affect shared business records, and permitted workspace activity can show those changes. Relevant conversation history and retrieved records are sent to the configured AI provider to interpret a request.

Information shared with connected AI applications.

When you approve an MCP connection, Sairo records the application, account, workspace, website scope, permissions, expiry and connection activity. It stores hashes of access and refresh tokens and records supported changes made through that connection.

An authorised application can receive permitted visitor conversations, knowledge, business information, leads and other tool results in response to its requests. Those records may include personal information a visitor or teammate provided. The application processes that information under its own terms, settings and retention practices; Sairo has no control over it once delivered.

Disconnect an application from Connected apps to stop future access through that connection. Disconnecting does not erase information already returned to the application or remove the Sairo change history. For deletion or access requests, identify both the Sairo workspace and any external service that received the information.

Optional voice dictation.

When a visitor or workspace user chooses dictation and grants microphone permission, a short recording is sent through Sairo to the configured transcription service, OpenAI GPT-4o mini Transcribe via OpenRouter. The returned text can be reviewed in the composer before it is submitted as a message.

Sairo processes the audio for that request and records usage; it does not save the audio as a conversation attachment or keep a copy. Submitted text follows the normal conversation data flow. Dictation is optional and typing is always available.

Service providers and where information goes.

Sairo shares information with the providers below only to provide, secure and support the service, under each provider’s service and data-processing terms. Those terms require the provider to protect the information and to use it only to perform its service for Sairo. Sairo does not permit providers to use your information for their own purposes, including advertising or training their models, and Sairo does not sell personal information to anyone.

Sairo’s servers and providers are located in the United States, so information is processed and stored there regardless of where you use the service. Applications you connect yourself, and the businesses whose websites you chat on, are not Sairo providers; they are separate recipients under your or their own control.

A workspace can add recipients of its own. If it configures an assistant action, Sairo sends that action’s address the information the assistant collected for it, such as an order reference a visitor typed, and records what came back. If it issues an API key, whoever holds that key can read the conversations, leads and saved answers its scope allows. Sairo shows every action call to the website’s own team and lets a key be revoked at any time, but these recipients are chosen by the workspace and governed by its arrangements with them, not by Sairo’s.

Providers that process information for Sairo
ProviderPurposeInformation involved
OpenRouter (United States)Routes AI requests to the configured model providers: Google Gemini 2.5 Flash Lite for generated replies and Ask Sairo, OpenAI text-embedding-3-small for search embeddings, and OpenAI GPT-4o mini Transcribe for optional dictationRelevant visitor and workspace messages, website excerpts, Ask Sairo requests and short dictation recordings
Resend (United States)Transactional email sent from accounts.sairo.app: invitations, password recovery, notifications and weekly recapsRecipient email address, message subject and body
Dodo PaymentsCheckout, subscription billing, invoices and the billing portal for paid plansBilling contact and payment details you enter with Dodo Payments; Sairo receives customer, subscription and invoice identifiers and status
Hostinger (United States)Servers and database hosting for the serviceAll service records described on this page
Google (cloud storage)Off-site copies of database backupsBackup archives, kept for up to 60 days
TwilioSMS follow-up and WhatsApp messages, only for a workspace that enables them. Neither channel is available in the current hosted service, because no Twilio account is connected to it.Phone number and message text for that workspace

How long records are kept.

Sairo keeps records for the periods below and deletes them automatically where a fixed period applies. Deleting a record from the live service does not immediately remove it from backups, which are kept for up to 60 days and then removed; Sairo does not restore deleted records from a backup except to recover from a failure, and it re-applies deletions after such a recovery.

Retention periods by record type
RecordKept for
Account profile, memberships and workspace settingsWhile the account and workspace exist. Deleted within 30 days of a verified deletion request, except invoices and payment records kept for as long as tax and accounting law requires.
Sign-in sessions30 days from sign-in, or until you sign out or revoke the session in Account security.
Password-reset linksValid for 30 minutes; the record is removed within one day of expiry.
Workspace invitations14 days, or until accepted or revoked.
Visitor conversations, leads, appointment requests, saved answers, indexed website content and Ask Sairo historyWhile the workspace exists, unless the workspace operator deletes or archives the record. Removed within 30 days of a verified workspace closure or deletion request.
Connected AI application accessA connection expires 30 days after approval unless renewed. Access tokens are short-lived and stored as hashes; expired and revoked records are removed within one day, and unused application registrations after 30 days.
Live chat presence and rate-limit recordsPresence connections are removed after one day of inactivity; rate-limit counters are stored as hashes and removed after one day.
Files attached to a conversationWith that conversation, and removed when it is. A file is available only to the website’s own team and the visitor who is in that conversation.
Reading activity on a websiteA row is kept while someone is reading and removed within thirty minutes of them stopping. It holds the page path without its query string, against a hash of the widget token.
Assistant action callsThe address called, what was sent and what came back are kept with the workspace so its team can audit them. Removed within 30 days of a verified workspace closure or deletion request.
API keysStored as a hash with a visible prefix, so a key can be recognised in a list but never read back. Removed when revoked.
Help centre articlesWhile the workspace exists. A published article is public, and also indexed as knowledge the assistant answers from; unpublishing removes both.
Operational service checks30 days.
Visitor blocksA browser block lasts until the website operator lifts it. A network address block expires after 30 days and is then deleted automatically.
Dictation recordingsNot stored by Sairo. The audio is sent to the transcription provider for that request only; the returned text follows the conversation rules above.
Email and SMS delivery recordsWith the workspace records above. The delivery provider keeps its own logs under its terms.
Database backupsUp to 60 days, then removed automatically.
Desktop app local dataRecent reads for up to 24 hours and unsent drafts for 7 days, encrypted on your device; removed on sign-out or through Settings.
Contact form enquiriesWhile the enquiry is open and for reasonable follow-up; removed on request.

Access, correction, deletion and consent.

You can change your name and password, see and revoke sign-in sessions and signed-in devices, disconnect AI applications and withdraw desktop AI permission from within the product. Workspace administrators can delete or archive saved answers, remove websites and their indexed content, and revoke members.

To request a copy of your data, a correction, or deletion of your account or workspace, use the contact form with the topic Privacy question, or write from the email address on the account. Sairo verifies the request against the account, confirms receipt within five business days, disables the account on confirmation and completes deletion within 30 days. Information already sent to an AI provider, an email recipient or an application you connected cannot be recalled from that recipient; Sairo will tell you which recipients were involved where it can.

If your conversation took place on another business’s website, that business controls the record. Contact it first so it can identify the relevant workspace and record; Sairo assists it and acts directly where the law requires. Depending on where you live, you may also have the right to object to or restrict processing, to receive your data in a portable format, and to complain to a data protection authority.

Consent for AI processing in the desktop app is requested before the first AI action and can be withdrawn in Settings. Website visitors choose whether to type a question, share contact details or use dictation, and a live specialist or the visitor can end a chat at any time. Withdrawing consent does not undo processing that has already completed.

Cookies, sessions and security.

Sign-in uses the HTTP-only sairo_session cookie, which expires after 30 days. The interface may store preferences such as theme, and the embedded assistant keeps a site-specific conversation reference in session storage so a visitor can reconnect after refreshing the page. Sairo sets no advertising or cross-site analytics cookies; the cookie notice lists every cookie and storage key.

Traffic between browsers, apps and the service uses HTTPS. Passwords are stored as salted scrypt hashes, and session, reset and connection tokens are stored as hashes. Every workspace action is checked on the server against the acting user’s role and scope. Operational and security records support troubleshooting and abuse prevention. Sairo does not claim an independent security certification; the security page describes the controls that exist.

Sairo for Mac and Windows.

The desktop app sends your sign-in details to Sairo over HTTPS and stores session credentials using the operating system’s protected storage. It sends an app-generated installation identifier, device name and app version so you can see and revoke signed-in devices. Passwords are not saved in the desktop app.

Recent workspace reads and unsent drafts are encrypted locally. Saved reads are available for up to 24 hours and drafts expire from use after 7 days; expired data is removed during subsequent cleanup. You can clear saved reads in Settings. Signing out removes protected account data and AI permission records, while retaining the random installation identifier and local appearance preferences.

Before an AI-related action, the desktop app asks you to allow or decline sending requests and relevant workspace records to the external AI providers described in the consent dialog. Settings provides a control to withdraw that permission for the current account and workspace on that device. Withdrawing permission does not cancel an already submitted operation, delete records already processed, or change another device, a connected application or the website’s existing AI service.

Desktop notifications and continued operation after closing the window are optional and off by default. Notifications use minimal text about waiting visitors or replies. The desktop app does not request access to your camera, microphone, contacts or location, includes no advertising or cross-app tracking, and sends no crash or usage analytics to third parties. Native exports are saved only to a location you choose.

Sairo for iPhone and Android.

The mobile apps sign you in to your existing account over HTTPS and keep the session token in the device’s secure storage. They send a device name and app version so you can see and revoke signed-in devices, and they request internet access only: no camera, microphone, contacts, photos or location access, and no advertising or analytics software.

Signing out removes the stored session from the device. Workspace records shown in the app are read from the service and follow the retention rules above; they are not copied into a separate mobile store.

Children, changes and contact.

Sairo is a business tool and is not directed to children under 16. Sairo does not knowingly collect personal information from children and deletes such information when it learns of it. A business installing the assistant on a website aimed at children must not do so without its own compliance review.

Material changes to this policy are announced on this page with a new date, and account holders are notified by email or in the product where a change affects how their information is used. Questions about this policy go to the contact form under Privacy question; Sairo answers privacy questions from the address shown on the account or from the business’s registered contact.

See what your website can answer.

Try a sample, review the result, and decide what comes next.