Privacy Policy
Last updated: September 29, 2026
Austur AI, a product of Inseris LLC, a Virginia limited liability company ("Austur," "we," "us," or "our"), provides an AI-powered conversational assistant that businesses deploy on their websites. This policy covers how we handle data across two contexts: (1) visitors to austur.ai (our marketing site and waitlist) and (2) visitors to websites that use the Austur chat widget ("tenant sites"). If you are a business using Austur to serve your customers, your use is also governed by our Terms of Service.
1. What we collect
On austur.ai (marketing site)
When you join our waitlist, we collect your email address, name, industry, and a description of your needs. Optionally, you may provide your business name and website URL.
On tenant sites (chat widget)
When you visit a page that includes an Austur-powered chat widget, or interact with the widget's features, we may collect:
- Chat messages you send and receive
- Engagement analytics where the business enables them, including page views and time on page (collected even before you open the widget), and widget usage events such as opening the assistant, watching a welcome video, or stepping through the fee estimator. These records use identifiers that may associate activity with conversations and visitor profiles on the same business’s site. Page-view analytics are disabled automatically if your browser sends a Global Privacy Control (GPC) signal.
- If you use the fee estimator's "Email this to me" option: your name, email address, and the estimator answers you selected — used to send you your estimate and delivered to the business as a lead
- Page context from the page where you opened the widget, including the URL, page title, headings, navigation links, structured data, and referrer domain
- Timestamps of your interactions
- Your browser's user agent string
- Approximate geographic location (country, city, region) derived from your IP address at the network edge
- Audio recordings if you use the voice input feature (processed for transcription, then deleted — see Section 3)
- Voice form-fill input, if you use voice to complete a form on a business's site — the transcript of what you say and the field values extracted from it (see Section 3)
- Contact information collected during conversation, including information the assistant may ask you for such as your name, email, phone number, service interest, location, and project details
For the chat widget, we use hashed identifiers for rate limiting and to recognize visitors within the same business’s site. Visitor identifiers can associate activity with conversations and visitor profiles. We do not use tracking cookies in the widget. See Section 6 for retention periods and the separate handling of marketing waitlist data.
2. How we use your data
Marketing site data is used to evaluate your fit for early access and to send you updates about Austur.ai — launch announcements, early access invitations, and occasional product news.
Chat widget data is used to:
- Generate AI-powered responses to your questions based on the business's knowledge base
- Provide the business with conversation summaries and visitor insights via email notifications (see Section 4)
- Send you the estimate you request from the fee estimator, and deliver it to the business as a lead
- Deliver lead and contact information to the business, including via email and webhook delivery to the business's configured systems
- Improve the quality of the assistant's responses for that specific business
- Detect and prevent abuse (rate limiting, spam detection)
We will never sell, rent, or share your personal information with third parties for their own marketing purposes.
3. AI processing and voice data
Your chat messages are processed by large language models (LLMs) to generate responses. Specifically:
- Conversation processing: Messages are sent to Google's Gemini API to generate responses grounded in the business's knowledge base.
- Speech-to-text: If you use voice input, your audio is processed by Cloudflare Workers AI for transcription. This service may use third-party models (including OpenAI) under the hood. Audio recordings are used solely for transcription and are not retained after processing.
- Voice form-fill: On some businesses’ sites you can complete a form by speaking instead of typing. We transcribe your audio and use the transcript to extract values for the form’s fields. Austur does not store the audio recording. To improve this feature’s accuracy, we may keep the transcript and extracted values on a 30-day schedule. Records older than 30 days are removed by our daily cleanup process. If your browser sends a Global Privacy Control signal, we skip this debug capture and still fill the form. If you submit the form, its contents are retained separately as a contact record.
We use conversation data to improve the assistant's performance for the specific business you interacted with — for example, refining how it answers common questions. We do not share your conversations across businesses or use them to build general-purpose AI products. Under our current provider agreements, AI providers process conversation data to generate responses and do not retain it for their own model training.
4. Visitor intelligence and profiles
We analyze conversations to extract structured signals that help the business understand visitor needs. These may include inferred service interests, budget comfort level, timeline urgency, and decision-stage indicators. This analysis is performed automatically and shared only with the business whose website you visited.
Visitor profiles are not shared across businesses.
5. Third-party services
We use the following services to operate Austur. Each processes data on our behalf under data processing agreements:
- Cloudflare (Pages, Workers, D1, R2, Workers AI) — hosting, application logic, database, file storage, and speech-to-text processing
- Google Cloud (Gemini API) — conversation AI processing
- Resend — email delivery for lead notifications and visitor insight digests sent to Tenants, and for estimate emails visitors request from the fee estimator
- Cloudflare Turnstile — bot protection on the waitlist form and on estimator and contact-form submissions on tenant sites, which may process your IP address and browser metadata
When a Tenant configures webhook delivery, lead and contact data is transmitted to the Tenant's own systems. Austur is not responsible for how Tenants handle data once it leaves the Service.
6. Data retention
- Waitlist submissions: Retained until you request deletion or until we no longer need them for the waitlist program.
- Chat, contact, estimate and engagement records: Chat conversations, contact-form and intake records, estimate requests, and widget engagement records are kept in our operational database on a 180-day schedule, measured from creation of each record. Records older than 180 days are deleted by our daily cleanup process. Updating a lead does not restart this period.
- Visitor profiles and session records are retained separately from conversation logs and may remain after those logs are deleted.
- Voice audio: Austur does not store audio recordings. Audio is processed for transcription.
- Voice form-fill debug records: Transcripts and extracted values captured for accuracy review follow a separate 30-day schedule, with older records removed by daily cleanup. We skip this debug capture when your browser sends a Global Privacy Control signal. Submitted form contents are retained separately as contact records.
- Widget rate-limit records: These records contain hashed identifiers and request counters. Our daily cleanup removes records whose current rate-limit window started more than two days earlier. New activity can restart that window.
- Marketing waitlist rate-limit records: The marketing waitlist uses a separate rate-limit store containing IP addresses. That store currently has no automatic age-based deletion.
The operational database retention periods above do not automatically remove summaries, downloaded exports, recovery copies, or emails already delivered to a business or retained by Austur. These copies require separate deletion handling.
7. Cookies and local storage
The austur.ai marketing site uses a session-storage flag to control a visual animation on first visit.
The widget stores conversation state in your browser’s session storage and a session identifier and timestamp in local storage. Sessions expire after one hour of inactivity, but local storage may remain until it is replaced when you return or you clear your browser data. Session cookies, where used, expire after one hour.
We may use cookies or similar technologies for analytics and site improvement. If we do, we will provide controls to manage your preferences.
8. Data security
All data is transmitted over HTTPS. Data at rest is stored on Cloudflare's infrastructure, which provides encryption at rest and in transit. We implement input sanitization, rate limiting, and bot protection to safeguard against abuse. Access to production data is restricted to authorized personnel.
9. International data transfers
Your data is processed on Cloudflare's global network and Google Cloud infrastructure. If you are located outside the United States, your data may be transferred to and processed in the United States or other jurisdictions where our service providers operate. We rely on Cloudflare's and Google's data processing agreements and standard contractual clauses to ensure appropriate data protection.
10. Children's privacy
Austur is not directed at children under 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will delete it promptly. If you believe a child under 18 has provided us with personal information, please contact us.
11. Your rights
You can request access to, correction of, or deletion of your data at any time by contacting us.
For EU/EEA residents (GDPR)
You have the right to access, rectify, erase, restrict processing, and port your data. You also have the right to object to processing and to lodge a complaint with your local data protection authority. Our legal basis for processing is legitimate interest (providing the service you or the business requested) and, where applicable, your consent.
For California residents (CCPA)
You have the right to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information. To exercise your rights, contact us using the information below.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact
Questions about this policy? Use the contact form on this site and we'll get back to you.