Privacy Policy
Last updated: July 31, 2026. This policy may be updated as the product evolves; the latest version will always be published on this page.
What we do
CS Solutions AI (operated by CitySoft Solutions) provides AI chat agents that website owners embed on their sites to answer visitor questions and capture enquiries. This policy describes what data the platform handles for both our customers (site owners with dashboard accounts) and visitors who chat with an agent on a customer's website.
Data we collect
- Account data: the email address and login credentials you use to create and access a dashboard account, plus billing details processed by our payment provider.
- Chat data: messages exchanged between website visitors and an AI agent are stored so that site owners can review conversation history and analytics. Visitors should avoid sharing sensitive personal information in chat.
- Lead data: contact details (such as a name, email, or phone number) that a visitor chooses to share during a conversation may be forwarded to the site owner through the notification channels they configure.
- Knowledge content: documents and website content that site owners upload to train their agents.
Cookies and sessions
The dashboard uses session cookies to keep you signed in. The embedded chat widget uses a session identifier so that a conversation can continue across messages. We do not use third-party advertising cookies.
How chat data is processed
Conversation messages are processed by large language model providers to generate agent responses, and are stored in our database scoped to the owning customer account. Aggregated analytics (such as message counts, topics, and sentiment) are derived from conversations and shown only to the owning site's account. We do not sell your data.
Security
Traffic to and from the platform is encrypted in transit using TLS. Stored integration credentials (such as API tokens for notification channels) are encrypted at rest. Each customer's data is isolated per tenant at the database layer. No system is perfectly secure, and we do not currently hold formal security certifications; SOC 2 readiness is on our roadmap. If you believe you have found a security issue, please contact us at sales@cssolutions.ai.
Data retention and deletion
- Chat transcripts: conversation messages are automatically and permanently deleted 12 months after a conversation is closed. The automated purge runs hourly and records counts-only evidence of what was removed — never the content itself.
- Leads and form submissions: contact details captured through chat or forms are stored encrypted and are automatically deleted at the end of the retention period the site owner configures for each form. Expired records are hard-deleted by the same evidence-logged hourly purge.
- Conversation insights: per-conversation topics, sentiment and summaries follow their source conversation out when retention or a verified subject-deletion request erases that conversation.
- Deletion on request:if you chatted with an agent on a customer's website, contact that site's owner — they have built-in tools to look up, export and erase the connected visitor data stored for your email address. Minimal salted deletion evidence and legally required billing records may remain without the conversation link. Site owners can request workspace or account deletion in the dashboard's Account > Danger zone, where any billing, ownership or stored-object blockers are shown and can be refreshed.
Contact
Questions about this policy can be sent to sales@cssolutions.ai or via our contact page.