Legal

Privacy Policy

Effective September 22, 2026

This policy explains what Chatbot Factory LLC ("Chatbot Factory", "we", "us") collects, why, and what you can do about it. It covers our website, chatbotfactory.io, and Mission Control, the private workspace our clients sign in to at app.chatbotfactory.io.

1. Who we are

Chatbot Factory LLC runs AI training workshops and a done-with-you LinkedIn outreach service. For the outreach service we work on behalf of our clients: they decide who they want to reach, and we operate the tools that help them do it. You can reach us any time through our contact page.

2. Information from our website

When you visit chatbotfactory.io we collect:

  • What you send us. If you fill in the contact form or a sign-up popup, we receive what you enter (such as name, email, job title, organization, website and your message) and use it to reply and to follow up about our services.
  • Usage and device data. Google Tag Manager and Google Analytics measure which pages are visited and how people find us. The Meta (Facebook) Pixel helps us measure and improve our ads. These tools use cookies and similar technologies.
  • Spam and error protection. Google reCAPTCHA checks that form submissions come from people, and Sentry records technical errors so we can fix them.
  • Bookings. If you book a call, Calendly collects the details you enter under its own privacy policy and shares them with us.

You can block or delete cookies in your browser settings, and use Google's opt-out tools at tools.google.com/dlpage/gaoptout and your ad preferences on Facebook. The site still works without them.

3. Mission Control (app.chatbotfactory.io)

Mission Control is invitation only. Each client has their own separate workspace and database, so one client's information is never stored with another's. Inside a workspace we store:

  • Account details for the people a client invites: name, email address and profile photo, taken from Google sign-in (see section 4).
  • Prospect information: details about the people a client wants to connect with, such as name, job title, company, public LinkedIn profile URL and recent public posts (see section 5).
  • Outreach work: draft connection notes, the version a person actually sent, the client's writing playbook and feedback, and when each step happened.
  • LinkedIn notifications a client chooses to forward to their workspace inbox (for example "invitation accepted" emails), so acceptances are tracked automatically. Job-alert emails are discarded without being stored.

We use this information only to provide the service to that client: drafting notes, showing the send queue and reporting results. A person on the client's side approves and sends every LinkedIn message; nothing is sent automatically. We do not sell client data or use it for advertising.

4. Google sign-in and Google user data

People sign in to Mission Control with their Google account. We request only the basic sign-in scopes (openid, email and profile), which give us your name, email address and profile photo. We do not request access to your Gmail, Google Drive, Calendar, contacts or any other Google data.

We use this information only to confirm that your email address has been invited, to sign you in to the right workspace, and to show your name and photo inside the app. If your address is not on the invitation list, no account is created.

Chatbot Factory's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train AI models.

5. People we contact for our clients

If you received a LinkedIn connection request through our service, your information came from your public LinkedIn profile and public posts, gathered using third-party research tools on our client's behalf. We use it only to help that client write a relevant, personal note, and a person decides whether to send it.

If you would like us to delete your information or never contact you again for any client, tell us through our contact page. We will remove your details and keep only the minimum needed (your profile URL) to make sure you are not contacted again.

6. Who we share information with

We share information only with service providers that help us run the website and Mission Control, under their own security and privacy commitments, and only as far as they need it:

  • Hosting and databases: Vercel (website), Hetzner (servers in Finland), Convex (Mission Control databases) and Supabase (a website feature).
  • Sign-in and security: Google (sign-in, reCAPTCHA) and Sentry (error monitoring).
  • Email and messaging: AgentMail (receiving forwarded LinkedIn notifications and sending workspace emails) and Slack (notifying us of website form submissions).
  • AI and research: Anthropic (drafting connection notes) and Apify (collecting public LinkedIn profile and post data for prospect research).
  • Analytics, advertising and booking: Google Analytics, Meta and Calendly, as described in section 2.

We may also disclose information if the law requires it, or to protect our rights or the safety of others. If Chatbot Factory is ever sold or merged, information may transfer to the new owner under this policy.

7. How long we keep information

We keep website enquiries for as long as needed to respond and follow up. We keep a client's Mission Control workspace for as long as we work together. When an engagement ends, or when a client asks, we delete or return the workspace data, except for anything we must keep for legal or accounting reasons and the do-not-contact records described in section 5.

8. Security

Mission Control is invitation only and uses Google sign-in, so there are no passwords for us to store. Every request to a workspace is checked against a short-lived token for that specific client, and each client's data lives in its own database. Connections are encrypted with HTTPS. No system is perfectly secure, but we work to protect your information and will tell affected clients promptly if a breach affects them.

9. Your choices and rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict how we use it, and to withdraw consent. To make a request, contact us through our contact page. We will answer within 30 days. If your information is in a client's workspace, we may involve that client, since they decide how it is used. You can also complain to your local data protection authority.

You can remove Mission Control's access to your Google account at any time at myaccount.google.com/connections.

10. Children

Our website and services are for businesses and professionals. They are not directed to children under 16, and we do not knowingly collect their information.

11. Changes and contact

If we change this policy we will update the date at the top of this page, and tell Mission Control clients directly about significant changes. Questions? Reach us through our contact page.