Security and data handling
What the widget collects, where it goes, and the controls that protect it. For a non-technical overview, see the Security page.
What the widget collects
| Data | Details |
|---|---|
| Visitor key | A random 256-bit key in the browser’s localStorage (one per website), so a returning visitor keeps their conversation. Only a SHA-256 hash of it is stored on our side. The widget sets no cookies. |
| Page views | URL, title and referrer of each page, including single-page-app navigation. Only URLs on your allowed domains are accepted. A new visit starts after 30 minutes without activity. |
| Visit details | IP address, user agent (shown as browser, OS and device type), landing page, the referrer when it is another site, and UTM parameters. Country, region and city only when location headers from Cloudflare are enabled for the ZebChat API. |
| Conversations | Messages, attachments and pre-chat or offline form answers. |
| What your page sends | Anything you pass to setUser, setTag and track. |
Isolation between customers
- Every table that holds customer data is protected by PostgreSQL row-level security. The API’s database role can’t bypass it, so a query without an organization context returns no rows.
- The organization in a request comes only from the URL and is checked against the caller’s membership; ids in requests are always re-checked on the server.
- Automated tests attempt cross-organization access through the API and directly in SQL.
Accounts and tokens
- Passwords are hashed with Argon2id.
- Refresh, email-link, invitation and visitor tokens are stored only as SHA-256 hashes.
- Access tokens expire after 15 minutes. Refresh tokens are single-use and rotate; reuse revokes the session.
- Logout, session revocation, password changes and role changes take effect at once, and close open realtime connections.
- An append-only audit log records changes to your organization, written in the same transaction as the change.
The widget
- The chat UI runs in a sandboxed iframe on ZebChat’s origin. Your page and the widget only exchange validated messages: the loader accepts them only from its own iframe, and the iframe only from its parent page.
- The widget loads only on your allowed domains. The site key is public by design; the domain check stops casual reuse of it, and identity verification is what proves who a logged-in visitor is.
- The identity secret is 256 bits, shown once, never returned by the API afterwards, and compared in constant time. Rotating or turning it off is recorded in the audit log.
- Rate limits apply per IP before authentication and per visitor and organization after it; Cloudflare Turnstile is optional.
Attachments
- Allowed: images (PNG, JPEG, GIF, WebP), PDF, text, CSV, Word, Excel and ZIP, up to 10 MB each and 10 per message. SVG and HTML are refused because they can contain scripts.
- Files are uploaded straight to private storage with a signed URL that fixes the type and size; the API checks the stored file before attaching it.
- Downloads use signed links (valid for at least 24 hours) that redirect to a 5-minute storage link. Anything but an image downloads as an attachment.
Internal notes
Notes are filtered out of every API response and realtime event a visitor can receive. Visitors can’t create them.
Privacy tools
- Cookie-consent mode: the widget stores nothing and records no page views until your banner calls consent(true); visitors can still chat. With regional consent, the region is decided on the server from the visitor’s country.
- Consent log: every decision is logged with the country, never the IP address. The log is kept up to 2 years, deleted with the visitor, and admins can export it.
- Export and erasure: admins can export a visitor’s data or erase it, including their conversations, from the visitor’s profile.
- Retention: choose how long ended conversations and their files are kept (from 30 days to 7 years, or unlimited). Visitor tracking older than 180 days is removed automatically.
See also the Privacy Policy, Data Processing Agreement and Subprocessors.
Coming soon
- Two-factor authentication (TOTP) and single sign-on
- IP allow-lists for API keys
Reporting a vulnerability
Email [email protected] with the subject “Security report”. Please don’t access other people’s data, and give us time to fix the issue before disclosing it.