Transcripts and privacyBeta
Voice input, whether conversations are stored, what visitors are told, and how to choose a lawful basis
This feature is in beta. It is usable, but details can still change.
The Behavior section decides how visitors can talk to the widget and whether their conversations are kept. By default nothing is stored.
Voice input
Switch on Voice input to let visitors speak their messages instead of typing. The recording is turned into text and sent like a typed message. Voice is billed the same way as text; see Limits and billing.
Page context
From loader 1.7.0 the bot learns the title and address (without parameters) of the page the visitor is on. It is not stored and can be switched off; see Page context.
Store transcripts
Transcript storage is off by default. With storage off, only anonymous aggregates are kept for Analytics, never message content.
Switch on Store transcripts to keep visitor conversations so you can read them later under History. Storing personal data brings GDPR obligations: you have to inform visitors and have a lawful basis. How the widget informs them is the next setting.
What visitors see
With storage on, you choose under What visitors see how the widget tells people. Storing and informing are two different questions:
| Mode | In the widget | For |
|---|---|---|
| Show nothing | no notice | Your own privacy policy already informs people about the storage. |
| Show a notice | one line above the input, non-blocking | Transparency visible at the point of collection. |
| Require consent | accept before the first message | When you rely on consent as your lawful basis. |
In every mode, nothing is stored unless Store transcripts is on. As soon as the widget displays anything (notice or consent mode), the privacy notice text is required; without it the widget cannot be published. Say what is stored, why, and link your privacy policy.
Widgets published before this setting existed stay on consent. An update never silently changes what your visitors were promised.
Choose a lawful basis
GDPR asks for two things that are often conflated:
- Transparency (Art. 13): you must inform people. A published privacy policy satisfies this. A click inside the widget is not required for it.
- Consent (Art. 6(1)(a)): only needed if that is the basis you rely on. A public authority may instead rely on public task (Art. 6(1)(e)) or legitimate interest (Art. 6(1)(f)), in which case a notice is enough.
Which basis applies is for you and your data protection officer to decide, not for us. Two things argue for consent:
- Special categories (Art. 9). People type things into a free-text box that you never asked for. On a municipal site, questions about benefits, care levels or debt are routine, and that raises the bar considerably.
- § 25 TDDDG (formerly TTDSG). The consent flag is stored on the visitor's device, which is a separate question from GDPR.
Read stored conversations
History lists the conversations this widget stored, each with its first question. Open one to read the full transcript. The section stays empty until Store transcripts is on and, in consent mode, visitors have agreed.
How long transcripts are kept
Stored transcripts are deleted automatically after the retention period, 90 days unless you set another one for this widget. Ask the setup assistant to change it.