Appearance
Privacy and consent
What is stored on your site
The chat sets no cookies. widget.js keeps a little state in your site's own storage, per bot, under the key wfc:<bot id>:
- the visitor token (who the visitor is to the chat server), the current conversation and its resume token;
- whether the chat was open, the unread count, and whether the visitor closed the greeting bubble.
It also notes in sessionStorage that the greeting was shown this session. The chat window itself stores nothing, except in the plain iframe embed, which has no widget.js to keep the state for it.
Choose where with the storage option: local (the default, localStorage), session (sessionStorage, forgotten when the tab closes) or none (nothing; each page load is a new visitor).
Cookie-consent banners
If your consent manager has to approve storage first, start without it and turn it on when the visitor agrees:
js
WirefaceChat.boot({ bot: 'pk_your_bot_id', storage: 'none' });
myConsentManager.onChange(granted => WirefaceChat.consent(granted));consent(true)turns storage on (local, or thestorageyou booted with if it wasn'tnone).consent(false)deletes what the chat stored on your site and stores nothing more; on the next page load the visitor is new to the chat.
The chat works the same either way; without storage, it just can't continue a conversation on the next page.
Signing out
When a user signs out of your site, call WirefaceChat.shutdown({ forget: true }) so the next person on that browser doesn't continue their conversation. The server also refuses to continue a signed-in user's chat for anyone else. See Identity verification.
What is stored on the server
Everything is in the server's database and files directory (DATA_DIR), on your machine:
- Visitors: a hash of their token, their language, browser user agent and, if known, name, email and your user id. IP addresses are not stored; a hash salted with the day's date is kept for rate limiting.
- Conversations and messages, with images, tool calls, ratings and usage.
- Leads.
- Camera frames, only while the conversation needs them: they are deleted after it ends (within about two hours) unless the bot keeps them (
vision.webcam.persistFrames), and your team only sees them withvision.webcam.shareWithHumanAgents.
Every uploaded image is decoded and re-encoded before it is stored, which removes EXIF data such as GPS position. Images a visitor attached but never sent are deleted after a day. Server logs leave out authorization headers, cookies, API keys, passwords, tokens and secrets.
Messages, images and audio are sent to the AI provider the bot uses, under your agreement with that provider.
Data requests (GDPR and similar)
Find a visitor by email or by your user id, export everything about them, or erase them:
sh
# find
curl -H "Authorization: Bearer $TOKEN" "https://chat.example.com/api/v1/visitors?email=ana@example.com"
curl -H "Authorization: Bearer $TOKEN" "https://chat.example.com/api/v1/visitors?userId=42"
# export: the visitor, every conversation with its transcript, and their leads, as JSON
curl -H "Authorization: Bearer $TOKEN" -o visitor.json "https://chat.example.com/api/v1/visitors/vis_.../export"
# erase: their conversations (with their files), leads and the visitor record
curl -X DELETE -H "Authorization: Bearer $TOKEN" "https://chat.example.com/api/v1/visitors/vis_..."These need an admin, or an API token with the privacy:write scope. Search results and exports leave out the visitor's token and IP hashes. Erasures are recorded in the audit log.
To delete a single conversation: DELETE /api/v1/conversations/{id}.
Retention
Under Settings in the admin panel (PATCH /api/v1/settings with { "retentionDays": 90 }), set how long to keep conversations. Once an hour the server deletes conversations whose last message is older than that, with their messages and files. 0 (the default) keeps them. Leads and visitor records are kept until you delete them.