What the bot can and cannot do inside your community, what data it touches, and where that data goes.
Last updated: July 2026Access is scoped to exactly what's needed to answer questions, nothing more.
Access is scoped per channel and revocable instantly.
| Data | Purpose | Retention |
|---|---|---|
| Conversations (user question + bot answer) | Quality assurance: catching and correcting bot mistakes | 30 days, auto-deleted |
| Flagged or escalated conversations | Extended quality review | 90 days, auto-deleted |
| Transaction hashes & contract addresses | Failed-transaction diagnostics | 30 days |
| Platform user IDs | Message delivery while a ticket or session is open | Deleted when it closes |
| Aggregate statistics (counts, categories, deflection rate) | Monthly reporting to your team | Contract duration, contains no personal data |
User identity in conversation logs is stored only as an irreversible cryptographic hash. Raw usernames are never written to conversation records. No emails, KYC data, or off-chain personal identifiers are ever collected.
Clients can review their own community's conversations in their dashboard at any time, strictly isolated per client, with one-click flagging of any answer for review. Your bot's work is fully auditable, no black box.
Receives message text for response generation. Per Anthropic's commercial terms, API inputs and outputs are not used to train models.
Industry-standard on-chain data and contract-intelligence providers, which receive only public identifiers (transaction hashes, contract addresses), data already visible on any block explorer. No message content is ever shared with them.
A third-party token-security database, receiving contract addresses only.
A complete, named subprocessor list is available to clients on request as part of our Data Processing Agreement.
EU-operated with GDPR-aware practices: data minimization, hashed identifiers, defined retention, deletion on request. A Data Processing Agreement is available on request. Client knowledge bases are fully isolated, so one protocol's documentation never informs another's bot.
Reach us at security@hextriage.io, acknowledged within 24 hours.
Ultimate control is yours: revoking the bot's channel permissions ends all access instantly, no action from us required.