LangBot User Privacy Policy

Version: 1.0 Effective Date: TBD Last Updated: January 27, 2025


Table of Contents

  1. Introduction
  2. Definitions and Scope
  3. Data Controller
  4. Information We Collect
  5. How We Collect Information
  6. Purpose and Legal Basis for Information Use
  7. Information Sharing and Disclosure
  8. Cross-Border Data Transfers
  9. Data Storage and Retention
  10. Data Security
  11. Your Rights
  12. Cookies and Tracking Technologies
  13. Automated Decision-Making and Artificial Intelligence
  14. Protection of Minors
  15. Self-Hosted Instances
  16. Plugins and Third-Party Services
  17. Changes to This Privacy Policy
  18. Contact Us
  19. Region-Specific Terms

1. Introduction

Welcome to LangBot (hereinafter referred to as "we", "us", or "the Platform"). We understand the importance of your personal information and are committed to protecting your privacy. This Privacy Policy (hereinafter referred to as "this Policy") is designed to explain how we collect, use, store, share, and protect your personal information, as well as the rights available to you.

Please read and fully understand this Policy before using our services. If you do not agree with any terms of this Policy, please stop using our services. By continuing to use our services, you acknowledge that you have read, understood, and agreed to be bound by this Policy.

This Policy is formulated in accordance with the Personal Information Protection Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, and other applicable laws and regulations, while also referencing the requirements of the EU General Data Protection Regulation (GDPR).


2. Definitions and Scope

2.1 Definitions

TermDefinition
LangBotThe intelligent chatbot platform software and related services developed and operated by the LangBot Team
LangBot CoreThe open-source bot core program that can be self-deployed
LangBot SpaceThe plugin marketplace, cloud service platform, and related online services operated by us
Personal InformationVarious information recorded electronically or by other means that relates to identified or identifiable natural persons, excluding anonymized information
Sensitive Personal InformationPersonal information that, once leaked or illegally used, may easily lead to infringement of the dignity of natural persons or harm to personal or property safety, including biometric data, religious beliefs, specific identities, medical health, financial accounts, location tracking, and personal information of minors under 14 years of age
User / YouNatural persons who use our services
Instance OperatorIndividuals or organizations that deploy and operate self-hosted LangBot Core instances
Bot End UserInstant messaging platform users who interact with LangBot bots
ProcessingOperations performed on personal information, including collection, storage, use, processing, transmission, provision, disclosure, and deletion

2.2 Scope

This Policy applies to the following services:

Service TypeDescriptionData Controller
LangBot Space PlatformPlugin marketplace, cloud services (Cloud Pods), developer servicesLangBot Team
Officially Hosted LangBot InstancesBot services directly operated by usLangBot Team
Self-Hosted LangBot CoreOpen-source software deployed by usersInstance Operator (not us)

Important Note: For self-hosted LangBot Core instances, the data controller is the instance operator, not the LangBot Team. We are only responsible for anonymous data collected through opt-in telemetry features. See Section 15 for details.


3. Data Controller

3.1 LangBot Space Platform

For LangBot Space platform services, the data controller is:

LangBot Team
Contact Email: privacy@langbot.app

3.2 Self-Hosted Instances

For LangBot Core instances self-hosted using our open-source software:

  • Data Controller: Instance Operator
  • Our Role: Software provider (not involved in data processing)

We do not control or bear responsibility for the data processing practices of third-party operated LangBot instances. Please consult the relevant instance operator for their privacy policy.


4. Information We Collect

4.1 LangBot Space Platform User Information

4.1.1 Account Information

Information TypeDetailsNecessity
Basic Account InfoEmail address, username, password (encrypted)Required
ProfileNickname, avatar, language preferenceOptional
Third-Party Login InfoGitHub username/email, Google email/nameRequired when using third-party login

4.1.2 Service Usage Data

Information TypeDetailsCollection Purpose
Access LogsIP address (aggregated), access time, request endpointsSecurity, service optimization
Plugin UsageDownload records, installation statisticsService improvement
Resource UsageCredit balance, Pod usageService provision

4.1.3 Payment Information

Information TypeDetailsNotes
Order InformationOrder number, amount, purchase content, transaction timeStored by us
Payment CredentialsThird-party payment IDProcessed by payment providers; we only store transaction identifiers

We do not store: Bank card numbers, payment passwords, complete payment credentials, or other sensitive payment information.

4.1.4 Developer Information

Information TypeDetailsApplicable To
Plugin Submission InfoAuthor name, plugin description, contact informationPlugin developers
API KeysAPI Key (encrypted)API users

4.2 Telemetry Data (from Self-Hosted Instances)

When telemetry is enabled on self-hosted instances (enabled by default, can be disabled), we collect the following anonymous statistical data:

Data ItemDescriptionContains Personal Information
Instance IDRandomly generated unique identifierNo
Software VersionLangBot version numberNo
Adapter TypePlatform used (e.g., QQ, Telegram)No
Model UsageLLM model nameNo
Processing TimeRequest response timeNo
Plugin ListNames of installed pluginsNo
Error InformationSanitized error typesNo

Telemetry data does not include:

  • User message content
  • User nicknames or IDs
  • Real IP addresses
  • Any personally identifiable information

Disabling Telemetry: You can set space.disable_telemetry: true in the configuration file to completely disable telemetry data transmission.

4.3 Bot End User Information (Official Hosted Instances Only)

For bot instances officially operated by us, the following information may be collected:

Information TypeDetailsStorage Method
Platform IdentifierPlatform-assigned user ID, group IDDatabase
Display InformationNickname (during session)Memory (not persisted)
Message ContentConversation text, images, etc.Configurable
Session DataConversation history, contextMemory / Database
Usage StatisticsMessage count, invocation countDatabase

5. How We Collect Information

5.1 Information You Directly Provide

  • Information filled in when registering an account
  • Information provided when completing your profile
  • Information authorized when logging in with a third-party account
  • Information filled in when submitting plugins
  • Information provided when contacting support or submitting feedback

5.2 Automatically Collected Information

  • Access logs and usage data
  • Device and browser information (via cookies)
  • Telemetry data (can be disabled)

5.3 Information from Third-Party Sources

  • Public information provided by OAuth login providers (GitHub, Google)
  • Transaction status information returned by payment providers

6. Purpose and Legal Basis for Information Use

6.1 Purposes of Use

PurposeDescriptionInformation Types Involved
Service ProvisionAccount management, plugin distribution, Cloud Pods operationAccount info, usage data
Identity VerificationLogin authentication, permission managementAccount info, session data
Payment ProcessingOrder creation, credit managementPayment info
Security ProtectionFraud prevention, abuse detection, security auditingAccess logs, IP addresses
Service ImprovementPerformance optimization, feature developmentTelemetry data, usage statistics
TroubleshootingTechnical support, error diagnosisLog data, error information
NotificationsService announcements, security alertsContact information

6.2 Legal Basis

Under Article 13 of the Personal Information Protection Law, we process your personal information based on the following legal bases:

Legal BasisApplicable ScenariosRegulatory Reference
Your ConsentMarketing communications, optional featuresPIPL Art. 13(1)
Contract PerformanceProviding services you requestPIPL Art. 13(2)
Legal ObligationsTax records, security compliancePIPL Art. 13(3)
Legitimate InterestsSecurity protection, service improvementPIPL Art. 13(6)

7. Information Sharing and Disclosure

7.1 We Do Not Proactively Share Your Personal Information

Except in the following circumstances, we will not share your personal information with third parties:

7.2 Sharing with Your Consent

With your explicit consent, we may share your information with third parties.

7.3 Service Providers

We may engage the following types of service providers to process your information:

Service TypeProviderShared DataPurpose
OAuth AuthenticationGitHub, GoogleEmail, usernameAccount login
Payment ProcessingAlipay, WeChat Pay, Stripe, PayPalOrder amount, order numberPayment completion
Cloud Infrastructure[Cloud provider]Encrypted user dataService hosting
Content Delivery[CDN provider]Static resource requestsAccess acceleration

We require all service providers to comply with strict data protection obligations.

7.4 Legally Required Disclosure

We may disclose your information in the following circumstances:

  • To comply with laws, regulations, court orders, or mandatory government requirements
  • To protect the rights, property, or safety of us, our users, or the public
  • To detect, prevent, or address fraud, security, or technical issues

7.5 Business Transfers

In the event of a merger, acquisition, or asset sale, your personal information may be transferred as a transaction asset. We will notify you before the transfer and ensure the recipient continues to comply with this Policy.


8. Cross-Border Data Transfers

8.1 Data Storage Locations

ServicePrimary Storage Location
LangBot Space[Data center location]
Telemetry Data[Data center location]

8.2 Cross-Border Transfer Scenarios

When we need to transfer your personal information abroad, we will:

  1. Conduct Security Assessments: Perform data export security assessments as required by national cyberspace authorities
  2. Sign Standard Contracts: Enter into standard contracts formulated by national cyberspace authorities with overseas recipients
  3. Obtain Your Separate Consent: Clearly inform you and obtain your separate consent before the transfer

8.3 Information Disclosure

When transferring data abroad, we will inform you of:

  • The name and contact information of the overseas recipient
  • The purpose and method of processing
  • The types of personal information involved
  • The methods and procedures for exercising your rights with the overseas recipient

9. Data Storage and Retention

9.1 Storage Methods

Data TypeStorage MethodSecurity Measures
Account InformationPostgreSQL DatabaseEncrypted storage, access control
Session DataRedis CacheAuto-expiration, memory isolation
Payment RecordsPostgreSQL DatabaseEncrypted storage, audit logs
Telemetry DataPostgreSQL DatabaseAnonymization
Plugin FilesS3 Object StorageEncrypted transmission, access control

9.2 Retention Periods

Data TypeRetention PeriodNotes
Account InformationDuration of account + 30 daysRetained for 30 days after deletion for recovery
Payment Records7 yearsTax regulation compliance
Access Logs90 daysSecurity audit requirements
Telemetry Data12 monthsStatistical analysis
Session DataCleared after session endsMaximum 24 hours
Conversation HistoryConfigured by instance operatorSelf-hosted scenarios

9.3 Data Deletion

When the retention period expires or you request deletion, we will:

  • Delete or anonymize your personal information
  • Notify third parties who have received the information to delete it
  • Except where retention is required by law

10. Data Security

10.1 Security Measures

We take the following measures to protect your personal information:

CategoryMeasures
Technical MeasuresHTTPS transmission encryption, database encryption, Argon2id password hashing, encrypted API key storage
Access ControlRole-based permission management, principle of least privilege, multi-factor authentication (admin panel)
Network SecurityFirewalls, DDoS protection, intrusion detection
Audit LogsSensitive operation logging, anomaly monitoring
Personnel ManagementConfidentiality agreements, security training, access approval

10.2 Security Incident Response

In the event of a personal information security incident, we will:

  1. Respond Immediately: Activate emergency plans to prevent further damage
  2. Assess Impact: Determine the scope of affected data and users
  3. Notify Regulators: Report to relevant regulatory authorities as required by law
  4. Notify Users: Inform affected users via email, in-app notifications, or other means
  5. Remediate: Take measures to mitigate damage and prevent recurrence

11. Your Rights

Under the Personal Information Protection Law and related legislation, you have the following rights:

11.1 Right to Know and Right to Decide

You have the right to know how we process your personal information and the right to decide whether to consent to specific processing activities.

11.2 Right of Access and Right to Copy

You have the right to access and copy your personal information. You can exercise this right by:

  • Logging into your account to view your profile
  • Contacting us to obtain a copy of your data

11.3 Right to Rectification and Supplementation

When you discover that your personal information is inaccurate or incomplete, you have the right to request correction or supplementation:

  • Modify directly in account settings
  • Contact us for assistance

11.4 Right to Deletion

You have the right to request deletion of your personal information in the following circumstances:

  • The processing purpose has been achieved or is no longer necessary
  • You withdraw consent and there is no other legal basis
  • We process information in violation of laws, regulations, or our agreement with you
  • Other circumstances specified by laws and regulations

Limitations on Deletion Requests:

  • Information required to be retained by laws and regulations (e.g., payment records)
  • Information related to public interest
  • Information necessary for contract performance

11.5 Right to Withdraw Consent

For personal information processed based on your consent, you have the right to withdraw consent at any time:

  • Disable telemetry: Set space.disable_telemetry: true
  • Unsubscribe from marketing: Click the "unsubscribe" link in emails
  • Delete account: Apply in account settings

Withdrawal of consent does not affect the lawfulness of processing carried out based on consent prior to withdrawal.

11.6 Right to Data Portability

You have the right to obtain your personal information in a structured, commonly used format and to request that we transfer it to a third party you designate (where technically feasible).

11.7 Right to Refuse Automated Decision-Making

For decisions made entirely through automated decision-making that significantly affect your rights and interests, you have the right to request an explanation and the right to refuse decisions made solely through automated means.

11.8 How to Exercise Your Rights

You can exercise the above rights through the following methods:

MethodDescription
Account SettingsView, modify, and delete certain information
Contact Emailprivacy@langbot.app
Online FormTBD

We will respond within 15 business days of receiving your request. For complex requests, we may need to extend to 30 business days, and we will notify you in advance.


12. Cookies and Tracking Technologies

12.1 Cookies We Use

Cookie TypePurposeNecessity
Essential CookiesSession management, security authenticationRequired (no consent needed)
Functional CookiesRemember preferences, language selectionOptional
Analytics CookiesTraffic statistics, performance monitoringOptional

12.2 Cookie Management

You can manage cookies through your browser settings:

  • View and delete stored cookies
  • Block specific or all cookies
  • Set cookie expiration times

Note: Disabling essential cookies may cause some features to not function properly.

12.3 Similar Technologies

In addition to cookies, we may use:

  • Local Storage (localStorage): Store user preferences
  • Session Storage (sessionStorage): Temporary session data

13. Automated Decision-Making and Artificial Intelligence

13.1 AI Model Usage

LangBot integrates multiple large language models (LLMs) to provide intelligent conversational services.

13.2 Data Usage Statement

We do not use your data to train AI models.

ScenarioData Used for TrainingNotes
LangBot Space UsersNoYour account and usage data are not used for model training
Self-Hosted InstancesNot applicableData is controlled by the instance operator
Third-Party LLM CallsDepends on LLM providerPlease refer to the respective provider's privacy policy

13.3 Automated Decision-Making

We may use automated processing for:

  • Content Moderation: Detecting prohibited content
  • Security Detection: Identifying abnormal behavior
  • Service Recommendations: Feature recommendations based on usage

You have the right to:

  • Understand the logic of automated decision-making
  • Request human review of decisions that significantly affect you
  • Refuse fully automated decision-making

14. Protection of Minors

14.1 Age Requirement

LangBot Space platform services are intended for users aged 14 and above. We do not intentionally collect personal information from minors under 14 years of age.

14.2 Guardian Responsibility

If you are the guardian of a minor and discover that your ward has used our services without your consent, please contact us immediately and we will take steps to delete the relevant information.

14.3 Minors Under 14

Under the Personal Information Protection Law, all personal information of minors under 14 is classified as sensitive personal information. If such information needs to be processed:

  • Explicit consent from parents or guardians must be obtained
  • Dedicated processing rules must be established
  • Strict protective measures must be adopted

15. Self-Hosted Instances

15.1 Responsibility Allocation

For instances deployed using LangBot Core open-source software:

RoleResponsible PartyResponsibilities
Data ControllerInstance OperatorEstablish privacy policy, handle user requests, ensure compliance
Software ProviderLangBot TeamProvide secure software, fix vulnerabilities

15.2 What We Do Not Control

For self-hosted instances, we do not control and are not responsible for:

  • User data collected by the instance operator
  • Storage and processing of message content
  • Privacy practices of the instance operator
  • Data processing by third-party LLM providers

15.3 Obligations of Instance Operators

If you deploy a LangBot Core instance, you should:

  • Establish and publish your own privacy policy
  • Comply with applicable data protection laws
  • Be responsible for bot end user data
  • Respond to user rights requests

15.4 Telemetry Data

Self-hosted instances have telemetry enabled by default, sending anonymous statistical data to LangBot Space. You can:

  • Review the data being sent (see Section 4.2)
  • Disable at any time: Set space.disable_telemetry: true

16. Plugins and Third-Party Services

16.1 Plugin Marketplace

The LangBot Space plugin marketplace offers plugins published by third-party developers.

Important:

  • Plugins are developed and maintained by third-party developers
  • Each plugin may have its own privacy policy
  • Please review the privacy terms before installing plugins
  • We are not responsible for data processing by third-party plugins

16.2 Plugin Developer Responsibilities

Plugin developers must:

  • Provide a privacy policy (if collecting any user data)
  • Comply with our developer agreement
  • Accurately disclose data collection practices
  • Respond to user privacy requests

16.3 Third-Party LLM Services

LangBot supports connecting to various third-party LLM services (such as OpenAI, Anthropic, DeepSeek, etc.).

Note:

  • Content sent to LLMs is processed by the respective providers
  • Please refer to each LLM provider's privacy policy
  • We do not control third-party LLM data processing

16.4 Instant Messaging Platforms

LangBot supports connecting to various IM platforms (QQ, WeChat, Telegram, Discord, etc.).

Note:

  • Platform messages are subject to each platform's privacy policy
  • Platform-assigned user identifiers are managed by the platforms
  • We only process publicly available information provided by the platforms

17. Changes to This Privacy Policy

17.1 Change Notification

We may update this Policy from time to time. When we do, we will:

  • Update the "Last Updated" date at the top of this Policy
  • For material changes, notify you 7 days in advance via email or in-app notification

17.2 Material Changes

The following circumstances constitute material changes:

  • Significant changes to the types of information collected
  • Significant changes to the purposes of information use
  • Significant changes to the scope of third-party sharing
  • Significant changes to your rights

17.3 Continued Use

After changes take effect, your continued use of our services constitutes acceptance of the updated Policy. If you disagree with the changes, please stop using our services and contact us to delete your account.


18. Contact Us

If you have any questions, comments, or requests regarding this Policy, please contact us through the following channels:

Contact MethodDetails
Privacy Emailprivacy@langbot.app
General Inquiriescontact@langbot.app
Official Websitehttps://langbot.app
GitHubhttps://github.com/langbot-app/LangBot

Response Time:

  • General inquiries: Within 3 business days
  • Rights requests: Within 15 business days

19. Region-Specific Terms

19.1 Users in Mainland China

If you are a user in mainland China, the following terms specifically apply:

  • Applicable Law: This Policy is governed by the Personal Information Protection Law, Cybersecurity Law, and Data Security Law of the People's Republic of China
  • Dispute Resolution: Disputes arising from this Policy shall be under the jurisdiction of the competent people's court in our location
  • Cross-Border Transfer: Before transferring personal information abroad, we will obtain your separate consent and complete security assessments as required by law

19.2 Users in the European Economic Area (EEA), United Kingdom, and Switzerland

If you are located in the EEA, UK, or Switzerland, the following GDPR-related terms apply:

RightDescriptionGDPR Article
Right of AccessObtain a copy of personal dataArt. 15
Right to RectificationCorrect inaccurate dataArt. 16
Right to Erasure (Right to Be Forgotten)Request data deletionArt. 17
Right to Restriction of ProcessingRestrict data processingArt. 18
Right to Data PortabilityObtain data in machine-readable formatArt. 20
Right to ObjectObject to specific processingArt. 21
Right to Lodge a ComplaintComplain to a data protection authorityArt. 77

Data Protection Officer (DPO) Contact: dpo@langbot.app (if applicable)

19.3 Users in California, USA

If you are a California resident, under the California Consumer Privacy Act (CCPA/CPRA), you have the following additional rights:

  • Right to Know: Understand the categories and purposes of personal information we collect
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information
  • Right to Non-Discrimination: Exercise of privacy rights will not result in discriminatory treatment

We do not "sell" your personal information (as defined by CCPA).


Appendices

Appendix A: Data Processing Activities

Processing ActivityData TypeLegal BasisRetention Period
Account RegistrationEmail, passwordContract performanceAccount duration
OAuth LoginThird-party authorization infoConsentAccount duration
Payment ProcessingOrder informationContract performance, legal obligations7 years
Telemetry CollectionAnonymous statisticsLegitimate interests12 months
Security AuditingAccess logsLegitimate interests90 days
Plugin DistributionDeveloper informationContract performancePlugin duration

Appendix B: Third-Party Service Providers

CategoryProviderPurposePrivacy Policy Link
OAuthGitHubThird-party loginhttps://docs.github.com/en/site-policy/privacy-policies
OAuthGoogleThird-party loginhttps://policies.google.com/privacy
PaymentAlipayPayment processinghttps://render.alipay.com/p/f/fd-iwntfhkl/index.html
PaymentWeChat PayPayment processinghttps://pay.weixin.qq.com/index.php/public/wechatpay_legal
PaymentStripePayment processinghttps://stripe.com/privacy
PaymentPayPalPayment processinghttps://www.paypal.com/webapps/mpp/ua/privacy-full

Appendix C: Glossary

TermDefinition
PIPLPersonal Information Protection Law of the People's Republic of China
GDPREU General Data Protection Regulation
CCPA/CPRACalifornia Consumer Privacy Act and its amendments
DPOData Protection Officer
LLMLarge Language Model
OAuthOpen Authorization Protocol
S3Object Storage Service

The LangBot Team reserves the right of final interpretation of this Privacy Policy.

Document Version: 1.0 Generated: January 27, 2025