- Docs
- Security
Security, privacy & GDPR
This guide is for workspace owners and admins. It covers how to secure your team's access, control what visitor data is stored and for how long, and handle privacy requests under GDPR and similar laws.
Two-factor authentication
Every teammate can protect their account with time-based one-time codes (TOTP) from an app such as Google Authenticator, 1Password or Authy.
- Open Account & security from your avatar menu (
/app/account) and choose Set up two-factor authentication. - Scan the QR code (or type the key) in your authenticator app, then enter the 6-digit code to turn it on.
- Save your 8 recovery codes. Each works once if you lose your phone, and they're shown only once. You can generate new ones later with your password.
After that, signing in asks for a code. Code attempts are rate-limited, and a code can't be reused. On the same page, Sign out other devices ends every other session. Ask everyone on your team to turn it on.
Roles
| Role | Can do |
|---|---|
| Agent | Inbox, contacts, live visitors, help center articles, reports and their own saved replies. |
| Admin | Everything an agent can, plus all settings, inviting and managing teammates, automation (chatbots, auto messages, rules), developer settings (API keys, webhooks), shared saved replies, tags, and exporting or deleting contacts. |
| Owner | Everything, including deleting the workspace and transferring ownership. |
Most teammates only need the Agent role.
Domain allow-list
By default your messenger works on any website that includes your snippet. To restrict it, list your domains in Settings → Security, separated by spaces, commas or new lines. www. is matched automatically, and *.example.com covers all subdomains and example.com itself. On other sites the messenger stays hidden. Your hosted chat page and help center at https://talkingdot.com always work.
Remember staging: add preview and staging domains too.
Identity verification
If your site tells the messenger who a logged-in user is, sign that identity on your server with an HMAC so nobody can pretend to be another user. Then turn on Require identity verification in Settings → Security. Without a valid signature, TalkingDot never switches a browser into an existing verified profile. See Identity verification.
IP address storage
In Settings → Privacy, choose what happens to visitors' IP addresses:
| Option | Stored |
|---|---|
| Full (default) | The complete address. |
| Truncated | IPv4 keeps the first three parts (/24, so 203.0.113.57 becomes 203.0.113.0). IPv6 keeps the first 48 bits (/48). |
| None | No IP address is saved. |
Country and city are worked out at request time from Cloudflare headers or a local GeoIP database on the server. No third-party lookup service is called. The setting applies to IP addresses recorded after you change it.
Data retention
| Data | Kept for |
|---|---|
| Closed conversations | Kept until you delete them, unless an auto-delete period applies. In Settings → Privacy you can delete closed conversations automatically a set number of days after closing, including their messages and attachments. If you don't set a period, the platform's default applies, which is to keep them unless the operator has set one. |
| Anonymous visitors who never started a conversation | Deleted after they've been inactive for the platform's visitor retention period (30 days by default), with their page history. |
| Page-view history | The platform's page-view period (90 days by default). |
| Contacts with conversations, leads and users | Until you delete them. Their closed conversations follow the auto-delete setting above. |
Clean-up runs automatically, and deleted data can't be recovered.
GDPR requests and exports
- Access and portability: from a contact's profile in Contacts, download a JSON export. It includes their profile, custom attributes, every conversation with its messages (attachment names included), tracked events and page views.
- Erasure: deleting a contact permanently removes them, their conversations, messages, attachments, notes, events and page history. This can't be undone. If you use webhooks, a
contact.deletedevent lets your other systems delete their copy too. - CSV export: export your contact list from Contacts, and report data from Reports.
- Email opt-out: visitors can stop reply notifications with the unsubscribe link in every email (see Email replies).
Only admins and the owner can export or delete contacts.
No cookies in the messenger
The messenger sets no cookies. It keeps a random visitor token in your site's localStorage under the key talkingdot_YOUR_WORKSPACE_KEY. That's how a returning visitor sees their past conversations. The server stores only a hash of that token. On shared computers, call TalkingDot('shutdown') when a user logs out of your site. This forgets the token so the next person starts fresh (see JavaScript API: log out).
Blocking visitors and abuse protection
Block a visitor from a conversation's More menu in the inbox, optionally including their IP address. Blocked visitors can't send messages, don't get chatbots or auto messages, and don't see the messenger unless they already have conversations with you. Their emailed replies are ignored. Their past conversations stay in your inbox. Blocks can target a contact, an email address or an IP address.
The platform also applies rate limits. These are the defaults, and the operator can change some of them:
| Limit | Default |
|---|---|
| Messages per visitor | 20 per minute (and 300 per hour per IP address) |
| New visitor profiles per IP address | 120 per hour |
| File uploads per visitor | 20 per hour |
| Transcript requests per visitor | 5 per hour |
| REST API requests per key | 120 per minute |
Known bots and crawlers don't create visitor profiles.
API keys and signed webhooks
Only admins can create API keys and webhooks. Every webhook delivery is signed with HMAC-SHA256 using the webhook's own secret and includes a timestamp, so your endpoint can reject forged or replayed requests. Failed deliveries are retried with back-off. See verifying webhook signatures and REST API.
DPA, subprocessors and reporting issues
- Data processing agreement: https://talkingdot.com/dpa
- Subprocessors: https://talkingdot.com/subprocessors
- Privacy policy, cookie policy and security overview: /privacy, /cookies, /security
- Security researchers can find contact details in
https://talkingdot.com/.well-known/security.txt.
Your responsibilities as controller
For the personal data your visitors share with you, you are usually the controller and TalkingDot is your processor. A short checklist:
- Update your privacy notice to say you use live chat provided by TalkingDot. Say what's collected (messages, name and email if given, approximate location, browser and device, pages viewed), why, and how long you keep it.
- Review the DPA and subprocessors, and list any extra recipients you add yourself, such as Slack, Discord, Telegram or webhook endpoints.
- Pick the IP storage and retention settings that match what your notice promises.
- Check your cookie or consent setup: the messenger uses
localStorage, not cookies. Ask your adviser whether your notice should mention it. - Answer requests on time using the export and delete tools above.
- Secure your team: two-factor authentication for everyone, the Agent role by default, and remove people who leave.
- Don't ask for sensitive data in chat, such as passwords, full card numbers or health information.