Skip to main content

Ask visitors for consent before a chat

Every chatbot shows a notice that visitors accept before they can chat. See what it says, what you can change, and what is recorded.

What visitors see first

Every chatbot opens on a consent notice. A visitor reads it and chooses one of two buttons before anything else happens. For a business called Acme Dental, the notice reads:

Before we chat: this chat is answered by an AI assistant, and sometimes by our team. Acme Dental and its service providers record and store your messages to respond to you. See our Privacy Policy.

Under it are two buttons of the same size: No thanks and Accept and start chat.

Until the visitor clicks Accept and start chat, the chat shows no greeting, no suggested questions, and no message box. Nothing the visitor does is sent or stored. The same notice shows on the chat link and in the website widget.

The notice cannot be switched off. There is no setting that hides it, removes a button, or accepts for the visitor.

A chatbot cannot be published without a Privacy Policy link. The words "Privacy Policy" in the notice open that link in a new tab.

  1. Open the Consent tab

    In the chatbot builder, click the Consent tab.
  2. Paste the link

    Paste the address of the privacy policy into Privacy Policy link (required to publish). It must start with https://.

  3. Save

    Click Save.

While a draft has no link, Publish is unavailable and the builder's header shows "Add a Privacy Policy link to publish." Click that line to jump to the field.

A live chatbot keeps its link. You can change it to another address, but you cannot empty it: the builder shows "A published chatbot needs a Privacy Policy link. Unpublish it first to remove the link."

What you can change

The Consent tab holds every part of the notice you can set. The preview on the right opens on the notice and follows what you type.

FieldLimitWhat it does
Business name80 charactersThe business the notice names. Leave it empty to use the client's name, or your agency's name for a chatbot with no client.
Opening line (optional)200 charactersA line of your own shown above the notice, such as a welcome.
Privacy Policy link512 charactersWhere "Privacy Policy" in the notice leads. Required to publish.
Accept button2 to 40 charactersThe label of the button that accepts. Leave it empty for "Accept and start chat".
Decline button2 to 40 charactersThe label of the button that declines. Leave it empty for "No thanks".
Phone and EmailShown to a visitor who declines, so they can still reach the business. Both are optional.

Button labels

A visitor accepts with the button, so the two labels must say what they do.

  • The accept button must contain one of the words accept, agree, consent, or yes, and none of the words that take it back, such as "no", "not", "don't", "later", or "maybe". "I agree" and "Yes, start chat" work. "Start chat", "Continue", and "Don't accept" are refused with "The accept button must say accept, agree, consent or yes."
  • The decline button cannot contain any of those four accepting words, and cannot be the same as the accept button. Otherwise it is refused with "The decline button can't read as acceptance."

The opening line

The opening line is where your own tone goes. It cannot turn using the chat into the acceptance: wording such as "By continuing you agree" or "By using this chat" is refused with "Remove wording like 'by continuing': visitors accept with the button."

What is fixed

The notice itself is not editable. The Consent tab shows it in a locked block marked "This wording is fixed.", with the business name filled in as you type it. Three things are always said, in these words:

  • The chat is answered by an AI assistant, and sometimes by a team.
  • The business and its service providers record and store the visitor's messages to respond.
  • The Privacy Policy is one click away.

Both buttons always show, side by side and at the same size. The chat's header also carries an AI assistant label, before and after the visitor accepts.

What "No thanks" shows

A visitor who clicks No thanks is not chatting, and nothing is sent or stored.

The chatbot hasOn the website widgetOn the chat link
A Phone or Email"No problem. You can reach Acme Dental at", then the phone and the email as links, and a Close button.The same card, with a Back button.
NeitherThe chat window closes back to the bubble."Chat closed." and a Back button.

Back returns to the notice. Opening the bubble again shows the notice again.

What is recorded for each acceptance

Each time a visitor clicks the accept button, one record is kept. It holds:

  • The date and time of the acceptance, and when it runs out.
  • The exact wording the visitor accepted, with the business name filled in, and the version of that wording.
  • The language of the notice, the label of the accept button, and the Privacy Policy link it pointed to.
  • The page the visitor was on: the address of the web page for the widget, or the chat link.
  • The chatbot, and its client when it has one.
  • A shortened network address, such as 203.0.113.0/24.

The visitor's full IP address is never recorded, and neither is their browser. A record cannot be edited or deleted on its own. Records are kept after the chatbot or the client is deleted, and are removed when your account's data is deleted.

No record is kept for a visitor who clicks No thanks or closes the chat.

When visitors are asked again

An acceptance lasts 30 days. A returning visitor in the same browser goes straight to the chat during that time, and sees the notice again after it.

Visitors are also asked again as soon as what they would read changes:

  • The business name, including a renamed client when Business name is empty
  • The opening line
  • The Privacy Policy link
  • Either button label

When you save one of these on a live chatbot, the builder confirms with "Saved. Visitors will be asked to accept the new notice." A visitor in the middle of a chat is returned to the notice on their next message, and their earlier messages come back once they accept.

Changing only the Phone or Email asks nobody again.

Check before sensitive uses

The Setup tab opens with a warning that stays on every visit:

Check before using this chatbot for health, children or payments. Chats are answered by AI and recorded. Don't ask visitors for health details, card numbers or information about children unless your business is set up to handle them.

The consent notice tells visitors that their messages are recorded. It does not make a chatbot suitable for collecting that kind of information.

What could go wrong

  • Publish is unavailable. The draft has no Privacy Policy link, or the link does not start with https://. Open the Consent tab and fix the field.
  • "Use a link that starts with https://" The link is not a full https:// address, or it carries a username and password.
  • "Enter a phone number, like +1 555 010 0199." or "Enter an email address, like hello@example.com." The contact for visitors who decline is not a phone number or an email address.
  • A visitor clicks the accept button and sees "We couldn't start the chat. Try again." The acceptance was not recorded, so the chat did not start. The visitor can click the button again.
  • A visitor clicks the accept button and sees "This notice was updated. Please read it again." You saved a change to the notice after their page loaded. The current notice is now on their screen.
  • The chat says "Chat is unavailable right now." instead of the notice. No published workflow answers the chatbot. See How chatbots work.

Next steps

Was this helpful?