Skip to content
Service status

Type to search

Widgets · 1 min read

Privacy policy and allowed domains

The two organization-wide settings every widget shares: the linked privacy policy and where widgets may be embedded.

Two widget settings are organization-wide rather than per-widget: the privacy policy linked from every widget, and the list of domains a widget is allowed to be embedded on. Together they’re what makes a public widget defensible.

  • The organization-wide policy — set one privacy policy URL for your organization, and it’s linked automatically from every widget you create.
  • Per-widget policy URL — a specific widget can override the organization-wide policy with its own URL, where that widget’s purpose genuinely needs different terms.
  • Removing a policy — remove the organization-wide policy at any time; widgets fall back to showing no privacy policy link until a new one is set.

A widget can only be embedded on a domain your organization has explicitly allowed — this is what stops your widget’s code being copied onto a site you never intended it for.

Widget settings include an Allowed domains view listing every site your organization has been approved for. Check it here before you hand an embed snippet to a colleague, rather than finding out after the widget fails to load.

The view is read-only. To add or remove a domain, contact support.

Every widget shows visitors a standing disclaimer that answers are generated by an AI model and important information should be double-checked — this is fixed and can’t be turned off per widget.

A visitor never sees your internal configuration — the widget’s instructions, the assistant model behind it, or (on a shared link) any references the answer might otherwise cite. They see only the conversation, the welcome message, and the privacy policy link.