Skip to content

Platform

Privacy and security for web integrations.

Web Chat and Feedback run in isolated EveryHello frames, check the configured embedding host, and treat installation keys and browser host values as public signals rather than authentication secrets.

Public keys and domain allowlists

Keys beginning with wgt_ and fdb_ must appear in browser source so a website can load its widget. They identify the installation; they do not authenticate a visitor or prove which server made a request.

Every widget request checks the configured domain claim and the expected EveryHello iframe request shape. Empty or malformed allowlists fail closed, and subdomains of an allowed host are accepted. Because a custom client can copy a key and forge browser headers, these checks reduce accidental and basic abusive use but are not an authentication boundary.

Web Chat separately applies fail-closed shared rate limits and plan-aware 24-hour AI spend brakes per visitor and public key before running the assistant. The monthly plan meter remains the final usage cap. Feedback uses shared submission throttles but does not consume the AI allowance.

Do not treat public widget keys as server secrets

Keep database credentials, provider tokens, and EveryHello server credentials out of browser code. Widget keys are the only EveryHello identifiers intended for these snippets, and you should rotate a key if it is being abused.

Iframe isolation

The customer-facing UI renders inside an iframe served by EveryHello. The Web Chat loader reads its script key and the host origin. The Feedback SDK also reads basic page context and values explicitly provided through its API.

Cross-window messages are checked against the expected EveryHello origin and iframe window before they change widget state. Feedback verifies the embedding page through the browser-stamped message origin.

Data handled by each product

ProductTypical data
Web ChatVisitor identifier, messages, conversation history, channel status, and records created by configured assistant actions or team handoff.
FeedbackFeedback kind, message or rating, optional attachment, optional reporter identity, source page context, browser details, and custom application context.

Data minimization

  • Pass only identifiers and context your team will use to resolve the conversation or review the feedback.
  • Call EveryHello.feedback.reset() when a user signs out or changes accounts.
  • Do not place access tokens, passwords, payment data, protected health information, or private URL query values in custom context.
  • Explain your use of support and feedback tools in your own privacy notice and consent flow where applicable.
  • Rotate a widget key from the authenticated setup page if you need to invalidate an existing installation.

Service limitation

EveryHello is not offered as a HIPAA-compliant service and does not provide a Business Associate Agreement. Do not use the widgets to process protected health information.

Content Security Policy

A restrictive site must allow the loader script and the customer-facing iframe. Merge the required sources into your current directives.

HTTP header
Content-Security-Policy:
  script-src 'self' https://www.geteveryhello.com;
  frame-src https://www.geteveryhello.com;

More information

Review the public Privacy Policy, Terms of Service, and product-specific setup guidance before deployment. Security or privacy questions can be sent to support@geteveryhello.com.