Overview
Serra AI is a service provided by CJA Photography. This Privacy Policy explains what information we collect when website visitors interact with a Serra AI chatbot, how that information is used, where it is stored, and what rights individuals have regarding their data.
This policy applies to end users — visitors who interact with Serra AI chatbots embedded on our clients' websites. If you are a business client of Serra AI, your data use is also governed by our Terms of Service.
Information We Collect
When you interact with a Serra AI chatbot, the following information may be collected:
| Data Type | What It Contains | Where Stored |
|---|---|---|
| Chat Transcripts | Timestamp, session ID, every message you type, every reply from Serra AI | Our secure cloud servers, with a backup to a private Google Sheet accessible only to the business owner |
| Contact Information | Name and email address, if provided | Our secure cloud servers, with a backup to a private Google Sheet accessible only to the business owner |
| Conversation Context | Active message history used to generate replies during your session | Server memory only; auto-cleared after 6 hours of inactivity and never written to permanent storage |
We do not collect payment information, government IDs, passwords, or sensitive personal categories of data through the chatbot.
How We Use Your Information
Information collected through the chatbot is used for the following purposes only:
- To allow the business whose website you visited to follow up with you regarding your inquiry
- To maintain a record of your conversation for context and quality review
- To improve the accuracy and usefulness of Serra AI's responses
We do not use your information to send unsolicited marketing emails, sell your data to third parties, or build advertising profiles.
How AI Responses Are Generated
Serra AI uses the Claude API, developed by Anthropic, to generate all chatbot responses. This means the messages you type into the chat are transmitted to Anthropic's servers for processing.
We do not use your messages to train any AI model.
Third-Party Services
Serra AI relies on the following third-party services, each with its own privacy policy:
| Anthropic (Claude API) | Processes chat messages to generate AI responses. Your messages are transmitted to Anthropic's API during each conversation. anthropic.com/privacy |
| Google (Google Sheets) | Chat transcripts and lead information are stored in private Google Sheets accessible only to the business owner. policies.google.com/privacy |
| Cloudflare | Security proxy and CDN layer for all traffic to api.serrachat.com. Standard Cloudflare access logs may apply. cloudflare.com/privacypolicy |
| Stripe | Handles billing and payment processing for Serra AI client subscriptions. Does not receive or process end-user chat data. stripe.com/privacy |
| Vercel | Hosts the Serra AI web infrastructure. Standard server-side request logs may be maintained as part of normal hosting operations. vercel.com/legal/privacy-policy |
Data Retention
We retain data only as long as necessary:
- Active accounts: Chat transcripts and lead data are retained for the duration of the active subscription
- After cancellation: Data is deleted upon written request to cja@serrachat.com
- Conversation context: Held in server memory only and auto-cleared after 6 hours of inactivity — never written to permanent storage
Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share information only in these limited circumstances:
- With the business you contacted: Your name, email, and chat transcript are shared with the website owner so they can follow up
- With third-party service providers: As described in Section 5, solely to operate the service
- When required by law: If required by court order, subpoena, or applicable law
Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of the information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request permanent deletion of your data at any time
- Opt-out: Choose not to provide your name or email — the chatbot can still answer general questions
To exercise any of these rights, email cja@serrachat.com. We will respond within 14 business days.
Children's Privacy
Serra AI is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at cja@serrachat.com and we will delete it promptly.
Security
We take reasonable steps to protect your data. Chat transcripts and lead information are stored on our secure cloud servers, with a backup to a private Google Sheet accessible only to the business owner. Active conversation context lives in server memory only and is cleared after 6 hours of inactivity — it is never written to permanent storage. All traffic is routed through a security proxy for an additional layer of protection.
However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of a Serra AI chatbot after changes constitutes acceptance of the updated policy.