Cookies

    We use one analytics cookie (Google Analytics) to understand which pages are useful. No ads, no reselling, and declining changes nothing about how the site works. Privacy Policy

    AI Deployment

    Your Website Chatbot Is Collecting Data. Say So.

    AI assistants on marketing sites store conversations, capture leads, and follow up. Regulators and visitors both expect you to disclose that before the first message. Here's the consent pattern we ship.

    If your website has an AI assistant, it is collecting data. The conversation is stored somewhere. The contact details a visitor types in are landing in a table. If the assistant does lead capture — and if it's on a marketing site, it does — that data feeds a follow-up motion the visitor may not know they entered.

    None of that is sinister. It's how the tool works. What gets companies in trouble is not the collecting — it's the not saying.

    ## The expectation has shifted

    Enforcement attention on undisclosed chatbot data collection has been rising, and the pattern in the cases that make the news is consistent: the issue is rarely the AI itself. It's that visitors weren't told they were talking to an automated system, weren't told the conversation was being recorded and stored, or weren't told the information they shared would be used to contact them.

    Those are old obligations in a new wrapper. Wiretap and session-recording statutes, state privacy laws, and basic unfair-practices doctrine all predate chatbots. A chat widget that silently logs conversations looks, to a regulator, a lot like an undisclosed recording. You don't need a novel legal theory to end up as a defendant — you need a chat bubble and no disclosure.

    ## What disclosure actually requires

    Strip away the legal texture and the requirements are plain.

    Tell people it's an AI. Before the conversation starts, not in a footer. Visitors should never discover mid-conversation that the helpful person was software.

    Tell people what you collect and why. Messages, contact details, and what you'll do with them. One honest paragraph beats a linked 4,000-word policy — though you should link the policy too.

    Get an affirmative act. A visible "I agree" the visitor clicks is worth more than implied consent from continued use, both legally and as a trust signal.

    Offer an out. Someone who doesn't want to share details with an AI should have a human path — a booking link, an email — without being punished for it.

    Keep a record. Consent you can't prove is consent you don't have. Store when the visitor agreed alongside the data they gave you.

    ## The pattern we ship

    We run an AI assistant named Gloria on our own solutions pages, so we built the consent gate we'd recommend to a client. The flow has three stages.

    First, the disclaimer. Before the chat unlocks, the visitor sees a plain-English notice: Gloria is an AI assistant, the messages and contact details are collected and stored, they're used only to respond to the inquiry, and continuing means consenting to follow-up. The privacy policy is linked in the same paragraph. There's one button — agree and continue — and an explicit alternative for people who'd rather book a call with a human.

    Second, identification. After consenting, the visitor provides name, phone, and company. This isn't buried in the conversation where consent gets murky; it's a labeled form, filled in knowingly.

    Third, the chat — and a record. The consent timestamp is stored with the contact record, and the visitor's agreement persists so returning visitors aren't re-gated on every page.

    The whole gate is maybe fifteen seconds of friction. What it buys is durable: every conversation in the log belongs to someone who was told what the system is and agreed to it.

    ## The objection, answered

    The pushback is always conversion: won't a consent screen scare people off? Some, yes — specifically the people who were never going to hand you working contact information anyway. The visitors who click through have pre-qualified themselves twice: they consented to follow-up, and they gave you a phone number knowing why you wanted it. Fewer leads, better leads, and no list built on people who didn't know they were on one.

    Undisclosed collection isn't a growth hack. It's a liability with a conversion rate.

    ## If you're deploying one

    Whether you build with us or on your own: put the disclosure before the first message, make consent a click, store the timestamp, link the policy, and leave a human door open. It's an afternoon of engineering. The alternative is explaining to a regulator — or to your customers — why you didn't think they needed to know.

    Back to articles

    Keep reading

    Related articles