Uploading documents to an AI chatbot is easy, which is exactly why it deserves a pause. A returns policy is harmless; a customer list is not; an internal runbook is somewhere in between. Before you upload anything to any platform, including this one, here are the questions worth answering and how to find the answers quickly.
1. What am I actually uploading?
Sort your candidate documents into three piles:
- Public. Already on your website or in a brochure. Policies, product guides, FAQs, syllabi. No new exposure.
- Internal but not sensitive. Process notes, onboarding guides, internal FAQs. Fine for an internal chatbot; think before exposing publicly.
- Sensitive. Anything with personal data about customers or staff, credentials, contracts with confidentiality clauses, unreleased plans. Do not upload these to a customer-facing chatbot, and think hard before uploading them anywhere.
Most website chatbots need only the first pile. If you find yourself uploading from the third, the chatbot is the wrong tool for that job.
2. Who can ask the chatbot questions?
A chatbot embedded on a public page or shared by public link can be questioned by anyone. Whatever is in its sources is, in effect, published, because a determined visitor can ask for it piece by piece. Match the sources to the audience: public sources on public chatbots, internal sources on chatbots shared only within the team.
3. Is my data used to train models?
Read the vendor's data policy for one sentence: does customer content train their models or third parties' models? Cortexvia's answer is that your uploads are used to answer questions for your chatbot and are not sold; the Data Usage Policy and Privacy Policy describe processing in full. Any vendor should give you an equally direct sentence. If you cannot find it in five minutes, that is the answer.
4. Where is it stored and who processes it?
Look for the infrastructure providers named in the policy and where they run. The Security Policy lists Cortexvia's approach; a serious vendor publishes the equivalent. Encryption in transit and at rest should be stated, not implied.
5. Can I delete it, and does deletion mean deletion?
You should be able to remove a source and have its content stop appearing in answers immediately, and to delete a chatbot entirely. Check the policy for retention after deletion. Test it: remove a source, ask a question only it could answer, confirm the chatbot now says the topic is not covered.
6. What does the chatbot say when it does not know?
This is a privacy question as well as a quality one. A chatbot that improvises when a question is outside its sources may combine fragments in ways you did not intend. One that says "not covered" and hands off stays inside the boundary you drew. Test this before launch with questions deliberately outside the sources.
7. Who on my team can change the sources?
A chatbot's sources are a publishing surface. Whoever can add a document can publish its contents to every visitor. Keep the account access as tight as your CMS access, and review the source list when people leave.
Reading a vendor's policy in five minutes
Search the privacy and data policies for these words: "train", "third party", "retain", "delete", "encrypt", "subprocessor". Each hit should be a clear sentence. Vague passages around any of them are the risk. Cortexvia's policies are linked from every page footer and written to answer exactly these searches.
A sensible default for a website chatbot
- Upload only what is already public or intended to be.
- Set support contacts so the handoff is a person, not a guess.
- Test the not-covered behaviour before launch.
- Review the source list monthly and remove anything stale.
- Read the vendor's data policy once, properly, and re-read it when it changes.
Do that and a website chatbot exposes nothing your website did not already expose, while answering the questions your website could not.
Frequently asked questions
Is a chatbot trained on my documents the same as sharing the documents? Functionally yes, for whoever can ask it. Visitors see answers, not files, but a persistent visitor can extract most of a document's facts. Upload only what the chatbot's audience may know.
Can I use a chatbot for internal documents safely? Yes, when the chatbot is shared only inside the team and the sources are appropriate for everyone on it. Treat the share link like a document link. The documentation chatbot page covers internal use.
What about student notes and copyrighted textbooks? Upload material you are entitled to use, and keep a chatbot containing a textbook private to the people who own the book. Your own notes are yours to share; a publisher's PDF is not.
