Skip to content

Software companies

Your own chatbot transcripts: are they licensable?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Your own chatbot transcripts may be licensable, but three documents decide: the chatbot vendor's terms, the privacy notice visitors saw, and your customer contracts. Even when rights are clear, value sits unevenly. Customer questions and handoffs to human agents carry most of it; the bot's own generated replies usually add little.

Key takeaways

  • The chatbot vendor agreement decides whether you can export full transcripts and whether the vendor kept its own rights to use them.
  • The privacy notice shown near the chat window is often the strongest limit on reusing public conversations.
  • Customer messages and handoffs to human agents carry more value than the bot's generated replies.
  • Chat windows collect names, emails, order numbers and sometimes passwords or card numbers, so preparation is heavier than for most support email.
  • Logged-in portal chats from business customers may also fall under customer contracts and data processing agreements.

Who owns chatbot transcripts?#

Chatbot transcripts are usually treated as the deploying company's records, but ownership alone does not settle whether they can be licensed. The vendor agreement, the privacy notice and your customer contracts each set limits, and any one of them can narrow what is possible.

Start with the vendor agreement. Look for how it defines your data, whether the vendor takes a license to use transcripts to improve its own service or models, what export rights you have, and what happens to transcripts when the contract ends. If the bot calls a third-party model, that provider's terms on inputs and outputs matter too.

This is general information, not legal advice. Privacy laws, and in some states wiretap or eavesdropping laws that require every party's consent to a recorded conversation, may apply to chat records, particularly where a third-party vendor processes the chat. How they apply depends on where visitors are and what they were told, and it is assessed deal by deal with counsel.

Who owns chatbot transcripts?
DocumentWhat to look forWhy it matters
Chatbot vendor agreementDefinition of customer data, vendor use rights, export and deletion termsDecides whether a full history can be exported and who else holds rights
Model provider termsRetention of inputs and any limits on using outputsAffects whether the bot's replies can be reused
Privacy notice and chat bannerWhat visitors were told about how conversations are usedReuse beyond what was disclosed may need new notice or consent
Customer contracts and DPAWhether portal chats count as customer data used only to provide the serviceBusiness customers' users may be covered by tighter terms
Internal retention policyHow long chats are kept and when they are deletedA license cannot rely on records that should already be gone

Which parts of a transcript carry value?#

The customer side of a chatbot transcript carries most of the value, because it shows how real people describe real problems in their own words. That phrasing, with its typos, half-explained context and follow-up questions, is hard to produce any other way.

The bot's own replies are a different matter. Scripted decision-tree menus repeat the same text in every conversation. Generative replies are another model's output, which buyers tend to discount and which some model terms restrict.

The handoff, where the bot gives up and a human agent takes over, is often the richest part. It marks exactly where automation broke down and shows how a person resolved the case.

Which parts of a transcript carry value?
Transcript componentTypical valueNotes
Customer messagesHighReal intents and phrasing; heaviest privacy load
Scripted bot menusLowRepetitive text that says little about the problem
Generative bot repliesLow to moderateUseful mainly as examples of failure; check model terms
Handoff and human repliesHighShows where automation failed and how a person fixed it
Outcome fieldsHigh when consistentResolved by bot, escalated, abandoned or rated
Bot configuration historyModerateIntents, flows and article sources give context by period

What privacy preparation do chatbot logs need?#

Chatbot logs need heavier privacy preparation than most support records, because visitors type freely into a small box before anyone can warn them. Names, email addresses, phone numbers, order numbers and home addresses are common, and some visitors paste passwords or card numbers despite the warning text.

Detection services can catch many of these. An archived version of the Amazon Comprehend developer guide, for example, lists detectable entity types that include names, addresses, emails, phone numbers, card numbers, card security codes and passwords, which shows how wide the problem runs. No tool catches everything, so a human review of a sample remains part of the job.

  • Drop technical metadata such as IP addresses, device details and cookie IDs unless a buyer has a clear need.
  • Remove pre-chat form fields that capture name, email and company.
  • Detect and remove contact details, account and order numbers, credentials and payment data.
  • Replace human agent names with consistent pseudonyms.
  • Exclude conversations about sensitive topics such as health or legal disputes.
  • Record what was removed, and how, in the privacy record for the package.

Public website bots, portal bots and internal bots differ#

Chatbot transcripts fall into three groups, and each raises a different rights question. A public website bot talks to anonymous visitors and prospects, so the privacy notice carries most of the weight, and consumer privacy laws such as the CCPA may apply depending on the company and the visitor.

A bot inside a logged-in product or customer portal talks to users at your business customers. Those conversations may be customer data under your subscription agreements and data processing agreements, which often limit use to providing the service. An internal IT or HR helpdesk bot talks to employees, so employee notices and workplace policies decide what is possible.

Keep the three groups separate in any inventory. Mixing them makes it impossible to apply the right limits to each conversation.

Illustrative: a payroll software company reviews its bot logs#

Illustrative: a fictional payroll software company runs a website bot for prospects and an in-app bot for customers' payroll administrators, both from the same messaging vendor. When it decides to switch vendors, the general counsel asks whether the transcripts are worth keeping and whether they could ever be licensed.

The review finds that the website privacy notice said conversations were used to answer questions and improve the company's service, nothing more. The in-app chats fall under customer agreements that restrict customer data to providing the service, and many of them contain employee pay details pasted in by administrators. The vendor agreement allows full export but grants the vendor rights to use de-identified content for its own product improvement.

The company exports everything before the contract ends and keeps it under its retention policy. On counsel's advice it parks all in-app chats and all website chats collected under the old notice. It then updates the website notice to describe de-identified use for AI development, so website conversations from that date forward, especially handoffs to sales staff, can be assessed later. The vendor's retained rights are noted in the records inventory, so any future rights review starts with the facts in hand.

What to keep before you switch or shut down a chatbot#

Keeping the surrounding records at a chatbot switch matters as much as keeping the transcripts, because a later rights review will ask what visitors were told and how the bot behaved at each point in time. Those answers are hard to rebuild once the vendor account is closed.

  • A full transcript export, including handoff events, tags and outcome fields.
  • Each version of the privacy notice and chat banner, with the dates it was live.
  • Each version of the vendor agreement and any data processing addendum.
  • Bot configuration history: intents, flows, article sources and model settings by period.
  • The vendor's confirmation of deletion once the contract ends.

How SourceX approaches chatbot transcripts#

SourceX treats chatbot transcripts as a rights-first record family: in the Rights step of the SourceX five-step transaction, vendor terms, privacy notices and customer contracts are reviewed before any preparation is scoped. A review may end with a narrower scope, such as handoff conversations from a period covered by a clear notice, or with no transcripts in scope at all.

Where a package proceeds, the SourceX Evidence Packet records which notice version applied to which conversations, what was removed during preparation and who authorized release. The supplier approves every step, and nothing is shared during the initial assessment.

Frequently asked questions

Can we license transcripts if our privacy notice never mentioned AI?

Possibly, but that gap is the first thing counsel will examine. A use not described in the notice may require updated notice or consent for future conversations, and older conversations are assessed against what visitors were actually told. Many companies start with conversations collected after an updated notice took effect.

Does our chatbot vendor have rights to our transcripts?

Some vendor agreements grant the vendor a license to use content, often de-identified or aggregated, to improve its products. That does not stop you from licensing your own copy, but it matters to a buyer asking about exclusivity and to a rights review asking who else holds the records.

Should we keep transcripts the vendor would otherwise delete?

Only within your own retention policy and what your privacy notice says. Exporting before a vendor deletes records makes sense when you have a business reason to keep them, but holding personal data longer than you told people you would creates its own risk.

Are voice bot recordings treated the same way?

Voice adds separate questions. Call recording rules, consent to record, voice characteristics and the accuracy of transcriptions all need review, and audio is harder to de-identify than text. Most companies review voice and chat as separate record families.

Are AI-generated replies worth licensing at all?

On their own, rarely. They show what one model said, not how a business solved a problem, and model terms may restrict reuse. They add value as context next to the customer's message and the human agent's correction, which together show where the bot fell short.

Sources

  • As documented in the Amazon Comprehend Developer Guide archived on GitHub in June 2023, Comprehend detects universal PII entity types including NAME, ADDRESS, EMAIL, PHONE, CREDIT_DEBIT_NUMBER, CREDIT_DEBIT_CVV and PASSWORD. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify