Trust
What Templ never does, who can read a case, who gets your data and how long it stays.
What Templ never does
Support messages cannot move funds or ask your wallet to sign.
- Templ never asks for a private key or recovery phrase.
- The widget asks your wallet only to connect and sign in.
- A support message can't start a signature, an approval or a transaction.
Templ refuses recovery phrases and the private key formats it recognizes. A 64-character hex value can be a transaction hash or a private key. Templ hides it from bots, webhooks, AI and exports unless the user shared it as a transaction. The user and your team still see it in the chat until someone redacts it.
With an EVM wallet, the widget calls 4 wallet methods: eth_requestAccounts, eth_accounts, eth_chainId and personal_sign.
Solana wallets cannot sign in to the widget yet.
Solana wallets cannot sign in to the Templ app yet.
Signing in costs nothing and moves no funds. Templ's servers only read public blockchain data, such as balances, receipts and logs. They refuse any request that would send a transaction.
Who can read a case
Every read checks who can access that case now.
- The person who asked
- The workspace manager
- Staff and AI agents the manager gives support access
Assignment, payments, names and badges grant no case access. Staff access and support setting changes need a wallet sign-in from the last 15 minutes. They also need confirmation. Removing someone's access cuts them off from history, notes, screenshots, search and exports.
Access checks keep cases private. Cases are not end-to-end encrypted. Templ and the providers below can process stored data.
What Templ's operators see
Templ's operator pages cannot open your workspace's cases.
Operators see cost totals, onboarding counts and a workspace list. The list has each workspace's name, manager, creation date and visibility. Operators also review safety reports, which carry a copy of the reported message. No app page or route lets operators open a workspace's cases.
Service providers
These providers receive only the data listed for their work.
The status shows what runs today. Feature availability lists every feature and whether it's on.
- CloudflareLive
Runs the site, the support software, its databases, private screenshot storage and logs.
Receives: Everything Templ stores, plus network details such as IP addresses.
- AlchemyLive
Reads public blockchain data, such as a balance or a payment. Requests come from Templ's servers, not your browser.
Receives: Public wallets and transaction details.
- dRPCLive
Makes the same blockchain reads as a second source. Templ uses an answer only when both agree.
Receives: Public wallets and transaction details.
- AnthropicConfigured, off
Runs enabled Templ-managed AI for customer workspaces.
Receives: Relevant case messages, selected context and knowledge for enabled AI. Improvement copies never go to Anthropic.
- OpenAIConfigured, off
Runs enabled AI for Templ's own support workspace and Templ Demo only.
Receives: Selected case messages, checked transaction facts and approved knowledge. Improvement copies never go to OpenAI.
- ResendConfigured, off
Sends support alert emails once they are on. They are not on yet.
Receives: The email address, a one-time code, confirmation links and case resume links. Never message text.
- Google AnalyticsConfigured, off
Counts clicks on the landing page and in setup once it's on. It's off, so no Google code loads.
Receives: Fixed event names and network details. No message text, wallets or chat links.
- Helius or ChainstackNot used
Checks stablecoin payments on Solana once checkout opens. Checkout is closed, and Solana sign-in needs no provider.
Receives: Nothing today.
- StripeConfigured, off
Monthly card billing is built and gated. It is not available yet.
Receives: Stripe handles card details. Templ receives Stripe IDs, card brand, last 4 digits and invoice status.
- Sourcify, Blockscout and EtherscanNot used
Look up a contract's published code to explain a transaction, once transaction checks are on. Not used today.
Receives: Contract addresses and chain IDs.
- Slack and DiscordNot used
Alerts your team in its own channel when a case needs a reply, once alerts are on. They are not on yet.
Receives: That a case needs a reply. No message text.
How long data stays
Templ keeps data for the times listed below.
| Data | How long |
|---|---|
| Resolved, abandoned and spam cases | Deleted 365 days after the last message |
| Open cases | Kept |
| Cases under a legal hold approved by Templ, for a whole workspace or one case | Kept while the hold applies. A hold stops an active deletion. Templ keeps the data that remains. Earlier versions of edited and deleted messages still go after 90 days. The schedule above starts again when the hold ends |
| Earlier versions of edited messages and the text of deleted ones | Up to 10 versions per message, removed after 90 days when the workspace next edits or deletes a message |
| Times, counts and flags for each case, with no message text | Deleted with the case, or 365 days after the case was resolved if that comes first |
| A user's request for a person, from Talk to a person in the chat | Saved as a handoff with the time, a reason code, who asked and the case it is for. It stays open until a person replies or the case is resolved. The team's activity list shows the user's account and time until the case is deleted. The case records keep the time and code |
| A case's AI mode, which only the team sees | Deleted with the case, along with who or which rule set it, when and why |
| Workspace activity log | Access changes: 365 days. Case activity: 90 days. At most 10,000 access changes and 2,000 case entries stay. New entries remove older ones of the same kind |
| Counts of requests Templ turned away for a workspace, by day and reason, with no names, wallets or IP addresses | 35 days. Older days go when the next refusal is counted |
| The retry ID of a turned-away request, so a retry counts once | 7 days. Older IDs go when the next refusal is counted |
| Resolved-case charges: times, state, price and a keyed user hash. No message text or wallet | 400 days after the case was resolved. Longer while it waits to go final or a dispute is open. Monthly totals stay with the workspace's balance |
| Counts of widget opens on websites a workspace hasn't approved, by day, with no website or visitor details | 35 days. Older days go when the next open is counted |
| App sign-in | 30 days |
| One-time sign-in challenge | 5 minutes |
| Widget sign-in | 1 hour. The tab keeps a token in browser storage until it closes. Templ keeps a matching sign-in record on Templ's servers |
| Guest credential that reopens a guest's case | 90 days on Templ's servers. The browser keeps the credential and case ID until replacement or deletion. It stops working after 90 days |
| Keyed one-way hash of a guest's IP address | Counts for 24 hours toward the 3 guest cases a day limit. Removed when the workspace next opens a guest case |
| Unsent drafts on your device | 7 days, at most 50 in the app |
| How long a waiting visitor's widget keeps checking for replies after a reload | Up to 1 day, as one time in the website's browser storage, with no message text |
| A "No, I still need help" answer to "Did this solve it?" | Until cleared. The browser keeps the team reply ID for each case, with no message text |
| Lines the widget shows after a send, such as "Received" or who replies next | Only in the page's memory while it's open. The widget saves none of them |
| When the team's AI agent last checked in | Only in the memory of Templ's servers, never saved, and forgotten when they restart. The agent counts as running for 1 minute after it checks in. Users see this only as "AI agent is typing" |
| Safety reports, with a copy of any reported message | 90 days, longer while held for a legal case |
| Stored contact requests | 365 days after each arrived |
| Log lines for onboarding counts | Up to 7 days in Cloudflare's logs |
| Staff roles, linked wallets, workspace settings and billing records | No automatic age expiry. Enabled workspace deletion removes workspace roles and settings. Account wallet links and necessary billing records remain separately |
When Templ cannot check legal holds, it stops deleting cases. It checks again 1 hour later. Cloudflare keeps its backups and logs on its own schedule. Templ has not finished checking those settings.
Activity log
The manager can see who changed access or worked on a case.
Each workspace keeps an activity log in 2 parts. An entry says who did it and when, never message text. Only the manager can read the log.
Access changes cover:
- staff access
- AI agent labels
- manager handovers
- support settings
- saved replies
- widget settings
- case downloads
Case activity covers:
- assigning a case
- resolving or reopening one
- adding a note
- asking a user to verify a wallet
- moving a guest case to a wallet
- deleting someone else's message
Templ keeps up to 10,000 access changes from the last 365 days. It keeps up to 2,000 case entries from the last 90 days. New entries remove older ones. The log does not record reads or status changes from the Status menu yet.
Who runs Templ
These are the operator details Templ can confirm today.
- Company
- templ.fun Ltd
- Company type
- BVI Limited Company
- Registered in
- British Virgin Islands
- Company number
- 2191511
- Registered on
- 28 October 2025
- Registered address
- Quijano Chambers, P.O. Box 3159, Road Town, British Virgin Islands
- Mailing address
- Quijano Chambers, P.O. Box 3159, Road Town, British Virgin Islands
- Governing law
- British Virgin Islands
Ask about your data
Ask Templ to help you access, correct or delete your data.
You can read your own chats, stop team messages and remove extra wallets from your account yourself. Deleting an account or a workspace isn't self-serve yet.
For a copy of your data, a correction, a deletion or any other data question, ask us. A person on the Templ team answers.
Legal requests and notices required by law go through Safety.