Listed sites only
The agent refuses to open anywhere you have not named. An empty list stops nothing, so Studio warns you while it is empty.
Allowed domains
✓example.com
✓www.example.com
✕pasted-elsewhere.comRefused
Security
You decide which ones it answers, what it may reach on their behalf, and what it is allowed to say about itself. Every setting lives in Studio and none of them costs credits to change.
What stands between a stranger on your website and your customers' records.
The agent refuses to open anywhere you have not named. An empty list stops nothing, so Studio warns you while it is empty.
Allowed domains
✓example.com
✓www.example.com
✕pasted-elsewhere.comRefused
Duvi never takes a visitor’s word for who they are. Your own endpoint says so, in an HS256 token that lives no more than 120 seconds and is verified before the agent speaks.
Your endpoint returns
A field that decides whose data comes back is filled from the verified customer. The agent never sees the value and cannot invent one.
Tool: look up an order
| Field | Filled by |
|---|---|
| customer_id | identity |
| order_ref | reference |
You paste a credential once and we encrypt it on arrival. Studio fills it into the request at call time, so the value never reaches the model.
Stored keys
stripe_liveEncrypted
••••••••••••Never shown
A standing line before the agent’s first message, in your words, telling people they are talking to software.
Shown before the first message
Replies are generated. Check anything important with our team.
Processed in the United States, and never sold. Conversations are also used to train Duvi models, which is set out in full further down.
Who trains on it
Duvi modelsYes
OpenAI, Google, AnthropicNo
Where each of those lives in Studio, and the detail behind it. Open any row.
Enter the domain only, with no scheme and no path. A www host counts as a different host, so add both if you serve both. That one catches almost everybody, and it is the usual reason a widget does not appear.
Anything that is not a browser can claim any origin it likes, so treat this as the lock on the front door. Access, below, is the lock on the safe.
Leave it open and anyone may start a conversation, with verified identity used whenever your endpoint supplies it. Close it and an unidentified visitor is refused before any model call.
The token must be HS256, addressed to duvi, and live for no more than 120 seconds. We allow 30 seconds of clock drift either way, and the widget refreshes 15 seconds early so a short life costs you nothing.
To rotate a signing key, add the new one alongside the old, deploy it, then switch which key is in use. Nobody is rejected part way through the change.
One line before the agent speaks, in your words. Off until you turn it on, and saving it empty stores nothing.
Keep it separate from the opening line. A disclaimer is a standing statement about what the thing is; an opening line is not, and you will want to change them at different times.
The value is entered once, in Studio, and never displayed again. Your tools refer to it by name rather than by value, and a field filled at call time never reaches the model.
Secrets belong in stored keys, never in a prompt. A determined visitor can often talk an agent into reading its own instructions back, so treat the prompt as something the customer may end up seeing.
We store conversations to run the platform, to bill your account, and to train and improve our models.
We do not sell personal information. Conversation data we handle for you is kept for as long as your agreement says. Here is everything that touches it.
Messages and call transcripts are used to train and improve Duvi models. Tell us before you build if your business needs to be left out of that.
Do not train on API traffic. OpenAI clears abuse logs within 30 days, Anthropic deletes inputs and outputs after 7.
Carries the calls on a number you already own.Phone only
Moves messages to and from your WhatsApp Business number.WhatsApp only
Does the same job through the WhatsApp Cloud API.WhatsApp only
Where we operate, and where your information is processed.Location
Roughly in the order they ask them.
Yes. Messages and call transcripts from the platform are used to train and improve Duvi models. Tell us before you build if your business needs to be left out of that.
No. OpenAI does not train on anything sent through its API unless you opt in, and clears its abuse logs within 30 days. Google gives the same undertaking on paid Gemini API traffic. Anthropic does not train on API traffic either and deletes inputs and outputs after 7 days.
Not if the field that selects the record is bound to identity. That value is filled from the verified customer and the agent never sees it, so it cannot be guessed or talked into changing.
A field the agent fills is whatever the visitor typed. Never use one for an account id or an order reference tied to an account.
Anyone who can load a page on a domain you have listed. An empty list places no restriction at all, which is why Studio warns you while it is empty. Switch Access to signed-in visitors only and that narrows to people your own server will vouch for.
The United States. Where a transfer needs safeguards, we put them in place.
As long as your agreement says. Anything else we hold, we keep only while the reason we collected it still applies, or while the law requires it.
Yes. Depending on where you live you can ask to see, correct, delete or restrict your personal information, including under the GDPR and the CCPA. Write to us and we will act on it.
We refuse the request rather than quietly giving you a worse answer. A new conversation will not open, and in one already running the next message is turned away while whatever is already streaming finishes.
No. Signing in sends you to that service, you approve the access there, and you land back in Studio. We never see the password. Services that use a key instead take one you created, encrypted the moment it arrives.