VendorScore · Customer support · Data-access posture

Can Intercom read your customer conversations?

A plain-language answer from Intercom's public Security, Legal and Fin pages. Intercom holds the keys, and Fin sends conversations to third-party LLMs.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, Intercom can read your conversations by design. Intercom holds the keys with no customer-managed key option found, Fin sends conversations to third-party LLMs, and Intercom trains its own Fin models on anonymized conversations unless you opt out.

47 / 100 overall

Scored configuration: Intercom Helpdesk + Fin AI Agent on a standard paid workspace with regional hosting (US/EU/AU). No customer-managed key option was found, so the default and scored configuration are the same.

Report confidence: Medium. Intercom's trust center (trust.intercom.com) returned no content.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Intercom's public documentation:

  • trust.intercom.com returned an empty JavaScript shell, so the encryption key hierarchy, employee-access tooling and report availability are unverified.
  • Whether some workspace types (for example EU/AU-hosted or trial) are automatically excluded from model training isn't confirmed: Unknown.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Intercom data access, AI training, GDPR and residency

Can Intercom read your customer conversations?

Yes, Intercom can read your conversations by design. Intercom holds the keys with no customer-managed key option found, Fin sends conversations to third-party LLMs, and Intercom trains its own Fin models on anonymized conversations unless you opt out. VendorScore rates Intercom 47/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Intercom Helpdesk + Fin AI Agent on a standard paid workspace with regional hosting (US/EU/AU). No customer-managed key option was found, so the default and scored configuration are the same.

Is Intercom data encrypted? Does Intercom offer BYOK?

Intercom's DPA says "All data sent to or from Intercom is encrypted in transit using TLS 1.2" and that customer personal data is encrypted at rest with 256-bit encryption on AWS. We found no BYOK, EKM or customer-managed key option, and there's no E2EE: Intercom holds the keys.

Can Intercom employees read my conversations?

On a need-to-know basis. Intercom's DPA says it "restricts access to Customer Data to only those people with a 'need-to-know' for a Permitted Purpose and following least privileges principles," with MFA and access reviews at least every 180 days. For EU- and AU-hosted workspaces, urgent out-of-region support requires a customer user to grant impersonation access. Fin and Copilot process conversation content in plaintext by design.

Does Intercom Fin train on my data?

Yes, unless you opt out. Intercom's Terms say: "Customer grants ... royalty-free right to access, use and display the Customer Data during the Term in order to provide and improve our Services, including for Intercom AI model training." Fin's custom models learn from successful conversations "for every business using Fin", with data anonymized, and "you can opt out of model training at any time." Intercom's security page says you can opt out of fine-tuning anytime, with data deleted within 30 days.

Is Intercom GDPR compliant? Where is the Intercom DPA?

VendorScore doesn't certify compliance; Intercom publishes a DPA at https://www.intercom.com/legal/data-processing-agreement. Intercom's Regional Data Hosting Addendum covers EU and AU hosting.

Who are Intercom's subprocessors, and which AI providers see my conversations?

Intercom's list (effective June 25, 2026) names, for US hosting, AWS and Snowflake ("including AI processing"), Mailgun, Sparkpost, Twilio, Cloudflare, OpenAI, PlanetScale, Anthropic, Google, Microsoft, ElevenLabs, Ably and Cartesia. EU and AU hosting lists differ, and AU AI processing via Bedrock runs in the USA. AI processors are in the core list, not just behind opt-in features. The list is published at https://www.intercom.com/legal/security-third-parties.

Can I keep Intercom data in the EU (data residency)?

Yes. Intercom offers US, EU or AU hosting; EU hosting runs on AWS eu-west-1 (Dublin), with listed exceptions for some features and out-of-hours support.

Compare Intercom

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (intercom.md), evidence dated 2026-10-07.