Privacy policy
This draft describes what the platform stores, why, and for how long. Where a decision has not been made, it says so instead of implying one.
This is a draft, pending legal review
The text below is an early draft written to state our intent plainly. It has not been reviewed by a lawyer and is not a final agreement. A reviewed version will replace it before any commercial launch.What we collect
Account data you provide: name, email address, password (stored only as a hash) and workspace name. Operational data the platform generates: API keys as hashes, request identifiers, audit records of important actions, and technical logs.
Message content
To deliver a message we necessarily process its content and the recipient's phone number, and we store the message, its delivery state and its timeline so you can see what happened. Message content is never used to train models and is never sold.
Why we process it
To operate the service you asked for: authenticate you, deliver and track messages, enforce plan limits, keep an audit trail, investigate faults and abuse, and meet obligations that apply to us.
Third parties
Messages are delivered through WhatsApp and, on the official path, through Meta — their handling of that traffic is governed by their own terms. Infrastructure is operated on servers rented by the platform team, and email is sent through a mail provider. A complete sub-processor list will be published with the reviewed version.
Where data is stored
The platform currently runs on a single server operated by the platform team, with its database and object storage in that same environment. No contractual data-residency commitment has been made yet; when one is made it will be stated here with the region named.
How long we keep it
Account and workspace data is kept while the account exists. Message and conversation records are kept so you can review your own history. Log retention is a plan-level setting shown on the pricing page, and final retention periods will be stated in the reviewed version.
Your rights
You can ask what we hold about you, ask for a correction, and ask for your account and its data to be deleted. Deletion removes the workspace's stored messages as well, so export anything you need first.
Security
Passwords are hashed with Argon2id, API keys are stored only as hashes and shown once, secrets are redacted from logs, and access to production is limited to the platform team. No system is perfect; if we discover a breach affecting you we will tell you.
Changes to this document
This draft will be replaced by a reviewed version. Material changes will be announced to account holders by email rather than quietly edited in place.