Privacy Policy

WhatsApp AI Agent — personal assistant service

Overview

This is a personal AI assistant service that the account owner runs on their own WhatsApp Business number using the official WhatsApp Cloud API provided by Meta. When you message that number, the service receives your message and — if automatic replies are enabled — may generate and send a reply.

What we receive and store

AI processing

When automatic AI replies are enabled, message content may be sent to third-party AI model providers to generate a response. Only the conversation text needed to produce a reply is sent, and only to providers the owner has configured. If AI replies are disabled for the service or for your conversation, your messages are not sent to any AI provider.

If you send an image, its image data is sent to Google Gemini online for OCR. If you ask a question about an image or PDF, or request an image edit, that file is also sent to Gemini so it can perform the requested task. Spreadsheet analysis and supported spreadsheet edits run in the service without sending spreadsheet contents to an AI provider. Media bytes used by these file workflows may be held temporarily in server memory while a follow-up session is active (up to 15 minutes); they are not written to the service's conversation database by these workflows. Generated image edits are AI previews and may not preserve exact fonts or layout. The account owner can disable these media workflows at any time from the service dashboard: with media processing off, images and documents are neither downloaded nor sent to any AI provider, and with AI image editing off, edit requests are declined while image OCR and questions keep working.

Message content is never used for advertising, sold, or shared with anyone other than the configured AI providers described above.

Google Drive access (owner authorization)

The application uses Google OAuth solely for the Google Drive functionality it needs: the account owner authorizes the application once, and generated notice documents (PDF files) are saved to a dedicated folder in the owner's own Google Drive so they can be re-downloaded through the bot on request.

Third-party services

Who can see stored data

Only the account owner, through a password-protected admin dashboard. The service does not display conversation content publicly.

Data retention and deletion

Data is kept only while the account owner operates the service. You can request deletion of your stored data at any time — see the Data Deletion page for how.

Security

Incoming webhook traffic is verified with Meta's signature mechanism, admin access is password-protected with server-side sessions, and provider credentials are stored only on the server. No system is perfectly secure, but the service is built to keep your data accessible only to the account owner.

Changes

This policy may be updated as the service evolves. The current version is always available at this URL.