Privacy Policy
Last updated: July 2026
1. Introduction
WiseChatt ("we", "us", "our") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data.
2. Information We Collect
We collect the following categories of information:
- Account data: name, email address, and hashed password when you register.
- Business data: your business name, Meta WhatsApp credentials (stored encrypted), and Google OAuth tokens.
- Conversation data: messages, contact details, and message metadata from your connected channels (WhatsApp, Instagram, Messenger and others) processed through your workspace.
- Usage data: log data, IP addresses, and feature usage for service improvement.
3. How We Use Your Information
- To provide and operate the Service
- To authenticate users and maintain sessions
- To route and deliver WhatsApp messages on your behalf
- To send service notifications and updates
- To detect and prevent fraud or abuse
- To comply with legal obligations
4. Data Isolation
Each WiseChatt workspace is fully isolated. Your conversations, contacts, users, and credentials are never accessible to other tenants on the platform.
5. Third-Party Processors
We use the following third-party services to deliver the platform:
- Meta (WhatsApp Business API): message delivery and WhatsApp API access
- MongoDB Atlas: database hosting
- Google: contact synchronisation, Gmail channel, and Calendar appointment booking (all optional, each with separate consent)
Each processor is bound by their own data processing agreements and privacy policies.
6. Meta Platform Data
WiseChatt is a registered Meta Tech Provider. When you connect a Meta asset (such as a WhatsApp Business Account, Instagram or Messenger account) to your workspace, we access and process data through the Meta platform solely to provide the Service on your behalf.
- We only request the permissions required to send and receive messages and manage your messaging assets.
- We do not sell Meta platform data, and we do not use it for advertising or to build user profiles.
- Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the limited-use requirements.
7. Google User Data
If you choose to sync your Google Contacts, WiseChatt requests read-only access to your contacts through the Google People API using the contacts.readonlyscope. This is entirely optional and is only initiated when you click "Sync Google Contacts".
- What we access: contact names, phone numbers, and contact group labels from your Google account. This Contacts Sync feature does not access your email, calendar, or files — see below for our separate, opt-in Gmail and Google Calendar features, each with its own distinct consent.
- How we use it: Google Contacts data is used solely to import your contacts into your workspace so you can message them through your connected channels. This is the only purpose for which we use Google Contacts data.
- What we do not do: we do not use Google user data for any purpose other than providing or improving this user-facing feature. Specifically, we do not use it for advertising or marketing, to build user profiles, or to train, develop, or improve any generalised or standalone artificial intelligence or machine-learning models. Any AI features in the Service operate only on the messages within your own workspace and are never applied to your Google Contacts data.
- How we store it: imported contacts are stored within your isolated workspace and are not shared with other tenants. You can delete them at any time.
- Sharing: we do not sell or transfer Google user data to third parties. We do not share Google user data except (a) to you and users within your own workspace, (b) as necessary to provide or improve the feature you requested, (c) for security purposes such as investigating abuse, or (d) to comply with applicable law.
WiseChatt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7a. Gmail Channel (Optional)
If you choose to connect Gmail as a messaging channel, WiseChatt requests access to your Gmail account through the gmail.modifyscope. This is entirely optional and is only initiated when you click "Connect Gmail" in your workspace settings.
- What we access: the content of emails sent and received on the connected Gmail account, so they can appear as conversations in your shared inbox alongside your other channels.
- How we use it: solely to let you read and reply to emails from within WiseChatt, including AI-assisted replies where you have enabled the AI assistant for your workspace.
- How we store it: connected account tokens are stored encrypted on your workspace; email content is stored as conversation history within your isolated workspace, same as messages from other channels.
- Sharing: we do not sell or transfer Gmail data to third parties, and do not use it for advertising, to build user profiles, or to train general-purpose AI models.
- Revoking access: you can disconnect Gmail at any time from your workspace settings, which stops further access immediately.
7b. Google Calendar (Optional)
If your workspace has appointment booking enabled, WiseChatt requests access to your Google Calendar so the AI assistant and your team can check availability and book appointments on your behalf. This is only initiated when you connect Google Calendar in your workspace settings.
- What we access: your calendar's event availability, and the ability to create, update, and cancel events representing customer appointments booked through WiseChatt.
- How we use it: solely to schedule, reschedule, and cancel appointments requested by your customers through your connected messaging channels.
- How we store it: connected account tokens are stored encrypted on your workspace; the resulting appointment details (customer name, phone number, appointment time, and a reference to the Google Calendar event) are stored within your isolated workspace.
- Sharing: we do not sell or transfer Google Calendar data to third parties, and do not use it for advertising, to build user profiles, or to train general-purpose AI models.
- Revoking access: you can disconnect Google Calendar at any time from your workspace settings, which stops further access immediately.
8. Mobile Application
The WiseChatt mobile app is a native shell around your dashboard. It requests the following device permissions, each only when you use the related feature and only after your consent:
- Camera and photos: to capture or select images and other media you choose to attach to conversations and message templates. We only access media you explicitly pick or capture; we do not scan your photo library.
- Microphone: to record voice messages when you choose to send them.
- Push notifications: with your permission, we collect a device push token to deliver notifications about new messages and account activity. You can revoke notification permission at any time in your device settings. The token is used solely to send you these notifications and is deleted when you sign out or uninstall the app.
Media you capture or select is uploaded only to your own workspace as part of the message or template you are creating. We do not access your camera, microphone, or photos in the background.
9. Data Retention
We retain your data for as long as your account is active. When you delete your workspace, we delete all associated data within 30 days, except where retention is required by law.
10. Security
We implement industry-standard security measures including encrypted credential storage, JWT-based authentication, and TLS for all data in transit. No system is 100% secure, so please use strong, unique passwords.
11. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. To exercise any of these rights, contact us at privacy@wisechatt.com.
12. Data Deletion
You can request deletion of your data at any time. Deleting your workspace from the dashboard removes all associated account, conversation, contact, and connected-channel data within 30 days. You may also disconnect any Meta asset at any time, which immediately revokes our access to that asset's data. To request manual deletion of your personal or Meta platform data, email privacy@wisechatt.com and we will process your request within 30 days.
13. Cookies
We use session cookies for authentication only. We do not use tracking or advertising cookies.
14. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect.
15. Contact
For privacy questions or data requests, contact privacy@wisechatt.com.