1. Data we collect
We collect only what we need to run the service:
- Account data — the name and email of the person who signs in (via Google sign-in), and the workspace they create.
- Business content — the information you add about your business, your saved replies, segments, and automation rules.
- Customer conversations — the messages exchanged between your business and your end customers on connected channels, and the contact records tied to them.
- Connection credentials — the tokens that let us send and receive on your connected channels, stored encrypted (see Security).
- Technical data — IP address, device/browser information, and log data used to keep the service secure and reliable.
2. Meta platform data (WhatsApp, Instagram, Messenger)
When you connect a Meta channel — a WhatsApp Business number, an Instagram professional account, or a Facebook Page/Messenger — you authorize us to access data through Meta's APIs on your behalf. This may include the connected account's profile, the messages your end customers send to you, their message content and attachments, and the profile name and identifier Meta provides for those end customers.
We use Meta platform data only to provide the messaging features you enable — delivering incoming messages into your inbox, letting your team (and, where you turn it on, our AI assistant) draft and send replies, and keeping a conversation history. We do not sell Meta platform data, we do not use it for advertising, and we do not share it except with the subprocessors described below or as required by law.
Our handling of Meta platform data follows the Meta Platform Terms and Developer Policies, the WhatsApp Business Terms, and Instagram's platform policies. If you disconnect a Meta channel or your access is revoked, we stop accessing new data from that channel and delete or de-identify the associated platform data on the schedule described in Data retention and deletion.
3. How we handle customer data
The conversations and contact records that flow through your workspace belong to you. We process them as your service provider — to operate the inbox, generate AI reply drafts from your own data, run the automations you configure, and produce reports for your team. We do not use your customers' data to train shared or third-party models, and we do not sell it.
Each workspace's data is isolated from every other workspace. You control who on your team can access it, and you remain the controller of that data as against your end customers — including responsibility for having the rights and consent to message them (see the Terms).
4. How we use data
- Provide the service — route messages, draft and send replies, run automations, and show reports.
- AI assistance — generate suggested replies from your own workspace data; sensitive, uncertain, or payment-related messages are held for a human to approve.
- Security and reliability — detect abuse, prevent fraud, debug, and keep the service available.
- Support and communication — respond to your requests and send service notices.
- Legal — comply with applicable law and enforce our Terms.
6. Data retention and deletion
We keep personal data only for as long as we need it to provide the service, and each category of data has its own retention rule:
- Account data — kept while your account is active, and deleted when your account or workspace is deleted.
- Customer conversations, contacts, and attachments — kept while your workspace is active so your team has its history. Deleting a conversation or contact in the app removes it from our production systems immediately; deleting your workspace removes all of them at once.
- Inactive workspaces — if a workspace goes 90 days with no messages sent or received and nobody signing in, we delete it and everything in it automatically. We email the workspace owner 30 days, 7 days, and 1 day before that happens, and signing in at any point resets the 90 days. This applies to every category on this list, including Meta platform data.
- Meta platform data (WhatsApp, Instagram, Messenger) — kept only while the channel is connected and only as long as needed to provide the messaging features you enable. If you disconnect a channel or revoke our access, we immediately delete that channel's credentials and stop receiving new data from it. The messages your business already exchanged stay in your workspace as your customer history, and are deleted when you delete them, when you delete the workspace, or by the 90-day inactivity rule above.
- Connection credentials (access tokens) — deleted immediately when you disconnect the channel, revoke our access, or delete your workspace.
- Technical and security logs — kept for up to 90 days for security, debugging, and abuse prevention, then deleted or de-identified.
- Your workspace's audit log — the record of who did what in your workspace. It is kept for the life of the workspace rather than 90 days, because it is a tamper-evident security record and removing entries from it would defeat its purpose. It is deleted in full when the workspace is deleted, including by the inactivity rule above.
- Backups — deleted data may persist briefly in encrypted backups; those copies are overwritten in the ordinary course of our backup cycle and purged no later than 90 days after deletion.
How to delete your data. You can delete data yourself, without contacting us, at any time:
- Delete individual records — open the conversation or contact in the app and delete it. It is removed from our production systems immediately and is no longer available to your team.
- Disconnect a channel — remove a connected channel (for example a WhatsApp number, Instagram account, or Facebook Page) from your workspace's channel settings. We immediately delete that channel's access credentials and stop receiving new data from it. The conversations your business already had through that channel remain in your workspace as your own customer history; delete them individually, or delete the workspace, to remove them too.
- Revoke access on Meta's side — you can also remove our access from your Facebook or Instagram account settings (Settings → Apps and websites, or Business integrations). Once revoked we can no longer access any data from that account, and we delete that channel's stored credentials immediately, exactly as if you had disconnected it in the app.
- Delete your entire workspace — go to Settings → General info in the app and use Delete workspace. This permanently and irreversibly deletes all workspace content — conversations, contacts, message attachments and media, automation rules, reports, connection credentials, and all Meta platform data — from our production systems immediately.
- Request deletion by email — if you prefer, or can no longer sign in, email support@otobiz.ai from the address associated with your account with the subject "Data deletion request". We will verify the request, complete the deletion within 30 days, and confirm to you in writing once it is done.
End customers (people who messaged a business through the service) should send deletion requests to that business, which controls the conversation data — deleting the contact in the app removes the conversation history. End customers may also email support@otobiz.ai and we will forward the request to the business and assist it in responding. We also honor data deletion requests that Meta sends us on a user's behalf.
Exceptions. We may retain limited records after deletion where the law requires it, or as needed to resolve disputes, prevent fraud and abuse, or enforce our agreements — for example invoices or records of a deletion request itself. Any such records are kept isolated, are not used for any other purpose, and are deleted once the reason for keeping them ends.
One of those records is worth naming, because it outlives a deletion by design: when a workspace is deleted we keep a one-way cryptographic hash of the email address it was created with, so that a free trial cannot be restarted indefinitely by deleting a workspace and signing up again. It is stored separately from workspace data, it is not reversible into an email address, we cannot use it to contact anyone or to rebuild anything that was deleted, and it is the only thing that survives. If you would like it removed as well, email us and we will remove it.
7. Data policy and security
- Isolation — every workspace's data is walled off at the database with row-level security, so one business can never read another's data.
- Encryption — data is encrypted in transit (TLS), and channel credentials are sealed with envelope encryption at rest.
- Access control — you decide which team members can see and act on conversations; internal access is limited to what is needed to run and support the service.
- Human-in-the-loop — sensitive, uncertain, payment, broadcast, and spend-related actions are held for human approval rather than sent automatically.
No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard measures and to notify you of material incidents as required by law.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete personal data, and to object to or restrict certain processing. End customers should direct such requests to the business they were messaging; we will assist that business in responding. To exercise a right that we control directly, contact support@otobiz.ai.
9. Children
Otobiz is a business tool and is not directed to children. We do not knowingly collect personal data from children under the age required by applicable law without appropriate consent.
10. Changes to this policy
We may update this policy as the product and the law evolve. When we make material changes we will update the date above and, where appropriate, notify you. Continued use of the service after an update means you accept the revised policy.
11. Contact us
Questions about this policy or your data? Email us at support@otobiz.ai.