Legal
Privacy Policy
How Chatbox AI handles personal information when businesses use our platform to message their customers on WhatsApp.
Last updated: 19 July 2026
1. Introduction and Scope
Chatbox AI ("Chatbox AI", "we", "us", or "our") operates a multi-tenant software platform, available at https://chatboxai.dev, that lets businesses connect their own WhatsApp Business number and use it to send broadcast campaigns, manage message templates, hold two-way conversations with their customers, store contact lists, run automations, and view analytics. This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and what choices you have.
This policy covers two very different groups of people, and the distinction matters:
- Business account holders — the organisations and individuals who sign up for Chatbox AI, log in to the dashboard, and pay for the service. For their account data, Chatbox AI is the data controller: we decide why and how that information is processed.
- End customers — the people a business messages through its own WhatsApp Business number using our platform. For that data, Chatbox AI is a data processor: we handle it only on the documented instructions of the business that uploaded or generated it. That business is the controller and is responsible for having a lawful basis and a valid opt-in for every contact it messages.
If you are an end customer who received a WhatsApp message sent through Chatbox AI and you want your data removed, your first point of contact is the business that messaged you. We will also assist — see section 9.
2. Information We Collect
2.1 Information the business account holder gives us. When you register for and use a Chatbox AI account, we collect:
- Account identity details — full name, business name, work email address, and phone number.
- Authentication credentials — we never store your password in readable form; only a salted one-way hash is retained.
- WhatsApp Business account credentials — the WhatsApp Business Account ID, phone number ID, and the access token issued to you by Meta so that we can send and receive messages on your behalf. Access tokens are encrypted at rest.
- Billing information — subscription plan, invoices, and transaction references. Card and bank details are captured and stored by our payment processor, Razorpay, and are never stored on Chatbox AI servers.
- Support correspondence — anything you send us by email or through in-product support channels.
2.2 End-customer data the business sends through the platform. When you use Chatbox AI to reach your own customers, the platform stores and processes on your behalf:
- Contact records you upload or create — phone numbers, names, tags, attributes, and custom fields.
- Message content — the text, media, and template variables of outbound campaigns, and the inbound replies your customers send back to your WhatsApp Business number.
- Conversation metadata — timestamps, delivery and read receipts, failure reasons, conversation categories, and assigned agents.
- Automation and template configuration — the rules, triggers, and approved message templates you set up.
We do not use end-customer data for our own purposes, do not sell it, and do not use it to build advertising or marketing profiles.
2.3 Data collected automatically. When you use the dashboard we collect technical and usage information:
- IP address, browser type and version, operating system, device type, and approximate region.
- Product usage events — logins, pages viewed, features used, campaigns created, and messages sent, used to produce your analytics dashboards and to understand how the product is used in aggregate.
- Application and error logs — request identifiers, API responses from Meta, and stack traces recorded for debugging and abuse prevention.
- Strictly necessary cookies and local storage entries used to keep you signed in and to remember interface preferences.
3. How We Use Information
We use the information described above to:
- Create and administer your account and authenticate you when you sign in.
- Deliver the core service — relaying your broadcasts, template messages, and conversation replies to and from the WhatsApp Business Cloud API.
- Store your contact lists and conversation history so they are available when you return.
- Execute the automations and routing rules you configure.
- Generate delivery, engagement, and usage analytics for your own account.
- Process subscription payments, issue invoices, and enforce plan limits.
- Provide customer support and respond to your enquiries.
- Monitor for spam, fraud, credential abuse, and violations of Meta's messaging policies, and take enforcement action where required.
- Maintain, secure, debug, and improve the platform, and meet our legal, tax, and accounting obligations.
- Send service communications such as outage notices, security alerts, billing reminders, and material changes to this policy.
Where AI features are used — for example to draft or summarise a reply — the relevant message text is sent to our AI sub-processor solely to return that result. It is not used to train third-party models.
4. WhatsApp Business API and Meta
Chatbox AI operates as a Business Solution Provider built on the WhatsApp Business Cloud API. We do not own or operate WhatsApp, and we do not issue phone numbers. Every business using Chatbox AI connects its own WhatsApp Business Account, which it holds directly with Meta Platforms.
As a result, all message traffic — outbound campaigns, template messages, and inbound customer replies — flows through Meta's WhatsApp Business Cloud API infrastructure. Meta receives and processes that message data, along with associated phone numbers and delivery metadata, under its own terms and privacy policy. Message templates you create are submitted to Meta for review and approval, and Meta determines whether they may be used.
This means Meta's WhatsApp Business Terms, Messaging Policy, and privacy policy apply in addition to this policy. When you use Chatbox AI you remain responsible for complying with them, including the requirement to obtain a valid opt-in from every recipient before messaging them and to honour opt-out requests promptly. We may suspend an account that generates sustained quality or blocking signals from Meta.
Access tokens issued by Meta and stored by Chatbox AI are held encrypted and used only to call the WhatsApp Business Cloud API on your behalf. You may revoke them at any time from your Meta Business Manager, which will immediately stop our access to your WhatsApp Business Account.
5. Legal Bases for Processing
Where data protection law requires us to identify a legal basis, we rely on the following:
- Performance of a contract — processing your account details, WhatsApp credentials, and message traffic is necessary to provide the service you subscribed to and to bill you for it.
- Consent — for optional marketing emails from Chatbox AI, and for non-essential analytics where consent is required. Consent may be withdrawn at any time without affecting the service. For end-customer messaging, the required consent is the recipient's WhatsApp opt-in, which the business account holder must obtain and be able to evidence.
- Legitimate interests — securing the platform, preventing fraud and spam, maintaining audit logs, understanding aggregate product usage, and improving reliability. We balance these interests against your rights and do not rely on them where they are overridden.
- Legal obligation — retaining invoices and tax records, and responding to lawful requests from competent authorities.
For end-customer data we process as a processor, the legal basis is established by the business account holder as controller; we act on its instructions.
6. Data Sharing and Sub-processors
We do not sell personal information and we do not share it with advertisers. We share data only with the service providers needed to run the platform, each bound by contractual confidentiality and data protection obligations:
- Meta Platforms — WhatsApp Business Cloud API. Receives message content, recipient phone numbers, template content, and delivery metadata in order to deliver messages.
- Razorpay — payment processing. Receives billing contact details and transaction data; card data is handled entirely within Razorpay's PCI-compliant environment.
- DigitalOcean — cloud hosting and managed databases, in the Bangalore region. Stores the platform's application data at rest.
- Anthropic — AI features such as reply drafting and conversation summarisation. Receives only the specific text needed to generate the requested output.
We may also disclose information where required by law, court order, or a valid request from a public authority; to establish or defend legal claims; or to protect the rights, safety, and property of Chatbox AI, our users, or the public. If Chatbox AI is involved in a merger, acquisition, or asset sale, data may be transferred to the successor entity, and we will notify affected account holders before it becomes subject to a different privacy policy.
7. Data Retention
We keep personal information only as long as needed for the purposes described in this policy:
- Account data is retained for the life of your subscription and deleted within 30 days of account closure, unless a longer period is legally required.
- Contact records, conversation history, and campaign data remain available while your account is active and are deleted when you delete them, when you delete your account, or within 30 days of account closure.
- WhatsApp access tokens are deleted immediately when you disconnect a WhatsApp Business Account or close your account.
- Billing and tax records are retained for the period required by applicable Indian financial and tax law, typically up to eight years.
- Technical and security logs are retained for up to 12 months, after which they are deleted or aggregated so that individuals can no longer be identified.
- Encrypted backups may persist for up to 35 days after deletion, after which they are overwritten on a rolling schedule.
8. Security
We maintain technical and organisational measures appropriate to the sensitivity of the data we handle:
- Encryption at rest — WhatsApp Business access tokens and other secrets are encrypted before being written to the database using authenticated symmetric encryption, with keys held outside the database.
- Encryption in transit — all traffic between your browser, our servers, and the WhatsApp Business Cloud API is protected with TLS.
- Credential handling — passwords are stored only as salted bcrypt hashes; sessions use signed, expiring tokens.
- Access controls — production access is limited to the small number of staff who need it, is individually authenticated, requires multi-factor authentication, and is logged.
- Tenant isolation — the platform is multi-tenant by design. Every record is scoped to a tenant identifier and every query is filtered by the authenticated account, so one business can never read or write another business's contacts, conversations, templates, or credentials.
- Operational hygiene — network firewalling, dependency patching, encrypted backups, and monitoring for anomalous activity.
No system can be guaranteed perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant supervisory authority without undue delay and describe what happened and what we are doing about it.
9. Your Rights
Subject to applicable law, you have the right to:
- Access — obtain confirmation of whether we process your personal information and receive a copy of it.
- Correction — have inaccurate or incomplete information corrected. Most account details can be edited directly in your dashboard settings.
- Deletion — request erasure of your personal information where we no longer have a lawful reason to keep it.
- Export and portability — receive your contacts, conversations, and campaign data in a structured, machine-readable format such as CSV or JSON.
- Objection and restriction — object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
- Withdraw consent — where processing relies on consent, withdraw it at any time.
To exercise any of these rights, email us at aryaditya760@gmail.com from the address associated with your account, stating which right you wish to exercise. We will verify your identity and respond within 30 days. If we need longer for a complex request, we will tell you why. There is no charge unless a request is manifestly unfounded or repetitive.
For step-by-step instructions on deleting your account, your contact lists, or a specific end customer's data, see our Data Deletion Instructions.
If you are an end customer, we will normally forward your request to the business that holds your data, since it is the controller and we act only on its instructions. You also have the right to complain to your local data protection authority.
10. International Transfers
Chatbox AI hosts its application data with DigitalOcean in the Bangalore, India region. However, some of our sub-processors operate globally, so your information may be transferred to and processed in other countries. In particular, Meta Platforms processes WhatsApp message traffic across its international infrastructure, and our AI and payment providers may process data outside India.
Where personal information is transferred across borders, we rely on appropriate safeguards — including standard contractual clauses or equivalent transfer mechanisms in our agreements with each sub-processor — so that the information continues to receive a comparable level of protection. You may request further detail on these safeguards by contacting us.
11. Children's Privacy
Chatbox AI is a business tool intended solely for use by adults acting on behalf of a business. It is not directed at children, and we do not knowingly collect personal information from anyone under 18 years of age. You may not create an account if you are under 18.
Business account holders must not upload contact lists consisting of minors or use the platform to market to children in breach of applicable law. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe a minor has provided us information, contact us at aryaditya760@gmail.com.
12. Changes to This Policy
We may update this Privacy Policy as the product evolves, as our sub-processors change, or as legal requirements shift. When we do, we will revise the "Last updated" date at the top of this page.
If a change materially affects how we handle your personal information — for example a new category of data, a new purpose, or a new sub-processor with access to message content — we will notify account holders by email or through an in-product notice before it takes effect. Continuing to use Chatbox AI after a change becomes effective means you accept the revised policy.
13. Contact Us
For any question about this policy, our data practices, a privacy request, or a suspected security issue, write to us at aryaditya760@gmail.com.
Please include your account email and a clear description of your request so we can respond quickly. We aim to acknowledge privacy enquiries within five business days and to resolve them within 30 days.
