Official Policy & Meta Compliance

Privacy Policy

Last Updated: August 23, 2026

Privacy Commitment: ConvoPilot provides a multi-tenant business software service. We process messaging and bot configuration data solely on behalf of our customer organizations to automate business communications across channels like WhatsApp.

1. Introduction

Welcome to ConvoPilot ("we," "our," or "us"). ConvoPilot operates a multi-tenant Software-as-a-Service (SaaS) platform that enables business organizations to create, configure, test, and manage automated customer support bots and conversational workflows across supported digital channels, including WhatsApp Business.

This Privacy Policy explains how we collect, store, process, protect, and handle personal and organizational information when you register for a ConvoPilot account, access our dashboard, configure bot workflows, or connect third-party communication channels such as Meta WhatsApp Business accounts.

2. Information We Collect

We collect information in the following categories:

  • Account & Profile Information: When an individual registers for ConvoPilot via Supabase Authentication, we collect their email address, encrypted authentication credentials, full name, and optional avatar URL.
  • Organization & Workspace Data: Details regarding your registered business workspace, including organization name, unique URL slug, business address, phone number, website, timezone, and assigned team member roles (Owner, Admin, Agent, Viewer).
  • Bot Configuration Data: Settings created within your workspace, such as bot name, description, avatar URL, default language, greeting messages, fallback responses, typing indicator preferences, response delays, AI model parameters (e.g. system instructions, temperature, token limits), and visual conversation flows.
  • Technical Log & Session Data: Browser type, operating system, IP address, request timestamps, and authentication session tokens necessary to secure your account.

3. Information Received Through Connected Services

ConvoPilot allows organizations to connect official third-party communication channels, primarily Meta platforms (such as WhatsApp Business Accounts and Instagram Professional accounts).

When an organization initiates Meta authorization via Meta Embedded Signup or Facebook Login for Business, we receive authorization credentials, Meta Business Account IDs, WhatsApp Business Account (WABA) IDs, and verified phone number identifiers necessary to route webhooks and messages to your bot.

4. How We Use Information

We process collected information for the following legitimate business purposes:

  • Providing, maintaining, and improving the ConvoPilot SaaS platform.
  • Authenticating authorized team members and enforcing multi-tenant role permissions.
  • Executing configured conversation flows and bot logic in response to incoming customer messages.
  • Delivering webhook notifications and automated responses to connected WhatsApp channels.
  • Facilitating human agent handoffs when bot automation transitions conversations to team members.
  • Ensuring platform security, monitoring for fraudulent activity, and resolving technical errors.
5. WhatsApp and Instagram Data

If you choose to connect a supported WhatsApp Business or Instagram Professional account to ConvoPilot, we process information made available through the connected service strictly to provide messaging, automation, customer-support, and AI bot functionality requested by you.

The information processed may include account identifiers, verified phone numbers, phone number IDs, incoming message content, sender phone numbers, timestamps, message delivery statuses, and other data necessary to deliver your bot workflows.

We use this information only for the purposes described in this Privacy Policy and to provide the services requested by the organization that connected the account. We do not use WhatsApp customer message content for advertising, marketing profiling, or unauthorized third-party sales.

6. AI and Bot Processing

ConvoPilot includes support for generative AI models (such as Google Gemini and OpenAI). When AI response modes or AI workflow nodes are enabled by an organization:

  • Your configured System Instructions, business profile details, and relevant conversation context are transmitted to the designated AI provider to generate natural language answers.
  • Data transmitted to AI model providers is processed in accordance with the enterprise API data policies of those providers, which state that API data is not used to train public foundational models.

7. Data Storage and Security

We implement industry-standard administrative, physical, and technical safeguards to protect all stored information:

  • PostgreSQL Row Level Security (RLS): Multi-tenancy is enforced directly at the database layer. Database policies guarantee that users in Organization A can never query, read, update, or delete records belonging to Organization B.
  • Encryption: All web traffic and API communications are encrypted in transit using Transport Layer Security (TLS/HTTPS). Sensitive channel credentials and access tokens are protected using server-side security measures.
  • Infrastructure: Our database and authentication systems are hosted on enterprise infrastructure provided by Supabase and Vercel.

8. Data Retention

We retain organization records, bot configurations, and conversation logs for as long as your workspace account remains active or as required to comply with our legal obligations, resolve disputes, and enforce our agreements.

Organizations can delete bot configurations or request permanent deletion of workspace records at any time.

9. Data Sharing and Disclosure

We do not sell, rent, or trade your personal or customer information. We only share information in the following limited circumstances:

  • Sub-processors and Service Providers: Trusted third-party vendors who provide infrastructure hosting (Vercel), database and authentication (Supabase), and AI computation (Google/OpenAI) under strict confidentiality agreements.
  • Third-Party Integrations: Meta Platforms, Inc., to facilitate WhatsApp and Instagram messaging via official APIs.
  • Legal Compliance: When required by applicable law, regulation, subpoena, or governmental request.

10. Third-Party Services

Our service interacts with third-party platforms such as Meta Platforms, Inc. Your use of third-party platforms is subject to their respective terms and privacy policies. We encourage you to review Meta's Privacy Policy regarding WhatsApp Business and Instagram data.

11. User Rights and Controls

Depending on your jurisdiction (such as GDPR in Europe or CCPA in California), you may have the right to access, rectify, port, or request erasure of your personal data.

Workspace owners can manage profile settings, disconnect channel integrations, or modify bot data directly within the ConvoPilot dashboard.

12. Data Deletion Instructions

If you want to request deletion of information associated with your ConvoPilot account, connected WhatsApp Business numbers, or stored customer messages, please visit our dedicated public Data Deletion page:

13. Cookies and Local Storage

ConvoPilot uses essential session cookies to maintain your authenticated login state and local storage keys (such as theme) to preserve your dark/light appearance preferences. We do not use invasive third-party cross-site tracking cookies.

14. Children’s Privacy

Our services are strictly intended for commercial and business use by individuals aged 18 and older. We do not knowingly collect personal data from children under the age of 16.

15. Changes to This Privacy Policy

We may periodically update this Privacy Policy to reflect changes in our service features, integration capabilities, or legal requirements. Updated policies will be posted to this URL with an updated revision date.

16. Contact Us

If you have questions, privacy inquiries, or data requests regarding this Privacy Policy, please reach out to our team: