Back to Home
Last Updated: January 2025
At ConvoKraft, we are committed to protecting your privacy and ensuring transparency about how we collect, use, and protect your information. This Privacy Policy explains our practices regarding data collection, processing, and your rights concerning your personal information.
1. Information We Collect
We collect information that you provide directly to us and information that is automatically collected when you use our services.
1.1 Information You Provide Directly
- Account Information: When you register for an account, we collect your email address, phone number, and any other information you choose to provide during registration.
- Authentication Data: We collect authentication credentials and tokens necessary for account access and security.
- Profile Information: We store user profile data including your WhatsApp business phone number, bot configurations, and preferences.
- Bot Configurations: Information about the AI assistants (bots) you create, including names, descriptions, and associated settings.
- Knowledge Base Content: Documents, files, and other content you upload to create knowledge bases for your bots.
- Chat Messages: Messages and conversations you have with our AI assistants through WhatsApp and other platforms.
1.2 Automatically Collected Information
- Usage Data: Information about how you interact with our platform, including pages visited, features used, and time spent on the platform.
- Device Information: Browser type, device type, operating system, IP address, and other technical information.
- Server Logs: Standard server logs including IP addresses, request timestamps, and access patterns.
- WhatsApp Integration Data: Messages received through WhatsApp webhooks, phone numbers, message metadata, and interaction data.
- Conversation History: Chat conversations and message exchanges stored to maintain context and improve service quality.
1.3 Third-Party Information
- Supabase Authentication: User authentication data managed by Supabase, including email verification status and session information.
- WhatsApp Business API: Message data, phone numbers, and metadata received through Meta's WhatsApp Business API.
- AWS Services: Data stored in AWS DynamoDB (user profiles, bot configurations) and AWS S3 (uploaded files and knowledge base content).
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Provision
- To create and manage your account and user profile
- To enable you to create, configure, and manage AI assistants (bots)
- To process and respond to messages sent through WhatsApp and other integrated platforms
- To maintain conversation context and history for improved AI responses
- To store and manage your uploaded files and knowledge base content
- To provide customer support and respond to your inquiries
2.2 Service Improvement
- To analyze usage patterns and improve our platform's functionality
- To enhance AI assistant performance and accuracy
- To develop new features and capabilities
- To troubleshoot technical issues and ensure system security
2.3 Communication
- To send you important updates about your account and our services
- To notify you about changes to our terms, policies, or services
- To respond to your support requests and inquiries
2.4 Legal and Security
- To comply with applicable laws, regulations, and legal processes
- To protect our rights, property, and safety, as well as that of our users
- To detect, prevent, and address fraud, security issues, and technical problems
3. How We Process Your Information
We process your information using the following methods and technologies:
- Data Storage: Your data is stored in secure cloud infrastructure including AWS DynamoDB (user profiles and bot configurations) and AWS S3 (uploaded files).
- Authentication: User authentication is handled through Supabase, which manages secure token-based authentication.
- Message Processing: WhatsApp messages are received through Meta's webhook system, processed by our AI backend, and responses are sent back through the WhatsApp Business API.
- AI Processing: Messages and conversation history are processed by AWS Bedrock AI agents to generate intelligent responses.
- Data Transmission: Data is transmitted over encrypted connections (HTTPS/TLS) to ensure security.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your information only in the following circumstances:
- Service Providers: We share data with trusted third-party service providers who assist us in operating our platform, including:
- Supabase (authentication and user management)
- AWS (cloud infrastructure, data storage, and AI services)
- Meta/WhatsApp (message delivery and WhatsApp Business API integration)
- Legal Requirements: We may disclose information if required by law, court order, or government regulation.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- With Your Consent: We may share information with your explicit consent or at your direction.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption of data in transit using TLS/SSL protocols
- Secure authentication mechanisms and token-based access control
- Regular security assessments and monitoring
- Access controls and authentication requirements for sensitive operations
- Secure cloud infrastructure provided by AWS
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy:
- Account Data: Retained for the duration of your account and for a reasonable period after account closure for legal and business purposes.
- Conversation History: Stored in memory during active sessions and may be retained for service improvement purposes.
- Uploaded Files: Retained as long as your account is active and associated with your bots.
- WhatsApp Messages: Processed in real-time and stored as necessary for conversation context and service delivery.
You may request deletion of your data at any time (see Section 7 below).
7. Your Rights and Data Deletion
You have the right to access, modify, and delete your personal information. To request deletion of your data, please contact us using one of the following methods:
When you submit a data deletion request, please include:
- Your account email address or user ID
- Confirmation that you want to delete your account and all associated data
- Any specific data categories you want deleted (if not requesting full account deletion)
We will process your request within 30 days and confirm when the deletion is complete. Please note that:
- Some information may be retained for legal or business purposes (e.g., transaction records, legal compliance)
- Deletion of your account will result in the permanent removal of all associated bots, files, and conversation data
- We may need to verify your identity before processing deletion requests
7.1 Additional Rights
- Access: You can request a copy of the personal information we hold about you.
- Correction: You can update your account information through your profile settings or by contacting us.
- Portability: You can request your data in a structured, machine-readable format.
- Objection: You can object to certain processing activities, subject to legal and contractual limitations.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
- Maintain your authentication session
- Remember your preferences and settings
- Analyze usage patterns and improve our services
You can control cookies through your browser settings, though disabling cookies may affect certain features of our platform.
9. Children's Privacy
Our services are not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately so we can delete that information.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using our services, you consent to the transfer of your information to these countries.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated policy on this page
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification (for significant changes)
Your continued use of our services after any changes indicates your acceptance of the updated Privacy Policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
This Privacy Policy is effective as of January 2025 and complies with Meta's Privacy Policy requirements for developers.