Back

Privacy Policy of watsi

Last updated: August 24, 2026

This Privacy Policy describes how watsi ("watsi", "we", "our", or "us") collects, uses, protects, and shares information when you use our services, including the website https://www.watsi.ai (the "Site"), the "watsi" mobile application for iOS and Android (the "App"), and our associated APIs and integrations (collectively, the "Services").

By using the Services, you accept the practices described in this policy. If you do not agree, please do not use the Services.

────────────────────────────────────────
1. WHO WE ARE
────────────────────────────────────────

watsi is a SaaS platform that helps small and medium-sized businesses manage customer conversations on WhatsApp, Instagram, Messenger, and the web widget on their own site, with automated responses powered by artificial-intelligence agents. watsi also imports leads generated from TikTok ads and, when the operator enables the channel, manages TikTok direct messages (see section 14). The Services are intended for business operators, not end consumers.

The watsi mobile App (iOS / Android) is an operational companion to the platform. Account creation and billing administration are handled exclusively from the website https://www.watsi.ai; the App only allows you to sign in with an account previously created on the website. This means that all user registration, company registration, subscription, and plan changes occur in the web environment, not on the mobile device.

────────────────────────────────────────
2. INFORMATION WE COLLECT
────────────────────────────────────────

2.1 Information you provide to us directly

• Account data: name, email address, password, company name, phone number, time zone, preferred language.
• Billing data: cardholder name, billing address. Card number and CVV are NEVER stored on our servers; they are processed directly by Stripe (a PCI-DSS Level 1 certified payment processor).
• Content you upload: imported contacts, message templates, internal notes, funnel configuration, profile images.

2.2 Information generated when using the Services

• Conversations: messages exchanged with your end customers through connected channels (WhatsApp Business, Instagram Direct, Messenger), including text, images, audio, documents, and metadata (timestamps, read status).
• Calendar events: appointments, reminders, and schedule blocks that you or your customers create.
• AI-generated summaries: the watsi agent may summarize conversations, extract customer data (name, phone, purpose of contact), and propose responses. These summaries are associated with the corresponding chat.
• Public contact metadata: for end contacts associated with connected messaging channels (WhatsApp, Instagram, Messenger), we may obtain public profile information — primarily the profile picture and display name — through the corresponding official channels or, complementarily, from data-enrichment providers. This information is used solely to display the contact in the watsi dashboard.

2.3 Technical information collected automatically

• Identifiers: internal user ID, company (workspace) ID, session ID, device push-notification token.
• Diagnostics: non-fatal error logs and crash reports, captured by Sentry. These logs include a technical stack trace but do not include message content or end-customer data.
• Usage metrics: aggregated product events (which screens are visited, which features are used), captured by PostHog.
• Device data: operating system, App version, device model, system language, anonymous device identifier.
• Connection data: IP address, user agent, session start and end timestamps.

2.4 Information we do NOT collect

• Precise location (GPS). The App does not request location permission.
• The operator's phone contacts (business contacts are imported manually or via API, never read automatically).
• Biometric data.
• Microphone or camera content beyond (a) the files you explicitly choose to attach to a conversation and (b) the audio of a WhatsApp call you place from the App, which is transmitted in real time to carry the call and is neither recorded nor stored.
• Data from minors (see Section 8).

2.5 Assistant call audio and transcripts (optional recording)

When the workspace (the operator) turns on call recording, the audio of calls with the AI assistant —phone calls (PSTN) and in-browser test calls— is recorded, transcribed, and stored encrypted to enable playback, transcript, and call summary. Recording is off by default; the operator decides whether to enable it. When it is active, the assistant speaks a notice at the start of the call stating that you are talking to an assistant and that the call may be recorded; the operator is responsible for notifying people and complying with the law applicable in its jurisdiction. Audio and transcripts are retained for 90 days and then deleted automatically (see Section 6). WhatsApp call audio is not recorded (see 2.4).

────────────────────────────────────────
3. PURPOSE OF PROCESSING
────────────────────────────────────────

We use your information to:

• Operate the Services: send and receive messages on your connected channels, generate AI responses, sync calendars, display the dashboard.
• Process payments and administer your subscription.
• Diagnose technical issues and improve stability through crash reports and logs.
• Analyze aggregate usage to prioritize product improvements.
• Send you operational notifications (account changes, reminders, integration failures).
• Comply with legal obligations (tax invoicing, record retention).

We do not use your information or the content of your conversations to train general artificial-intelligence models. The AI providers we work with (Anthropic, OpenAI, Google Vertex) also do not train models with data sent through their enterprise API, per their terms of service.

────────────────────────────────────────
4. PROVIDERS AND THIRD PARTIES WITH WHOM WE SHARE DATA
────────────────────────────────────────

To operate the Services we work with the following providers. Each processes data only to the extent necessary for its function:

• Supabase — database, authentication, and storage. Data stored in regions defined by Supabase (typically US-East). https://supabase.com/privacy
• Google Cloud Platform — compute infrastructure and storage of files uploaded in chats (images, audio, documents). https://cloud.google.com/terms/cloud-privacy-notice
• Anthropic (Claude), OpenAI (GPT), and Google Vertex AI — language models that generate the AI agent's responses. Conversation content is transmitted to the provider's API, processed, and returned. Providers do not train models with data sent via their enterprise API. https://www.anthropic.com/legal | https://openai.com/policies | https://cloud.google.com/terms/aiml
• Meta Platforms — to send and receive messages on WhatsApp Business, Instagram, and Messenger. Meta is responsible for message delivery on its platform. https://www.facebook.com/privacy
• TikTok / ByteDance — for lead generation from TikTok ad forms and, when the operator enables the channel, to send and receive TikTok direct messages (DMs). See Section 14 for details on TikTok data handling. https://www.tiktok.com/legal/privacy-policy
• Sentry — error and crash reporting. https://sentry.io/privacy/
• PostHog — product analytics. https://posthog.com/privacy
• Stripe — payment processing. PCI-DSS Level 1. https://stripe.com/privacy
• Resend — transactional email delivery (verification, password recovery, notifications). https://resend.com/legal/privacy-policy
• Google APIs — optional Google Calendar and Google Meet synchronization when the user authorizes it. https://policies.google.com/privacy
• LiveKit — real-time audio transport for WhatsApp calls placed from the App. Call audio is relayed through LiveKit while a call is in progress; it is not recorded or stored by us. https://livekit.io/legal/privacy-policy
• Expo (Expo Application Services) — delivery of push notifications to your device, relayed to Apple APNs and Google FCM. Receives the device push token and the notification content. https://expo.dev/privacy

We do not sell your personal data to third parties under any circumstances.

────────────────────────────────────────
5. INTERNATIONAL TRANSFERS
────────────────────────────────────────

Our own systems — database, authentication, application services, and file storage — operate exclusively in the United States. Some of the providers listed above process data on servers located outside Mexico, primarily in the United States. By using the Services, you acknowledge and authorize these transfers. We only work with providers that have standard contractual clauses or equivalent certifications (DPF, ISO 27001, SOC 2) to protect your data during transfer.

────────────────────────────────────────
6. DATA RETENTION
────────────────────────────────────────

• Conversations and contacts: retained while your account is active.
• Server logs: 30 days.
• Sentry crash reports: 90 days.
• PostHog metrics: 1 year at the aggregate level.
• Recorded call audio and transcripts: 90 days, after which the recording and its transcript are deleted automatically (see 2.5).
• Billing records: 5 years due to Mexican tax obligations.
• Account data after deletion: when you use the "Delete account" button in the App (or request it by email), your user identity is deleted immediately. If you were the last member of your workspace, that workspace's entire data graph — conversations, messages, contacts, appointments and files — is permanently purged by an automated daily process within 90 days. Encrypted backups may retain data for a further period beyond those 90 days before being purged. Billing records are kept for the tax retention period stated above, and audit records are retained in anonymized form.

────────────────────────────────────────
7. YOUR RIGHTS
────────────────────────────────────────

As the data subject, you have the right to:

• Access the information we hold about you.
• Rectify inaccurate data.
• Delete your account and associated data. You can do this directly from the App: Settings → Profile → Delete account. You may also request it by writing to soporte@watsi.ai.
• Object to processing or request restriction, in the cases provided by applicable law.
• Receive a copy of your data in a structured format (portability).
• Withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal.
• File a complaint with the competent data-protection authority (in Mexico, INAI: https://www.inai.org.mx).

To exercise any of these rights, write to us at soporte@watsi.ai. We will respond within 20 business days of receiving the request.

────────────────────────────────────────
8. CHILDREN'S PRIVACY
────────────────────────────────────────

The Services are intended exclusively for people over 18 years old in their role as business operators. We do not intentionally collect personal data from children under 13. If you are a parent or guardian and believe a minor has provided us with personal information, please contact us at soporte@watsi.ai so we can delete it.

────────────────────────────────────────
9. SECURITY
────────────────────────────────────────

We apply technical and organizational measures to protect your data:

• Encrypted connections with TLS 1.2+ between the client and our servers.
• Encryption at rest for the database and stored files.
• Authentication with signed JWT tokens and periodic rotation.
• Role-based access control (Supabase RLS) to ensure each company only accesses its own data.
• Audit logs of sensitive operations.
• Internal incident-response program.

No internet transmission or electronic storage is 100% secure. We make reasonable efforts, but cannot guarantee absolute security.

────────────────────────────────────────
10. COOKIES AND SIMILAR TECHNOLOGIES
────────────────────────────────────────

The Site uses strictly necessary cookies to maintain your session, which do not require your consent. Product analytics (PostHog) and third-party advertising-measurement technologies (Meta Pixel), which may be linked to your identity, are NOT activated until you accept them in the cookie notice: if you decline, they are not loaded and the Site works just the same. We also use cookieless analytics (Plausible), which does not identify you or follow you across sites. You can change your mind by clearing the Site's cookies from your browser settings, and limit personalized advertising from your Meta account's ad settings. The mobile App does not use traditional cookies; it uses secure local identifiers (Keychain on iOS, Keystore on Android) to maintain the session.

────────────────────────────────────────
11. CHANGES TO THIS POLICY
────────────────────────────────────────

We may update this Policy periodically. When changes are material (for example, new data providers or new processing purposes), we will notify you by email and/or via a prominent notice within the Services at least 15 days in advance. Continuing to use the Services after the change takes effect constitutes acceptance.

────────────────────────────────────────
12. CONTACT
────────────────────────────────────────

If you have questions, concerns, or requests about this Policy or your data:

• Email: soporte@watsi.ai
• WhatsApp: https://wa.me/526634404555
• Postal address: watsi, Inc., 41 West Highway 14 #129, Spearfish, SD 57783, United States.

Data controller: watsi, Inc., a corporation incorporated in the State of Delaware, United States, with its address at 41 West Highway 14 #129, Spearfish, SD 57783, United States. Its operating team is located in Mexico.

────────────────────────────────────────
13. GOOGLE DATA — GOOGLE API SERVICES USER DATA POLICY
────────────────────────────────────────

This section specifically describes how watsi receives, uses, stores, and shares information obtained from Google APIs (Google Calendar, Google Meet, Google OAuth) and complies with the Google API Services User Data Policy, including the Limited Use requirements.

13.1 Google data we request

When a user connects their Google account to watsi from Settings → Integrations, we request the following OAuth permissions (scopes):

• openid, userinfo.email, userinfo.profile — to identify the connected Google account and display the email in the interface.
• https://www.googleapis.com/auth/calendar — to create, read, update, and delete events in the calendars the user selects during the connection flow.
• https://www.googleapis.com/auth/calendar.events — to detect conflicts before confirming an appointment and to reflect events created outside watsi within the CRM.
• https://www.googleapis.com/auth/meetings.space.settings — so that, when the business enables it, the Google Meet video calls watsi creates for an appointment let guests join straight from the link instead of waiting to be admitted. Only the access setting of those meetings is changed.

13.2 What we use Google data for

Data obtained via Google APIs is used exclusively to:

• Create, modify, and cancel calendar events when the operator or the AI agent confirms, reschedules, or cancels an appointment with an end customer within the CRM.
• Read existing events in the connected calendar to detect scheduling conflicts before confirming a new booking.
• Display externally created events in the CRM timeline, so the operator has a unified view of their schedule.

We do not use Google data for any other purpose.

13.3 Limited Use compliance

watsi complies with the Google API Services User Data Policy, including the Limited Use section. Specifically:

• We do not transfer data obtained from Google APIs to third parties, except to the extent strictly necessary to operate the service the user requested, to comply with applicable law, or as part of a merger, acquisition, or asset sale with prior notice to the user.
• We do not use or transfer data obtained from Google APIs for advertising purposes, including personalized or remarketing advertising.
• We do not allow humans to read data obtained from Google APIs, except: (a) with the user's explicit consent for specific support cases, (b) for security reasons (investigation of abuse or vulnerabilities), (c) to comply with applicable law, or (d) when the data has been aggregated and irreversibly anonymized.
• We do not use data obtained from Google APIs to develop, improve, or train generalized artificial-intelligence models.

13.4 Storage and security

• Access tokens (access_token) and refresh tokens (refresh_token) are stored encrypted at rest in our database.
• Synchronized calendar events are stored only with the fields necessary (title, time, attendees, location) for the CRM to function.
• Access to Google data is restricted to the workspace that connected the account — no other watsi customer has access to that data.
• We apply the security measures described in Section 9 of this policy.

13.5 Retention and deletion

• The user can disconnect their Google account at any time from Settings → Integrations → Google Calendar → Disconnect.
• Upon disconnection, watsi immediately revokes the OAuth token with Google (via Google's official revocation endpoint) and deletes the locally stored tokens. After that, watsi can no longer read or write data in the user's Google account.
• Previously synchronized events are retained in the CRM until the user deletes the corresponding records or closes their watsi account (see Section 6 on general retention).
• The user can also manually revoke access from https://myaccount.google.com/permissions without going through watsi.

13.6 Contact for Google APIs matters

For specific questions about the handling of data from Google APIs, write to us at soporte@watsi.ai with the subject "Google APIs Data Request" and we will respond within 20 business days.

────────────────────────────────────────
14. TIKTOK DATA — TIKTOK / BYTEDANCE PLATFORM DATA
────────────────────────────────────────

This section specifically describes how watsi receives, uses, stores, shares, and deletes information obtained from the TikTok/ByteDance platforms: the TikTok Marketing API (lead generation) and, when the operator enables the channel, TikTok Business Messaging (direct messages).

14.1 TikTok data we receive

Lead generation, when the operator connects a TikTok advertising account:
• Data from the lead form the end user submits in a TikTok ad: name, email, and phone, plus any custom fields the operator has configured.
• Campaign identifiers: lead id, advertiser id, and form id.

Direct messages (DMs), only when the operator enables the TikTok channel:
• open_id: a stable identifier for the end user's TikTok account (not a phone number).
• Display name and public profile picture of the TikTok account (optional enrichment).
• The content of messages the end user initiates with the operator.

14.2 What we use TikTok data for

• Import into the operator's CRM the leads generated in TikTok ads, with deduplication against existing contacts.
• Display and manage TikTok conversations in the operator's dashboard and, via the AI agent, generate responses to messages the end user initiates.
• TikTok DMs operate in reactive mode: we only reply to conversations initiated by the end user, within the time window allowed by TikTok. watsi does not send mass or proactive messages on this channel.

We do not use TikTok data for advertising or remarketing purposes, nor to develop, improve, or train generalized artificial-intelligence models. Message content is transmitted to the AI providers described in Sections 3 and 4 solely to generate the agent's response; those providers do not train models with data sent through their enterprise API.

14.3 Storage, location, and security

• TikTok data is stored on the same infrastructure described in Sections 4, 5, and 9: a database managed by Supabase (United States) and files on Google Cloud Platform (United States).
• Company (workspace) isolation through row-level access control (RLS): each operator only accesses their own TikTok data.
• Encryption at rest and TLS in transit. Integration credentials are kept restricted to the workspace that connected the account.
• TikTok data is not accessed from restricted countries.

14.4 Retention

• Raw TikTok lead events are retained with their payload for up to 30 days, and as operational metadata for up to 365 days, after which they are purged.
• Normalized leads are retained in accordance with the general retention policy (Section 6) or until the operator deletes them.
• TikTok conversations are retained while the account is active, subject to Section 6.

14.5 Data deletion on request

• The end user may request deletion of their TikTok data, and TikTok/ByteDance may transmit that request to watsi. watsi processes these requests by deleting, as applicable, the user's TikTok messages and conversation (identified by their open_id) or the imported lead (identified by its lead id), including derived records, and keeps an audit log of the deletion as evidence of compliance.
• The operator can disconnect the TikTok account at any time from Settings → Integrations; disconnecting revokes and deletes the stored credentials.
• For TikTok data-deletion requests, write to us at soporte@watsi.ai with the subject "TikTok Data Deletion Request" and we will respond within 20 business days.

14.6 Contact for TikTok data matters

For specific questions about the handling of data from TikTok/ByteDance, write to us at soporte@watsi.ai with the subject "TikTok Data Request" and we will respond within 20 business days.

By using watsi, you acknowledge that you have read and understood this Privacy Policy.