Legal · Privacy

Privacy Policy

Effective July 24, 2026

This policy explains what data Zitrabot collects when you or your customers use our WhatsApp, Instagram, and web-chat AI assistants, and how that data is used, shared, and protected.

01

Who this applies to

This Privacy Policy covers two groups of people: business owners who create an account and deploy a Zitrabot assistant ("Account Holders"), and the end customers who message an Account Holder's WhatsApp, Instagram, or embedded web-chat assistant ("End Users"). Where the two are treated differently, this policy says so explicitly.

If you are an End User messaging a business that uses Zitrabot, the Account Holder is the data controller for your conversation — they decide what the assistant is for and what happens with a handed-off conversation. Zitrabot processes that conversation on their behalf to run the service.

02

Data we collect

We collect different data depending on how you use Zitrabot.

  • Account data: name, email address, hashed password, and business details you provide when registering or completing onboarding.
  • Bot configuration: the training data, description, and integration settings you use to configure an assistant.
  • Conversation data: message content, timestamps, and sender identifiers (WhatsApp phone number, Instagram-scoped user ID, or an anonymous web-chat session ID) for conversations handled by an assistant, including any images submitted (for example, payment receipt screenshots).
  • Calendar data: if you connect Google Calendar, we store the OAuth tokens needed to create, reschedule, and cancel meetings on your behalf, and read enough of your calendar's free/busy status to avoid double-booking.
  • Payment data: subscription and billing status, and transaction references from our payment processor. We do not store full card numbers — those are handled directly by our payment processor.
  • Technical data: IP address, device/browser information, and request logs, collected automatically for security and reliability purposes.
03

How we use your data

Except where noted below for Google user data, we use collected data to:

  • Operate the assistant: generate replies using a third-party AI model, execute configured actions (like creating a Google Meet or looking up an order), and route conversations to a human agent when needed.
  • Maintain your account: authenticate you, enforce plan limits, and send service-related emails (verification codes, password resets, billing notices).
  • Improve reliability and security: detect abuse, debug issues, and prevent duplicate message processing.
  • Meet legal and contractual obligations, including responding to lawful requests from authorities.
04

Google user data & the Google API Services User Data Policy

If you connect Google Calendar, Zitrabot's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We request read/write access to your Google Calendar for one purpose only: to power the assistant's meeting-scheduling feature. Specifically, we use this access to create, reschedule, and cancel Google Meet meetings on your behalf, and to check your calendar's free/busy status so the assistant doesn't double-book you. We do not use Google user data for any other purpose.

We do not use Google user data for advertising or marketing, we do not sell it, and we do not use it to train AI models. When a customer asks your assistant to schedule or check a meeting, the relevant calendar details (for example, a proposed time, a busy/free result, or a meeting summary) are passed to our AI model provider (OpenAI) solely so the assistant can respond to that specific request within the same conversation — this is the only third-party sharing of Google user data that occurs, and it exists only to provide the feature you requested.

We do not grant any human at Zitrabot access to your Google user data except where necessary for security, to comply with law, with your consent, or to investigate abuse consistent with Google's policies.

Google OAuth tokens are stored securely and used only for the API calls above. You can revoke Zitrabot's access to your Google Calendar at any time from your dashboard, or directly from your Google Account's third-party access settings — doing so immediately stops all further Google data access.

05

Third parties we share data with

We do not sell personal data. We share data with the following categories of service providers, strictly to deliver the service:

  • Meta Platforms, Inc. — to send and receive WhatsApp and Instagram messages via their APIs, as required for the assistant to function on those channels.
  • OpenAI — conversation content is sent to generate the assistant's replies. OpenAI processes this data under its own API data-use terms and does not use API data to train its models by default.
  • Google — if you connect Google Calendar, meeting details and calendar availability are exchanged with Google's Calendar API strictly to provide the scheduling feature described above (see "Google user data & the Google API Services User Data Policy").
  • Cloud infrastructure and storage providers — including our database host and image storage provider, to store account, conversation, and receipt-image data securely.
  • Payment processors — to handle subscription billing and, where applicable, bank-transfer receipt verification.
  • Email delivery providers — to send verification, password-reset, and transactional emails.
06

Data retention

We retain account and conversation data for as long as your account is active, plus a limited period afterward to comply with legal, tax, or dispute-resolution obligations. You can request deletion of your account and associated bots at any time; this permanently removes your bots and their configuration. Conversation records may be retained for a shorter, additional period to resolve billing disputes or investigate abuse before final deletion.

07

Your rights

Depending on where you're located, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Account Holders can manage most of this directly from the dashboard; End Users should contact the business they messaged first, since that business controls the conversation, or contact us directly and we'll coordinate with them.

08

Security

We apply industry-standard safeguards including encrypted transport (HTTPS), hashed passwords, access-controlled infrastructure, and signature verification on inbound webhook traffic. No system is perfectly secure, and we encourage you to use a strong, unique password and enable any additional account protections we offer.

09

International data transfers

Our service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) to protect data transferred internationally.

10

Children's privacy

Zitrabot is intended for business use and is not directed at children. We do not knowingly collect personal data from children under 13 (or the minimum age required by local law). If you believe a child has provided us with personal data, contact us and we'll remove it.

11

Changes to this policy

We may update this policy as our service evolves. We'll update the "Effective" date above and, for material changes, notify Account Holders by email or in-app notice.

Questions?

Reach us at zitranet@zitranet.com and we'll get back to you within our standard 24hr response window.