Privacy Policy
Safe AI Global Private Limited makes WhatsApp on Rails (WAM). This policy explains what happens to personal data in three places: this website, which collects close to nothing; the hosted service, where your account and the data your linked number handles live; and a deployment you run yourself, where none of it reaches us at all.
1What this policy covers
- This website
- The pages you are reading. Section 2 describes what they collect, which is close to nothing.
- The hosted service
- Your account at WAM, the numbers you link to it, and everything the service stores to do its job. Sections 3 to 6 cover it.
- A deployment you run yourself
- The same software on your own infrastructure. The data it handles never reaches us. Section 7 documents what it processes so you can meet your own obligations.
2What this website collects
These are static pages. There are no cookies, no analytics, no tag managers, no advertising pixels, no session recording, no fonts or scripts or images loaded from a third party, and no forms. Opening this site does not create a record with us and does not identify you to anyone.
Our hosting provider produces ordinary server logs as a by-product of serving the page, typically an IP address, a timestamp, the requested path and a user agent string. Those exist for security and reliability. We do not use them to build a profile, we do not combine them with other data, and we do not attempt to identify you from them.
3Your account on the hosted service
When you create an account we store your name, your email address, a hash of your password rather than the password, and the secret and recovery codes for your two-factor authenticator. We store the plan you are on and, if you subscribe, the identifier and status of that subscription. We keep an audit trail of account security events: sign-ins, failed attempts, key creation and revocation, and administrative actions, with the time and the account concerned.
We use this to run your account, to secure it, to bill you, and to answer you when you write to us. We do not use it for advertising and we do not sell it.
4What the service stores for your linked numbers
To operate a number on your behalf the service has to hold the same things WhatsApp Web would hold on a laptop. All of it is stored in your account and used only to provide the service to you.
- Pairing credentials
- The keys created when you scan the code from your phone. They are equivalent to a signed-in session for that number and are deleted when you unlink it.
- Messages
- Sender, recipient, timestamps, text and media references for messages the linked number sends and receives. Media itself is stored only when a feature you use needs it, such as an automation that reads an attachment.
- Contacts and groups
- Phone numbers, WhatsApp identifiers, display names and group membership, accumulated from what the protocol delivers. WhatsApp offers no contact download; this store only contains what arrived through ordinary use of the number.
- Automations and run records
- The flows you build, and a record of each test or live run with what each step sent and received. Header values are redacted before they are written down, because that is where credentials usually sit.
- Credentials you add
- API keys for providers such as OpenRouter that you enter for the AI step. They are used only to make the calls your flows describe. The console shows a masked preview and there is no way to read one back out.
- Activity log
- A record of operations performed through the API and the console, so you can see who did what with your number.
We do not read your messages for any purpose other than delivering the service you asked for, we do not use them for advertising, and we do not use them to train models. Our staff access account data only to support you, at your request, or to investigate a breach of our policies, and every such access is logged.
5Third parties the service talks to
- WhatsApp and Meta
- Using the service sends and receives data through WhatsApp servers operated by Meta. That traffic is governed by WhatsApp’s privacy policy, not this one, and neither of us can opt out of it while using WhatsApp.
- Our payment partner
- Pro subscriptions are processed by a payment provider acting as merchant of record. It collects your card details and billing address directly; we receive a customer identifier, the subscription status and the last four digits of the card, never the full number. Its privacy policy is shown at checkout.
- Destinations you configure
- When you build an automation that calls your own server, an n8n webhook or a model provider such as OpenRouter, the content you wire into that step is sent there. You chose the destination and its terms apply to what arrives. We send nothing to those services on our own initiative.
- Hosting and email
- Providers who host the service and deliver our email, bound to process only on our instructions.
7If you run the software yourself
None of the data described in section 4 reaches us. The software carries no telemetry and opens no connection back to us. You are the data fiduciary under the Digital Personal Data Protection Act, 2023, and the controller under the General Data Protection Regulation where it applies; you decide whose data is processed and why, and the duties of notice, consent, rights requests and breach reporting are yours. Where we operate a deployment for you under a written agreement, we act as a processor on your documented instructions and that agreement governs.
8Who is responsible for what
For your account details, we are the data fiduciary and controller. For the messages, contacts and group data your linked number handles, you are the fiduciary and controller and we process it on your instructions to provide the service. That means you decide whom your number writes to and on what basis, and you answer their requests; we answer yours.
9Where data is held
Safe AI Global is incorporated in India. Our hosting, payment and email providers may store data outside India. Where personal data crosses a border we rely on the transfer mechanisms permitted under the applicable law, including the standard contractual clauses under the General Data Protection Regulation where the transfer involves the European Economic Area.
10Security
- Two-factor authentication is required on every account, and a password alone never produces a session.
- Console access tokens live in httpOnly cookies that page JavaScript cannot read; the live event stream uses a separate ticket that expires in about a minute.
- API keys are bound to one number and carry only the permissions you grant. A request for a number you do not own returns "not found", so the API cannot be used to discover which numbers exist.
- Outbound calls made by automations run in a separate container that holds no credentials and cannot reach private networks.
- Passwords are checked against the leaked-password lists at sign-up. Sign-in and code verification are throttled with escalating lockouts.
- The pairing code shown when you link a number is never stored or published anywhere.
No system is perfectly secure. If we learn of a breach affecting your data we will tell you without undue delay and, where the law requires it, notify the relevant authority.
11Your rights
Under the Digital Personal Data Protection Act, 2023 you may ask us for a summary of the personal data we process about you and how, ask us to correct, complete, update or erase it, nominate someone to exercise these rights on your behalf, withdraw a consent as easily as you gave it, and raise a grievance with us.
If the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies to you, you also have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority.
Write to tech@safeai.global to exercise any of these. We respond within thirty days. There is no charge. Most of what you might ask for you can also do yourself: unlink a number, delete an automation, revoke a key or close the account from the console.
If you are not our customer but your data was handled by a number one of our customers operates, we will tell you so promptly and, where we can, point you to the operator, because they are the one who can act on it.
12Retention
- Website server logs: under our hosting provider’s retention period, ordinarily no more than thirty days.
- Account details and audit trail: for the life of the account and ninety days after it is closed, then deleted.
- Message history, contacts and run records: for as long as the number stays linked. Unlinking a number deletes its pairing credentials at once and its stored data within thirty days.
- Billing records: seven years, as tax law requires.
- Email correspondence: three years from the last message, or longer while a legal matter is live.
- Do Not Contact suppression entries: for as long as needed to honour the request, as the Do Not Contact Policy explains.
13Children
Neither this website nor the service is directed at people under eighteen, and we do not knowingly process a child’s personal data. If you operate a number in a setting where children may be reached, the verifiable parental consent the Digital Personal Data Protection Act, 2023 requires is your responsibility.
14Changes to this policy
We publish changes on this page with a new effective date and email account holders about material ones. Where a change materially reduces the protection this policy offers, it takes effect no earlier than fourteen days after publication.
15Questions, requests and grievances
Send anything about this policy to tech@safeai.global.
Under the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, you may raise a grievance with our Grievance Officer at the same address, marking your message for their attention.
We acknowledge grievances within twenty-four hours and aim to resolve them within thirty days. If you are not satisfied, you may complain to the Data Protection Board of India, or to your own supervisory authority if you are outside India.