This policy has not yet been reviewed by outside legal counsel. It accurately describes what Chatmeo collects and who it's shared with, but shouldn't be treated as a substitute for professional legal review before relying on it at scale.
How Chatmeo collects, uses, and protects information — for the businesses who build bots with us, and the people who chat with those bots.
This policy applies to two different people, and we're specific below about which one each section means:
If you're an end user chatting with a Chatmeo-powered bot, the business you're messaging is the one responsible for that conversation and its own privacy practices — Chatmeo processes that conversation on their behalf, as described below.
| Category | Examples |
|---|---|
| Account | Name, email address, hashed password, profile image |
| Bot configuration | Flows, prompts, welcome messages, uploaded knowledge-base documents, branding/theme choices |
| WhatsApp connection | WhatsApp Business Account ID, phone number ID, display phone number, an encrypted long-lived access token |
| Usage | Conversation counts, message volume, login activity, feature usage |
| Security | Two-factor authentication method and (if enabled) an encrypted authenticator secret |
| Category | Examples |
|---|---|
| Conversation content | Messages sent to and received from the bot, and a per-visitor or per-contact identifier used to keep a conversation's history together |
| WhatsApp identifiers | If messaging via WhatsApp: your WhatsApp ID (phone number) and the message timestamps Meta provides |
| Widget technical data | If chatting via an embedded widget: the domain the widget was loaded from, for basic abuse prevention |
When a bot uses an AI-generated response, the relevant conversation history and your configured system prompt are sent to a third-party AI provider — currently xAI (Grok) or OpenRouter, depending on how the bot is configured — to generate the reply. That provider processes the request and returns a response; it does not use your conversations to improve models we don't control, beyond whatever that provider's own terms specify.
Uploaded knowledge-base documents attached to an AI-enabled part of a flow are stored as extracted text and included the same way, only when relevant to generating a reply.
Connecting a bot to WhatsApp uses Meta's Embedded Signup flow. When an account holder connects a number:
Meta's own WhatsApp Business Policy and Meta Privacy Policy also apply to how Meta handles data in transit through WhatsApp.
No system is perfectly secure, but we design storage of anything sensitive — tokens, passwords, verification codes — around the assumption that a breach of the database alone shouldn't hand over anything usable.
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing:
To exercise any of these rights, contact us using the details in Contact us. We'll respond within 30 days.
Chatmeo is not directed at children, and account holders must be old enough to enter a binding agreement in their jurisdiction. We don't knowingly collect personal information from children through account registration.
Chatmeo is based in Nigeria, and the infrastructure and service providers we rely on — hosting, database, AI providers, WhatsApp/Meta — are located in other countries, including the United States. Your information may be processed outside the country you're in as a result. Where required, we rely on standard contractual protections and our providers' own compliance commitments to safeguard data that crosses borders this way.
If we make material changes to this policy, we'll update the effective date above and, where required, notify account holders directly.
Questions about this policy, or a request to access, export, or delete your data:
Chatmeo
novapixelstudios001@gmail.com
Port Harcourt, Nigeria