chatmeoSign in
Effective August 9, 2026 · v1.0

This policy has not yet been reviewed by outside legal counsel. It accurately describes what Chatmeo collects and who it's shared with, but shouldn't be treated as a substitute for professional legal review before relying on it at scale.

Privacy Policy

How Chatmeo collects, uses, and protects information — for the businesses who build bots with us, and the people who chat with those bots.

In short

  • We store your account, bot configuration, and conversation history for as long as your account is active.
  • Message content is sent to an AI provider (xAI or OpenRouter) to generate bot replies, and to Meta's WhatsApp Business Platform to deliver and receive WhatsApp messages.
  • WhatsApp access tokens are encrypted at rest and deleted the moment you disconnect a number.
  • We don't sell personal information, to anyone, ever.

Contents

  1. 01Who this policy covers
  2. 02Information we collect
  3. 03How we use it
  4. 04AI providers & message content
  5. 05WhatsApp Business Platform
  6. 06Who we share data with
  7. 07Retention & deletion
  8. 08Security
  9. 09Your rights & choices
  10. 10Children's privacy
  11. 11International transfers
  12. 12Changes to this policy
  13. 13Contact us

01Who this policy covers

This policy applies to two different people, and we're specific below about which one each section means:

  • Account holders — the businesses and individuals who sign up for Chatmeo to build and operate a bot (referred to here as "you," "your bot").
  • End users — the customers, visitors, or contacts who chat with a bot built on Chatmeo, whether through an embedded website widget or a connected WhatsApp number.

If you're an end user chatting with a Chatmeo-powered bot, the business you're messaging is the one responsible for that conversation and its own privacy practices — Chatmeo processes that conversation on their behalf, as described below.

02Information we collect

From account holders

CategoryExamples
AccountName, email address, hashed password, profile image
Bot configurationFlows, prompts, welcome messages, uploaded knowledge-base documents, branding/theme choices
WhatsApp connectionWhatsApp Business Account ID, phone number ID, display phone number, an encrypted long-lived access token
UsageConversation counts, message volume, login activity, feature usage
SecurityTwo-factor authentication method and (if enabled) an encrypted authenticator secret

From end users chatting with a bot

CategoryExamples
Conversation contentMessages sent to and received from the bot, and a per-visitor or per-contact identifier used to keep a conversation's history together
WhatsApp identifiersIf messaging via WhatsApp: your WhatsApp ID (phone number) and the message timestamps Meta provides
Widget technical dataIf chatting via an embedded widget: the domain the widget was loaded from, for basic abuse prevention

03How we use it

  • Operate the service: run your bot's flows, generate replies, and deliver them over the channel a conversation came in on.
  • Maintain your account: authentication, two-factor verification, password resets, service emails.
  • Keep a conversation history so an account holder's inbox reflects what customers actually said.
  • Enforce usage limits and prevent abuse of the platform.
  • Improve reliability and fix problems — we look at aggregated usage and error data, not individual conversation content, for this.

04AI providers & message content

When a bot uses an AI-generated response, the relevant conversation history and your configured system prompt are sent to a third-party AI provider — currently xAI (Grok) or OpenRouter, depending on how the bot is configured — to generate the reply. That provider processes the request and returns a response; it does not use your conversations to improve models we don't control, beyond whatever that provider's own terms specify.

Uploaded knowledge-base documents attached to an AI-enabled part of a flow are stored as extracted text and included the same way, only when relevant to generating a reply.

05WhatsApp Business Platform

Connecting a bot to WhatsApp uses Meta's Embedded Signup flow. When an account holder connects a number:

  • Chatmeo receives a long-lived access token from Meta, which is encrypted at rest and used only to send messages and manage the webhook subscription for that number.
  • Inbound WhatsApp messages arrive through Meta's webhook platform; Chatmeo verifies each delivery is genuinely from Meta before processing it.
  • Automated replies are only sent within the messaging window Meta's platform allows (currently 24 hours from the customer's last message) — outside that window, we don't attempt to send one.
  • An account holder can pause automated replies at any time without affecting the underlying Meta connection, or fully disconnect — which revokes Chatmeo's access with Meta and immediately deletes the stored token.

Meta's own WhatsApp Business Policy and Meta Privacy Policy also apply to how Meta handles data in transit through WhatsApp.

06Who we share data with

We share information only with the service providers that make Chatmeo work, under agreements that limit what they can do with it — never for advertising, and never sold.

ProviderPurpose
Meta / WhatsApp Business PlatformSending and receiving WhatsApp messages you've connected
xAI / OpenRouterGenerating AI bot replies
ResendTransactional email (verification, password reset, notifications)
Database & hosting infrastructureStoring and serving the application and its data

We may also disclose information if required by law, or to protect the rights, safety, or property of Chatmeo, our users, or the public.

07Retention & deletion

  • Account and bot data is retained for as long as the account is active.
  • Conversation history is retained so account holders can review it in their inbox, until the account holder deletes it or closes their account.
  • A WhatsApp access token is deleted immediately on disconnect — not just deactivated.
  • Account holders can request deletion of their account and associated data by contacting us below.

08Security

  • Passwords are hashed, never stored in plain text.
  • WhatsApp access tokens are encrypted at rest (AES-256-GCM) with a key separate from the one used for authentication secrets, so rotating one never exposes the other.
  • Data in transit is encrypted (HTTPS/TLS).
  • Optional two-factor authentication (email code or authenticator app) is available on every account.

No system is perfectly secure, but we design storage of anything sensitive — tokens, passwords, verification codes — around the assumption that a breach of the database alone shouldn't hand over anything usable.

09Your rights & choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing:

  • If you're in the European Economic Area or United Kingdom, these rights are given to you under the General Data Protection Regulation (GDPR).
  • If you're a California resident, you have similar rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we've collected and to request its deletion.
  • Wherever you are, you can ask us what we hold about you, correct it, or ask us to delete it — we don't require you to prove a specific law applies before we'll act on a reasonable request.

To exercise any of these rights, contact us using the details in Contact us. We'll respond within 30 days.

10Children's privacy

Chatmeo is not directed at children, and account holders must be old enough to enter a binding agreement in their jurisdiction. We don't knowingly collect personal information from children through account registration.

11International transfers

Chatmeo is based in Nigeria, and the infrastructure and service providers we rely on — hosting, database, AI providers, WhatsApp/Meta — are located in other countries, including the United States. Your information may be processed outside the country you're in as a result. Where required, we rely on standard contractual protections and our providers' own compliance commitments to safeguard data that crosses borders this way.

12Changes to this policy

If we make material changes to this policy, we'll update the effective date above and, where required, notify account holders directly.

13Contact us

Questions about this policy, or a request to access, export, or delete your data:

Chatmeo
novapixelstudios001@gmail.com
Port Harcourt, Nigeria

← Back to chatmeo© 2026 Chatmeo.