Who is responsible
This notice covers signup and the dedicated WhatsApp Business connection service at waba.openally.ai, operated by Matterward Labs Private Limited (“Matterward Labs”, “we”). It supplements the OpenAlly Privacy Policy.
We are responsible for your OpenAlly account, service security, and support information. The business connecting an inbox decides why its customers’ messages are handled and is responsible for its customer privacy notice. We process that business correspondence on its behalf to provide the connection and actions it authorizes. Meta, WhatsApp, and any AI service you choose have their own terms and responsibilities.
Business owners and people who have messaged a connected business can contact support@openally.ai about this service. If your request concerns a business’s customer records, contact that business too.
Information this service handles
- Account and setup: OpenAlly account, workspace and device identifiers; Premium eligibility; signup mode, progress and expiry; the business account and phone-number identifiers selected during Meta signup.
- Connection: Meta authorization grants, the Meta identity returned when we verify a grant, registration credentials where needed, business/display names, business phone number, currency, connection health and import consent.
- Customer correspondence: message text, customer identifiers and names, attachments or media references, delivery/read receipts, interactive replies and submitted form fields. Eligible coexistence can also share contacts, history and messages sent from the WhatsApp Business app.
- Your controls: designated device, agent assignment, human takeover, reply approvals, automation rules, spending estimates, consent evidence references and opt-out state.
- Support and service operation: information you send support and categorical reliability counts. The reliability dataset excludes account, device, business, customer and message identifiers, message content, tokens and prices.
Business profiles, templates, linked catalogs/products and supported WhatsApp forms are fetched from Meta when needed. Attachments pass through authenticated service requests between Meta and your device; their identifiers can also appear in retained correspondence.
Where messages go and why
Meta sends events for your connected inbox to our Cloudflare-hosted service. It verifies and temporarily stores encrypted correspondence, then delivers it to your designated OpenAlly device. Authorized outgoing messages pass through this service to Meta and then to the customer. The hosted connection does not run your agent.
Your device keeps the working conversation history and runs the agent. A supported local model handles the model request locally. If you select an external AI provider, that provider receives the relevant request; if you choose OpenAlly cloud AI, the OpenAlly service and its disclosed AI-processing provider receive it. Review the OpenAlly Privacy Policy and the chosen provider’s terms before enabling replies involving customer information.
We use business correspondence only to deliver the service and authorized business actions. We do not sell it, use it for advertising, or use it to train AI models. You must configure any AI provider you choose consistently with the business-data restrictions.
History import is a separate optional choice for eligible coexistence. Imported history does not itself trigger AI replies. You can connect without choosing an import; Meta determines which history is available.
How long information is kept
- Signup: a session is usable for 15 minutes. Temporary authorization material is cleared on completion, cancellation or expiry; progress records remain for one additional day after expiry.
- Message bodies: encrypted incoming correspondence is removed when your designated device acknowledges saving it, or at its original seven-day expiry. Outgoing proposal bodies are also temporary and removed after acknowledgement or expiry. Retries do not restart the seven-day period.
- Delivery metadata: incoming event identifiers/digests can remain until that original expiry to prevent duplicate delivery. Outgoing status, approval/budget records, conversation control and consent metadata remain with the service inbox after a body is removed, until the inbox’s service data is erased.
- Connection records: grants and connected account settings remain while needed for the connection. Disconnecting one number erases that inbox’s delivery and automation data; account credentials remain if other numbers still use that account. Disconnect every number to remove the account’s service connection.
- Deletion records: a completed Meta deletion job keeps its random confirmation code and result until 30 days from the request. Its identity context is removed on completion. Minimal identifiers and security timestamps can remain to prevent old authorizations or callbacks from restoring deleted data.
- Reliability counts: the categorical dataset has no customer join key and follows Cloudflare Analytics Engine’s three-month retention.
These are active-service storage periods. Cloudflare’s database recovery history can cover the previous 30 days, so removal from the active service does not mean an immediate removal from all infrastructure recovery copies. Device history, your backups, Meta’s records, recipients’ copies and AI-provider records have separate lifecycles.
Pending deletion jobs retry until service cleanup finishes; a pending result is not a completed deletion. Support requests and any records we must keep to resolve a dispute or meet a legal obligation are handled under the OpenAlly Privacy Policy.
Security and browser storage
Connection grants, registration credentials and temporary message bodies are encrypted at rest by the service. Account and device authorization, scoped access checks, verified Meta webhook signatures, short-lived signup tickets and limits on request sizes protect access. Encryption does not mean the service cannot process correspondence for delivery, and no system guarantees absolute security.
The signup browser uses an essential, secure, HTTP-only session cookie lasting up to 15 minutes. The one-use link is consumed and removed from the address bar; it is not a password. We do not put Meta access tokens in browser storage. Meta’s login window and signup software receive the information needed to authenticate you and follow Meta’s Privacy Policy and cookie practices. You can cancel before granting access.
Hosting providers necessarily process network requests, including IP addresses and browser information, to serve and protect the site. Our WABA reliability counts do not include this information. These pages do not add advertising trackers.
Recipients and international processing
Cloudflare provides the hosted connection and storage. Meta/WhatsApp provides signup, business messaging, asset management and its own billing. Your designated device, authorized business users and the model service you select receive information needed for their role. Support providers receive information you include in a support request. We may disclose information where legally required or necessary to protect legal rights.
These services may process information outside your country. We do not promise that the hosted connection is confined to the location of your device. Applicable transfer arrangements and wider account-service recipients are described in the OpenAlly Privacy Policy; contact support@openally.ai for questions about processing arrangements for your business.
Your choices and privacy requests
You can decline optional history import, choose your model, disable automation, take human control, and disconnect an inbox. The deletion guide explains what each removal method covers and how to request help without access to the app. Removing Meta permissions alone may stop access without removing already-held service records.
Depending on applicable law, you may request access, correction, deletion or a copy of your personal information, object to or restrict processing, or withdraw consent for optional processing. We may verify your authority before acting. Where you are a customer of a connected business, that business handles requests for its own customer records; we can assist with the service data we hold. You may also complain to the competent data-protection authority.
We process account/setup information to provide the service you request; optional history sharing follows your choice; service-security information supports preventing misuse; and legal compliance may require particular records. Your business is responsible for the lawful basis for its customer messaging. The OpenAlly Privacy Policy provides the broader rights and grievance route.
Email support@openally.ai with “WhatsApp Business privacy” in the subject. Include your account email and the business number where relevant. Do not send passwords, verification codes, access tokens, payment-card information or unnecessary customer conversations. If this notice changes, we will update the date above.
