Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains what Whatsclaw (operated by Hashlabs Holdings) collects, why, and how it’s protected. Whatsclaw is currently an invite-only alpha; this policy will evolve as the product does.

1. What we collect

  • Account: your name, email, profile photo (from Google sign-in), and timezone.
  • WhatsApp: for chats you link, the chat list, message text, sender names, and timestamps; voice notes are transcribed to text. Content is only ingested for chats you haven’t marked “off-limits”.
  • Google Calendar & Gmail: only if you connect them — calendar events, and email metadata/content returned by searches the assistant runs on your behalf.
  • Assistant-generated data: commitments, reminders, scheduled messages, routines, wiki notes, and memory the assistant records about you and your contacts from the above, so it can act on your behalf.

2. How it’s used

Solely to operate the Service for your account: understanding your messages, tracking commitments, answering questions, drafting and (only when authorized) sending messages, and managing your calendar and email. We do not sell your data or use it for advertising.

3. Never used for AI training

Your data — messages, voice notes, emails, calendar content — is never used to train AI models. We use AI providers on terms that exclude our traffic from model training.

4. Who processes your data (sub-processors)

  • Groq — runs the language model that reads your messages and generates replies, and the speech-to-text model that transcribes voice notes.
  • Google — Calendar and Gmail APIs, accessed only via the OAuth scopes you explicitly grant, and only while connected.
  • Supabase — hosts the database and handles authentication; all rows are scoped to your account.

5. Third-party (contact) data

Group chats and personal conversations may include messages from people who have not individually agreed to AI processing. We minimize this by processing only chats you choose to share, never auto-replying to anyone without your direction, and giving you full control to mark any chat off-limits at any time. If you are contacted by someone using Whatsclaw and want your messages excluded, ask them to mark that chat off-limits, or contact us directly.

6. Security

  • WhatsApp session credentials and Google OAuth tokens are encrypted at rest (AES-256-GCM envelope encryption) — never stored in plaintext.
  • Every database query is scoped to your account; no user can read another’s data.
  • Every send/schedule/delete action passes through a permission gate outside the AI’s control — the model itself cannot grant permissions or bypass a chat you’ve marked read-only or off-limits.
  • We keep minimal logs and never log full message content in shared logs.

7. Data retention & deletion

Your data is retained while your account is active. You can disconnect WhatsApp or Google at any time from Settings/Integrations. Deleting your account permanently removes your profile and all associated data — chats, messages, commitments, reminders, memory, and connected-service tokens — and cannot be undone.

8. Children

Whatsclaw is not directed at, and should not be used by, anyone under 18.

9. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected here with an updated date.

10. Contact

Questions about this policy or a data request can be sent through your existing point of contact.