Back to sign in

Data Use Policy

Last updated August 26, 2026

The short version

The Privacy Policy explains what we collect. This page explains what we do with it — and, just as importantly, what we do not do with it.

  • Your customer list is not our customer list. We never message your contacts for our own purposes, and we never merge your contacts into a shared pool.
  • We do not sell personal information. Not to advertisers, not to data brokers, not to anyone.
  • We do not train an AI model on your messages. When you press an AI button, that specific text goes to an AI provider to produce that specific result.
  • Each brand is walled off in the database. A contact belongs to one brand and is invisible to your other brands unless you deliberately share it across your account.
  • Consent is recorded, not assumed. Every consent and every withdrawal is stored with the channel, the method, the time and the wording that applied.
  • Old data is removed on a schedule that applies to the whole platform, and cannot be extended for one account.

1. Who decides what happens to the data

For your contacts, you decide and we act on your instructions. You choose the list, the message and the timing. We provide the machinery and the safety checks. If a customer of yours wants their record corrected or deleted, that request belongs to you, and you can pass it to us to carry out.

For your own account information, we decide, and the Privacy Policy explains why.

2. What we use your data for

  • Delivering messages. The contact’s phone number or email address is decrypted at the moment of sending and handed to the channel that carries it.
  • Compliance checks before a send. On SMS and WhatsApp the platform checks consent, then quiet hours, then the per-contact frequency cap, and refuses the send if any of them fails.
  • Reporting. Opens, clicks, deliveries and failures are aggregated into your campaign reports.
  • Abuse prevention. Outgoing content is scored against known spam and phishing patterns, and account-level spam, bounce and complaint rates are monitored.
  • Support. With your request, so that we can reproduce a problem you are reporting.
  • Audit. Significant actions are written to an audit record that identifies the actor and the change.

3. What we do not do

  • We do not sell, rent or share your contacts with advertisers or data brokers.
  • We do not market to your contacts.
  • We do not combine contacts from different accounts, or use one customer’s data to benefit another.
  • We do not use your message content to train AI models.
  • We do not read your inbox conversations except where you ask us to for support, or where we are investigating abuse or are compelled by law.

4. Separation between brands and accounts

A brand is a separate tenant. Separation is enforced by the database itself rather than by a filter in the application code, so a query cannot accidentally return another brand’s rows. A contact is private to the brand that owns it. Sharing a contact across the brands in your own account is a deliberate action, and even then it never crosses to a different customer.

Team permissions are granular: reading the inbox, writing in the inbox, sending campaigns and exporting contacts are separate permissions, so you can let someone answer messages without letting them download your list.

5. Consent records

For each contact and each channel we store how consent was obtained, when, from what network address, and which version of the consent wording was in force. If double opt-in was used, the confirmation is recorded too. When consent is withdrawn we store when and by what method. Campaigns only target contacts whose record is active, so once consent is withdrawn every later send skips that person.

One thing to be clear about: a one-click unsubscribe in an email withdraws consent automatically. An SMS reply such as STOP does not. The inbound message is stored, the keyword is recorded on it, and the conversation appears in your shared inbox — but withdrawing that person’s consent is an action someone on your team has to take. Watch your inbox and act on those replies. This is described the same way in the Acceptable Use Policy.

6. Data you connect from elsewhere

If you connect an online store or another business tool, the credentials you provide are encrypted and are never returned to your browser. A connector reads from the other system on a schedule and reports what it found; it does not silently rewrite your contact records.

7. AI features

AI writing and suggestion features send the text of your prompt, and the content you asked to improve, to a third-party AI provider to generate the result. Treat an AI prompt like a message to an outside company: do not paste a customer’s personal details into it.

8. Retention and deletion

Messages 365 days, contact activity 180 days, automation run history 90 days, delivery notification records 30 days, expired sessions 30 days. Audit records are never removed by the clean-up. These are platform-wide values, not account settings.

Erasing a contact removes the contact, its messages, its activity and its consent records together in one operation, and writes an audit entry. It is carried out by us on request — there is no self-service erase button in the product today. Send the request to [email protected].

9. Exporting your data

You can export contacts from the product, subject to your team permissions, and read your data through the API. If your account is closing, request a full export within 30 days of closure by writing to [email protected].

10. When we must disclose

We disclose personal information where the law requires it, where a channel provider requires it to investigate abuse, or to protect people from harm. Where we are permitted to tell you, we will.

11. Changes

We will give notice of material changes through the product or by email. This version is dated 26 August 2026.

12. Contact

[email protected], or CyberCraft Bangladesh at Section-12, Block-D, Road-25/B, Plot-S/10, Pallabi, Mirpur, Dhaka-1216, Bangladesh.