Security & data
Your digital employee serves your customers, so it sees data about your business and about your people. This page says, with no inflated acronyms, what we do to look after it — and who the minimum necessary gets shared with so the service can run.
Last reviewed:
What we do
Your data never mixes with anyone else's
Every query to the system carries your account with it: asking for your own data answers; asking for another customer's answers “it does not exist”. We test it with controls in both directions, and that check happens on every request, not in a separate setting somebody could forget to switch on.
The database's public key cannot read anything
On top of the application, the database has a lock of its own: row-level access rules are active on all of its tables, and the public key had its read permission revoked — today and for any table created tomorrow. We verify it by trying to read with that same key.
Personal data is stored encrypted
Your contacts' email addresses and phone numbers are stored encrypted at rest. For searching and de-duplicating we use fingerprints (hashes), not the value in the clear.
Everything travels over HTTPS
The chat, the portal and the API only speak over encrypted connections (TLS).
Two-step access and one login per person
The portal supports two-step verification, and each person on your team signs in with their own email and password — the audit log records who did what.
Commercial email with one-click unsubscribe
Every email that is not strictly transactional carries its one-click unsubscribe link (the standard Gmail and Outlook require), and the suppression list is honoured before each send.
You can leave and delete everything
You have a dedicated page to request deletion of your data, and cancellations schedule a purge with advance notice. Deleting means deleting.
Habeas data (Colombia's Law 1581)
We handle enquiries and complaints about your personal data under Colombia's data protection law, and our privacy policy publishes the channel to exercise those rights.
Who the minimum gets shared with
Running the service takes providers. These are all the ones that touch service data, and what for:
- Anthropicthe AI model that writes the digital employee's replies
- Googlebackup AI model for when the main one is unavailable
- OpenAIvoice-note transcription and generated images
- Supabasethe database where accounts and conversations live
- Renderthe servers the system runs on
- Vercelthe servers that serve this site and the portal
- Stripepayments — we never see or store your card
- Metathe official WhatsApp and Instagram connection
- Twiliothe phone numbers and the calls
- ElevenLabsthe digital employee's voice on calls
- Resendsending the system's emails
- Sentrythe technical error log, with none of your customers' data
Your rights
You can access, correct or delete your data whenever you want: the channel is in the privacy policy and on the data deletion page. If something here does not add up, or your legal team needs a detail, write to us and we answer directly — no script.
