Two things worth knowing before you read on. Arutai never sends a message to your customer on its own — the AI produces drafts and a person presses send. And personal data is pseudonymised before any conversation content reaches an external language model. Both are enforced in the architecture, not by policy alone.

1. Introduction

Arutai ("we", "us", "our platform") is a business-communication analytics platform that connects to WhatsApp Business and Instagram Direct accounts to help companies manage, analyse and improve their customer correspondence. This policy describes what personal data we collect, why, how we process it, who we share it with, and what rights you have.

This policy applies to:

  • Users of the Arutai web platform and mobile app — employees of our business customers
  • End customers of businesses using Arutai, whose correspondence may be processed through our platform

By using Arutai you agree to the practices described here.

2. Who controls the data

The business using Arutai is the controller of its correspondence data: it is a party to the conversation and the holder of the records. Arutai LLC acts as a processor, operating on that business's instructions under a contract or public offer. We do not access correspondence on our own initiative and we are not an independent party to it.

For any question about this policy, contact [email protected].

3. What data we collect

3.1 Platform user data (business accounts)

  • Full name and email, for registration and sign-in
  • Organisation name and business details
  • Role within the organisation
  • Sign-in times and session activity
  • Subscription and payment status — we never store full card details

3.2 End-customer data (contacts of businesses using Arutai)

  • Phone numbers (WhatsApp) and Instagram handles — displayed in masked form inside the platform, for example +996 70x xxx 567. Unmasked identifiers are stored in the database but are never shown in the interface.
  • Display names as provided by the messenger
  • Correspondence content — text messages, voice-message transcripts where processed, image descriptions, and timestamps from WhatsApp and Instagram conversations
  • Conversation metadata: read status, delivery status, message direction

3.3 Data produced by AI analysis

  • Conversation risk scoring
  • Intent and sentiment classification
  • Session outcome prediction, for example whether a sale closed
  • AI-generated insight summaries
  • Reply drafts — shown only to the business's own staff, never sent automatically

3.4 Technical and usage data

  • IP addresses and device identifiers
  • Browser type and operating system
  • In-app navigation and feature usage, to improve the platform
  • API request logs and error logs

4. How we use data

PurposeLegal basis
Providing the platform and its featuresPerformance of a contract
Authentication and account securityLegitimate interest / contract
AI analysis of correspondence and insight generationLegitimate interest (business analytics)
Generating reply drafts for human reviewLegitimate interest
Detecting churn risk and conversation-health signalsLegitimate interest
Improving the platform and fixing defectsLegitimate interest
Sending transactional email (account, billing)Contract
Meeting legal obligationsLegal obligation

Important: AI-generated drafts are suggestions only. Arutai never sends a message to an end customer automatically or without explicit confirmation by the business's own staff. This is a foundational product principle with no exceptions.

5. Third-party services and sub-processors

We use the following sub-processors. Each handles data only to the extent needed to provide its service and is bound by a data-processing agreement.

ServicePurposePrivacy policy
SupabaseDatabase storage, authenticationsupabase.com/privacy
OpenAIAI analysis of correspondence contentopenai.com/policies/privacy-policy
Google Gemini (Google LLC)AI analysis of correspondence contentpolicies.google.com/privacy
Trigger.devBackground job processing (imports, sweeps)trigger.dev/legal/privacy
Expo / EAS (650 Industries, Inc.)Mobile app build and deliveryexpo.dev/privacy
Meta PlatformsMessage delivery via WhatsApp Business APIfacebook.com/privacy/policy
Meta PlatformsMessage delivery via Instagram Graph APIfacebook.com/privacy/policy
VercelWeb application hostingvercel.com/legal/privacy-policy

Personal data is pseudonymised before it is sent to any external language model. Phone numbers, handles and names are replaced at a single enforcement point in our code before any content leaves our systems. This is a legal requirement under the Digital Code of the Kyrgyz Republic, and it is covered by automated tests.

We never sell personal data to third parties.

6. Data retention

Data typeRetention period
Account and organisation dataUntil account deletion, then 30 days
Correspondence messages and metadataUntil deleted by the organisation or the account closes
AI analysis and insightsMatches the retention of the related correspondence
Audit and security logs12 months
Billing records7 years (statutory requirement)

Once a retention period ends, data is irreversibly deleted from all systems, including backups, within 90 days.

7. Data security

  • All data in transit is encrypted with TLS 1.2 or higher (HTTPS)
  • All data at rest is encrypted in the PostgreSQL database managed by Supabase
  • Tenant isolation: each organisation can access only its own data, enforced at the database level by row-level security policies
  • Least-privilege support access: Arutai staff can access an organisation's data only with that organisation's explicit, time-limited grant, and every access is audited
  • Phone numbers and contact identifiers are masked in the interface to minimise exposure of personal data to platform users

8. International data transfers

Arutai runs on infrastructure located primarily in the European Union and the United States. Where personal data is transferred outside your country of residence, we apply appropriate safeguards — standard contractual clauses or equivalent mechanisms under applicable law.

9. Your rights

Depending on your jurisdiction, you may have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data (the "right to be forgotten")
  • Restriction — request that we limit how we use your data
  • Portability — receive your data in a machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdrawal of consent — where processing relies on consent, withdraw it at any time

To exercise these rights, contact [email protected]. We respond within 30 days. If you are an end customer of a business that uses Arutai, we recommend contacting that business directly — it is the controller of your correspondence data and we process it on its behalf.

10. Cookies

The Arutai web platform uses cookies for authentication session management (strictly necessary) and security (CSRF protection). We do not use advertising or tracking cookies and we do not participate in cross-site tracking. See the cookie notice for detail on this marketing site.

11. Children

Arutai is a business-to-business platform. It is not intended for, and not directed at, anyone under 18. We do not knowingly collect data about minors.

12. Changes to this policy

We may update this policy from time to time. For material changes we will notify users by email and update the "last updated" date at the top. Continuing to use the platform after changes take effect constitutes acceptance of the updated policy.

13. Contact

For anything related to data privacy:

Email: [email protected]
Phone / WhatsApp: +996 999 147 741
Entity: Arutai LLC (ОсОО «Арутай»), Bishkek, Kyrgyz Republic

Full registration details — registration number, tax ID and registered address — are available on request for a data-processing agreement, procurement, or a supervisory authority request. Email [email protected].