Privacy Policy
Last updated: August 10, 2026
JewelX AI is a multi-tenant platform that helps businesses (“workspaces”) manage WhatsApp customer conversations: keyword auto-replies, AI-assisted responses, a live team inbox, broadcasts, analytics, and a per-workspace knowledge base. This policy explains what information the platform processes to provide that service, and how it is handled.
Information processed
- Business account information: workspace name, plan, and settings configured by the business.
- User/account information: email address, name, and authentication data for people who sign in to manage a workspace.
- WhatsApp contact identifiers: the phone numbers and profile names of people who message a connected business, and their opt-in/opt-out status.
- WhatsApp messages: the content of messages sent to and received from a connected business, and delivery/read status events reported by WhatsApp.
- AI conversation/context data: recent conversation history and retrieved knowledge-base content, which may be sent to a configured AI provider to generate a reply.
- Knowledge-base content: PDF, Word, URL, or pasted text a business uploads so the AI assistant can answer from it.
- Technical/security logs: request metadata, error logs, and webhook delivery records used to operate and secure the service.
- Authentication/session information: session cookies and sign-in metadata used to keep a user signed in to their workspace.
We do not request or process information beyond what is listed above. We do not sell personal data.
Purpose of processing
Information above is used to:
- provide WhatsApp messaging automation for a workspace;
- route, display, and respond to customer inquiries in the inbox;
- generate AI-assisted replies and ground them in a workspace's knowledge base;
- authenticate users and administer workspace accounts and roles;
- maintain security, detect abuse, and prevent duplicate/replayed messages; and
- troubleshoot issues and improve the reliability of the service.
Third-party processors and providers
The platform relies on the following categories of external providers:
- Meta / WhatsApp Business Platform: delivers inbound messages to the platform and outbound replies to end users.
- Supabase: hosts the application database, authentication, and file storage.
- Configured AI provider(s):a workspace's AI replies are generated by whichever provider is configured for that workspace — currently GLM (Z.ai), Google Gemini, or OpenRouter. Only the provider actually selected (with automatic failover to a secondary provider if the primary is unavailable) processes message content necessary to generate a response; content is not sent to every supported provider simultaneously.
- Voyage AI: used only where a workspace enables semantic knowledge-base search, to generate embeddings of uploaded content. If not enabled, knowledge-base search falls back to in-database full-text search and Voyage AI is not used.
- Infrastructure/hosting providers: the application runtime and container registry used to run and distribute the service.
Data retention
Information is retained only for as long as needed to operate the service for an active workspace, satisfy contractual or legal obligations, and maintain security (for example, abuse prevention and audit logs). When a workspace is deleted, its associated data is deleted or anonymized as described in our Data Deletion instructions, subject to any retention required by law or for legitimate security purposes.
Data deletion
See /data-deletion for how to request deletion of workspace or account data.
Your rights
You may request access to, correction of, or deletion of your information by contacting singaporearun2003@gmail.com. We may need to verify your identity or authority over a workspace before acting on a request.
Security
We apply reasonable technical and organizational measures appropriate to the data we process, including encryption of WhatsApp access tokens at rest, signed and verified WhatsApp webhook delivery, role-based access to workspace data, and access logging. No method of transmission or storage is completely secure, and we do not claim certification against any specific security standard.
Policy updates
We may update this policy as the service changes. The date at the top of this page reflects the most recent update.