Privacy Policy

What we read, and what we keep.

eida sits on a WhatsApp account that carries other people's words, so this document is not a formality. It is written to be read once, in full, by the person deciding whether to link an account — and it says the uncomfortable parts out loud rather than burying them in clause 14.

Effective 14 August 2026 Version 1.0 Applies to eida.ai and the eida console

01 Who we are

eida is a service that reads the WhatsApp chats a team switches on, proposes the work it finds, and — once a person approves it — writes that work into the task manager the team already uses.

This policy is issued by [registered entity name], [registered address] (“eida”, “we”, “us”), which operates eida.ai and the eida console.

Anything in this document that describes what the software can or cannot do is a description of how it is built, not a policy we could quietly relax. Where that distinction matters, we say so.

02 Whose data, and who is responsible

There are two quite different relationships on this page, and mixing them up is how privacy policies become useless.

When you are our customer

Your team links a WhatsApp account and picks chats to watch. Everything that comes out of those chats belongs to you and your clients — not to us. You decide what is watched, you decide what is approved, and you decide when it stops. In data-protection language you are the controller (a Data Fiduciary under India's Digital Personal Data Protection Act, 2023) and we are your processor (a Data Processor). We act on your instructions and for no purpose of our own.

When you are visiting this website

If you fill in a form on eida.ai or email us, we decide what to do with that — so for those details we are the controller. Section 11 covers it and it is short, because there is very little of it.

The consequence

We do not sell, rent, mine, or train models on your chats or your clients' messages. We do not build a profile of anybody from them. There is no version of eida where your conversations become our product.

03 What eida reads

eida connects to a WhatsApp account the same way the desktop app does: somebody on your team scans a QR code from their phone. That connection gives eida two very different levels of access, and the difference is the whole of our privacy story.

The names of every chat on that account

This is unavoidable — a chat list arrives as a chat list. eida can see that a group called “Kiran — Interiors” exists on the linked account, along with every other group and contact name. We say this plainly during setup, and the software will not leave the pending state until that disclosure has actually been recorded. That is a database constraint, not a screen somebody can skip.

The contents of only the chats you switch on

Message contents are a separate step. A chat you have not ticked in the picker is never decrypted at all — not read and discarded, not filtered later: never turned into readable text in the first place. There is nothing to leak from a chat you did not pick, and you can switch one back off in a second.

What it does with a watched message

Messages that arrive in a watched chat pass through a filter that discards most of them locally. What survives is sent to our extraction model to decide whether it contains a request. Media — photos, voice notes, documents, video — is not downloaded, not opened and not stored.

Worth knowing

eida only sees messages that arrive while it is connected. It does not read your history, and if the connection drops, messages sent in that window are never seen at all. This is a real gap in coverage, not a privacy feature we are dressing up — it is on our public roadmap to close, and when it is closed we will say so here.

04 What eida stores

For each piece of work eida proposes, it keeps the minimum that lets a human judge it and defend it later:

  • The proposal — a title, a due date if one was mentioned, a client, and a suggested assignee.
  • The quote — the single message the proposal was built from, word for word. Every proposal is checked back against the real message before you see it, and if the words are not there it is discarded rather than shown.
  • Who said it, where, and when — the sender's name or number, the chat it arrived in, and the timestamp.
  • What a human decided — approved, edited, rejected or observed, and when.

It also stores what it needs to keep working: the list of chats on the account and which ones are watched, the encrypted session that keeps the WhatsApp connection alive, your workspace settings, and a record of which messages have already been looked at so the same line is never proposed twice.

What it does not store

  • The conversation around a quote. One message per proposal, never the thread.
  • Anything at all from a chat you have not switched on.
  • Media of any kind.
  • Messages that the filter or the model decided were not work. They are not written down.
One thing we want to be straight about

Reading a couple of messages around an ask would make the proposals noticeably better — “make it Friday instead” means nothing on its own. It is on our roadmap and it would weaken the promise in this section. If we build it, it becomes an explicit setting you turn on, this policy changes before it ships, and we will tell you rather than let you find out.

05 Why we are allowed to

Where you are our customer, we process your data because you asked us to and because we have a contract with you to run the service. Our written agreement with you is our instruction; we do nothing outside it.

The people in your chats are a harder question, and section 10 answers it honestly rather than pretending it away.

For the website and enquiries, we rely on your consent — you typed your email into a form — and on our legitimate interest in replying to somebody who asked us a question.

06 Who else touches it

The complete list of companies that can come into contact with data eida holds. It is short deliberately, and this page is the current version of it.

Google
The Gemini API, which reads a candidate message and decides whether it is a request. Google's API terms state that paid API content is not used to train their models.Purpose: extraction
Supabase
Managed PostgreSQL. Everything in section 4 lives here.Purpose: database hosting
Vercel
Hosting for the review console and this website.Purpose: application hosting
Formspree
Delivers the enquiry forms on eida.ai to our inbox. It never touches chat data.Purpose: website forms
Your task manager
The destination you chose — your own dashboard, Trello, Notion or another tool. Approved work is written there, with its quote. What happens to it after that is governed by their terms and your account, not ours.Purpose: the entire point

We also disclose data if a law or a valid court order requires it. If that ever happens and we are permitted to tell you, we will.

If eida is ever acquired or merged, your data would move with the service. You would be told before it did, in time to close your account and have it deleted.

Where it is processed

Our database and console are hosted in [region]. The extraction model runs on Google's infrastructure, which may process the request outside that region. Where data leaves the country it was collected in, that transfer is covered by the providers' standard contractual protections.

07 How long we keep it

  • Proposals and their quotes — for as long as your workspace is open, because a task's receipt is worth nothing if it expires before the argument does. Delete any of them from the console at any time.
  • The record of messages already seen — for as long as your workspace is open. It holds no message text; without it the same request would be proposed to you repeatedly.
  • The WhatsApp session — until you unlink, at which point it is destroyed and the account has to be paired again from scratch.
  • Enquiries and email — up to 24 months, then deleted.

When you close your workspace, everything above is deleted within 30 days. Backups roll off within 90 days. Work already written into your own task manager stays there — it is yours, in your system, and we could not remove it even if you asked.

08 How it is protected

  • Everything travels over TLS and is encrypted at rest by our database provider.
  • The console refuses to start without a configured password and signing secret. A deployment that forgot to set them serves nothing rather than serving your clients' conversations.
  • Where eida writes into a customer's own system, it signs in as an ordinary member of that team, constrained by that team's own permissions. We hold no privileged service keys, and revoking us is disabling one user.
  • Access to production data is limited to the people who run the service and is used only to keep it running or to fix something you have reported.
The honest limit

Today a workspace shares one console password, which means the approval record can name the workspace but not the individual who approved. That is a real weakness, we know it, and per-person sign-in is being built. Until it ships, only give the console password to people you would trust with the chats themselves.

If we ever suffer a breach affecting your data, we will tell you and the relevant authority without undue delay, with what we know and what we are doing about it.

09 Your rights

Depending on where you live, you have the right to ask what we hold about you, to get a copy, to have it corrected, to have it deleted, to restrict or object to how it is used, and to withdraw consent. If you are in the EU or UK you also have the right to complain to your data protection authority; in India you may complain to the Data Protection Board.

Most of these you can exercise yourself in the console — see the whole ledger, edit a proposal, delete one, unwatch a chat, unlink the account. For anything else, write to privacy@eida.ai and we will respond within 30 days. We do not charge for this, and we will never make you worse off for asking.

10 If you are in one of these chats

You may be reading this because a business you message on WhatsApp uses eida, and you did not sign up for anything. That is a fair objection and it deserves a straight answer rather than a clause.

Here is what is true. The business you are talking to controls that account and has chosen to have its own chats read, in the same way it might forward your message to a colleague or paste it into its task list. eida does not read your other conversations, is not on your phone, and cannot send you anything — there is no send function in the product. What it may keep is a single sentence you wrote, alongside who said it and when, attached to a job that the business agreed to do for you.

If you want to know whether a specific business is using eida, or you want a quote of yours removed, ask them first — they control the workspace and can delete it in a tap. You can also write to privacy@eida.ai and we will pass it on and help make it happen.

11 The website itself

eida.ai sets no cookies and runs no advertising or analytics trackers. There is no banner to dismiss because there is nothing to consent to.

If you submit a form we receive what you typed — usually an email address, the tool you use and the size of your team — and we use it to reply to you and nothing else. Our hosting provider keeps standard server logs, including IP addresses, for security and reliability, on their usual short retention.

We load fonts from Google Fonts, which means your browser makes a request to Google when the page opens.

12 About WhatsApp

eida is not affiliated with, endorsed by, or connected to WhatsApp or Meta. WhatsApp offers no official way for a business to read its own group chats, so eida links to the account the way a desktop client does. We think it is important you understand that before you link anything:

  • Your use of WhatsApp remains governed by WhatsApp's own terms, and linking a third-party client may not sit comfortably with them.
  • Accounts connected this way can in principle be restricted or banned by WhatsApp. What actually gets accounts banned is sending behaviour — bulk messages, mass group adds, spam reports — and eida does none of it, because it cannot send. We will not pretend the risk is zero.
  • Only link an account whose owner understands and agrees to all of this. In practice: ask the person whose number it is.

13 Changes

When this policy changes we update the date at the top and raise the version. If a change actually affects what we read, keep or share — as opposed to fixing a typo — we will email every workspace before it takes effect, not after. Old versions are available on request.

14 Contact and complaints

Privacy questions, requests and complaints: privacy@eida.ai. Anything else: hello@eida.ai.

Grievance Officer
[name] · privacy@eida.aiAs required under India's DPDP Act, 2023
Postal address
[registered address]

If you are not satisfied with our response you can complain to your data protection authority — the Data Protection Board of India, or your national supervisory authority in the EU or UK.

This document describes eida as it is built today, on 14 August 2026, including the parts that are not finished. If you find something on this page that does not match what the software actually does, tell us — that is a bug in the most serious sense, and we will treat it as one.

Read the terms of service →