Privacy Policy
Effective Date: September 18, 2026
Fernloop Technologies Limited, a New Zealand company that provides the WhatsApp AI Pro product ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our desktop application and related services.
Information We Collect
We collect the following types of information:
- Account information: your name, email address and password (we store only a hash of it), and your answer to "How did you hear about us?" if you give one when you sign up.
- Billing information: payments are processed by Stripe. We keep your Stripe customer and subscription IDs and any refund requests, but not your card number.
- Content sent to AI features: when an AI feature runs in the desktop app, the browser extension or your account dashboard, the content it needs passes through our servers. This can include your customers' messages, messages you type, recent conversation history, contact names and phone numbers, voice notes, images and documents, and your company profile. Data Storage and Security explains what is sent and what we keep.
- Company profile and assistant settings: your company profile (including products, prices, policies and business knowledge), your assistant's name and reply preferences, reply templates, and the lessons the app learns from your edits; these lessons may quote customer messages.
- Enterprise Inbox data: if you turn on Enterprise Inbox, the conversations, contacts, notes, drafts and files it copies to our servers.
- Usage and device data: which features you use and how much (for AI requests: the feature, the model, the amount of text and the response time); IP addresses and user agents, which our servers record with sign-ins, AI requests and in their request logs; and, when you sign in, a device name (in the desktop app, your computer's name; on the website, your browser and operating system), your operating system and the app version. The desktop app also sends usage events to Mixpanel, linked to your account.
- Website usage: with your consent, how you use this website, as described under Third-Party Services and Cookies.
- Emails and support communications: copies of the emails we send you, which links in them you click (see Email Link Tracking), and the messages you send us.
How We Use Your Data
We use the information we collect to:
- Provide the service, including AI replies, translation, voice transcription, summaries, follow-ups and customer profiles
- Process payments and manage your subscription
- Send account emails, service updates and security notifications
- Respond to your support requests
- Check and improve the quality of AI replies, using the reply logs described under Data Storage and Security
- Understand how the website and apps are used, find problems and improve features
- Measure our advertising: when Google Ads or Meta Pixel is enabled and you have accepted cookies, we share page views and sign-up and download events with Google and Meta to learn which ads lead to sign-ups (see Third-Party Services)
- Protect the service against abuse, for example by limiting request rates and blocking abusive accounts or networks
- Comply with legal obligations
Data Storage and Security
The desktop app keeps your WhatsApp conversations, contact list, customer profiles and CRM records in a database on your computer. The app also writes log files on your computer, which contain short excerpts of messages you receive, send or translate, voice-note transcripts and imported documents, with contact names and chat IDs. Our servers do not keep a copy of your chat history or contact list, except as described below.
The following leaves your computer:
- AI requests: AI features send content through our servers to a third-party AI model provider (see Third-Party Services), which returns the result. Some of this happens automatically in every mode, including Watch: voice notes and images in one-to-one chats are transcribed or described; incoming messages shown in the chat you have open, including group chats, are sent for translation, and voice notes in them are transcribed; messages you send yourself in one-to-one chats are analyzed to keep track of what you promised customers; and in Watch mode, most incoming messages are analyzed together with recent conversation history, the contact's name, your notes and per-chat instructions, CRM details, a conversation summary and parts of your company profile, such as product names, trade terms and sales policies. Drafting a reply sends recent conversation history, a summary of the conversation, the contact's name, your notes, CRM details and your company profile. The app drafts replies in Auto, Suggest and Team modes. In any mode, including Watch, it can also draft a reply to a message it held back and retried later, such as one that arrived while the app was offline or shortly after you replied yourself; a follow-up when something you promised a customer is due; and, when Catch-up on startup is on (the default), replies to chats from the last 24 hours that are still unanswered when the app opens. In Watch and Team modes, messages you type are translated into the customer's language when you press Enter. Follow-ups, re-engagement messages, document analysis and learning from your edits send similar content. Translation and voice transcription cannot be turned off.
- Message classifications: when the app has an AI model classify an incoming message (for example, as an automated reply or a promotion) or decide whether to send a contact a re-engagement message, we keep the result and the model's short reasons, which may describe the message or the contact. These records are not deleted automatically.
- Customer lookups: when you ask the app to analyze a customer, our servers use the customer's phone number, their WhatsApp Business profile and the profile the app already has for them to search the web with an AI model provider, may look up business contacts on Google Places, and may read the customer's website. We keep the result together with the phone number and chat ID. These results are not deleted automatically.
- Company profile and settings: the app copies your company profile (including products, prices, policies and business knowledge), assistant name, reply preferences and reply templates to our servers whenever they change, so that AI requests and your account dashboard can use them. When you import documents or a website, the extracted text is sent for analysis; we keep the resulting profile, which can include passages quoted from the source as evidence, but not the full text.
- App status and lessons: the app reports its settings, draft statistics and the lessons it has learned from your edits, which may quote customer messages, together with a random install ID. We delete status reports after 180 days and keep the current lessons.
- Reply logs: for replies the AI drafts, we keep the reply and details of the model's output, without redaction, and, for the browser extension, any instruction you gave and the chat ID, which usually contains the customer's phone number. We also keep the customer's message and a summary of the conversation after an AI model has replaced names, phone numbers, email addresses, street addresses and order or account numbers with placeholders. This step can miss things, and other details, such as company names, products, prices and quantities, are kept. We delete reply logs after 90 days.
- Enterprise Inbox: if you turn on Enterprise Inbox, the app copies messages from one-to-one chats (including some earlier messages and a summary when a conversation is first copied), images and documents, voice-note transcripts, drafts, customer notes and CRM details, and your contact list to our servers, or to your own Inbox server if you run one, so that your team can work from them. This data is currently not deleted automatically.
- Telegram: if you connect a Telegram bot, the app sends customer names or phone numbers, customer messages and their translations, AI drafts and daily summaries directly to Telegram.
- Slack and WeCom: if you connect Slack or WeCom (企业微信, operated by Tencent) instead, the app sends the same information directly to that service. In Team mode on Slack, everyone in the team channel you choose can read the drafts.
- Spreadsheet lookups: if you connect a spreadsheet for the AI to look up (a local .xlsx, .xls or .csv file, or a public Google Sheet), the app reads the file on your computer or downloads the sheet directly from Google. When you add one, the purpose you write, the column names and summary statistics about the columns are sent to our servers to describe the table; cell contents are not. Rows the AI looks up to answer a customer are included in AI requests.
- Usage analytics: the desktop app sends usage events, such as first launch, sign-ins, mode changes, first use of features and WhatsApp Web connection errors, to Mixpanel, linked to your account ID, email address and name, together with your plan, workspace, language, operating system and app version. It does not send message content. There is currently no setting to turn this off.
Our staff can view data stored on our servers, such as company profiles, assistant settings, reply logs, message classifications and customer lookup results, to provide support and check quality.
Our API servers are located in Singapore. This website, including sign-in and your account dashboard, is hosted by Vercel. The services listed under Third-Party Services may process data in other countries, including the United States. Connections between our apps and our servers are encrypted (HTTPS).
Third-Party Services
We use the following third-party services:
- Stripe: Processes payments. Stripe's privacy policy governs how your payment information is handled.
- Amazon Web Services: Hosts our servers, in Singapore.
- Vercel: Hosts this website, including sign-in and your account dashboard, so AI Nexus requests and email-link clicks also pass through Vercel. With your consent, Vercel Web Analytics also counts page views.
- Resend: Delivers the emails we send you, such as sign-up and password-reset codes, and receives the emails you send us.
- AI model providers: Our servers pass content from AI features to third-party AI model providers, including OpenAI, which generate replies, translations, transcriptions, summaries and customer profiles (see Data Storage and Security). This covers the desktop app, the browser extension and AI Nexus in your account dashboard. When you use AI Nexus, what you type, documents you attach, the text of web pages you link to, and your company profile are sent.
- Google Places: When you ask the desktop app to analyze a business contact, our servers may look up the contact's phone number, or name and address, on Google Places.
- Mixpanel: Receives usage events from the desktop app, linked to your account ID, email address and name (see Data Storage and Security).
- Telegram: If you connect a Telegram bot to the desktop app, the app sends customer names or phone numbers, messages and AI drafts to Telegram (see Data Storage and Security).
- Slack and WeCom: If you connect Slack or WeCom (operated by Tencent) to the desktop app, the app sends customer names or phone numbers, messages and AI drafts to that service (see Data Storage and Security).
- Microsoft Clarity: With your consent, records how you use the website (clicks, scrolling, mouse movement and the pages you visit) and turns this into session replays and heatmaps. Text you type into form fields is masked, and all text in the sign-in, sign-up and password-reset forms and in your account dashboard is masked. We give Clarity a random visitor ID that stays in your browser across visits. When you sign in, we attach your account ID to it, so recordings made in the same browser before you signed up or after you sign out can be linked to your account. Clarity can also set cookies on Microsoft's domains, such as CLID, which recognizes your browser across sites that use Clarity, and MUID, which Microsoft uses for advertising, analytics and other purposes. Microsoft's use of this data is covered by the Microsoft Privacy Statement.
- Google Ads and Meta Pixel: When enabled, and only with your consent, these tags send Google and Meta page views and actions such as starting or completing a sign-up (including your answer to "How did you hear about us?") or clicking a download link, so that we can measure our ads.
- YouTube: Some of our guides embed YouTube videos. Until you click play, the page shows only a preview image loaded from YouTube's image server (i.ytimg.com). Clicking play loads the YouTube player in YouTube's privacy-enhanced mode (youtube-nocookie.com), and YouTube may then store information in your browser, such as cookies.
We do not sell or rent your personal information.
Cookies
Strictly necessary: the cookies that sign-in needs (session and security cookies), and a note in your browser's local storage recording your choice on the cookie banner.
Only after you accept the cookie banner: Vercel Web Analytics, Microsoft Clarity and, when enabled, Google Ads and Meta Pixel, as described under Third-Party Services. Clarity sets cookies on this site (such as _clck and _clsk) and can set cookies on Microsoft's domains (such as CLID and MUID), and we keep the Clarity visitor ID described above in local storage; signing out does not remove it. Google Ads and Meta Pixel set their own advertising cookies. If you decline, or have not decided yet, none of these tools load.
If you arrive through a link with campaign tags (utm_ parameters), we keep those tags in your browser's session storage for the visit. They are sent only as part of the analytics events above, so only after you accept.
Not controlled by the cookie banner: YouTube videos embedded in some of our guides. The preview image is loaded from YouTube when it comes into view, and the YouTube player loads when you click play, whether or not you have accepted the cookie banner. Once the player loads, YouTube may set its own cookies.
To change your choice, clear this site's cookies and local storage in your browser settings. This also removes the Clarity visitor ID, and the cookie banner will appear again. Cookies on Microsoft's domains may not be removed this way; if not, clear them separately in your browser settings.
Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your account and associated data.
- Export: Request an export of your data in a portable format.
- Opt-out: Unsubscribe from non-essential communications at any time.
To exercise any of these rights, please contact us using the information below.
Data Retention
Unless listed below, we keep the information described in this policy until your account is deleted. These records are deleted automatically sooner:
- Reply logs: after 90 days
- App status reports: after 180 days
- Email link-click records: after 180 days (see Email Link Tracking)
- Server error logs: after 30 days
You can ask us to delete your account and associated data by contacting us (see Contact Us). We will delete your personal data within 30 days of your request, except where the law requires us to keep it. Data held by third-party services, such as Stripe and Mixpanel, is kept under their own policies; where we can, we will ask them to delete it.
Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal information from children under 16.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website and updating the effective date.
Email Link Tracking
When we send you a product email — a welcome message, an Enterprise trial notice, or a notice that your access was extended — the links to our guides, our download page and our overview presentation pass through a redirect on our own domain before taking you there.
We record which link was clicked, on which day, and the time of the first click that day, linked to your account. These records do not include your IP address or your browser's user agent. However, the click passes through our website host (Vercel) and our web server, whose request logs record the full link address, which includes your account ID, together with an IP address and the user agent. We do not use tracking pixels, so we cannot tell whether you opened an email — only whether you followed one of these links.
We use this for one purpose: to learn which guides are actually useful, and to stop sending links nobody reads. These records are deleted after 180 days. You can ask us to delete yours sooner by writing to us.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
- WhatsApp: +64 20 4046 6889