Privacy Policy
Privacy Policy
Effective 1 September 2026. This policy describes what Automix AI does with personal data — not what we intend to do one day. Where our practice is weaker than you might expect, this page says so rather than leaving it out.
Automix AI is operated by Dr. Vivek Trivedi from Gujarat, India. We build a platform of specialist AI workspaces; Wavy, our WhatsApp customer-engagement workspace, is the product most customers use, and the other specialists are at varying stages of availability marked on each product page.
Most privacy policies are written from a template and then loosely fitted to the product. This one was written the other way round: from the database schema and the code that reads it. That means it is specific, and it also means it admits things a template would have smoothed over — that we do not yet delete old messages on a schedule, that we have no two-factor authentication, and that deleting your account is something a person does rather than a button you press. We would rather you knew that before you trusted us with anything.
Two different roles
Whose data, and who is answerable for it
This distinction runs through everything below, so it comes first. Automix handles two quite different kinds of personal data, and our obligations differ for each.
- Your data, as our customer. Your name, email address, phone number, sign-in credentials and workspace settings. Here Automix decides what is collected and why, so Automix is answerable to you for it. This policy governs it.
- Your customers' data, which you put into Automix. The contacts you import, the conversations they have with you, the documents you upload. Here you decide what is collected and why; Automix processes it on your instructions. You are answerable to those people, and you are responsible for having a lawful basis to message them. We help — the consent machinery described below is strict by design — but we do not become the party they should complain to, and we cannot grant their requests without you.
If one of your customers contacts us directly about their data, we will tell them to contact you and let you know they asked, unless the law requires otherwise.
What we store
The actual categories
About you, the account holder. Email address, full name, phone number, and either a password (stored only as a bcrypt hash, never in readable form) or a reference to the Google account you signed in with. We also record whether your email is verified, your role in the workspace, and the time of your last sign-in.
Security and audit records. IP address and browser user-agent string against significant account and workspace events, so that we and you can reconstruct who changed what. Ordinary web-server request logs exist as well. Where a shared dashboard link is opened, we store a salted hash of the viewer's address rather than the address itself.
What you put in the workspace. Your business details, brand and offer settings, operating rules, and any connected-account credentials you authorise. Contacts you add or import — name, phone number, whatever custom attributes you choose to store, lead stage, and consent state. The content of conversations: message text, media files, and interactive message payloads.
Media, kept on our own storage. When a customer sends your WhatsApp number a photo, document, or voice note, we copy it out of Meta's servers onto ours, because Meta deletes it. That copy lives in our object storage until deleted.
Sensitive categories, if you use the agents that handle them. Two products deliberately touch data that deserves naming:
- Health information. The Doctor workspace stores medical documents, clinician names, issuing facilities and dates of birth for the people whose records you manage. Where a record belongs to someone under 18, the system requires you to record a guardian's consent before the profile can be created.
- Identity and financial documents. The document-AI features can read Aadhaar numbers, PAN, GST registration numbers and bank statements. Identifiers of this kind are stored only as the last four digits — the system refuses to put a full identifier in any other field — and long digit sequences in extracted document text are masked. No part of Automix stores a complete card number, bank account number, IFSC code, UPI ID or IBAN in any field.
Anonymous website measurement. We run self-hosted Umami on our own servers to count page views and understand which Automix pages are useful. It is cookieless and first-party: it does not create an advertising profile, follow you across sites, or send analytics data to a third-party analytics company. We do not use session replay or heatmaps. Ordinary web-server request logs and this measurement can include technical request data such as IP address, browser, device, referrer, and the page requested.
What we never collect. No biometric data of any kind. No advertising profile: there is no Google Analytics, no Tag Manager, and no Meta pixel anywhere in this site. See the Cookie Policy for the two specific places where another company's cookies do appear.
Why
What we use it for, and what we never do with it
Account data is used to give you access, keep the account secure, bill you, and contact you about the service. Workspace and conversation data is used to operate the workspace you configured — delivering messages, generating replies you have asked an agent to draft, and showing you your own history. Security records are used to investigate incidents and to show you who did what.
We do not sell personal data. We do not share it with advertisers, data brokers, or anyone building a marketing profile. We do not use your customers' conversations to train models — the AI providers we use are called through their business APIs to answer a single request, and the output is returned to your workspace.
Who else sees it
Every company involved in delivering the service
This is the complete list of third parties that personal data can reach when the corresponding feature is in use. Where a feature is not configured in your workspace, no data flows to the company named.
- Meta Platforms — recipient phone numbers and the full content of every WhatsApp message, because that is what sending a WhatsApp message means. Governed by Meta's own terms as well as ours.
- OpenRouter — where an AI feature is used, the text it needs to do its job: the relevant conversation excerpts, the customer text being replied to, or the document being analysed.
- Zoho (ZeptoMail) — recipient address, subject and body of email we send on your behalf and of our own service email.
- Our object storage provider — every uploaded or received media file and document, held in our own bucket.
- Google — if you sign in with Google, your identity token; if you connect Google Drive, the files you export to it. Google Fonts also serves the typefaces on our pages, which discloses your IP address to Google on every page view. We are moving those files onto our own servers.
- Airtable — only if you connect it: contact name, phone number and opt-in status, synchronised to your own base.
- Payment providers — where a payment is taken through a gateway, that gateway handles the payment itself. Card and bank details go to them and never to us; no complete card or account number is stored anywhere in Automix.
We will also disclose data where the law compels it, and to professional advisers under confidentiality. If Automix is ever sold or merged, data may transfer with the business, and you will be told before that changes who controls it.
Where data is held. Automix runs on servers we control. The providers above operate internationally, so data reaching them may be processed outside India under their own arrangements.
How long
Retention — including where we have no schedule
This is the section most policies write as an aspiration. Here is what the software actually does.
What is deleted on a timer. Three things, and only three:
- Voice-call recordings and transcripts in the Wani workspace, kept 90 days by default, adjustable by you.
- Interview recordings in the Bharti hiring workspace, kept 30 days.
- Health records in the Doctor workspace, where you can set a retention period per profile. If you do not set one, they are kept until deleted — the system will not silently discard a medical record because a default expired.
What has no automatic deletion. Everything else, plainly: message content, contacts, conversations, mirrored media, document extractions, AI processing logs, webhook delivery records and audit events are retained until you or we delete them. There is no scheduled purge job for these, and we are not going to imply one by quoting a period we do not enforce. Audit events are deliberately append-only, because a security log you can quietly edit is not a security log.
What that means in practice. If retention limits matter to you — because of your own regulatory obligations, or simply because you do not want a five-year-old conversation sitting in a database — delete what you no longer need, or write to us and we will delete it for you. Every contact, conversation, document and record can be deleted individually from within the product today.
Your rights
What you can ask for, and what actually happens
Under India's Digital Personal Data Protection Act 2023, and equivalent rights elsewhere, you can ask for access to your personal data, correction of it, deletion of it, and information about who it has been shared with. Automix honours all four. The mechanics differ, so here they are honestly:
- Access and correction. Most of your data is visible and editable in the product. For anything that is not, email us and we will compile it. There is no one-click export bundle yet; we assemble it by hand, which is why we ask for up to 30 days.
- Deletion of specific records. Immediate and self-service. Contacts, conversations, documents, media and health records each have a delete control in the product.
- Deletion of your whole account. There is no self-service button. Write to us and a person carries it out in two parts — the workspace and its contents, then the sign-in identity — because they live in two separate systems. We complete this within 30 days and confirm in writing when it is done. We will say what, if anything, we must keep and why: normally only billing records we are required to retain, and append-only security logs recording that the deletion happened.
- Withdrawing consent. Where we rely on your consent, you can withdraw it at any time. This does not undo processing already carried out.
- Nominating someone. The DPDP Act lets you nominate a person to exercise your rights if you die or become incapacitated. Tell us in writing and we will record it.
How to ask. Email vivek@automixai.in with “Data request” in the subject line. We acknowledge within 7 days and complete within 30. If we need to verify who you are first, we will ask for the minimum that establishes it.
Support access to your workspace. Worth knowing because it is unusual: our staff cannot browse into your workspace at will. If we need to look at it to help you, the product asks you for permission, the request expires unanswered after 72 hours, an approval lasts 24 hours, and you can revoke it at any moment from your settings.
Consent
How we handle your customers' consent
This matters to you commercially as well as legally, because getting it wrong is what gets WhatsApp numbers banned.
Automix records consent per contact and per message category — marketing, utility, authentication and service — mirroring WhatsApp's own categories, and keeps an append-only history of every change with its source and evidence, so you can answer a challenge from Meta with a record rather than an assurance.
The gate fails closed. A contact is blocked from a campaign if they have opted out, and equally if there is simply no consent record for that category. Silence is not permission. This is checked again at the moment of sending, not only when a campaign is built, so a consent withdrawn mid-campaign takes effect immediately. An email unsubscribe writes to the same consent record as WhatsApp, so unsubscribing in one channel stops the other.
Replying STOP opts someone out automatically. The built-in opt-out rule is switched on for every workspace, so a contact who replies STOP is recorded as opted out without anyone on your side having to act. What it will not do is read intent: it matches the keyword, so a person who writes “please stop messaging me” in their own words is not caught by it. Watch your inbox for those and opt them out by hand.
One thing you must handle yourself. Contacts you import arrive with the master opt-in flag on, so the per-category consent record is what actually protects them. Import only people who have genuinely agreed to hear from you.
Security
The controls that exist, and the ones that do not
In place. Passwords are hashed with bcrypt and never stored readably. All traffic is served over HTTPS, with plain HTTP redirected. Session cookies are HttpOnly, Secure and SameSite=Lax. Sign-in sessions expire and refresh tokens rotate on every use. Credentials for connected accounts are held in an AES-256-GCM encrypted vault that refuses to operate if its key is missing rather than falling back to storing them in the clear. The two credentials that would let someone act as you — the WhatsApp access token that sends from your number, and the signing secret your own server uses to trust our webhooks — are encrypted in the database with the same cipher, so a database backup or a stray read replica does not carry them in the clear. Every database query is scoped to a single workspace, taken from your verified session — no part of the API accepts a workspace identifier from the request, so one customer cannot ask for another's data by changing a number in a URL. Rate limits apply to reads, writes and message sending. Significant account and security events are written to an append-only audit log.
Not in place, stated plainly. There is no two-factor authentication yet. There is no account lockout after repeated failed sign-ins. There is no IP allowlisting. We hold no security certification, have not completed an external audit, and make no compliance-framework claim. Our audit logging covers account and workspace events but does not yet extend to every billing action.
What we are not claiming. That our security is complete, or that every stored value is encrypted at rest. No system is without weaknesses and ours is young. Use a strong, unique password, give team members the least access they need, and revoke support access when you no longer need it.
If you find a security problem, email vivek@automixai.in with “Security” in the subject. We will acknowledge within 2 working days, will not pursue anyone who reports a genuine issue in good faith without exploiting it, and will tell affected customers about a breach that puts their data at risk without waiting to be asked.
Children
Age, and children's data
Automix AI is a business tool and is not for children. You must be 18 or older to hold an account. We do not knowingly collect personal data from children as account holders, and we do not operate an automated age-verification check — we rely on that requirement in the Terms. If you believe a child has created an account, tell us and we will delete it.
Separately, a workspace may legitimately hold records about a child — a paediatric patient record, for example. Where the Doctor workspace is used for someone under 18, the product requires a guardian's consent to be recorded before the profile can be created. If you handle children's data this way, you are responsible for having that consent genuinely, and for the additional care the DPDP Act requires of you.
Contact
Who is responsible, and how to complain
Dr. Vivek Trivedi is responsible for data protection at Automix AI. Reach him at vivek@automixai.in, or on +91 79841 00350.
If you are unhappy with how we handled a request or your data, say so to that address, marked “Complaint”. We will respond within 30 days with what we found and what we did. If you remain unsatisfied, you may complain to the Data Protection Board of India, and you do not need our permission to do so.
Changes
If this policy changes
When we change this policy we update the effective date at the top. For a change that materially affects your rights or widens what we do with your data — a new category of data, a new third party receiving it, a new purpose — we will email account holders before it takes effect, not after.
This policy is kept in the same repository as the software it describes, and a change to the code that makes a statement here untrue is meant to change this page in the same commit. That is how we intend to keep it accurate rather than merely current.
Questions
Straight answers
Do you sell my data or my customers' data?
No. We do not sell personal data, share it with advertisers or data brokers, or use your customers' conversations to train AI models. The only companies that receive data are the ones listed in this policy, each because it is doing a specific job you have asked for.
How long do you keep my messages?
Until you or we delete them. Only voice-call recordings (90 days), interview recordings (30 days) and health records with a retention period you set are deleted automatically. For everything else there is no scheduled purge, and we would rather tell you that than publish a retention period the software does not enforce.
Can I delete my account myself?
Not with a button — not yet. Email vivek@automixai.in and a person will do it within 30 days, in two parts because the workspace and the sign-in identity live in separate systems, and will confirm in writing when it is complete. Individual contacts, conversations and documents you can delete yourself, immediately.
Is my data encrypted?
Traffic is encrypted in transit over HTTPS. Passwords are hashed and never stored readably. Credentials for connected accounts sit in an AES-256-GCM vault, and your WhatsApp access token and webhook signing secret are encrypted in the database with the same cipher. Your messages and contacts are not — they are stored so the product can read them back to you. We are not claiming that every stored value is encrypted at rest, because that would not be true, and a security claim that is nearly true is not worth publishing.
Do you have SOC 2, ISO 27001, or similar?
No. We hold no security certification and have not completed an external audit. If that is a requirement for you, we would rather you knew now than discovered it during procurement.
Who is responsible if my customer complains about a message I sent?
You are. You decide who to contact and on what basis, and you are responsible for having their consent. Automix gives you the machinery to record and honour that consent, and blocks sends where consent is missing, but it does not become the party your customer should complain to.