Privacy Policy
Last updated 23 June 2026
This policy explains what personal data JibuSasa collects, why we collect it, who we share it with, and the choices you have. It covers our website, the staff console, and the WhatsApp assistant we operate on behalf of organizations.
Who we are
JibuSasa provides software that lets an organization answer WhatsApp enquiries automatically and hand conversations to their staff. Each organization that signs up is a separate tenant with its own data.
When an organization uses JibuSasa to talk with its customers, that organization is the data controller for those conversations, and JibuSasa acts as a data processor on their behalf. For our own website and account holders, JibuSasa is the controller.
Data we collect
- Account data. Names, email addresses, hashed passwords, and roles for staff members who sign in to the console.
- Organization data. Your organization name, and the configuration you provide, including WhatsApp identifiers and AI provider settings.
- Conversation data. Messages sent to and from your WhatsApp Business number, the sender's WhatsApp ID and profile name, timestamps, delivery identifiers, and conversation status such as whether a chat was escalated to a person.
- Knowledge content. Documents you upload or paste so the assistant can answer questions, along with the numerical embeddings generated from them.
- Technical data. Server logs needed to operate and secure the service, such as request metadata and error traces.
We do not intentionally collect special category data. Please avoid putting sensitive personal information into knowledge documents.
How we use data
- Answering enquiries. Message content and relevant knowledge are used to generate replies.
- Human handover. Conversations are shown to your staff so they can take over when needed.
- Follow ups. If a customer stops replying, the assistant may send a short check in message, according to the settings your organization chooses.
- Running the service. Authentication, security, troubleshooting, and preventing abuse.
We do not sell personal data, and we do not use your conversations or knowledge content to train our own models.
AI providers and sub processors
To generate replies, message content and relevant knowledge extracts are sent to the AI provider your organization selects and configures with its own API key. Depending on that choice this may be Anthropic, OpenAI, Google, or another compatible provider, including one you host yourself. Their handling of that data is governed by their own terms and privacy policies.
We also rely on:
- Meta Platforms. Delivery of WhatsApp messages through the WhatsApp Business Cloud API.
- Embeddings provider. Converting knowledge documents into vectors so relevant passages can be retrieved.
- Hosting and database providers. Running the application and storing data.
Storage, security, and location
Data is stored in our managed database. Sensitive credentials, including AI provider API keys and WhatsApp access tokens, are encrypted at rest using AES GCM encryption. Inbound WhatsApp webhooks are verified with a signature, and console access requires an authenticated session token.
Each organization's conversations, staff, and knowledge are logically separated so one tenant cannot access another's data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
How long we keep data
Conversations and knowledge content are kept while your organization's account is active, so your team has history and the assistant has context. If you delete a document, a conversation, or your account, the related records are removed from our production database, and residual copies may persist in backups for a limited period before expiring.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority.
If you messaged an organization's WhatsApp number and want your data removed, please contact that organization directly, since they control those conversations. We will support them in responding. For data we control, contact us using the details below.
Children
The service is intended for use by organizations and their staff, and is not directed to children. If a school or similar organization uses JibuSasa to communicate about a child, the messages are exchanged with the parent or guardian who contacts them.
Changes to this policy
We may update this policy as the service evolves. When we make material changes we will update the date at the top of this page and, where appropriate, notify account holders.
Contact us
For privacy questions or requests, email privacy@jibusasa.app.