Privacy Policy
This policy explains what Neura Chat does with personal data — the data of the businesses who use it, and of the people they message on WhatsApp.
Last updated: 22 August 2026
Who we are
Neura Chat is a WhatsApp automation platform operated by Neuraxine, India. For anything in this policy, contact us at privacy@neuraxine.in.
Businesses using Neura Chat connect their ownWhatsApp Business Account. We are not a Business Solution Provider and we do not resell WhatsApp messaging — every message is sent and received under the customer's own Meta credentials.
Two kinds of people, two roles
This distinction determines who is responsible for what, so it comes first.
- Our customers — the businesses who sign up. For their account data we are the data controller.
- Their contacts— the people who message a customer's WhatsApp number. For that data the customer is the controller and we are a processor: we store and process those messages on the customer's instruction and do not use them for our own purposes.
If you were messaged by a business using Neura Chat and want your data removed, contact that business first — they control it. If you cannot reach them, write to us and we will help.
What we collect
Account data.Your email address, your organisation's name, your role in it, and the timestamps of these records. If you sign in with Google we receive your email address and name from Google, nothing else.
WhatsApp connection data. Your WhatsApp Business Account ID, phone number ID, Meta App ID, and an access token. The access token is encrypted with AES-256-GCM before it is written to the database and is never displayed back to you.
Conversation data.The phone numbers, WhatsApp profile names and any tags of the contacts who message you, the content of those messages, our replies, and delivery and read receipts. Media is referenced by Meta's media ID rather than copied to our servers.
Configuration you create. Chatbot flows, FAQ entries, AI Assistant instructions, automations, templates, products and integration credentials. Integration credentials are encrypted at rest in the same way as WhatsApp tokens.
Operational logs. Webhook deliveries, bot decisions and errors, retained so that you can audit why an automated reply was or was not sent.
We do not use tracking cookies or third-party advertising pixels. The only cookies set are the ones needed to keep you signed in.
What we do with it
- Deliver the service: receive your inbound WhatsApp messages, match them against the bots and rules you configured, and send the replies.
- Show you your inbox, contacts, campaigns and analytics.
- Authenticate you and keep your organisation's data separated from every other organisation's.
- Diagnose faults, and show you an audit trail of what the automation did.
- Bill you, and contact you about your account.
We do not sell personal data. We do not use your customers' messages to train AI models, and our AI provider is contractually bound not to train on data sent through their API.
Who else processes it
We use the following sub-processors. Each one only receives what it needs to perform its function.
| Provider | Purpose | Region |
|---|---|---|
| Meta Platforms | WhatsApp Business Platform — delivers and receives every message | United States, Ireland |
| Supabase | Database, authentication and file storage | Per project region |
| Vercel | Application hosting and edge network | United States |
| Anthropic | Generates AI Assistant replies. Only used when you enable an AI Assistant, and only the conversation it is replying to is sent | United States |
Message content necessarily passes through Meta — that is what sending a WhatsApp message means. Meta's handling of it is governed by the WhatsApp Business Data Transfer Addendum and their own privacy policy.
How we protect it
- Tenant isolation is enforced in the database, not just in application code. Every table has row-level security, and a query can only reach rows belonging to an organisation the signed-in user is a member of.
- Credentials are encrypted at rest with AES-256-GCM. WhatsApp access tokens and third-party integration credentials are never returned to the browser.
- Inbound webhooks are cryptographically verified. Every delivery is checked against an HMAC-SHA256 signature using a constant-time comparison before its contents are trusted.
- API keys are stored as hashes. The key itself is shown once at creation and cannot be recovered afterwards.
- All traffic is served over HTTPS.
No system is perfectly secure. If you believe you have found a vulnerability, please email privacy@neuraxine.in rather than disclosing it publicly, and we will respond.
How long we keep it
Conversation and configuration data is kept for as long as your account is active, because an inbox you cannot scroll back through is not an inbox. Operational logs are kept for a shorter period, sufficient to investigate faults.
When you delete your organisation, its data is deleted with it — contacts, conversations, messages, bots and credentials all cascade from the organisation record. Backups age out on their own schedule, within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. These rights apply under the GDPR, and comparable rights exist under India's Digital Personal Data Protection Act and several other regimes.
Exercise any of them by emailing privacy@neuraxine.in. We will respond within 30 days. For deletion specifically, see our data deletion instructions.
Children
Neura Chat is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
Changes
If we change this policy materially we will email account owners before the change takes effect. The date at the top always reflects the current version.
Contact
Neuraxine
India
privacy@neuraxine.in