Legal
Privacy Policy
Last updated 9 September 2026
This policy explains how Xunoia (“we”) processes personal data when you use TextBind. It applies to operators of a TextBind workspace and, where we act as a processor, to people who message a customer’s WhatsApp number. For processor terms see the DPA.
1. Who is responsible
Controller for your account, billing, and website analytics: Xunoia, reachable at privacy@textbind.com.
Processor for WhatsApp message content, transcripts, identities, and action payloads that belong to a customer workspace: Xunoia, on that customer’s documented instructions.
2. Data we collect
Account
- Name, email, password hash (via better-auth), workspace name.
- Authentication cookies and session identifiers.
Workspace configuration
- Meta App ID, WABA ID, Phone Number ID, display phone, verified name.
- Encrypted Meta App Secret, access token, TextBind app secret, and API authentications.
- Action schemas, HTTP templates, system prompt extras, budgets.
Runtime (on behalf of the customer)
- WhatsApp phone numbers, link codes (hashed), user IDs you assign.
- Message text, voice transcripts, media metadata, tool args, and replies.
- Audit logs (default 90 days) and conversation turns (last 20).
- Voice objects in object storage (default 30 days).
Website
- Essential cookies described in the Cookie Policy.
- Server logs (IP, user agent) for security, typically 30 days.
We do not sell personal data. We do not use end-user WhatsApp content to train foundation models.
3. Why we process it
- Provide, secure, and bill the Service (contract).
- Detect abuse and protect the Service (legitimate interests / legal obligation).
- Send product and security notices (contract / legitimate interests). Marketing email only with consent where required.
- Comply with law and Meta incident requests that are legally binding on us.
4. Sharing
- You / your APIs. We POST tool calls to URLs you configure, including identity fields.
- Meta. We send and receive WhatsApp Cloud API traffic using your tokens.
- Sub-processors: hosting, database, object storage, email, LLM, and speech-to-text providers listed in the DPA (currently may include Vercel or equivalent host, MongoDB, Cloudflare R2, Anthropic, Google, Sarvam, Deepgram, Inngest). We will keep an updated list at privacy@textbind.com on request.
- Professional advisers, or authorities when legally required.
5. International transfers
Data may be processed in India, the United States, the EU, or other regions where our sub-processors operate. Where required we use appropriate safeguards (standard contractual clauses or equivalent).
6. Retention
- Account data: life of the account, then up to 90 days after deletion unless law requires longer.
- Audit logs: 90 days default.
- Voice notes and audio: 30 days default.
- Conversation memory: last 20 turns, overwritten continuously.
7. Your rights
Depending on your location you may have rights to access, correct, delete, restrict, port, or object to processing, and to withdraw consent. Workspace operators should contact us; WhatsApp end users should contact the business they messaged first. You may lodge a complaint with a supervisory authority.
To exercise rights: privacy@textbind.com. We may need to verify the requester.
8. Security
Secrets are encrypted with AES-256-GCM. Passwords are hashed by the auth provider. See Security. No method is 100% secure.
9. Children
The Service is not directed to children under 18. We do not knowingly collect their data.
10. Changes
We will post updates on this page and change the “Last updated” date.
