Skip to content

Privacy policy

Last updated: · Effective: · Version 1.6

WhatsAssist ("WhatsAssist", "we", "us", "our") operates the WhatsAssist Android application and the website at opergen.com (collectively, the "Service"). Your privacy is fundamental to how we built this product. This Privacy Policy explains what we collect, why, how we use it, and what choices you have.

If you don't agree with this policy, please don't use the app or our services.

1. Plain-English overview

In one minute:

  • WhatsAssist reads only the notifications you allow on your Android phone.
  • We use those messages to write and send replies for you. It answers automatically on every plan, and one switch stops it.
  • Your conversation memory is encrypted at rest and in transit.
  • We never train AI models on your conversations.
  • We never sell or share your data for advertising.
  • You can request deletion of everything in Settings → Account.
  • You can write to support@opergen.com for any privacy question or request.

2. Who we are

Operator
WhatsAssist
Data controller
WhatsAssist
Operating from
Bengaluru, Karnataka, India
All inquiries
support@opergen.com
Privacy contact
support@opergen.com

For postal correspondence, including service of notices, email support@opergen.com first and we will provide a postal address appropriate to your matter.

3. What this policy covers

This policy applies to:

  • The WhatsAssist Android app
  • Our websites at opergen.com and its subdomains
  • Our APIs and backend services
  • Customer support interactions via support@opergen.com

It does not cover third-party services you connect to (WhatsApp, Instagram, Telegram, etc.). Those have their own privacy policies, which apply when you use them.

4. What we collect

4.1 Information you give us directly

  • Account information: email address, name (optional), country.
  • Payment information: processed entirely by Google Play. We see your plan and your country; we never see your card details, and no other payment processor is involved.
  • Business knowledge uploads: a PDF, a photo, a chat export, or text you paste in, to teach WhatsAssist about your business.
  • Support communications: what you write to us at support@opergen.com.

4.2 Information from your device (via Android Notification Access)

When you grant Notification Access we receive:

  • Message text shown in notifications from messaging apps you enable.
  • Sender names shown in those notifications.
  • Notification timestamps.

We do not receive:

  • Messages that are not delivered as notifications.
  • Media content (photos, voice notes, videos). Only placeholder text like "Photo".
  • Your full address book.
  • Anything from apps you have not enabled.
  • Anything from your screen, keyboard, microphone, camera, or location.

You can revoke Notification Access any time in Android Settings → Notifications → Notification access.

4.3 Information collected automatically

  • Device info: model, OS version, app version, language, country, screen resolution.
  • Usage info: features used, draft acceptance/rejection rates, errors and crashes.
  • Approximate location: inferred from IP at country/city level. No precise GPS.
  • Performance metrics: latency, error rates, anonymized request shapes.

4.4 Information from third parties

  • Sign in with Google: name, email, Google account ID.
  • Google Play: subscription status, country.
  • Analytics: aggregated event data only, with IPs truncated.

5. Why we collect it (legal bases)

Under GDPR (UK and EU residents):

Purpose Legal basis
Provide the app and servicesPerformance of a contract (Art. 6(1)(b))
Write and send replies using your messagesPerformance of a contract (Art. 6(1)(b))
Process payments and renewalsPerformance of a contract (Art. 6(1)(b))
Improve reliability (crash data)Legitimate interest (Art. 6(1)(f))
Service-related emailsPerformance of a contract (Art. 6(1)(b))
Optional marketing emailsConsent (Art. 6(1)(a)). Opt out any time
Comply with legal obligationsLegal obligation (Art. 6(1)(c))
Defend against fraud / abuseLegitimate interest (Art. 6(1)(f))

Under India's DPDP Act 2023, our lawful grounds are consent (for processing of personal data) and legitimate use for purposes defined in §7 of the Act.

6. How we use your information

  1. Write replies from your messages and your memory, and send them for you unless you have switched that off.
  2. Maintain your conversation memory and the business information you upload.
  3. Improve the quality of replies for you (your memory does not improve any other user's replies).
  4. Operate, maintain, and improve our services.
  5. Process subscriptions and payments.
  6. Respond to support requests at support@opergen.com.
  7. Detect and prevent fraud, abuse, and security incidents.
  8. Comply with legal obligations.

7. What we do NOT do with your information

  • We do not train AI models on your messages or memory.
  • We do not sell your data to anyone, for any purpose.
  • We do not share your messages with advertisers or marketers.
  • We do not read your messages outside of generating drafts you requested.
  • We do not use your data to build cross-app advertising profiles.
  • We do not permit our AI sub-processors to use your data to train their general-purpose models, per the enterprise terms under which we invoke them.

8. Cookies and similar technologies

opergen.com has no login, no server-side session and no form processor, so nothing here needs a cookie to work. One thing on the site can set cookies, and whether it does so before or after you are asked depends on where you are.

  • Functional (localStorage only): remembers the country you selected on /pricing so prices stay in your currency, and remembers your answer to the analytics question below. Neither leaves your browser and neither is transmitted to us.
  • Analytics. This site can load Firebase Analytics (the same Google Analytics 4 measurement used inside the app, named in the sub-processor table above), which sets first-party cookies to count page views and tell a repeat visit from a new one. It counts pages. It does not profile you, and there is no advertising use of any of it.
    • In the EEA, the UK and Switzerland, you are asked first. Nothing is fetched, nothing is initialised and no cookie is set until you choose “Allow”. Choose “No thanks” and no script is fetched at all; the answer is remembered so you are not asked again, and every page works identically either way.
    • Everywhere else it loads with the page, without a bar, and you can switch it off at any time with the button below.

    Your browser works out which of those applies, on your device, with no network call and nothing sent to us. It uses your timezone and your browser language, and it is deliberately cautious: anything it cannot place, and any European timezone it does not recognise, is treated as needing to be asked. A choice you make yourself always overrides that guess, in both directions.

  • No advertising cookies. No third-party tracking pixels. No cross-site profiling.

Analytics on this browser

The choice is stored in this browser only, as a single localStorage value. Turning it off takes effect on the next page you load, and clearing this site’s data resets it.

Until 2026-09-02 this section said the site ran no analytics of any kind, and while it said so that was true. On 2026-09-02 analytics was added behind an explicit opt-in everywhere. On 2026-09-03 that became the region-aware rule described above, because an opt-in bar shown to everyone measured essentially nothing while still being the more intrusive thing to look at. Each step is recorded here rather than quietly replaced: a policy that changes without saying it changed is worth less than one that never claimed anything.

Inside the Android app, technical storage required for the app to function is used, and the app includes Firebase Analytics, which is named in the sub-processor table above and is what the analytics rows in Section 4.3 and Section 12 refer to. There are no advertising SDKs, no attribution SDKs, and no cross-app tracking.

9. Who we share with

We share personal information only with:

9.1 Service providers (data processors)

See Section 10 for the current sub-processor list.

9.2 Legal and safety

We may share information if required by law, court order, or to protect the rights, property, or safety of WhatsAssist, our users, or the public. We narrowly scope any disclosure and challenge overbroad requests where lawful.

9.3 Business transfers

If WhatsAssist is acquired, merged, or sells material assets, your information may be transferred. We will notify you and any acquirer is bound to this Privacy Policy unless you accept new terms.

10. Sub-processors

We engage the following sub-processors to deliver the Service. Each has a data-processing agreement that restricts use of your data to providing services to us, and prohibits onward training of general-purpose AI models on your content.

Sub-processor Purpose Region
Google Cloud Platform Hosting, storage and encrypted databases United States / EU multi-region
Google Gemini Enterprise Writes the reply United States
Google Play App distribution and subscription billing United States
Firebase Crashlytics Crash and error reporting United States
Firebase Analytics Product analytics: in the app always, and on opergen.com only with consent United States
Firebase Cloud Messaging Push notifications to your own phone United States

We will update this list with at least 14 days' notice via this page before engaging a new sub-processor that processes user personal data. The sub-processor page says what we send each of them. For DPA copies, email support@opergen.com.

11. International data transfers

WhatsAssist is operated from India. Our sub-processors are primarily in the United States and the European Union. When we transfer data across borders:

  • EU/UK users: we rely on Standard Contractual Clauses (EU 2021/914 and the UK Addendum) approved by the European Commission and the UK ICO, plus supplementary measures (encryption in transit and at rest, contractual prohibitions on government access except where legally compelled).
  • Indian users: transfers are made in accordance with the DPDP Act 2023 and any notifications issued under §16 of the Act.
  • Other regions: transfers are made under analogous safeguards required by the applicable jurisdiction.

For information about transfer impact assessments, email support@opergen.com.

12. How long we keep your data

Data type Retention
Active account dataWhile your account is active
Conversation memory (all plans)Kept until you delete it. We do not expire it on a schedule today; if we introduce one we will say so here first
Business uploads (catalogs, FAQs)Until you remove them
Crash logs90 days
Analytics eventsNo longer than 14 months, which is the maximum event-level retention Google Analytics offers on our plan
Support tickets24 months after resolution
Billing records7 years (legal / tax requirement)
Deleted account dataWe begin erasing on request and target 30 days. We are still completing the parts of that erasure that reach every one of our systems, and we will not claim it is finished until it is. Where law requires retention we keep only what it requires
Backups containing deleted dataOur database keeps seven daily backups and seven days of transaction logs, so a backup holding deleted data rotates out within about a week

13. Your rights

Depending on your jurisdiction, you have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR; §11 DPDP)
  • Correct inaccurate data (Art. 16 GDPR; §12 DPDP)
  • Delete your data ("right to be forgotten") (Art. 17 GDPR; §12 DPDP)
  • Restrict or object to processing (Art. 18, 21 GDPR)
  • Portability: receive a machine-readable copy (Art. 20 GDPR)
  • Withdraw consent at any time (Art. 7 GDPR; §6 DPDP)
  • Nominate someone to exercise your rights on your behalf (DPDP §14)
  • Not be subject to solely-automated decisions with legal effect (Art. 22 GDPR)
  • Lodge a complaint with your data protection authority

14. How to exercise your rights (Data Subject Requests)

  1. Email support@opergen.com from the email address linked to your WhatsAssist account, with the subject line DSR: [your request].
  2. We acknowledge within 5 business days.
  3. We may verify your identity if your request affects sensitive data; verification will use the minimum data necessary.
  4. We respond substantively within 30 days of identity verification. Where law permits an extension (up to 60 additional days for complex requests), we will tell you why and when to expect a response.
  5. If we cannot fulfil your request in part or whole (e.g., a legal retention obligation), we will tell you why and what your further options are.
  6. Access, correction, deletion, and portability requests are free. Manifestly unfounded or excessive requests may incur a reasonable fee or be refused, with reasons.

You can also delete your account in-app: Settings → Account → Delete account.

EU users: complaints to your national Data Protection Authority. UK users: Information Commissioner's Office (ICO). Indian users: Data Protection Board of India. California users: see Section 18.

15. Security

We protect your data using:

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest, using Google Cloud's managed encryption
  • Role-based access control with audit logging on infrastructure access
  • Two-factor authentication on all team accounts
  • Automated dependency and vulnerability scanning
  • Code review on changes to systems that handle your data

What we do not yet have. We have not commissioned an independent third-party security audit, and we do not hold SOC 2, ISO 27001 or any comparable certification. We would rather tell you that than imply otherwise. If either changes we will say so here.

No system is 100% secure. If we discover a breach affecting you, we will notify you and the relevant authorities within the timelines required by law (72 hours under GDPR; without undue delay under DPDP §8(6)).

16. Children's privacy

WhatsAssist is not directed at children under 13 (or 16 / 18 depending on jurisdiction). We do not knowingly collect data from children below the applicable age threshold. If we learn we have collected such data, we will delete it promptly. If you believe a child has provided data to us, email support@opergen.com.

17. Third-party services

WhatsAssist integrates with messaging apps you have already installed (WhatsApp, Instagram, etc.) via Android Notification Access. We are not affiliated with, endorsed by, or controlled by Meta, Telegram, Google, or any messaging platform. Your use of those apps is governed by their own terms and privacy policies. WhatsAssist cannot guarantee that those apps' policies or technical changes won't affect your experience.

18. California residents (CCPA / CPRA)

If you're a California resident, you have the following rights:

  • Right to know what categories of personal information we collect (see Section 4).
  • Right to delete your personal information.
  • Right to correct inaccurate information.
  • Right to opt out of "sale" or "sharing": we do not sell or share your personal data for cross-context advertising and have not in the prior 12 months.
  • Right to limit the use and disclosure of sensitive personal information.
  • Right to non-discrimination for exercising any of these rights.

To exercise these rights, email support@opergen.com with the subject CCPA Request.

19. India residents (DPDP Act 2023)

If you are an individual in India ("Data Principal"), the Digital Personal Data Protection Act, 2023 grants you rights similar to those described above, including the right to access, correction, erasure, grievance redressal, and nomination. Our Grievance Officer can be reached at support@opergen.com with the subject DPDP Grievance. We will respond within the timelines prescribed by the DPDP Act and any subordinate rules.

20. Changes to this policy

  • We will revise the "Last updated" date at the top.
  • For material changes, we will notify you via email or in-app notice at least 14 days before the change takes effect.
  • Your continued use after a change means you accept the updated policy.
  • Prior versions are archived and available on request via support@opergen.com.

What changed in version 1.1 (24 August 2026). Three things this policy said were not true of the system it described, and we corrected them rather than leaving them standing. The retention table promised that conversation memory on the Free plan was kept to a rolling window and that deleted account data was erased within a fixed period; nothing in our systems enforced either, so both are gone and this policy now says plainly that we keep your history until you delete it. Section 15 listed per-user encryption keys, an annual third-party security review and a documented incident response plan among our security practices. We do not have those three, and the section now says which controls we do have and which we do not.

None of our actual practices changed on that date, because the removed statements never described them. We are recording it here because a correction a reader cannot see is not much of a correction, and because losing a stated retention window is worth knowing about even when it was never enforced.

What changed in version 1.2 (25 August 2026). Three more corrections, found by reading this page against the systems it describes. RevenueCat has been removed from the sub-processor table and from Section 4. It was listed as handling subscription state and named as a payment processor, and we do not use it: billing runs through Google Play and we verify purchases against Google's own API. We were naming a company we send nothing to. Two retention periods were also wrong: analytics events said 13 months, which is not a retention period Google Analytics offers, and now states the 14-month maximum our plan allows; backups said 90 days, and now says what our database is actually configured to keep, which is seven daily backups and seven days of transaction logs.

What changed in version 1.3 (25 August 2026). Who "we" are. Every earlier version of this policy named OperGen Technologies Private Limited as the legal entity, the data controller and the country of incorporation. That company is not registered, so this page was identifying its controller by a name no registrar could confirm, which is the one field in a privacy policy a reader is entitled to rely on absolutely. The identity block now says what is true. The operator and data controller is WhatsAssist, reachable at support@opergen.com, operating from Bengaluru, Karnataka, India. Nothing about who holds your data, where it goes, or what we do with it has changed. Only the name we were putting on it. The same correction was made to the Terms and to the structured data this site publishes to search engines.

What changed in version 1.4 (25 August 2026). The Google Play Data Safety summary in Section 22 was wrong in two places and both were corrections in the direction of collecting more, not less. It said we collect no photos, and we do: if you send a photo of a price list or a menu, that is a photo, and it now has its own row alongside a new one for files and documents, which covers a PDF or a chat export. It also marked message history optional, and it is not: writing a reply needs our servers because the model runs there, so a message is sent whether or not you would prefer it stayed on the phone. There is no toggle for that and there never was one. A note under the table now also explains what the "Shared" column means, because a column of No against a page that names Google as a sub-processor invites exactly the wrong conclusion.

What changed in version 1.5 (25 August 2026). Five corrections, found by reading this page line by line against the product before translating it into four languages. Section 1 still said we draft replies you review and send. We do not: it answers automatically on every plan, which every other page on this site was corrected to say on 24 August, and this one was missed. Section 5, Section 6 and the Play summary in Section 22 carried the same framing and now describe writing and sending. Section 4.1 listed CSVs among the things you can upload; no upload path has ever accepted one, and the four kinds that exist are named instead. Section 8 described cookies and an analytics provider that this website does not have: opergen.com sets no cookies at all and runs no analytics of any kind, and saying otherwise overstated what we collect. The same section now names Firebase Analytics inside the Android app plainly, rather than claiming no third-party trackers while shipping one.

21. Contact us

All privacy matters
support@opergen.com
Grievance Officer (India)
support@opergen.com, subject: DPDP Grievance
CCPA requests
support@opergen.com, subject: CCPA Request
Operating from
Bengaluru, Karnataka, India

We typically respond within 5 business days, faster for urgent requests.

22. Google Play Data Safety summary

This mirrors the disclosures we make in our Google Play Data Safety section.

On the "Shared" column. Google Play defines sharing as transferring your data to a third party, and excludes transfers to a service provider that processes it on our behalf under contract. Writing a reply sends the message to Google's AI platform, and storing it uses Google Cloud, both under the data-processing terms linked in the sub-processor table above. So those are processing, not sharing, and the column says No. It is not a claim that your messages stay on our own machines: Section 9 and the sub-processor table say exactly where they go, and you should read those rather than this column.

Data type Collected Shared Optional Purpose
Email addressYesNoNoAccount management
NameYesNoYesPersonalization
User IDYesNoNoAccount, analytics
Messages in appYesNoNoCore functionality (writing replies)
Message historyYesNoNoApp functionality
App info and performanceYesNoNoDiagnostics, crash reporting
Device or other IDsYesNoNoAnalytics, security
Approximate locationYesNoNoRegional pricing, analytics
PhotosYesNoYesApp functionality (a photo of a price list or menu, if you send one)
Files and documentsYesNoYesApp functionality (a PDF or a chat export, if you send one)
VideosNoNon/an/a
Audio filesNoNon/an/a
ContactsNoNon/an/a
Precise locationNoNon/an/a
Web browsing historyNoNon/an/a
Financial info (cards)NoNon/an/a

Encrypted in transit: Yes · Deletion supported: Yes · Play Families Policy: No (not directed at children)


This Privacy Policy is published in English. If we make it available in other languages, the English version controls in case of conflict.