← Back to Home

Privacy Policy

Last updated: November 3, 2025

1. Introduction

Welcome to NobuChat, operated by CosmicBytes LLC ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-driven WhatsApp automation platform (the "Service").

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide to us when you:

  • Register for an account
  • Use our Service
  • Contact our customer support
  • Subscribe to our newsletter or marketing communications

This information may include:

  • Name and contact information (email address, phone number)
  • Company name and business information
  • WhatsApp Business account credentials
  • Payment and billing information
  • Communication preferences

2.2 Automatically Collected Information

When you access our Service, we automatically collect certain information, including:

  • Device and browser information
  • IP address and location data
  • Usage data and analytics
  • Cookies and similar tracking technologies

2.3 WhatsApp Message Data

To provide our automation services, we process WhatsApp messages and conversations. This data is processed in accordance with WhatsApp's Business API terms and is used solely to deliver our Service functionality.

2.4 Information from Meta Platforms

When you connect your WhatsApp Business Account through the Meta (Facebook) Business Platform, we may receive:

  • WhatsApp Business Account information (phone number, display name, profile picture)
  • Message content sent and received through your WhatsApp Business Account
  • Message metadata (timestamps, delivery status, read receipts)
  • Customer contact information (phone numbers, names if provided)
  • Business profile information
  • Webhook event data

Important: We only access and process this data to provide you with the requested automation services. We do not use this data for any other purpose without your explicit consent.

2.5 Meta Platform Integration

NobuChat uses the WhatsApp Business API, which is provided by Meta Platforms, Inc. ("Meta"). Our integration with Meta's services is subject to:

  • Meta's Terms of Service
  • Meta's Data Policy
  • WhatsApp Business API Terms
  • Meta Business Tools Terms

Data Access Permissions: When you authorize NobuChat to access your WhatsApp Business Account, we request the following permissions:

  • whatsapp_business_messaging: To send and receive messages on your behalf
  • whatsapp_business_management: To manage your WhatsApp Business Account settings
  • business_management: To access your Meta Business Manager account

You can revoke these permissions at any time through your Meta Business Settings.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our Service
  • Process your transactions and manage your account
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and customer service requests
  • Improve and optimize our Service through analytics and research
  • Train and improve our AI models and automation capabilities
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our terms and policies
  • Send you marketing communications (with your consent)

3.1 WhatsApp Data Processing

We process WhatsApp message data strictly for the following purposes:

  • Delivering automated responses to your customers
  • Routing messages to appropriate team members
  • Providing conversation management and organization
  • Generating analytics and insights about your business communications
  • Maintaining message history for your business records

We do NOT:

  • Sell, rent, or share your WhatsApp message data with third parties for their marketing purposes
  • Use your customer conversation data for advertising purposes
  • Share identifiable message content with Meta or other platforms unless required for service delivery
  • Use your data to build profiles on your customers for our own purposes

3.2 AI Model Training

We may use anonymized and aggregated data derived from your conversations to improve our AI models. This data is stripped of all personally identifiable information and cannot be traced back to you or your customers. You can opt out of this by contacting us at privacy@nobu.chat.

4. Data Sharing and Disclosure

We may share your information in the following situations:

  • Service Providers: We may share your information with third-party vendors, service providers, and contractors who perform services for us (e.g., hosting, analytics, payment processing)
  • Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition
  • Legal Requirements: When required by law, court order, or to protect our rights and safety
  • With Your Consent: We may share your information for any other purpose with your explicit consent

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

5.1 Meta Platform Security

When integrating with Meta's platforms, we adhere to Meta's Business Tool Security requirements:

  • We use secure OAuth 2.0 authentication for all API connections
  • All API calls are made over HTTPS with TLS 1.2 or higher
  • Access tokens are encrypted and stored securely
  • We implement rate limiting and abuse prevention
  • We regularly review and update our security practices
  • We comply with Meta's Platform Terms and Developer Policies

5.2 Data Breach Notification

In the event of a data breach affecting your information, we will notify you and relevant authorities as required by applicable law, including GDPR's 72-hour notification requirement where applicable.

6. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer need your information, we will securely delete or anonymize it.

6.1 WhatsApp Message Retention

Message data retention varies based on your subscription plan and settings:

  • Active conversation messages are retained for the duration of your subscription
  • You can configure automatic deletion of messages after a specified period
  • Upon account termination, message data is deleted within 30 days unless legally required to retain
  • Backup data is securely deleted within 90 days of account termination

6.2 Meta Platform Data

We do not store copies of data received from Meta platforms longer than necessary to provide our Service. Real-time data is processed and may be cached temporarily for performance, but is not permanently stored unless required for your business records within our Service.

7. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Right to access and receive a copy of your data
  • Right to rectify inaccurate or incomplete data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

To exercise these rights, please contact us at privacy@nobu.chat.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws.

9. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.

12. Meta/Facebook Platform Compliance

12.1 Platform Data Use

As a third-party application integrated with Meta platforms (Facebook, WhatsApp Business API), we comply with:

  • Meta Platform Terms
  • Meta Platform Policy
  • Meta Business Tools Terms
  • WhatsApp Business Policy
  • Meta Developer Policies

12.2 Data Handling Commitments

We commit to the following regarding data obtained from Meta platforms:

  • We only request permissions necessary for our Service functionality
  • We do not use data from Meta platforms for purposes unrelated to our Service
  • We do not transfer data from Meta platforms to any ad network, data broker, or other advertising or monetization-related service
  • We do not use Meta platform data to build or augment user profiles
  • We do not use Meta platform data for surveillance purposes
  • We comply with all applicable data deletion requests within the timeframes specified by Meta

12.3 User Rights Regarding Meta Data

You have the following rights regarding data we receive from Meta platforms:

  • Revoke Access: You can revoke NobuChat's access to your WhatsApp Business Account at any time through your Meta Business Settings
  • Data Deletion: You can request deletion of data we've obtained from Meta platforms by contacting privacy@nobu.chat
  • Data Access: You can request information about what data we've obtained from Meta platforms
  • Review Permissions: You can review and modify the permissions NobuChat has to your Meta accounts at any time

12.4 Compliance with Meta's Data Deletion Requirements

When you delete your WhatsApp Business Account or revoke NobuChat's access:

  • We will delete all data obtained from Meta platforms within 30 days
  • We will confirm deletion upon request
  • We maintain a data deletion callback endpoint as required by Meta
  • We log all deletion requests for compliance purposes

12.5 Prohibited Uses of Meta Platform Data

We explicitly do NOT:

  • Sell or license data obtained from Meta platforms
  • Use Meta platform data for independent analytics services
  • Use Meta platform data to retarget users on or off Meta platforms
  • Use Meta platform data to make eligibility determinations (credit, insurance, employment, etc.)
  • Combine Meta platform data with data from other sources without user consent
  • Use Meta platform data for AI training unless explicitly permitted and anonymized

12.6 WhatsApp Business API Specific Policies

For WhatsApp Business API integration:

  • We comply with WhatsApp's Commerce Policy
  • We ensure you obtain necessary consents from your customers before messaging
  • We respect opt-out requests and do not facilitate spam
  • We maintain message templates in compliance with WhatsApp guidelines
  • We do not facilitate prohibited content as defined by WhatsApp policies

12.7 Business Messaging Standards

We require our users to:

  • Obtain proper consent before sending marketing messages
  • Provide clear opt-out mechanisms
  • Respect user preferences and privacy
  • Comply with applicable anti-spam laws (CAN-SPAM, GDPR, etc.)
  • Not use the Service for harassment, abuse, or illegal activities

12.8 Platform Updates and Compliance

We continuously monitor and comply with updates to Meta's policies and terms. If Meta's policies change in a way that affects our Service, we will update our practices and notify you as required.

13. Your Responsibilities

As a user of NobuChat with access to customer data through WhatsApp:

  • You are responsible for obtaining necessary consents from your customers before collecting and processing their data
  • You must comply with all applicable privacy laws in your jurisdiction
  • You must provide your customers with a privacy policy that accurately describes how their data is collected and used
  • You are responsible for responding to your customers' privacy requests (access, deletion, etc.)
  • You must not use the Service to violate your customers' privacy rights or applicable laws

14. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

Company: CosmicBytes LLC

Address: New Mexico, USA

Email: privacy@nobu.chat

Data Protection Officer: dpo@nobu.chat

Meta Platform Data Requests: meta-privacy@nobu.chat

GDPR Compliance

If you are a resident of the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR). NobuChat is committed to facilitating the exercise of these rights in accordance with GDPR requirements.

Legal basis for processing: We process your personal data based on consent, contractual necessity, legal obligations, and legitimate interests as outlined in this policy.

CCPA Privacy Rights (California)

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising your CCPA rights

We do not sell personal information. To exercise your CCPA rights, contact us at privacy@nobu.chat.