What we read, and what we keep.
eida sits on a WhatsApp account that carries other people's words, so this document is not a formality. It is written to be read once, in full, by the person deciding whether to link an account — and it says the uncomfortable parts out loud rather than burying them in clause 14.
01 Who we are
eida is a service that reads the WhatsApp chats a team switches on, proposes the work it finds, and — once a person approves it — writes that work into the task manager the team already uses.
This policy is issued by [registered entity name], [registered address] (“eida”, “we”, “us”), which operates eida.ai and the eida console.
Anything in this document that describes what the software can or cannot do is a description of how it is built, not a policy we could quietly relax. Where that distinction matters, we say so.
02 Whose data, and who is responsible
There are two quite different relationships on this page, and mixing them up is how privacy policies become useless.
When you are our customer
Your team links a WhatsApp account and picks chats to watch. Everything that comes out of those chats belongs to you and your clients — not to us. You decide what is watched, you decide what is approved, and you decide when it stops. In data-protection language you are the controller (a Data Fiduciary under India's Digital Personal Data Protection Act, 2023) and we are your processor (a Data Processor). We act on your instructions and for no purpose of our own.
When you are visiting this website
If you fill in a form on eida.ai or email us, we decide what to do with that — so for those details we are the controller. Section 11 covers it and it is short, because there is very little of it.
We do not sell, rent, mine, or train models on your chats or your clients' messages. We do not build a profile of anybody from them. There is no version of eida where your conversations become our product.
03 What eida reads
eida connects to a WhatsApp account the same way the desktop app does: somebody on your team scans a QR code from their phone. That connection gives eida two very different levels of access, and the difference is the whole of our privacy story.
The names of every chat on that account
This is unavoidable — a chat list arrives as a chat list. eida can see that a group called “Kiran — Interiors” exists on the linked account, along with every other group and contact name. We say this plainly during setup, and the software will not leave the pending state until that disclosure has actually been recorded. That is a database constraint, not a screen somebody can skip.
The contents of only the chats you switch on
Message contents are a separate step. A chat you have not ticked in the picker is never decrypted at all — not read and discarded, not filtered later: never turned into readable text in the first place. There is nothing to leak from a chat you did not pick, and you can switch one back off in a second.
What it does with a watched message
Messages that arrive in a watched chat pass through a filter that discards most of them locally. What survives is sent to our extraction model to decide whether it contains a request. Media — photos, voice notes, documents, video — is not downloaded, not opened and not stored.
eida only sees messages that arrive while it is connected. It does not read your history, and if the connection drops, messages sent in that window are never seen at all. This is a real gap in coverage, not a privacy feature we are dressing up — it is on our public roadmap to close, and when it is closed we will say so here.
04 What eida stores
For each piece of work eida proposes, it keeps the minimum that lets a human judge it and defend it later:
- The proposal — a title, a due date if one was mentioned, a client, and a suggested assignee.
- The quote — the single message the proposal was built from, word for word. Every proposal is checked back against the real message before you see it, and if the words are not there it is discarded rather than shown.
- Who said it, where, and when — the sender's name or number, the chat it arrived in, and the timestamp.
- What a human decided — approved, edited, rejected or observed, and when.
It also stores what it needs to keep working: the list of chats on the account and which ones are watched, the encrypted session that keeps the WhatsApp connection alive, your workspace settings, and a record of which messages have already been looked at so the same line is never proposed twice.
What it does not store
- The conversation around a quote. One message per proposal, never the thread.
- Anything at all from a chat you have not switched on.
- Media of any kind.
- Messages that the filter or the model decided were not work. They are not written down.
Reading a couple of messages around an ask would make the proposals noticeably better — “make it Friday instead” means nothing on its own. It is on our roadmap and it would weaken the promise in this section. If we build it, it becomes an explicit setting you turn on, this policy changes before it ships, and we will tell you rather than let you find out.
05 Why we are allowed to
Where you are our customer, we process your data because you asked us to and because we have a contract with you to run the service. Our written agreement with you is our instruction; we do nothing outside it.
The people in your chats are a harder question, and section 10 answers it honestly rather than pretending it away.
For the website and enquiries, we rely on your consent — you typed your email into a form — and on our legitimate interest in replying to somebody who asked us a question.
07 How long we keep it
- Proposals and their quotes — for as long as your workspace is open, because a task's receipt is worth nothing if it expires before the argument does. Delete any of them from the console at any time.
- The record of messages already seen — for as long as your workspace is open. It holds no message text; without it the same request would be proposed to you repeatedly.
- The WhatsApp session — until you unlink, at which point it is destroyed and the account has to be paired again from scratch.
- Enquiries and email — up to 24 months, then deleted.
When you close your workspace, everything above is deleted within 30 days. Backups roll off within 90 days. Work already written into your own task manager stays there — it is yours, in your system, and we could not remove it even if you asked.
08 How it is protected
- Everything travels over TLS and is encrypted at rest by our database provider.
- The console refuses to start without a configured password and signing secret. A deployment that forgot to set them serves nothing rather than serving your clients' conversations.
- Where eida writes into a customer's own system, it signs in as an ordinary member of that team, constrained by that team's own permissions. We hold no privileged service keys, and revoking us is disabling one user.
- Access to production data is limited to the people who run the service and is used only to keep it running or to fix something you have reported.
Today a workspace shares one console password, which means the approval record can name the workspace but not the individual who approved. That is a real weakness, we know it, and per-person sign-in is being built. Until it ships, only give the console password to people you would trust with the chats themselves.
If we ever suffer a breach affecting your data, we will tell you and the relevant authority without undue delay, with what we know and what we are doing about it.
09 Your rights
Depending on where you live, you have the right to ask what we hold about you, to get a copy, to have it corrected, to have it deleted, to restrict or object to how it is used, and to withdraw consent. If you are in the EU or UK you also have the right to complain to your data protection authority; in India you may complain to the Data Protection Board.
Most of these you can exercise yourself in the console — see the whole ledger, edit a proposal, delete one, unwatch a chat, unlink the account. For anything else, write to privacy@eida.ai and we will respond within 30 days. We do not charge for this, and we will never make you worse off for asking.
10 If you are in one of these chats
You may be reading this because a business you message on WhatsApp uses eida, and you did not sign up for anything. That is a fair objection and it deserves a straight answer rather than a clause.
Here is what is true. The business you are talking to controls that account and has chosen to have its own chats read, in the same way it might forward your message to a colleague or paste it into its task list. eida does not read your other conversations, is not on your phone, and cannot send you anything — there is no send function in the product. What it may keep is a single sentence you wrote, alongside who said it and when, attached to a job that the business agreed to do for you.
If you want to know whether a specific business is using eida, or you want a quote of yours removed, ask them first — they control the workspace and can delete it in a tap. You can also write to privacy@eida.ai and we will pass it on and help make it happen.
11 The website itself
eida.ai sets no cookies and runs no advertising or analytics trackers. There is no banner to dismiss because there is nothing to consent to.
If you submit a form we receive what you typed — usually an email address, the tool you use and the size of your team — and we use it to reply to you and nothing else. Our hosting provider keeps standard server logs, including IP addresses, for security and reliability, on their usual short retention.
We load fonts from Google Fonts, which means your browser makes a request to Google when the page opens.
12 About WhatsApp
eida is not affiliated with, endorsed by, or connected to WhatsApp or Meta. WhatsApp offers no official way for a business to read its own group chats, so eida links to the account the way a desktop client does. We think it is important you understand that before you link anything:
- Your use of WhatsApp remains governed by WhatsApp's own terms, and linking a third-party client may not sit comfortably with them.
- Accounts connected this way can in principle be restricted or banned by WhatsApp. What actually gets accounts banned is sending behaviour — bulk messages, mass group adds, spam reports — and eida does none of it, because it cannot send. We will not pretend the risk is zero.
- Only link an account whose owner understands and agrees to all of this. In practice: ask the person whose number it is.
13 Changes
When this policy changes we update the date at the top and raise the version. If a change actually affects what we read, keep or share — as opposed to fixing a typo — we will email every workspace before it takes effect, not after. Old versions are available on request.
14 Contact and complaints
Privacy questions, requests and complaints: privacy@eida.ai. Anything else: hello@eida.ai.
- Grievance Officer
- [name] · privacy@eida.aiAs required under India's DPDP Act, 2023
- Postal address
- [registered address]
If you are not satisfied with our response you can complain to your data protection authority — the Data Protection Board of India, or your national supervisory authority in the EU or UK.
This document describes eida as it is built today, on 14 August 2026, including the parts that are not finished. If you find something on this page that does not match what the software actually does, tell us — that is a bug in the most serious sense, and we will treat it as one.
Read the terms of service →