Privacy Policy — Athak
Last updated: 17 September 2026.
Athak provides AI employees (receptionist and customer-care assistants) for businesses. This policy explains what we store, what leaves our servers, and how you control your data. Questions: kushdewanta@gmail.com.
What we store
- Business accounts (email + salted scrypt password hash) and sessions.
- Business settings: enabled features, channel configurations, and webhook-action configs (action secrets are stored encrypted at rest and are never returned by the API).
- Knowledge you add (documents, FAQ text, website content) and datasets — used to answer your customers.
- Conversation transcripts (customer + AI messages, actions taken) and the business records your AI employees create: contacts, appointments, tickets, and orders.
- Admin-configured API keys for AI/voice providers (server-side only; never sent to browsers; encrypted at rest).
Payments
Subscription payments are processed by Razorpay. Card, UPI, and bank details are entered on Razorpay's secure checkout and handled by Razorpay under its own privacy and PCI-DSS obligations — Athak never sees or stores your card or UPI credentials. We store only your plan, subscription id, and payment references needed to manage your subscription.
What leaves the server
- Conversation text plus retrieved snippets of your own content are sent to the configured AI provider to generate replies (bring-your-own key supported).
- Notification emails and messages you configure (lead alerts, owner notifications) are sent through the channels you connect, to your own inboxes/numbers.
- Webhook actions POST the parameters the AI filled in to the URL you configured — nowhere else.
WhatsApp and the Meta platform
When a business connects a WhatsApp number, Athak receives messages and related data through the WhatsApp Business Platform (Meta) so its AI receptionist can reply on the business's behalf. Specifically:
- What we receive from Meta: inbound messages the business's customers send to the connected WhatsApp number (text and, where applicable, media), together with the sender's WhatsApp display name and phone number, and message status/delivery events.
- How we use it: solely to operate the service the business asked for — routing the customer's message to the business's AI employee, generating and sending a reply, and recording the conversation and any resulting contact, appointment, ticket, or order in that business's dashboard. As described in
What leaves the server, the message text plus retrieved snippets of the business's own content are sent to the configured AI provider to generate the reply.
- What we do not do: we do not sell WhatsApp data, do not use it for advertising, and do not share it beyond the AI provider needed to answer the message and the business that owns the number.
- Retention and deletion: WhatsApp conversation data is retained under the same rules as the rest of your data (kept until deleted). A business can delete conversations and contacts from the dashboard, disconnect the WhatsApp channel at any time, or request full account and data deletion by emailing
kushdewanta@gmail.com.
Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including their limited-use requirements.
Voice audio
With the default stack (Whisper speech-to-text; Piper text-to-speech), audio is processed in memory on the server — never written to disk, never sent to a third party. If you explicitly configure a cloud voice provider, audio for those turns is sent to that provider.
Cookies and tracking
The dashboard uses a first-party session cookie for login only. The embeddable website widget sets no cookies, contains no third-party trackers, analytics, or CDNs, and talks only to your backend's origin.
Your controls
- Delete conversations, knowledge, datasets, and individual AI employees from the dashboard at any time — deletion removes the associated data.
- Cancel your subscription from Account → Billing; see the Cancellation & Refunds Policy.
- Request account and data deletion by emailing kushdewanta@gmail.com.
What we don't do
- We do not sell your data or your customers' data.
- No automatic retention expiry — data is kept until you delete it.
Contact
Privacy questions or data requests: kushdewanta@gmail.com. We respond within 2 business days.
