Privacy Policy

Last updated: May 19, 2026

AutoTalk respects privacy and protects personal data in accordance with the Brazilian General Data Protection Law (LGPD). This policy explains how AutoTalk collects, uses, stores, shares, and deletes personal data when you use our websites, app, APIs, messaging integrations, AI automation, and related services.

1. Controller and Contact

For account, billing, website, support, security, and product-operation data, the controller is AutoTalk, CNPJ 51.389.524/0001-57, Jaguariuna, Sao Paulo, Brazil. Privacy requests can be sent to [email protected].

2. Our Role for Customer Content

When a customer uses AutoTalk to manage conversations, contacts, workflows, files, API data, and AI automations for its own business, that customer is normally the controller of the end-customer data. AutoTalk acts as operator/processor and handles that data to provide, secure, support, and maintain the platform according to the customer's configuration and lawful instructions.

3. Data We Collect

  • Business users: name, email, phone number, password hash, company name, role, permissions, language, notification settings, billing profile, and support messages.
  • End customers and contacts: identifiers from messaging platforms, names when provided, conversation history, message metadata, files, media, order, appointment and service records, custom records, and workflow outputs configured by the customer.
  • Technical data: IP address, device/browser information, authentication/session events, security logs, usage meters, API requests, errors, performance traces, masked session replay, and local preferences such as language and theme.
  • Payment data: plan, subscription status, invoices, customer/subscription/payment references, currency, billing period, and payment outcome. AutoTalk does not store full card numbers.

4. Purposes and Legal Bases

  • Provide accounts, authentication, team management, subscriptions, invoices, API access, messaging, storage, AI automation, notifications, support, and product administration.
  • Route messages through customer-selected channels such as WhatsApp, Instagram, Facebook, Telegram, Discord, Twitch, website widgets, APIs, and webhooks.
  • Run AI features using configured providers and customer-provided or AutoTalk-managed API keys, including text generation, tool calls, embeddings, and audio transcription.
  • Measure usage, enforce limits, calculate overage, prevent abuse, troubleshoot errors, secure the platform, comply with legal obligations, and communicate operational notices.
  • LGPD bases may include contract performance, legitimate interest, legal obligation, consent where required, regular exercise of rights, and the controller customer's legal basis for end-customer data.

5. AI Processing

AutoTalk does not use customer content to train AutoTalk-owned models. Customer content may be sent to the AI provider selected or configured by the customer, such as OpenAI, Anthropic, Google Gemini, DeepSeek, or OpenRouter, only to provide the requested feature, debug failures, secure the service, or comply with law. Provider behavior may also be governed by the customer's own provider agreement when the customer uses bring-your-own-key.

6. Cookies, Local Storage, and Telemetry

AutoTalk uses necessary cookies and similar technologies for authentication, session security, CSRF protection, language/theme preferences, and app operation. The app also uses Google reCAPTCHA for abuse prevention, Firebase Cloud Messaging for push notifications when enabled, and Sentry for error, performance, and masked replay diagnostics. Sentry replay is configured to mask text, inputs, and media. In line with the data minimization principle (LGPD Art. 6, III), Sentry is configured to limit automatic personal-data collection: authentication tokens and session headers are not transmitted to Sentry. User identifiers, IP address, and request metadata are sent only to the extent necessary for diagnostics, security, and abuse prevention.

7. Sharing and Subprocessors

We share personal data with subprocessors only as needed to provide, secure, bill, monitor, and support AutoTalk. This includes hosting, database, storage, messaging, AI, payment, email, analytics, monitoring, secrets, and anti-abuse providers. The current list is available on the Subprocessors page.

8. International Transfers and Hosting

Data may be hosted or processed in Brazil, the United States, Canada, Europe, and other locations where AutoTalk or its subprocessors operate. AutoTalk uses contractual, technical, and organizational safeguards for international transfers, including provider agreements, access controls, encryption in transit, tenant isolation, and vendor due diligence.

9. Security and Staff Access

AutoTalk applies TLS/HTTPS, access controls, tenant isolation, secret management, logging, monitoring, backups/provider durability, and operational security controls. AutoTalk personnel and authorized contractors access customer data only on a need-to-know basis for support, debugging, security, legal compliance, abuse prevention, and service operation.

10. Retention and Deletion

We retain account, company, billing, operational, and customer content while the account or company remains active and as needed for legal, tax, security, billing, dispute, backup, and audit purposes. Customers can configure retention policies for certain data categories. When a company deletion is requested, AutoTalk schedules deletion and permanently purges company-scoped data after the configured deletion process, currently up to about 60 days. Some limited records may be retained longer where required by law, security, billing, or dispute handling.

11. Your LGPD Rights

Under the LGPD, data subjects may request confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, review of automated decisions where applicable, objection to irregular processing, and revocation of consent. They may also petition the ANPD. If your data was processed by an AutoTalk customer, we may direct the request to that customer as controller. Send requests to [email protected].

12. Children and Sensitive Data

AutoTalk is a business platform and is not intended for children. Customers are responsible for ensuring that their use of AutoTalk, including any sensitive or regulated data in conversations, complies with applicable law and required consents.

13. Changes

We may update this policy as the product, law, or subprocessors change. Material changes may be communicated through the app, website, email, or policy update. Continued use after the effective date means the updated policy applies.