Privacy Policy
Last updated: October 2026
1. Who we are
Central de Mensajes is a service operated by HUMAN SOFTWARE J.Y. SOCIEDAD ANONIMA, a company incorporated under the laws of the Republic of Costa Rica. We provide a multichannel messaging platform with artificial intelligence for small and medium-sized businesses.
For any question about this policy, contact us at [email protected].
2. Data we collect
We collect the following information when you use our platform:
- Account information: name, email address, phone number and Google profile data (name, email address and profile picture) when you sign in with Google.
- Business information: business name, description, opening hours, products or services, and any context you provide to set up the AI assistant's automatic replies.
- Processed messages: WhatsApp conversations, Facebook messages and comments, and Instagram direct messages and comments that you manage through our platform. These messages belong to your customers and we process them only to provide the service.
- Audio messages: audio files sent by your customers through WhatsApp, which we transcribe so the AI assistant can reply.
- Calendar data (only if you connect Google Calendar): see section 5.
- Usage data: information about how you interact with the platform, including pages visited, features used, session times and technical system logs.
- Technical data: IP address, browser type, operating system and session cookies.
3. How we use your data
- Providing the service: connecting your messaging accounts, showing conversations in the unified inbox and letting you reply to your customers.
- Automatic AI replies: generating suggested or automatic replies using your business context and the conversation history.
- Audio transcription: converting voice messages to text so they can be managed and answered.
- Appointments: offering your customers real available times and recording, confirming and cancelling the appointments they book.
- Analysis and improvement: understanding how the platform is used to fix errors and improve performance.
- Service communications: sending you important notices about your account, platform updates or changes to this policy.
- Security: detecting, preventing and investigating fraud or violations of our Terms of Service.
We do not use your data or your customers' data to train our own artificial intelligence models, and we do not sell it to third parties.
4. Third parties with access to data
To operate the service, we share data with the following providers:
Meta Platforms (WhatsApp, Facebook, Instagram)
We access your messaging channels through Meta's official Business APIs. Your customers' messages travel through Meta's infrastructure under Meta's privacy policy. You are responsible for complying with Meta's usage policies as an API user.
Google (Gemini AI and Google Analytics)
We use Google Gemini to generate automatic AI replies. The conversation excerpts needed to generate a reply are sent to the Gemini API. We also use Google Analytics to measure the use of the platform and the marketing website.
Deepgram (audio transcription)
Audio files sent by your customers through WhatsApp are sent to Deepgram to be transcribed into text. The audio is not kept on Deepgram's servers longer than needed to complete the transcription.
Cloudflare
The entire platform runs on Cloudflare infrastructure. The application runs on Cloudflare Workers; your account data, business configuration and conversation history are stored in Cloudflare D1; files that you and your customers send (images, audio, documents) are stored in Cloudflare R2; sessions are kept in Cloudflare KV; and the emails we send you go out through Cloudflare's email service. Server logs and HTTP request data also pass through its infrastructure. Everything is encrypted in transit and encrypted at rest.
5. Google user data (Google Calendar)
Connecting a Google account is optional and is started by you from your agenda settings. Signing in with Google alone does not give us access to your calendar.
What we access
If you connect Google Calendar, we ask for these permissions (scopes):
https://www.googleapis.com/auth/calendar.calendarlist.readonly: to list the calendars in your Google account so you can choose which one to link to an agenda. We use it for nothing else.https://www.googleapis.com/auth/calendar.events: to read the events of the calendar you chose, and to create and cancel events on that calendar only for appointments booked through Central de Mensajes.openid,emailandprofile: to identify which Google account you connected.
We do not request access to your Gmail, Drive, contacts or any other Google product, and we do not request the full calendar scope.
How we use it
- We read the events on the linked calendar (times, titles and descriptions) to know when you are busy, so the assistant and your public booking page offer only free times, and to show those events in your agenda.
- We create an event for each appointment booked through the platform, and cancel it when the appointment is released or cancelled.
- We use your calendar list only to show the calendar picker.
We use Google user data only to provide and improve these user-facing features. We do not use it for advertising, we do not sell it, and we do not allow humans to read it unless you ask us for support, it is needed for security, or the law requires it.
Storage and protection
We store the identifiers of your linked calendar and the events we read or wrote, together with their times, titles and descriptions, in Cloudflare D1. Your Google access and refresh tokens are stored encrypted with AES-256-GCM, and all traffic is encrypted in transit.
Sharing
We do not transfer Google user data to third parties, except to the infrastructure providers listed in section 4 that host the service, as needed to comply with the law, or as part of a merger or acquisition with prior notice to you. We do not use Google user data to train generalized artificial intelligence or machine learning models.
Limited Use
Central de Mensajes' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deleting
You can unlink a calendar or disconnect your Google account at any time from your agenda settings; when you do, we revoke our access token with Google. Events we already wrote to your Google calendar stay there, because they are real appointments with people attached; you can delete them in Google Calendar. You can also revoke access at any time at myaccount.google.com/permissions. To have the Google data we stored deleted, write to [email protected] or use the data deletion page.
6. Processing messages through Meta (WhatsApp / Facebook / Instagram)
By connecting your Meta accounts to our platform, you authorize us to act as a data processor on your behalf to manage your customers' messages. This means that:
- We process your customers' messages only to provide the contracted service.
- We do not read or analyze your customers' messages for purposes other than those described in this policy.
- Meta API access tokens are stored encrypted with AES-256-GCM in our database.
- You, as the business operator, are the data controller for your customers' data and are responsible for informing them appropriately about the use of automation tools.
- We do not sell, rent or share your customers' data with third parties not mentioned in this policy.
7. Data security
We implement technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), encryption at rest for sensitive data (API tokens with AES-256-GCM), role-based access control, and HMAC-SHA256 signature verification on all Meta webhooks. However, no system is completely infallible and we cannot guarantee absolute security.
8. Data retention
We keep your data while your account is active. If you cancel your account, we will delete your personal information and conversation history within 30 calendar days after the cancellation is confirmed. We may keep anonymized or aggregated data for longer periods for internal analysis. Billing records may be kept for as long as applicable Costa Rican law requires.
9. Your rights
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Deletion: request deletion of your account and personal data.
- Portability: request your data in a structured, machine-readable format.
- Objection: object to the processing of your data for certain purposes.
To exercise any of these rights, write to [email protected]. We will respond within 30 business days of your request.
10. Cookies
We use strictly necessary cookies to keep your session authenticated. We also use Google Analytics cookies to understand how our marketing website is browsed. You can set your browser to reject cookies, although this may affect how the platform works.
11. Children
Our service is intended exclusively for people over 18 who operate businesses. We do not knowingly collect information from minors. If we learn that we have collected data from a minor, we will delete it immediately.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice on the platform at least 15 days before they take effect. Continued use of the service after that date constitutes acceptance of the changes.
13. Contact
If you have questions or concerns, or wish to exercise your rights, contact us:
HUMAN SOFTWARE J.Y. SOCIEDAD ANONIMA
Operator of Central de Mensajes
Costa Rica
[email protected]