Legal
Privacy Policy
Last updated: July 17, 2026
1. Introduction
We at Entagl (together with our affiliates, "Entagl", "we", "our" or "us") respect your privacy and are strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices with respect to Personal Data that we collect from or about you when you use our website, applications, and services (collectively, "Services"). Data is protected with encryption in transit and at rest as described in the Data Encryption & Security section below.
2. Information We Collect
2.1 Payment Information
When you make a payment, we process your payment information through Stripe, our secure payment processor. During this process:
- Payment card details are securely collected and processed directly by Stripe
- We receive only limited information about your payment method (such as the last four digits of your card)
- Billing address and contact information for payment verification
- Transaction history related to your purchases
2.2 Information from Social Media Platforms
When you connect your Facebook or Instagram account, we may collect the following information. This information is used only to provide the Services and is protected with AES-256-GCM server-side encryption at rest and TLS encryption in transit. Access is limited to authorized personnel for support and operations.
- Profile information (name, username, profile picture)
- Email address
- Posts, comments, and media content
- Account interactions and engagement data
- Messages (when using our messaging features)
2.3 Permissions We Request
Depending on the channels and features you enable, we request the following permissions through the Meta (Facebook, Instagram, WhatsApp) APIs:
- Basic profile information access
- Access to pages, posts and media content
- Permission to read and send messages
- Ability to read and respond to comments
- Business asset management (business_management) to list and connect your pages and WhatsApp accounts
- WhatsApp Business account management and messaging
- Ads account access (ads_read, ads_management, pages_manage_ads) — only if you enable the optional Ads features
- Page conversion events (page_events, Meta Conversions API) — only if you enable ad performance tracking
3. How We Use Your Information
We use the collected information to provide the Services. Sensitive information such as customer messages and contact details (names, emails, phone numbers) is stored encrypted:
- Provide and maintain our services
- Send and receive messages on your behalf
- Manage your social media interactions
- Generate AI responses and conversation insights for your dashboard
- Measure usage for billing and analyze service performance to improve the product (see the Analytics & Tracking section)
- Ensure security and prevent fraud
Data Encryption & Security
Entagl implements enterprise-grade security measures to protect your data using industry-standard encryption protocols.
Encryption Standards
Sensitive data — customer conversation messages, contact information, and uploaded conversation media — is protected with AES-256-GCM server-side encryption at the application level. Our databases, file storage, and backups are additionally encrypted at rest, and all data is encrypted in transit using TLS/SSL. Encryption keys are managed by Entagl; access to data is limited to authorized personnel for support and operations.
What Data Is Encrypted
- Customer conversation messages and chat history (application-level AES-256-GCM). AI-generated conversation summaries are stored on encrypted infrastructure without additional application-level encryption.
- Contact information including names, email addresses, and phone numbers (application-level AES-256-GCM)
- Account information — stored on encrypted infrastructure (encryption at rest)
- Uploaded files, images, audio recordings, and documents exchanged in conversations, including photos, PDFs and videos a customer sends through a secure upload link. These are encrypted with AES-256-GCM before they are stored, kept in private storage that is never publicly accessible, and are only ever served to the business through a signed, expiring link.
- Business configuration and settings — stored on encrypted infrastructure (encryption at rest)
4. Data Storage and Security
We implement appropriate technical and organizational security measures to protect your information. Your data is stored securely and accessed only when necessary to provide our services.
We retain your information only for as long as necessary to provide our services and fulfill the purposes outlined in this policy. You can request deletion of your data at any time.
5. Your Rights and Controls
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Withdraw consent for data processing
- Revoke access to your social media accounts
Data Portability and Export: You can export your data yourself at any time while your account is active. Your account settings include a self-service data export that generates a downloadable archive of your contacts, conversations, and associated media, delivered to you by email as a secure, time-limited download link. We recommend exporting your data before you cancel, because retention and deletion timelines begin once the account closes. This export right is in addition to the access, correction, and deletion rights listed above.
You can exercise some of these rights through your Entagl account. If you are unable to exercise your rights through your account, please submit your request through privacy@entagl.com. You can contact our data protection officer at privacy@entagl.com.
Verification: In order to protect your Personal Data from unauthorized access, change, or deletion, we may require you to verify your credentials before you can submit a request to know, correct, or delete Personal Data. If you do not have an account with us, or if we suspect fraudulent or malicious activity, we may ask you to provide additional Personal Data for verification. If we cannot verify your identity, we will not be able to honor your request.
6. Third-Party Services
Our service integrates with messaging platforms and AI providers through their official APIs. When you use these integrations, you are also subject to their respective privacy policies:
- Facebook Privacy Policy
- Instagram Privacy Policy
- WhatsApp Business Terms of Service
- OpenAI Enterprise Privacy
- Google Gemini API Terms of Service
- Anthropic Privacy Policy
We share personal data only with the service providers ("subprocessors") required to operate Entagl — see the full Subprocessors list below. Messaging platforms (Meta, Telegram, TikTok) receive the message content needed to deliver conversations on their networks, and Twilio receives phone numbers and message content for SMS and notification delivery. To generate AI responses, our AI providers (OpenAI, Google, Anthropic) receive the conversation history and the relevant business context for your workspace (such as your services, FAQs, and business information) with each AI turn; voice audio is processed by Google for voice features. Messages, images, voice messages, files and videos are encrypted at rest and in transit within our systems.
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes. We have agreements with OpenAI and Google so that data submitted through Entagl platform keys is not used to train their models. If you connect your own AI provider API keys (BYOK), your data is processed under your own agreement with that provider.
Your business information, offers, and business logic are your property. We use them only to operate your workspace and AI agents, and we do not sell them or share them with third parties for those parties’ own purposes.
Google User Data
When you connect your Google Business Profile to Entagl, we access a limited set of data from Google in order to power the Reputation features — reading your reviews, drafting replies for you, and publishing the replies you approve.
Limited Use: Entagl's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access:
- The list of business locations your Google account owns or manages, so you can choose which to connect.
- Review content, star ratings, dates, and the reviewer name and profile photo exactly as Google returns them.
- Basic business information needed to identify the location, such as its name, address and website.
How we use it:
- To display your reviews inside your own Entagl workspace.
- To generate suggested replies using your business information, services and tone-of-voice settings.
- To publish a reply back to your listing — either one you approved, or one your own auto-reply rules authorised in advance.
- To alert you when a review needs your attention, based on the rules you set.
How we store it: Google data is encrypted at rest, scoped to your workspace alone, and never combined with another business’s data. The access tokens that authorise the connection are encrypted separately and are never exposed to your browser.
Who we share it with: Review text is sent to our AI model providers for the sole purpose of generating a suggested reply. Those providers operate under agreements that prohibit training on your data and require zero retention. We do not sell Google user data, we do not use it for advertising, retargeting or personalised advertising, we do not use it to assess credit-worthiness or for lending, and we do not transfer it to data brokers or resellers.
Human access: Entagl staff do not read your Google review data. Access is blocked at the application layer for our internal support, administration and quality-review tools. The only exceptions are the ones Google’s policy permits: when you give explicit, time-limited, revocable in-product consent for a specific support request; where necessary to investigate a security incident or abuse; where required by law; or in aggregated, de-identified form for internal operations.
Retention and deletion: Disconnecting the integration revokes our access token and deletes the cached Google data within 30 days. Deleting your Entagl account deletes it immediately. You can also revoke Entagl’s access at any time from your Google account permissions page.
Subprocessors & Service Providers
We use the following service providers to operate Entagl. Each receives only the data needed for its purpose:
- Amazon Web Services (AWS) — cloud hosting for all customer data (databases, file storage, queues, caching) in the United States (us-east-1), transactional email (SES), message-text analysis for language detection (Comprehend), and machine translation (Translate). Voice-call media for EU WhatsApp calls is relayed through an EU region (eu-south-1).
- OpenAI — AI response generation, media analysis, and knowledge-base search. Receives conversation history, business context, uploaded knowledge files, and customer media. No-training / zero-data-retention arrangement on Entagl platform keys.
- Google (Gemini API / Google Cloud Vertex AI) — AI response generation, language detection, translation, voice conversations, and knowledge search. HIPAA-enabled workspaces are routed through Google Cloud Vertex AI.
- Anthropic (Claude) — AI response generation (alternate and backup models) and conversation-quality tooling. Receives conversation history and business context.
- Meta Platforms (Facebook, Instagram, WhatsApp) — message delivery and channel integration; optional ads features and conversion events if you enable them.
- Telegram — message and media delivery for the Telegram channel.
- TikTok (ByteDance) — message and comment delivery for the TikTok channel.
- Twilio — SMS and WhatsApp notification delivery and call telephony. Receives phone numbers, message content, and call audio.
- Zadarma — telecom partner for Turkish phone numbers. Receives the identity documents and address needed to register a Turkish number in your name (as Turkish law requires), plus call metadata for calls to that number. Entagl does not keep a copy of the documents after upload.
- Clerk — account authentication. Processes your name, email, sign-in identity, and session data.
- Stripe — payment processing and subscription billing.
- HubSpot — optional CRM sync that you configure. Can receive contact details, lead data, conversation transcripts, and form submissions when you enable syncing.
- Shopify — optional store integration (products, orders, and customer data from your store).
- Nylas — optional calendar sync (appointment details, attendee names and times).
- SendGrid — support-ticket email delivery.
- Expo — mobile push-notification delivery (device tokens and notification previews).
- Serper — web search used by the AI’s website-search tool (search queries, which may be derived from conversation content).
- Firecrawl — website content retrieval for onboarding import and the AI’s website-search tool.
- Segment (Twilio) — product analytics (account identifiers and usage events).
- FingerprintJS — device identification on public chat surfaces, used solely for fraud and abuse prevention.
We may update this list as the service evolves. Material changes will be reflected on this page.
Workspaces Managed by Agencies
Some Entagl customers are agencies or service providers that manage workspaces on behalf of their own clients. In that case the client business remains the controller of its customers’ personal data, the agency acts as that business’s processor, and Entagl acts as a subprocessor. The Data Processing Addendum in our Terms of Service describes these roles and applies the corresponding Standard Contractual Clauses module to international transfers.
If you have messaged a business whose workspace is managed by an agency, direct privacy requests (access, correction, deletion) to that business or to the agency managing it — we support them in fulfilling your request as described in this policy.
WhatsApp Business API Privacy Information
How we process and protect your WhatsApp messages
- When using our WhatsApp integration, Meta acts as a data processor on behalf of Entagl.
- WhatsApp messages are retained like all other conversation data: for as long as your account is active, or until you delete the conversation or request deletion of your data.
- Messages are encrypted between users and the WhatsApp Cloud API using the Signal protocol.
- Message data may be processed and stored in different regions based on Meta's infrastructure.
- We do not share your WhatsApp messages with third parties except the service providers required to operate the service (see the Subprocessors section of our Privacy Policy).
- You can revoke access to your WhatsApp business account at any time through our platform.
For more information about WhatsApp's data practices, please refer to the WhatsApp Business Terms of Service and WhatsApp Cloud API Privacy & Security documentation.
7. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date on this page, unless another type of notice is required by applicable law.
8. Contact Us
If you have any questions about this Privacy Policy or our practices, please contact us at:
Email: privacy@entagl.com Address: 1111B S Governors Ave STE 48482, Dover, DE 19904
9. Data Deletion Policy for Meta Developer Apps
In compliance with Meta's Developer Policies, we provide users with the ability to request the deletion of their data. Below are the instructions and procedures for users to request data deletion from our application.
WhatsApp Data Deletion
How to request deletion of your WhatsApp Business API data
- To request deletion of your WhatsApp Business API data, please email us at delete@entagl.com with subject 'WhatsApp Data Deletion Request'.
- We will process your request within 30 days and remove all WhatsApp messages, media, and connection information from our systems.
- For deletion of data stored by Meta, you will need to contact them directly through your Meta Business dashboard.
- Some data may be retained as required by law or for legitimate business purposes such as security and fraud prevention.
- We may need to verify your identity before processing your data deletion request.
How to Request Data Deletion
If you would like to request the deletion of your personal data from our app, please follow the steps below:
- Contact Us by Email:
Send an email to delete@entagl.com with the subject line: "Data Deletion Request." - Include Necessary Details:
In your email, please provide the following information to help us process your request:- Your full name
- Your account username or email associated with the app
- Any additional details to help identify your account or data (e.g., specific activity or service you used within the app)
- Processing Your Request:
Once we receive your request, we will:- Verify your identity to ensure the request is legitimate
- Remove your data from our records in accordance with applicable laws and our data retention policies
- Confirm the completion of your data deletion request via email
Data Deletion Timeline
We aim to process all data deletion requests within 30 days of receipt. However, in rare cases, additional time may be required depending on the complexity of the request or technical constraints.
Additional Notes
- Third-Party Services: If you used third-party services integrated with our app, you may need to contact those services directly to request data deletion from their records.
- Data Retention Requirements: Certain data may be retained as required by law or for legitimate business purposes, such as preventing fraud or resolving disputes.
If you have any questions about our Data Deletion Policy or need further assistance, please don't hesitate to reach out to us at delete@entagl.com.
10. Shopify Integration Privacy Policy
This section specifically addresses our privacy practices for Shopify merchants using our app integration.
Data Minimization
Yes, we process only the minimum personal data required to provide value to merchants. We collect and process only the data necessary to:
- Enable AI-powered customer support automation
- Provide conversation analytics and insights
- Facilitate multi-channel communication
- Ensure service security and functionality
Personal Data We Process
We transparently inform merchants about the personal data we process and our purposes:
- Customer Data: Names, email addresses, phone numbers, and conversation content for providing automated customer support responses
- Merchant Data: Store information, product details, and order data to provide contextually relevant customer service
- Usage Data: Analytics on conversation patterns, response effectiveness, and system performance for service improvement
- Technical Data: API access tokens, webhook configurations, and integration settings for service functionality
Purpose Limitation
We limit our use of personal data to the purposes described in this policy. We use aggregated usage data and AI conversation analysis to operate the service, power your dashboard insights, and bill usage (see Analytics & Tracking). We do not use personal data for:
- Marketing to your customers without explicit consent
- Selling or sharing data with third parties for their own commercial purposes
- Profiling for purposes unrelated to the service
- Any purpose not disclosed in this privacy policy
Customer Consent Management
Yes, we respect and apply customers' consent decisions by:
- Honoring opt-out requests for automated communications
- Respecting marketing communication preferences
- Implementing consent withdrawal mechanisms
- Providing clear consent collection interfaces for merchants
Data Sales Policy
We do not sell customer data. We respect customers' decisions to opt-out of data sales, though this is not applicable to our business model as we:
- Never sell personal data to third parties
- Do not engage in data brokerage activities
- Use data solely for providing our AI customer support services
- Maintain strict data confidentiality
Automated Decision-Making
Our AI features perform automated processing of conversations. Depending on how you (the merchant) configure your agent, the AI can automatically reply to your customers, answer questions, collect contact details, book and modify appointments, and share payment or checkout links — without per-message human review. Safeguards:
- You control which AI capabilities are enabled for your workspace
- You can pause the AI or take over any conversation at any time
- All AI activity and conversation history is visible in your dashboard for review
- Bookings and similar actions are visible and reversible in your dashboard
- Your customers can always request a human
Data Retention
We retain personal data for as long as your account is active, and we delete it within 30 days of a verified deletion request. Sensitive data is protected with AES-256-GCM server-side encryption at rest and TLS in transit; access is limited to authorized personnel for support and operations. Current retention practices:
- Customer conversation data: retained while your account is active, or until you delete it or request deletion
- Account and billing data: retained while your account is active and thereafter as required for legal, tax and accounting compliance
- Technical and application logs: retained for approximately 30 days
- Database backups: automatically purged on a 7-day rolling window
- HIPAA-enabled workspaces: access-audit logs are retained 90 days in-database and archived for 6 years as required by HIPAA
- Files a customer uploads through a secure upload link: kept for the period the business chooses — from 7 days up to 1 year, and 90 days if the business does not change it — or for a shorter period the customer picks from the options offered. The customer can only shorten the period, never extend it. Files are deleted automatically once that period ends, and the business can delete any file in one click at any time before then. Deleted files are removed immediately and any remaining copy is permanently erased from our storage within 30 days.
Data Encryption
Yes, we encrypt data both at rest and in transit:
- Data in Transit: all data transmission uses TLS (HTTPS)
- Data at Rest: stored data is encrypted at rest using AES-256; sensitive fields (messages, contacts, media) are additionally encrypted at the application level using AES-256-GCM
- Backup Encryption: database backups inherit the same at-rest encryption
Data Environment Separation
We separate environments as follows:
- Separate databases and infrastructure for development and production
- Automated tests run only against isolated, disposable databases — never against production data
- Access controls limit cross-environment access
Data Loss Prevention
We maintain a data loss prevention strategy:
- Automated daily database backups with a 7-day rolling retention
- Highly-available database deployment with synchronous standby replication (Multi-AZ)
- Continuous monitoring and alerting on backup and database health
Staff Access Controls
We limit staff access to customers’ personal data:
- Role-based, workspace-scoped access control in the application
- Staff access limited to authorized personnel on a need-to-know basis for support and operations
- Administrative actions are logged
Staff Credential Security
Staff access to systems containing personal data uses individually assigned credentials and is limited to a small number of authorized personnel.
- Individually assigned credentials for internal systems
- Access limited to authorized personnel
- Credentials revoked when no longer needed
Access Logging
We log access and administrative activity as follows:
- Administrative actions on customer workspaces are logged with user identification and timestamps
- For HIPAA-enabled workspaces, all access to protected data (viewing contacts, conversations, and messages) is audit-logged, retained 90 days and archived for 6 years
- Logs are stored securely with restricted access
Security Incident Response
We operate security monitoring and will notify affected customers of personal-data breaches as required by applicable law:
- Automated security monitoring and alerting on our infrastructure
- Web application firewall in blocking mode
- Breach notification to affected customers and authorities in accordance with applicable law (including GDPR timelines)
11. Third-Party CRM Integrations
When you connect a third-party CRM (such as HubSpot) to your Entagl workspace, certain data may be shared with that CRM provider based on your configuration.
Data That May Be Shared
Based on your field mapping configuration, the following types of data may be synced to your connected CRM:
- Contact information (name, email, phone number)
- Lead source and channel information
- Custom fields you configure for sync
- Lifecycle stage and lead status
- Contact creation and update timestamps
How Data Flows
Data sharing with CRMs is entirely controlled by you:
- You explicitly authorize the connection via OAuth
- You configure which fields to sync and when
- You choose sync triggers (on lead capture, on update, manual)
- You can filter which contacts are synced (all contacts or leads only)
CRM Provider Privacy Policies
Once data is sent to your CRM, it is subject to that provider's privacy policy and data handling practices:
How to Stop Data Sharing
You can stop data sharing at any time:
- Disable automatic sync in your CRM integration settings
- Disconnect the CRM integration entirely
- Contact your CRM provider to delete data already synced
Note: Disconnecting the integration removes our access to your CRM but does not delete data already synced. You must contact your CRM provider directly to delete that data.
12. Analytics & Tracking
We use analytics to operate, secure, and improve Entagl:
- Product analytics (Segment): account identifiers (email, name, workspace) and usage events such as features used and errors encountered
- AI conversation analysis: our systems use our AI providers to analyze conversation content to generate the statistics and insights shown in your own dashboard (such as topics, outcomes, and sentiment) and to meter usage for billing
- Device identification (FingerprintJS): used on public chat surfaces solely for fraud and abuse prevention
We do not sell analytics data or use your conversation content to build advertising profiles.
14. International Data Transfers
Entagl is operated from the United States, and personal data is stored in AWS data centers in the US (us-east-1 region). If you use the Services from outside the US, your personal data — and your customers’ personal data — is transferred to and processed in the United States. Where we process personal data protected by EEA, UK, or Swiss data protection law, we rely on the European Commission’s Standard Contractual Clauses (SCCs), which are incorporated into our Data Processing Addendum (see our Terms of Service), together with the technical and organizational safeguards described in this policy. Voice-call media for EU WhatsApp calls is relayed through an EU region (eu-south-1) before processing.
15. California Privacy Rights (CCPA/CPRA)
If you are a California resident, this section applies to you. In the preceding 12 months we have collected the following categories of personal information:
- Identifiers (name, email, phone number, account IDs)
- Commercial information (subscription, billing and transaction records)
- Internet or electronic network activity (product usage, interactions with our website and app)
- Audio and visual information (voice messages, call audio and media shared in conversations)
- Professional or business information (your business details)
- Inferences (AI-generated conversation insights shown in your dashboard)
You have the right to: know and access the personal information we hold about you; delete your personal information; correct inaccurate personal information; opt out of "sale" or "sharing" of personal information; limit use of sensitive personal information; and not be discriminated against for exercising these rights.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, with one exception you control: if you enable Meta ads features (conversion tracking), event data is sent to Meta — you can disable this in your integration settings at any time.
To exercise your California privacy rights, email privacy@entagl.com with the subject "California Privacy Request", or use the tools in your account. We verify requests as described in the Verification section above.
16. HIPAA & Business Associate Agreements
For customers that handle protected health information (PHI), Entagl offers a HIPAA program:
- A self-service Business Associate Agreement (BAA) that workspace owners can review and e-sign in Settings once HIPAA is enabled for the workspace
- PHI access-audit logging: records of who viewed contacts, conversations, and messages, retained 90 days in-database and archived for 6 years
- AI processing for HIPAA workspaces routed through HIPAA-eligible endpoints (Google Cloud Vertex AI, and OpenAI under a BAA with zero data retention)
- Encryption of PHI at rest and in transit as described in this policy
- For HIPAA-enabled workspaces, only the business can set how long files uploaded through a secure upload link are kept — the customer cannot change it — and those files are analyzed only by HIPAA-eligible AI services covered by a Business Associate Agreement
Do not submit PHI through Entagl unless a BAA is in place for your workspace. Contact privacy@entagl.com to enable the HIPAA program.