Privacy Policy

Last updated September 21, 2026

This Privacy Policy explains what information Agent Messenger ("we," "us," "our") collects, how we use it, and the choices you have. It applies to the Agent Messenger dashboard and the WhatsApp/AI agent connection it provides.

1. Overview

Agent Messenger exists to let an AI agent read WhatsApp messages and contacts on your behalf, and to give you a dashboard to manage that account directly. Doing that necessarily involves handling real conversations — including messages from people who contact you and have no direct relationship with us. This policy is written to be specific about what that means in practice, not just to state general principles.

2. Information we collect

Account information

Email address, display name, and a hashed password (or, if you sign in with Google, the identity information Google shares with us for that purpose).

Message content

When you connect a WhatsApp account, we store the messages sent and received through it — including their text and media — so that features like search, chat history, and debugging work. This content is stored in our database without encryption at rest. That includes messages from people who message your connected number and are not themselves Agent Messenger customers; they haven't agreed to anything with us directly, and their message content is retained the same way. This is the single most sensitive category of data this Service holds, and we treat it accordingly — access is scoped to the account that owns it everywhere in our system.

Contacts and tags

Names, phone numbers, tags, and notes for the contacts associated with your connected accounts.

Billing information

Subscription plan, billing status, and payment history. Card and payment details are collected and processed by our payment processor, Polar — we don't store your full card number ourselves.

Connected-agent data

If you authorize an AI assistant or other client, we record the connection, the read-only access you granted it, and a log of every tool call it makes — what it called, when, on which account, and whether it succeeded — as your audit trail.

Technical and usage data

Standard technical data generated by using the Service — log data, device/browser information, and similar diagnostic information.

3. How we use information

  • To provide the Service — connecting your WhatsApp account, running the dashboard, and letting an authorized agent read within the scope you granted it.
  • To enforce the access controls the Service is built around, including scoping every read to the account that granted it.
  • To process payments and manage your subscription.
  • To maintain the audit trail so agent activity on your account is answerable after the fact.
  • To provide support, secure the Service, and comply with legal obligations.

We don't sell your data, and we don't use your message content to train AI models.

4. How we share information

We share information with:

  • Service providers who help us run the Service — our payment processor (Polar), our sign-in provider (Google, if you use it), and the infrastructure that keeps your WhatsApp connection running.
  • An AI agent you choose to connect. This is your decision, made through an OAuth consent screen naming exactly what access you're granting — we don't share your data with any AI provider on our own initiative.
  • Legal and safety reasons — if required by law, or to protect the rights, safety, or property of Agent Messenger, our users, or others.

5. Data retention

We retain your information for as long as your account is active, and for a reasonable period afterward in case you return or as needed for legal, accounting, or security reasons. If you'd like your account and associated data deleted sooner, contact us — see Section 7.

6. Data security

We use reasonable technical and organizational measures to protect your information, including scoping data access by account ownership throughout our system. As noted in Section 2, message content is stored unencrypted to support features like search — this is a deliberate tradeoff, not an oversight, and it means the practical protection for that data is who can reach our database, not encryption at rest. No method of storage or transmission is completely secure, and we can't guarantee absolute security.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. We don't yet have self-service tools for all of these, so for now the way to exercise any of them is to email us at support@messengeragent.dev — we'll respond and fulfill valid requests within a reasonable time. You can update your profile and notification preferences directly in Settings, and revoke a connected agent's access at any time from the MCP page.

8. Children's privacy

The Service is not directed at children, and you must be at least 18 (or the age of legal majority where you live) to use it. We don't knowingly collect information from children.

9. International transfers

Your information may be processed in a country other than where you live. Where required, we take steps intended to ensure an adequate level of protection for information transferred internationally.

10. Changes to this policy

We may update this policy from time to time. If a change is material, we'll make reasonable efforts to notify you before it takes effect.

11. Contact

Questions about this policy, or a request under Section 7? Reach us at support@messengeragent.dev.