Last updated: August 10, 2026
Zync — AI-powered WhatsApp receptionist. This policy covers the Zync service (the “Service”).
Zync (“Zync”, “we”, “us”) operates the Service, an AI receptionist that answers WhatsApp enquiries, checks your availability, and records bookings into your Google Calendar.
Zync is operated by an individual developer based in Romania. Contact: server@denishub.com.
Zync is a paid subscription service for service businesses. It connects your WhatsApp Business number to an AI assistant that talks to your customers, checks your Google Calendar for availability, and confirms bookings.
The Service requires an account (email and password) and, when you subscribe, payment details processed by our payment provider.
What we do NOT collect:
— No card numbers or payment details: billing is processed entirely by Stripe.
— No contact lists or address books from your phone.
— No precise location data.
— No browsing or advertising trackers, and no cross-site tracking.
— Your data is not used to train AI models (see section 6).
Data you submit:
— Account data: name, email address, and a hashed password you provide when creating an account.
— Business configuration: business name, services, business hours, bot persona, knowledge base, and fallback phone number you enter in the dashboard.
Messaging data: WhatsApp messages sent to or from your business number through the Service, including customer phone numbers, message text, and delivery statuses. This data is stored so your receptionist can serve returning customers and keep conversation context.
Calendar data: Google Calendar access, granted by you, used only to check availability and create bookings on your behalf. Your Google refresh token is stored encrypted and scoped to the minimum permissions required.
Usage data: server logs and error records needed to operate, secure, and debug the Service (IP address, timestamps, request paths). We do not run third-party analytics on this site.
You are the data controller for the conversations between your business and your end customers: you decide how those conversations are used to run your business.
Zync acts as a data processor for those messages: we process them on your instruction, solely to provide the receptionist service (answering enquiries, checking availability, creating bookings, and keeping conversation history).
Where we process data about your account (email, billing, configuration), Zync is the controller for that account data, under the terms of this policy.
We use the data above to: provide the Service (answer messages, check availability, create bookings, maintain conversation history); operate and secure it (billing, support, abuse prevention); and communicate with you about your account.
No advertising, no targeting:
Messages and other data received through the WhatsApp Business API are never used for advertising, marketing to third parties, or building audiences or targeting profiles.
No surveillance:
WhatsApp data is not used to monitor, profile, or surveil end users beyond what is strictly necessary to provide the receptionist service.
AI model training:
Your data is not used to train AI models. AI replies are generated through API-based model providers that, by their own policies, do not train on API data.
We do not sell your data.
Incoming customer messages are sent to an AI model provider to generate a reply. Depending on your configuration, this is either OpenAI (GPT-4 family via the OpenAI API) or a self-hosted, OpenAI-compatible endpoint you operate (for example, via OmniRouter on your own infrastructure).
The provider receives only the message text and the business configuration needed to generate a response. As API providers, they do not train on this data.
Generated output is probabilistic:
AI-generated replies may contain inaccuracies or errors. The Service is designed for booking conversations and should not be relied on for medical, legal, financial, or emergency advice. Zync does not generate images, so no image-authenticity considerations apply.
We share only the minimum data each processor needs, under data-processing terms:
Our use of the WhatsApp Business API complies with the Meta Platform Terms and the WhatsApp Business Solution Terms.
| Provider | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database and authentication | supabase.com/privacy |
| Stripe | Subscription billing | stripe.com/privacy |
| Calendar API (on your instruction) | policies.google.com/privacy | |
| Meta (WhatsApp) | Messaging platform (messages transit Meta’s infrastructure) | whatsapp.com/legal/privacy-policy |
| OpenAI | AI reply generation | openai.com/policies/privacy-policy |
— Messaging and booking data: retained while your account is active; deleted within 30 days of account closure.
— Account data: retained until you close your account; deleted within 30 days.
— Billing records: retained as required by tax law (typically 5–10 years, country-dependent).
— Server logs: retained for up to 30 days for security and debugging.
— Calendar tokens: retained until you disconnect Google Calendar or close your account.
Your data is stored on the server infrastructure that hosts the Service. Some sub-processors — such as Stripe and Meta/WhatsApp — may process data in the United States and other regions.
Where data is transferred outside the EEA/UK, we rely on appropriate safeguards, including Standard Contractual Clauses and the processors’ compliance with applicable adequacy decisions.
As part of standard internet routing, data may transit through other regions in transit.
GDPR (EEA/UK): you have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent at any time. Legal bases for processing (Article 6 GDPR): performance of a contract (6(1)(b)), consent (6(1)(a)), legitimate interests (6(1)(f)), and legal obligation (6(1)(c)).
CCPA (California): you have the right to know, delete, and correct your personal information, and to opt out of sale or sharing. Zync does not sell personal information.
How to exercise your rights: email server@denishub.com. We respond within 30 days. We may need to verify your identity first. You may also lodge a complaint with your data-protection authority (in Romania, ANSPDCP).
End customers: end customers who message a business through the Service may exercise their data rights by contacting that business directly. The business can action the request through us at server@denishub.com.
End customers can stop automated conversations at any time — for example by replying “STOP” — and the business must honour such requests.
The Service is intended for businesses and is not directed at children under 16 (EEA) or under 13 (US). We do not knowingly collect their data. If you believe a child has submitted data, contact server@denishub.com and we will delete it.
We protect data with encryption in transit (HTTPS/TLS), hashed passwords, per-account access controls, and rate limiting. Google Calendar tokens are stored encrypted and scoped to the minimum permissions. Payment data is never stored on our servers — it is handled entirely by Stripe.
If we become aware of a breach affecting your data, we will notify you without undue delay and take steps to contain it.
We may update this policy as the Service evolves. Material changes will be announced in the dashboard and by email, and the “Last updated” date at the top of this page will be revised. Continued use of the Service after changes take effect means you accept the updated policy.
Questions about this policy or your data? Email server@denishub.com (we reply within 30 days).