Privacy Policy
This policy describes what Assista.bot collects, where it is stored, who else sees it, and how long it is kept. It describes the service as actually built — where something is not yet possible, that is stated rather than implied.
1. Who this covers
People who use the bot. You send messages to the bot's WhatsApp number and it acts on them.
People who don't. The bot's number is publicly reachable, so anyone can message it. Messages from numbers that are not on the access list are rejected before anything is read, stored, or sent to any third party. One record is kept: the sender's phone number is written to an operational log, retained 30 days, so that unexpected traffic can be investigated. Nothing else about the message is retained, and no reply is sent.
2. What is collected
Only what you send, and what the bot derives from it in order to work.
| Category | Examples | Source |
|---|---|---|
| Identifier | Your WhatsApp phone number | Meta, with each message |
| Message content | Text you send; the transcript of a voice note; images you send | You |
| Things you asked to be kept | List names and items, reminders and their times, facts you asked to be remembered | You |
| Profile | Time zone, language, name if you tell it, coordinates if you set a weather location | You, or inferred from how you write |
| Conversation history | Recent messages, so the bot can follow a conversation | You |
| Calendar data | Events read, created or deleted on your Google Calendar | Google, with your consent |
| Operational records | Message identifiers, reminder identifiers and times, transcription confidence scores | The system |
Not collected: payment details, location beyond a weather coordinate you choose, contacts, or anything from other conversations on your phone. The bot only sees messages sent directly to it.
3. Where it is stored, and for how long
Everything is stored in Amazon Web Services, in the eu-central-1
region (Frankfurt, Germany). The database is encrypted at rest with a
customer-managed key.
| Data | Retention |
|---|---|
| Lists, reminders, remembered facts, profile | Kept until you delete them |
| Conversation history | 30 days, then deleted automatically |
| Duplicate-message records | 24 hours |
| Voice note audio | Not stored at all — streamed for transcription and discarded |
| Images | Not stored — passed for processing and discarded |
| Operational logs | 30 days |
| Database backups | Point-in-time recovery, rolling 35 days |
| AWS account activity records | Retained for security auditing |
Operational logs contain your phone number, message identifiers, reminder identifiers and times, and language-detection scores. They do not contain the content of your messages, your transcripts, your list items, or your calendar.
4. Who else sees it
The bot is not useful without sending some of what you write to other services. In each case, only what that service needs:
Anthropic — the content of your messages, images, recent conversation history, your lists and remembered facts are sent to Anthropic's API so that Claude can understand the request and act on it. This is the core of how the bot works. Anthropic states that it does not train its models on inputs or outputs submitted through its API; see Anthropic's own privacy policy for the authoritative position.
Amazon Web Services — hosting, storage and, for voice notes, Amazon Transcribe. Voice audio is streamed to Transcribe for conversion to text and is not written to storage.
Google — if you connect a calendar, calendar data is exchanged with the Google Calendar API. See §5.
Meta (WhatsApp) — the messaging channel itself. Meta necessarily sees every message between you and the bot, under Meta's own terms and privacy policy.
Open-Meteo — for the daily briefing, a latitude and longitude are sent to fetch a forecast. No identifier is sent with it, so this request is not linked to you.
Nobody else. Your data is not sold, rented, shared for advertising, or used to build profiles for anyone. There is no advertising in this service.
5. Google user data
When you sign in, the bot requests your basic Google identity — the openid,
email and profile scopes — to know which account you are.
When you connect Google Calendar, it requests two narrow scopes, never the broad
calendar scope: calendar.events, to read your events for the daily
briefing and "what's on today" and to create, change or delete a single event when you ask;
and calendar.calendars.readonly, used for one read-only call
(calendars.get on your primary calendar) immediately after you consent, to
confirm which Google account the new authorisation belongs to so that it can never be
attached to the wrong WhatsApp number.
Nothing wider than that is touched: the list of calendars on your account is not read, no calendar other than the one you connect is accessed, and calendars themselves are never created, deleted, shared or reconfigured.
Assista.bot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means calendar data is used only to provide the features you asked for, is never used for advertising, is never sold, and is not used to train any model. Calendar event contents are sent to Anthropic only as needed to answer a request that concerns them — for example, summarising your day.
Your Google authorisation is stored as an encrypted refresh token. You can revoke it at any time at myaccount.google.com/permissions, which immediately and permanently ends the bot's access to your calendar. Revoking access does not delete data already stored by the bot; to remove that, see §7.
6. How it is protected
- Messages from numbers not on the access list are rejected before processing.
- Every incoming request from Meta is verified with a cryptographic signature.
- The database is encrypted with a customer-managed key; credentials are held in encrypted parameter storage, never in code or configuration.
- Each user's data is separated in code: the identifier that selects whose data to read is taken from the verified message, never from anything the AI model produces, so a request cannot be manipulated into reaching another person's data.
- Account activity is logged and monitored, with alerts on suspicious findings.
No system is perfectly secure, and this one is a personal project rather than an enterprise service. Please see the Terms of Service.
7. Your choices and how to exercise them
See what is held. Ask the bot — it can read back your lists, reminders and remembered facts.
Delete individual things. Ask the bot to remove a list item, cancel a reminder, or forget a fact. This deletes the record.
Delete everything. Email support@assista.bot from the address associated with your account, or message the bot, and all data associated with your phone number will be erased: database records, stored Google authorisation, and conversation history. This is currently a manual process carried out by the operator rather than a self-service button, and will be completed within 30 days of the request. Operational logs containing your phone number expire on their own within 30 days.
Withdraw calendar access. Revoke at myaccount.google.com/permissions at any time.
Stop using it. Stop messaging the bot. Nothing further is collected. Your existing data remains until you ask for it to be deleted, or you can ask for deletion at the same time.
If you are in the EEA or the UK, you have rights of access, rectification, erasure, restriction, portability and objection under the GDPR. Our legal basis for processing your personal data is your consent, given when you choose to use the assistant and when you connect your Google Calendar; you can withdraw it at any time (see above), which does not affect processing already carried out. You may also lodge a complaint with your local data-protection authority — in the UK, the Information Commissioner's Office; in the EEA, the supervisory authority in your country of residence.
8. Children
This service is not intended for anyone under 16 and is not directed at children.
9. Changes
If this policy changes materially, the updated version will be published here with a new date, and existing users will be told through the bot before the change takes effect.
10. Cookies and local storage
The website stores two things on your device, and neither is used to track you. There is no analytics, no advertising network, no tag manager, and no third-party script of any kind on this site — nothing here reports your visit to anyone.
| What | Kind | Why | How long |
|---|---|---|---|
assista_session |
Cookie | Keeps you signed in after you log in with Google. Set only when you sign in — never on a plain visit. | 30 days, or until you sign out |
assista-theme |
Local storage | Remembers whether you chose the light or dark appearance. | Until you clear your browser storage |
assista-cookie-notice |
Local storage | Remembers that you dismissed the notice about this page, so it isn't shown again. | Until you clear your browser storage |
The session cookie is HttpOnly (script on the page cannot read it),
Secure (sent over HTTPS only) and SameSite=Lax (not sent from
other sites). It holds a random identifier, nothing about you.
Why there is no "accept cookies" button. All three exist only to provide something you asked for — staying signed in, the appearance you picked, and not being shown the same notice twice. Storage that is strictly necessary for a service you requested does not require consent, only that you are told about it, which is what this section does. Asking permission for something that has to be set anyway would be a dialogue with no honest "no" in it. If tracking or analytics is ever added, that changes, and you would be asked properly first.
You can clear all three at any time through your browser's settings. Clearing the session cookie signs you out; the site keeps working without the other two.