Shathi App
Privacy policy
This draft explains current data handling. Owner identity, processor details, retention periods and contact need confirmation before public launch.
Draft policy · owner details and legal review pending
Last updated: 1 October 2026Who operates the service
Controller / legal entity: [owner must supply legal name, address and jurisdiction]. Support and rights contact: [owner must supply contact].
Data collected
WhatsApp number (wa_id), profile name, incoming message text, reminder text and schedules/status, bKash transaction ID (TrxID), amount/date/status, monthly and daily usage counters, processed-message receipts, consent and waitlist number/name/source, and allowlist records. Hashed IP/number waitlist abuse counters are also collected. The waitlist verification checks a Turnstile token; Cloudflare supplies the connecting IP for abuse control. Tokens are used for verification, not as a customer profile.
Why we use it
To understand and manage requested reminders, send confirmations and reminders, handle subscriptions and owner payment review, provide requested invitation access, enforce quotas, prevent abuse and retry/replay duplication, and respond to deletion and pause requests. This service does not sell personal data. The owner must confirm applicable legal bases and local requirements before launch.
Processors and service boundaries
Meta (WhatsApp) processes your number and message content for messaging. The configured AI provider receives reminder text to parse your request. Cloudflare hosts the Worker and D1 database and verifies waitlist requests through Turnstile. The owner must name the configured AI provider, review processor agreements, and document any cross-border processing before launch. Erasure in this service does not erase independent Meta/provider records; their own policies apply.
Retention
Active reminders and account data remain while used, subject to [owner must set inactive-account, message-log, waitlist and backup retention]. Payment/legal records remain for [owner must set legal retention]. Hashed waitlist IP/number abuse counters, quota-prevention counters and hashed retry/replay receipts have [owner must set appropriate retention]. Current-month erased allowance totals reset with the next monthly allowance window; other retained lifetime cost/legal counters and replay records require an owner retention policy. No fixed retention period is claimed here.
Your choices and rights
Send stop or বন্ধ to pause subsequent sends without deleting schedules. Send start or শুরু to resume. Send delete my data or ডাটা মুছে দাও and confirm the sender-owned button within ten minutes. Contact the owner to request access, correction or other applicable rights. The owner must supply a working rights contact before launch.
What erasure removes and retains
Confirmation removes reminders, monthly/daily usage rows, message logs, waitlist and allowlist entries, profile name, referral and pending drafts. Payment rows keep wa_id, TrxID, amount and date with a retained marker and internal primary key. A tombstone keeps wa_id/deleted_at, current-month erased create/send allowance totals and lifetime confirmation/legal/cap-notice counters to prevent account recreation resetting limits. Processed receipts keep hashed message IDs, with sender/time blanked, to prevent retries rebuilding erased data. Hashed waitlist IP/number abuse counters remain independently after erasure; their retention period must be set by the owner.
Limits of pause and deletion
Messages already accepted or in flight with Meta cannot be recalled. Subsequent sends pause, and generation guards prevent late work rebuilding erased service data. A later ordinary incoming message can reactivate the account, subject to invitation access and retained quotas. Deletion does not reset the current month’s allowances.
Website preferences and changes
Language choice is stored locally in your browser. No analytics or advertising pixel is enabled by default. Turnstile loads only when a configured form is activated; its verification is processed by Cloudflare. Contact: [owner must supply]. Changes to this policy will be dated here.
Shathi App
OpenRouter
shathiapp@gmail.comMake room for what matters.
Start with one thing you want to remember.
Start on WhatsApp