1. Who We Are
esek.io ("we", "our", "us") operates a business messaging platform that connects service providers ("Business Customers") with their customers ("End Users") via the WhatsApp Business Platform and, where enabled, Instagram and Facebook Messenger. We act as a Technology Provider under the Meta Business Platform and process data on behalf of our Business Customers in accordance with Meta's Platform Terms and Business Messaging guidelines. This policy explains how we collect, use, and protect personal data.
2. Data We Collect
We collect data from two audiences: Business Customers who register to use our platform, and End Users who communicate with those businesses via WhatsApp, Instagram, or Facebook Messenger.
From Business Customers
- Account data: name, email address, and password hash of registered agents.
- Onboarding data: when a business connects via Meta Embedded Signup, we receive the WhatsApp Business Account ID, phone number ID, business verification status, and a scoped access token. We store only what is necessary to operate the integration.
- Product usage data: events recording how our apps and website are used, such as which screen was opened, which action was taken, and which errors were shown. Screens are recorded as route patterns, so identifiers that appear inside a page address are not collected. Each event carries a randomly generated session identifier that puts one visit in order: in the apps it lasts until the app is closed, and on our website until the browser tab is closed. When a registered agent is signed in we also record the agent identifier once per session, so usage in that session can be associated with that account. We also record that operational events occurred, for example that an order was created or a payment settled, using identifiers, statuses and counts only, never the contents of a message. All of this is stored in our own database. We do not send it to an external analytics provider.
- Operational logs: log entries and error traces generated during normal operation.
- Mobile advertising measurement data: if you allow tracking through Apple's App Tracking Transparency prompt, the iOS app sends installation and activation events, a device identifier, and basic app and device metadata to Meta App Events so we can measure the performance of our Meta advertisements. We have disabled collection of Apple's advertising identifier (IDFA). If you deny or restrict tracking permission, Meta App Events is not initialized and this data is not sent.
- Signup security and provenance data: a one-way, keyed fingerprint of the IP address used when a workspace is first created, the sign-in method, and a coarse client platform. We use this only to prevent abuse, distinguish internal testing from external signups, and diagnose signup problems. We do not retain raw IP addresses or full user-agent strings for this purpose.
From End Users (via WhatsApp conversations)
- Conversation data: WhatsApp phone number, display name, and messages exchanged through the platform.
- Media files: images, videos, documents, and audio messages sent or received via WhatsApp.
Connected Instagram and Facebook Messenger accounts
When a Business Customer enables these channels and authorizes a connection, we receive the selected professional Instagram account or Facebook Page identifier, account name, authorizing account identifier, granted permissions, and access credentials. We encrypt the credentials and use them to operate that business's messaging connection.
For customers who message a connected account, we receive a Page-scoped Messenger customer identifier or Instagram-scoped customer identifier, available profile name, message content, supported attachments, and any reply, story, or referral context supplied by Meta. We keep each account's conversations separate. Authorized staff can link a channel identity to an existing customer record. We do not infer that two people are the same person from a matching profile name. Supported attachments may be stored privately so staff can view them after the provider's temporary download link expires.
When authorized staff open a conversation or ask Iska (Copilot) for a customer profile, we may also retrieve the available profile name, Instagram username and profile link, and profile photo URL from Meta. We store an available display name on the channel identity; the additional profile fields are fetched on demand rather than saved to that customer record.
Authorized staff can read and reply to these messages. When the business enables AI assistance and the applicable consent requirements are met, message text and relevant history are processed by the AI providers described below. The retention and deletion rules for these channels are described in section 8.
From End Users (via AI phone calls)
When a Business Customer turns on the AI phone assistant, calls forwarded to the phone number we provide are answered by an AI voice assistant on that business's behalf. The assistant says that it is an AI assistant at the start of every call. For each such call we collect:
- Caller identity: the caller's phone number, as delivered by the telephone network or by WhatsApp. We also use that number to create or match a contact record in the Business Customer's own customer list.
- Call transcript: a written record of what was said during the call, produced by speech-to-text.
- Call summary and messages: a short written summary of the call, and any message the caller asked us to leave for the business.
- Call metadata: when the call started and ended, how long it lasted, the number that was dialled, and whether it was answered.
AI calls and voicemail. During AI answering, call audio is processed live. We keep the written transcript, summary and message as the record of the call. We also keep a private recording of the call audio, both the caller's side and the assistant's side, for up to 7 days. We use it only to investigate problems and check quality, and then it is deleted automatically. It is not used to train AI models and is not shared for advertising. Depending on where the call comes from, callers may hear at the start of the call that it is recorded. Erasing a call, or deleting the workspace, deletes this recording immediately. When the business has insufficient minutes and balance, direct phone calls switch to voicemail: callers hear a greeting asking them to leave a message after the tone, and we privately store up to two minutes of their message. Authorized workspace members can play it. Erasing the caller’s record also deletes this recording.
Calls answered by the AI phone assistant end automatically after five minutes.
Optional device permissions
- Microphone (mobile apps): our iOS and Android apps may request microphone access when you choose to record a voice message in chat. Audio is not captured in the background or outside the action you started. Audio from Copilot voice sessions is described in section 5.
3. Legal Basis for Processing
- Contractual necessity: processing Business Customer data is required to provide the platform service under our terms.
- Legitimate interest: processing End User conversation and phone call data is necessary for Business Customers to communicate with their customers and for us to maintain platform reliability. We rely on legitimate interest also to measure how our own product and advertising perform, so that we can improve them.
- Consent: where required by applicable law (e.g. optional microphone access), we rely on your explicit consent, which you may withdraw at any time.
4. How We Use Data
- To provide the messaging and booking service to connected businesses.
- To generate AI-assisted replies, signals, suggestions, images, and booking confirmations on behalf of the Business Customer. This includes the customer-facing AI surfaces: the Chat Agent (which drafts or sends replies to End Users on the business's behalf), the AI phone assistant (which answers forwarded phone calls on the business's behalf, can book appointments and take messages during the call, and writes up what was said afterwards), and the silent Signal Capture pass that extracts quotes, commitments, and handoff brief fields from human-replied chats for the merchant's later review; and the merchant-facing surfaces: Copilot (in-app assistant, including real-time voice when enabled), Ads suggestions (campaign name and creative copy), and image generation for business assets (logo, catalog photos, ad creative).
- To send transactional email notifications (e.g. new conversation alerts).
- To improve platform reliability and diagnose technical issues.
- With your App Tracking Transparency permission, to measure iOS app installations and activations attributable to our Meta advertisements.
We use WhatsApp, Instagram, and Facebook Messenger data strictly for the purposes described above. We do not use End User data for advertising, profiling, or any purpose unrelated to providing the messaging service.
5. Data Sharing
We do not sell personal data. Data may be shared with the following third-party processors:
- Meta (WhatsApp, Instagram, and Facebook Messenger): account authorization and messages are processed through the official API for the connected channel.
- Meta (App Events, iOS only): after you allow tracking through Apple's App Tracking Transparency prompt, installation and activation events, a device identifier, and basic app and device metadata are transmitted for advertising measurement. The SDK is configured not to collect IDFA and remains inactive if permission is denied or restricted.
- Telephony: calls to the phone numbers we provide for the AI phone assistant are routed by DIDWW, which receives the call's metadata, such as the caller's phone number and the number that was dialled. It does not handle the call audio. The audio is carried by Twilio, which therefore processes the caller's phone number and what is said while the call is in progress. Twilio also handles call recordings, SMS one-time sign-in codes, caller number lookups, and the documents needed to register a phone number with regulators.
- Text-to-speech providers: when the AI phone assistant speaks a reply, the text of that reply is sent to Google Gemini to turn it into speech. Google Gemini is also used to transcribe voicemail messages.
-
Third-party AI providers: we use third-party AI APIs to power the customer-facing Chat Agent, the AI phone assistant, the silent Signal Capture pass on human-replied chats, the merchant-facing Copilot (including its voice mode), Ads suggestions (campaign name and creative copy), and image generation. The current providers include OpenAI and Google Gemini, with the provider depending on the feature; we may add or substitute providers in the future. If we change the set of providers used for Business Customer data, we will update this policy and re-prompt for consent in-app before routing that data to the new provider.
The following categories of data are transmitted to the AI provider strictly to generate the requested response:- The text of messages being processed (End User WhatsApp, Instagram, or Facebook Messenger messages, or the Business Customer's prompt to Copilot, or a text prompt for image generation).
- Relevant conversation history needed for the model to produce a coherent reply.
- Business context the assistant needs to answer (e.g. the Business Customer's catalog, hours, pricing, the customer thread the merchant is viewing, lead status, and the merchant-authored notes document used to tune the Chat Agent, most of which is information already publicly available about the business).
- When voice mode is enabled in the merchant-facing Copilot, the microphone audio captured during an active voice session is streamed to the provider's realtime API for transcription and reply generation. Audio is not captured outside of an active voice session. We also keep a private copy of the audio from voice sessions in our own storage for up to 7 days, to investigate problems and check quality. It is then deleted automatically. It is not used to train AI models and is not shared for advertising.
- When the AI phone assistant answers a call, the audio of that call is streamed live to the provider's realtime API so the assistant can understand the caller and speak back, and the provider returns the transcript to us as text. We also send a short summary of that caller's most recent earlier contact with the business, where one exists, so the assistant does not make them repeat themselves. We also keep a private recording of the call in our own storage for up to 7 days, as described in section 2.
The AI provider processes this data as our sub-processor under their API Data Processing Addendum. Per the providers' API terms in effect as of the "Last updated" date above, data submitted via the API is not used to train the providers' models and is retained only for the period needed to provide the service and for limited abuse-monitoring purposes. We have confirmed that each AI provider we use provides protection for this data substantially equivalent to that described in this policy. - Infrastructure providers: Google Cloud Platform (US region, Iowa) hosts our servers, databases and file storage, and Firebase Cloud Messaging delivers push notifications.
- Email: Resend sends our transactional email.
- Other Google services: Google Cloud Translation receives message text to translate it, Google Web Risk receives links found in messages to check them for safety, and Google Maps Platform receives business addresses to look them up.
- Billing and sign-in: Paddle, the merchant of record for subscriptions bought on our website, receives billing details and the customer's email address. Apple and Google handle Sign in with Apple, Google Sign-In, and purchases made in their app stores.
- Meta (Conversions API): to measure our own advertising, we send Meta signup events with a hashed email address or phone number and a hashed internal account identifier. For visitors who accepted marketing cookies, or who are outside the EU, the EEA and the United Kingdom and have not declined them (a Global Privacy Control signal counts as declining), the events also carry Meta's ad click identifier and browser identifier and the address of the signup page. When a lead reaches our own workspace from one of our click-to-WhatsApp ads, we also send Meta a lead event with the ad click identifier, our WhatsApp Business Account identifier and the contact's hashed phone number.
- Integrations a Business Customer connects: when a Business Customer connects its own account with Morning (Green Invoice), iCount, Tranzila, Cardcom, Grow (Meshulam), Shippo or Google Drive, we pass data to that provider at the Business Customer's direction. Before outbound sales calls, phone numbers are checked against Israel's national do-not-call registry.
The full list of sub-processors, with what each one receives and where it processes data, is on our Sub-processors page.
6. Google Account Data
Connecting a Google account to esek.io is optional. You can use every part of esek.io without it, and you see exactly what you are granting on Google's own consent screen. Two things use it:
- Google Sign-In. We receive your name, your email address and your Google account identifier, and we use them to sign you in.
- Google Drive. You pick the files yourself in Google's own file picker, and we are given access to those files only. The rest of your Drive stays closed to us. A one-off import, such as a catalog spreadsheet, reads the file once. A document you link so that its content stays current is read again when it changes, until you remove it.
Removing a linked document in Settings deletes the access we hold for it. You can also revoke it directly at https://myaccount.google.com/permissions.
esek.io's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to anyone, we do not use it for advertising, and we do not allow humans to read it except where you have asked us to, where it is needed for security, or where the law requires it.
7. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our servers are hosted and where Meta and most of our sub-processors operate. Each sub-processor and the place where it processes data are listed on our Sub-processors page. For transfers from the EU, the EEA and the UK, we rely on the EU-US Data Privacy Framework (including its UK Extension) where the recipient is certified under it, and on Standard Contractual Clauses (with the UK Addendum for UK data), together with data processing agreements with each processor.
8. Data Retention
- WhatsApp conversation messages and media: retained for up to 12 months from the date of the last message in the conversation, or until the Business Customer deletes the conversation, whichever is sooner.
- Instagram and Messenger records: messages, channel identifiers, stored display names, and message-event records remain as workspace records until erased or the workspace is deleted. We do not automatically delete these records after 12 months. Moving a conversation to trash allows recovery for seven days; permanent deletion is performed by a weekly cleanup after that period, or sooner if the workspace owner permanently deletes it. Social attachments in our private storage expire 12 months after the individual message was sent, or sooner when the associated conversation or social data is permanently erased. This attachment expiry does not erase the message text or customer record.
- Business Customer account data: retained for as long as the account is active.
- IP-derived signup fingerprint: retained for up to 90 days, then deleted. The remaining coarse signup context does not contain the IP address.
- Product usage data: retained for as long as it is useful for measuring and improving the service. We do not delete it on a fixed schedule. It contains no conversation content and no message media.
- AI phone call records: the transcript, summary, caller number, and call metadata are kept as business records of the workspace they belong to. We do not delete them on a fixed schedule. They are retained for as long as that workspace exists. When the workspace is deleted they are removed from the live service and held in a workspace backup for 30 days, in case the deletion is reversed, and then permanently deleted.
- Call audio and Copilot voice audio: recordings of AI phone calls and of Copilot voice sessions are kept in private storage for up to 7 days and then deleted automatically. Erasing a call deletes its recording immediately. Deleting the workspace deletes all of them immediately. They are not copied into the workspace backup.
- Upon workspace deletion: associated workspace data, including conversations, media, and connection credentials, is removed from the live service and permanently removed from the workspace recovery backup within 30 days. Deleting a staff account removes that person’s profile and access, not the workspace’s records.
Whose record a call is. A record of a call to a business is that business's own customer record, in the same way a written note of the call would be. It is not part of the personal account data of the staff member who works there. Two consequences follow, and we would rather state them plainly than leave them to be discovered:
- Deleting a staff account, including the owner's, removes that person's profile, credentials, and access. It does not remove the business's call records. Those are removed when the workspace itself is deleted.
- Removing a caller from a Business Customer's contact list does not by itself erase the call records already logged against that caller.
If you called a business that uses esek.io and you want the record of your call erased, ask the business, or write to us at privacy@esek.io. Erasing a call clears the caller's phone number, the transcript, the summary, any message taken, and any recording of the call we still hold, and marks the call as erased on request. What remains is how long the call lasted and what it cost the business, which says nothing about who called or what was said. We keep that much because it is the evidence for a charge already made.
Disconnecting a social account and deleting its data. Disconnecting Instagram or Messenger stops new messaging through that connection and clears its stored credentials. It does not by itself erase existing conversations or records the business already holds. To request erasure of social-platform data, contact privacy@esek.io with the connected account or Page and the business concerned. We verify the request and its scope, including records shared with other channels, and confirm the outcome. A request that still needs verification or review is not treated as a completed deletion. Customers who do not have an esek account can use the same contact address.
When Meta sends us a verified authorization-revocation notice, we stop the affected connection and clear its credentials. When Meta sends a data-deletion request, we also begin erasure of the associated social data and return a confirmation code and status-page link. Shared records, exports, recovery backups, or AI history may require additional review before the request can be marked complete. Removing a disconnected channel from the connection list only hides that connection; it does not erase its history.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict certain processing. To exercise any of these rights, contact us or see our Data Deletion page for the deletion request process. We will respond within 30 days.
10. Children's Data
Our service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it promptly.
11. Cookies and Local Storage
The web application uses a cookie to keep you signed in and a short-lived cookie that protects connecting a Google account. It keeps your sign-in, your settings, your cookie choice and a random identifier that helps prevent repeated trials in your browser's local storage. If you arrive through a referral link, a cookie remembers the referral for 60 days. The application loads Google's libraries only when you connect Google Drive, loads Paddle's checkout only when you pay, and stores a notification token only if you turn on browser notifications.
Our marketing website and signup flow also store, in your browser, a randomly generated identifier and the campaign parameters from the address you arrived on. We use them to measure how the site performs and to attribute a signup to the advertisement that led to it. They are set by us and stay in our own systems, with one exception: for visitors who accepted marketing cookies, or who are outside the EU, the EEA and the United Kingdom and have not declined them, the Meta ad click identifier from that address is sent to Meta with the signup, as described under Meta (Conversions API) in section 5.
Our marketing website additionally carries advertising tags from Meta and Google Ads. These tags set their own cookies and report page views to Meta and Google so we can measure and attribute our advertising. They load only after consent. Visitors in the EU, the EEA and the United Kingdom are asked before they load; elsewhere they load without a prompt. A browser that sends a Global Privacy Control signal is treated as having declined, wherever the visitor is. The tags do not load on the application's own screens.
12. Security
All data is transmitted over TLS. Passwords are hashed with bcrypt. Database access is restricted to authenticated services inside our private network. Access tokens received during WhatsApp Embedded Signup or Instagram and Messenger authorization are stored encrypted and scoped to the minimum required permissions.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered Business Customers. Continued use of the platform after changes constitutes acceptance of the updated policy.
14. Contact
Questions about this policy? Contact us at privacy@esek.io.
15. Who we are
The controller of the personal data described in this policy is Zak Goichman, trading as esek.io, a sole proprietor (עוסק מורשה) registered in Israel. For customer messaging data processed on a Business Customer’s behalf, that business determines the purposes of processing and esek.io acts as its processor.
- Registered address: Herzl 100, Tel Aviv, Israel
- Email: privacy@esek.io
Our Israeli business registration number is available on request from legal@esek.io.