Privacy Policy
Last updated: 21 September 2026
CallThem (“CallThem”, “we”, “us”) is a business communication platform at callthem24.com that lets companies send and manage WhatsApp and email conversations, contacts and campaigns, with an AI assistant trained on the company’s own knowledge base. This policy explains what data we handle, why, who we share it with, and the choices you have. It applies to the CallThem web app and the CallThem Platform API.
Who is who What we collect Google user data How we use data Who we share with Retention & deletion Security Your choices Contact
1. Who is who
CallThem is used by companies (our customers). A company’s staff sign in, connect their own WhatsApp number and, optionally, their own Telegram bot and email account, and upload their own contacts and knowledge. For the contact and conversation data a company puts into CallThem, the company is the data controller and CallThem acts as its processor: we handle that data only to provide the service the company asked for. For our customers’ own account, sign-in and billing data, CallThem is the controller.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | Name, email address, sign-in identity (email/password or Google sign-in via Firebase Authentication), role, company name | To create and secure your account |
| Contacts & tables | Names, phone numbers, email addresses and custom fields that a company imports or types in | To let the company message and manage its own contacts |
| Messages | WhatsApp messages sent and received through the company’s connected WhatsApp Business number, including text, voice notes and images, delivery status, and the sender’s WhatsApp profile name | To show conversations, deliver messages and power AI replies and follow-ups |
| Telegram messages | If a company connects its own Telegram bot: the text messages people send to that bot, the sender’s Telegram display name and username, and the replies sent back. The bot token is kept on our servers only and is never shown in the app | To show conversations and power AI replies |
| Knowledge base | Documents, FAQs and product information a company adds for its AI assistant | To let the AI answer customers using the company’s own information |
| Connected email account | For Gmail: your email address, display name and OAuth tokens. For SMTP/IMAP: the server settings and credentials you enter. Messages handled by AI email auto-reply (see section 3) | To send email, and optionally reply to incoming email, on your behalf |
| Billing & usage | Plan, wallet balance, message/photo/voice usage counts, invoices | To meter usage and bill you |
| Technical data | Server logs (timestamps, request paths, error messages, IP addresses) | Security, debugging and abuse prevention |
We do not knowingly collect data from children under 16, and the service is intended for business use.
3. Google user data (Gmail)
If you choose Connect with Gmail, CallThem asks Google for access to your Google account. We request the minimum needed for what you turn on:
| Permission (scope) | When requested | What we do with it |
|---|---|---|
gmail.send — send email on your behalf | Always, when you connect Gmail | We send only the emails you (or automations you configure in CallThem) create. We cannot read your mailbox with this permission. |
userinfo.email, userinfo.profile | Always, when you connect Gmail | To show which Gmail account is connected and to use your name as the sender name. |
gmail.modify — read and modify your mail | Only if you turn on “AI auto-reply to incoming emails” (you are asked separately, and can decline and still send email) | We list recent unread messages in your inbox, read them, generate a reply with the AI assistant using your company’s knowledge base, send that reply from your account, and remove the “unread” label so it is not answered twice. We do not delete or move your mail. |
Limited Use disclosure. CallThem’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In line with those requirements:
- We use Google user data only to provide the email sending and (if you enable it) AI auto-reply features you can see in the app. We do not use it for advertising, and we do not sell it or transfer it to data brokers or advertising platforms.
- We do not use Gmail data to develop, improve or train generalized AI or machine-learning models.
- We do not allow people at CallThem to read your Gmail content unless you ask us to (for example, for support), it is necessary for security or abuse investigation, or the law requires it. Automated processing is limited to generating the reply you enabled.
- When AI auto-reply is on, the text of an incoming email is sent to the AI provider configured for your company (for example OpenAI) only to draft the reply, together with relevant excerpts of your company’s knowledge base. It is not shared for any other purpose.
- We keep a log of the incoming messages and automatic replies handled by AI auto-reply (sender, subject, message text, time) so you can review what was sent. We skip automated mail such as newsletters, mailing lists, bounces and no-reply senders, and cap how many auto-replies are sent.
- Your Google OAuth tokens are stored on our servers, are used only to perform the actions above, and are never shown in the app.
You are in control. You can turn AI auto-reply off at any time in Email → Gmail. Choosing Disconnect Gmail revokes CallThem’s access at Google and deletes the stored tokens. You can also remove CallThem’s access yourself at any time at myaccount.google.com/permissions.
4. How we use data
- To provide, operate, secure and support the service (sending and receiving WhatsApp and email messages, showing conversations, running campaigns, follow-ups and scheduled messages).
- To generate AI replies and content from a company’s own knowledge base at that company’s request.
- To meter usage, bill, and prevent fraud and abuse (for example rate limits on one-time-code messages).
- To communicate with you about your account, security and service changes.
- To comply with legal obligations. We do not sell personal data and we do not show advertising.
5. Who we share data with
We share data only with service providers that are needed to run CallThem, and only as needed for the feature in use:
- Google (Firebase Authentication and Firestore database, and Gmail if you connect it).
- Meta and Gupshup — the WhatsApp Business Platform and its business solution provider, which carry WhatsApp messages to and from the company’s WhatsApp Business number. Their own privacy terms also apply to WhatsApp messages.
- Telegram — the messaging platform that carries messages to and from a company’s own Telegram bot, if it connects one. Telegram’s own privacy terms also apply to those messages.
- AI providers such as OpenAI, which receive the text needed to generate a reply, transcribe or read a voice note or image, or build search embeddings for your knowledge base. A company may supply its own AI provider key.
- Email providers you connect (Gmail or your own SMTP/IMAP server), and, if you set it up, an inbound-email relay such as Mailgun.
- Our cloud hosting provider, which runs our servers.
- Authorities or other parties where the law requires it, or to protect rights and safety; and a successor if CallThem is ever acquired (you would be told).
Data may be processed in countries other than your own, including where these providers operate.
6. Retention and deletion
- Account, contact, message and knowledge data are kept while your company account is active so the service can work.
- Disconnecting Gmail or removing SMTP settings deletes the stored credentials/tokens immediately.
- You may ask us to delete your account and the company data we hold (including the AI auto-reply log) at any time by contacting us below; we do this within 30 days, except for records we must keep by law (such as invoices) or for security investigations.
- Server logs are rotated regularly and are not kept indefinitely.
7. Security
Traffic between your browser and CallThem uses HTTPS. Access to data is limited by role (developer admin, company admin, staff) and enforced by Firebase Authentication and database rules; API keys for the Platform API are stored hashed; our Google sign-in handshake is protected against forgery with signed, expiring state. No system is perfectly secure, so please use a strong password and tell us immediately if you suspect misuse of your account.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Company staff can edit or delete contacts and content in the app directly. If you are a customer or contact of one of our business users and want your data removed, please contact that business first — they control it — or contact us and we will pass your request on. You can also complain to your local data-protection authority.
9. Changes to this policy
If we make material changes we will update the date above and, where appropriate, notify you in the app or by email before they take effect.
10. Contact
Questions or requests about privacy: raymond@callthem24.com, or use the Help button inside the app to reach us on WhatsApp.