Privacy Policy
Effective 26 August 2026 · KhyalDesk (khyaldesk.com)
Who we are
KhyalDesk is a WhatsApp and Instagram CRM with an AI team inbox, made for businesses that answer customers on messaging channels. This policy covers the marketing site (www.khyaldesk.com), the web dashboard (app.khyaldesk.com) and the KhyalDesk Android app. Questions or requests about your data go to support@khyaldesk.com.
Two kinds of data
Account data we control: when you sign up we collect your name, email address and password (held by our authentication provider — we never see the password itself), your workspace details and your in-app preferences such as avatar and notification sound.
Customer data we process for businesses: when a business connects its WhatsApp number or Instagram account, the messages its customers send — text, images, voice notes and documents, along with the sender's phone number or Instagram username — flow through KhyalDesk so the business's team and its AI assistant can reply. For that data the business is the controller and KhyalDesk is a processor acting on its instructions.
What we collect and why
- Account details (name, email, role, workspace) — to run your team inbox and let teammates see who handled what.
- Conversation content (messages and media from connected channels) — to display threads, route them to the right person, and generate AI-drafted or AI-sent replies where the business has enabled that.
- Knowledge-base and catalog content the business uploads — so the AI can answer from it.
- Device push tokens (Android app) — a Firebase token registered when you sign in, used only to deliver new-message notifications to your device. It is deleted when you sign out.
- Usage and diagnostic records — request logs and AI usage metrics for reliability and billing. Our logs record identifiers only; message contents never appear in our logs.
We do not sell personal data, and we do not use customer conversations to train AI models.
The Android app and notifications
The KhyalDesk Android app is for business team members, not end customers. It signs in with your KhyalDesk account, shows the same inbox as the dashboard, and uses Firebase Cloud Messaging to notify you of new messages. A notification contains the customer's display name and a short preview of the message; media is shown only as a label (for example “📷 Photo”). The app requests the notification permission after sign-in and works without it — you just won't be alerted while the app is closed. Signing out removes your device's push token from our servers.
Service providers
We rely on a small set of processors, each receiving only what its job needs:
- Supabase (database, authentication and file storage — hosted in Mumbai, India)
- Vercel (application hosting)
- WasenderAPI (WhatsApp message delivery) and social-api.ai (Instagram messaging)
- Fireworks AI and Jina AI (AI model inference and embeddings for replies and search)
- Google Firebase Cloud Messaging (Android push notifications)
- Resend (transactional email such as team invitations)
- Shopify (live product and stock lookups, only where a business connects its store)
Retention and deletion
Conversation history is kept for as long as the business's workspace is active, because a CRM's value is its history. Businesses can request deletion of a workspace — including its conversations, media and knowledge base — by writing to support@khyaldesk.com, and we complete verified deletion requests within 30 days. If you are a customer of a business that uses KhyalDesk and want your conversation data removed, contact that business, or contact us and we will pass the request to them.
Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Access inside KhyalDesk is scoped per workspace: row-level security ensures one business can never read another's data, and provider credentials are held server-side only.
Your rights
You may ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete your account. Email support@khyaldesk.com from the address on the account and we will respond within 30 days.
Children
KhyalDesk is a business tool and is not directed at children under 13. We do not knowingly collect personal data from children.
Changes to this policy
When we change this policy we update the effective date above; material changes are announced to workspace owners by email. Continued use after a change means acceptance of the updated policy.