Privacy Policy
Last updated · v0.1
Cosend is WhatsApp coexistence and automation infrastructure operated by True North Tech Group LLC, Wyoming, USA. This policy explains what personal data we handle, why, for how long, and what you can do about it.
1. Controller and processor
The distinction matters, and the whole Data Processing Addendum rests on it:
- We are the controller of your account data — the name, email address and workspace settings of the people who sign in to Cosend, and our billing records.
- We are a processor of your customers' data — WhatsApp message content, phone numbers, contact records and anything your automations touch. That data is yours. We process it on your documented instructions and for no purpose of our own.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash or identity-provider subject, organization and seat membership | You, at sign-up |
| Billing data | Plan, subscription state, invoices, usage counts. Card details are handled by Stripe and never reach our servers | You, and Stripe |
| Connection data | WhatsApp Business Account and phone-number identifiers, connection settings, webhook URLs, encrypted credentials | You, and Meta |
| Message data | Message content and media, phone numbers, message identifiers, delivery statuses, direction and timestamps | Meta, on your behalf |
| Connector data | Only what your automations send to or read from a connected service | You, through your automations |
| Operational data | API request logs, IP addresses, user-agent strings, audit events, error metadata | Automatically, when the service is used |
3. Message content
By default, Cosend stores the content of the WhatsApp messages it routes. That is what makes the shared inbox, the 180-day history import, AI replies and content-based automation triggers possible. We are not going to describe that as anything other than what it is.
Message content is processed to deliver and receive messages through Meta's WhatsApp Business Platform, to render your inbox, to run the automations you configure, and — only if you enable AI — to generate replies. It is isolated per organization at the database level by row-level security, so one customer's data is not reachable from another's session. We do not sell it, and we do not use it to train models.
Direct-delivery mode is the alternative, and it is free on every plan. Set a connection to direct and Cosend records metadata only — timestamp, direction, message identifier, contact hash, type and status — forwards the full payload to your endpoint, and never writes the body. It is a per-connection setting, so a workspace can run some connections in direct mode and others normally. Turning it on disables the inbox, history import, AI and content-based triggers for that connection, and the dashboard tells you so before you save rather than failing later.
4. Lawful basis
Under Article 6 GDPR, for the data we control:
| Purpose | Basis |
|---|---|
| Providing the service you signed up for | Contract — Art. 6(1)(b) |
| Billing, invoicing and tax records | Legal obligation — Art. 6(1)(c), and contract |
| Security, abuse prevention, rate limiting and audit logging | Legitimate interests — Art. 6(1)(f) |
| Service email about your account, incidents and billing | Contract — Art. 6(1)(b) |
| Product analytics on the marketing site | Legitimate interests — Art. 6(1)(f). Cookieless and not tied to an identity, see §10 |
For message data we act on your instructions as processor, and the lawful basis for processing your customers' data is yours to establish as controller. The DPA sets that out.
5. Retention
Deletion is hard deletion of the database row and the stored object, not a flag, and it is carried out by a scheduled sweep per organization.
| Data | Default | Configurable |
|---|---|---|
| Message content and media | 3 months on Free, 12 on Starter, 24 on Growth and Scale | 3, 6, 12 or 24 months, or until you delete it |
| Message metadata, without the body | As above | As above |
| Webhook delivery payloads | 30 days | No |
| Automation run logs | 90 days | 30, 90 or 365 days |
| Audit events | 24 months | No |
| Usage events, as billing records | 7 years | No |
Lowering a retention setting schedules a sweep and tells you how many records it will delete before you confirm. If you cancel, your data is retained for 30 days and then deleted — export it before or during that window.
6. Google user data
Cosend connects to Google Sheets, Google Calendar and Google Forms only when you choose to connect them, and only through Google's own OAuth consent screen. This section describes the manner in which Cosend accesses, uses, stores and shares Google user data.
What we access
Three scopes, and no others:
- drive.file — Google Sheets. This grants access only to the individual files you select through the Google Picker, or that Cosend creates itself. Cosend cannot list, search, browse or open any other file in your Drive.
- calendar.app.created — Google Calendar. This grants access only to the calendars and events Cosend itself creates.
- forms.responses.readonly — Google Forms. This grants read access to the responses of forms you connect.
How we use it
Only to run the automation you configured: appending or reading a row in a sheet you picked, creating or updating an event Cosend created, or reading a form response in order to trigger a WhatsApp message. Cosend does not use Google user data for any other purpose.
How we store it
OAuth refresh tokens are stored encrypted with per-record keys and are never written to logs. Data read from a Google API is held only for the duration of the automation run that requested it, except where your own automation writes it into your Cosend data — a form response copied into a message, for example — in which case it is retained under your message retention setting in §5 and deleted with it.
How we share it
Cosend does not sell Google user data, does not use it for advertising or ad targeting, does not use it to develop, improve or train generalised AI or machine-learning models, and does not use it for creditworthiness or lending purposes. It is not transferred to any third party except the sub-processors listed at /subprocessors that are necessary to operate the service, or where required by law. Humans do not read it, other than with your explicit consent, where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised. Where one of your own automations passes Google data into an AI step, that content reaches the AI sub-processor named at /subprocessors — at your configuration, and only while AI is enabled.
Cosend's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Cosend's access at any time, from your Google Account permissions page or by disconnecting the integration in the Cosend dashboard. Revoking access stops future calls immediately; data already written into your Cosend workspace is removed under §5 or on request.
7. Sub-processors
The current list, with each vendor's purpose, the data categories they can see and where they process it, is published at /subprocessors and generated from the same source the service is configured from. The same list is available as machine-readable JSON at /subprocessors.json.
Two entries there are worth stating here because they are unusual. Message content reaches an AI provider only when you enable AI — if you use Cosend for routing and the inbox, you have no AI sub-processor at all. And our error tracking never receives message content: secrets and message bodies are wrapped in a type that cannot be serialised, so redaction is structural rather than a pattern match that might miss.
8. International transfers
Your database, your API hosting and your automation execution are in Germany. Some sub-processors are outside the EEA — they are marked as such at /subprocessors. Where personal data is transferred out of the EEA we rely on the European Commission's Standard Contractual Clauses, which are incorporated into our DPA.
9. Your rights
If you are in the EEA or the UK you have the rights below. For account data, exercise them directly with us. For message data we are the processor — if you are the end recipient of a WhatsApp message, your request goes to the business you were messaging, and we will assist them with it.
| Right | How to exercise it |
|---|---|
| Access — Art. 15 | Email [email protected] |
| Rectification — Art. 16 | Edit it in the dashboard, or email us |
| Erasure — Art. 17 | Delete the record or the workspace in the dashboard, or email us. Deletion is hard deletion, and it reaches sub-processors |
| Restriction — Art. 18 | Email us |
| Portability — Art. 20 | Export your data from the dashboard, in a machine-readable format |
| Objection — Art. 21 | Email us. Where we rely on legitimate interests you can object at any time |
| Complaint | You may complain to your local supervisory authority. We would rather you told us first |
We respond within one month, as Art. 12(3) requires. We do not charge for a request unless it is manifestly unfounded or excessive.
10. Cookies and analytics
This website sets no analytics or advertising cookies, so there is no consent banner. Our product analytics is cookieless: it records page views without a cookie, without a device identifier and without anything that identifies you personally. We have chosen that deliberately, and the absence of a banner is the visible consequence.
The Cosend dashboard sets a session cookie when you sign in. That cookie is strictly necessary to keep you signed in and is not used for tracking.
11. Contact
Privacy questions, data-subject requests and anything in this policy: [email protected]. Everything else: [email protected].
True North Tech Group LLC, Wyoming, USA. We will update this policy when what we do changes, and the date at the top of the page is the date of the last change.