Brella Home

Template · replace bracketed text before publish

Privacy policy

Last updated: [DATE]. Operator: [COMPANY / LEGAL NAME], [ADDRESS], [EMAIL].

What this product is

Brella is a personal AI assistant. You (or your agent) send messages; we store them so the assistant can remember, file tasks, and brief you. This is not Meta’s hosted Business Agent. If you connect a WhatsApp 3rd-party agent, that pipe only lets the account creator talk to the agent.

What we collect

  • Account: name, email, password hash or Google id, timezone, phone if you add it.
  • Assistant data you provide: chats, dumps, memories, tasks, projects, notes, people, pipeline, calendar items, settings.
  • WhatsApp agent token if you paste one (treat as a secret; stored encrypted at rest [CONFIRM]).
  • Technical: IP, device, logs needed to run and debug the service.

How we use it

To operate the assistant: generate replies, file records, send briefings/nudges you asked for, and show the dashboard. We send message text and relevant memory to our language-model provider ([PROVIDER], [REGION]) to produce replies and embeddings. We do not sell your content. We do not use your chats to advertise to you.

Model providers

Content you send to the assistant is processed by [LLM PROVIDER] under their terms. Do not paste secrets you would not put in email. [STATE WHETHER PROVIDER TRAINS ON API DATA — default: we contract “no training” where available.]

WhatsApp

Official 3rd-party agent: Meta/WhatsApp also processes those messages under their terms. Unofficial “scan WhatsApp” add-ons (if offered) are not Meta-approved; you accept extra account-ban risk. We will warn you in-product before any unofficial connect.

Retention

We keep assistant data until you delete it or close the account, plus a short backup window ([X] days). Agent platform media/updates on WhatsApp’s side expire on their schedule (currently ~30 days on that API).

Your rights

Access, export, correct, delete. Email [PRIVACY EMAIL]. You can wipe memory or the whole account from Settings. [GDPR/CCPA clauses as applicable to [COMPANY JURISDICTION].]

Security

HTTPS, hashed passwords, access limited to running the service. No method is perfect. Report issues to [SECURITY EMAIL].

Children

Not directed at children under 16. We do not knowingly collect their data.

Changes

We will post updates here and [email material changes]. Continued use after the date means you accept the new policy.

← Home