MirageCHAT

Privacy Policy

Last updated: 3 September 2026

MirageCHAT (“MirageCHAT”, “we”, “us”) provides a business messaging platform that lets customer‑support agents receive and reply to conversations from connected channels such as WhatsApp and Instagram. This Privacy Policy explains what information the MirageCHAT mobile application (the “App”) processes, why, and the choices you have.

MirageCHAT is a business‑to‑business tool. Agents access the App using credentials issued by their organization (the “Workspace”). The Workspace is the data controller of the end‑customer conversations processed through the platform; MirageCHAT acts as a data processor on the Workspace’s behalf.

1. Information we process

CategoryExamplesPurpose
Account information Agent name, email address, role, workspace, and the account permissions assigned by the administrator Authenticate the agent and show only the accounts they are allowed to use
Messages & media Conversation text, photos, videos, voice notes, and files exchanged with end‑customers through connected channels Display conversations and let the agent reply. This content belongs to the Workspace.
Location — only when shared The device’s location, read once at the moment the agent taps “Send location” in a chat Send the location to the customer as a message. It is never read in the background, never tracked, and never stored beyond the sent message.
Contacts — only the one chosen The name and phone number of a single contact the agent picks from the device’s address book Send that contact card to the customer as a message. The address book is never read as a whole, never uploaded, and nothing is kept apart from the contact actually sent.
Device & push token A push notification token and device model/OS version Deliver new‑message notifications to the correct device
Diagnostics Crash and error information Keep the App stable and secure

The App does not collect your location, contacts, calendar, SMS, or advertising identifier. Camera, microphone, and photo‑library access are used only when you choose to attach or record media inside a conversation.

2. How we use information

We do not sell your personal information and we do not use conversation content for advertising.

3. Connected platforms and the permissions we hold

A Workspace connects its own business accounts. Each connection is made on the platform’s own sign-in screen; we never see or ask for a platform password, and we request only the permissions listed here.

Meta Platforms — WhatsApp Business, Messenger and Instagram.

PermissionData receivedPurpose
public_profileThe connecting administrator’s Meta user ID, name and profile pictureIdentify who is signed in
pages_show_listThe list of Facebook Pages the Workspace managesLet the Workspace choose which Page to connect
pages_manage_metadataPage subscription to webhooksReceive inbound Messenger messages in real time
pages_messagingMessenger conversations and message content with the PageShow the conversation in the inbox and let the agent reply
pages_read_engagementRead and reaction metadata on Page conversationsShow delivery and read receipts
instagram_basic, instagram_business_basicThe linked Instagram Business account ID, username and profile pictureIdentify the Instagram account inside the inbox
instagram_manage_messages, instagram_business_manage_messagesInstagram Direct conversations sent to the connected Business accountShow Instagram DMs and allow replies inside Meta’s messaging window
whatsapp_business_messagingInbound and outbound WhatsApp Business messages, phone-number IDs, and the templates the Workspace approved with MetaTwo-way WhatsApp messaging with the Workspace’s own clients
whatsapp_business_managementWABA ID, phone-number assets, template list and statusLet the Workspace view and pick approved templates
Human AgentAllow a human agent (not a bot) to reply inside Meta’s extended messaging window when the client wrote first

We do not request user emails, friend lists, posts, ads or audiences, or any data unrelated to inbox messaging.

TikTok — used only by Social Auto Pilot, and only for the business’s own account.

ScopeData receivedPurpose
user.info.basicDisplay name and avatar of the connected accountShow which account a post is about to go to
user.info.profileProfile picture, display name, verified badge, bio and profile linkThe connected-account card shown beside the schedule
user.info.statsFollowers, likes, following and total videos of the business’s own accountTikTok Insights. Read live each time the panel is opened and never stored
video.listThe videos already published to the connected account, with cover image and linkShow what actually went live beside what is still scheduled
video.publishDirect Post: publish the content the business uploaded, on the schedule it set
video.uploadGranted together with the Content Posting API and cannot be unselected. MirageCHAT never uses it — we do not upload drafts to a creator’s TikTok inbox, only Direct Post above

We store the account’s TikTok identifier and display name, the access and refresh tokens needed to publish on its behalf, and the record of what was posted and when. The counts shown in Insights are not stored. We receive no viewer data and no other account’s content. Every photo and video published is uploaded by the business itself.

4. Sharing and sub-processors

We do not sell or rent personal data. We do not use platform data to build advertising profiles or to train foundation models. Data is shared only with the providers needed to run the service:

Sub-processorPurposeRegion
Contabo GmbHServer hosting, the PostgreSQL database, and stored mediaEuropean Union
Meta Platforms, Inc.Inbound and outbound messaging over WhatsApp, Messenger and InstagramEU / US (with SCCs)
TikTok (ByteDance Ltd.)Publishing to a connected TikTok account, when the Workspace enables itEU / US (with SCCs)
Google LLCFirebase Cloud Messaging — push notification delivery to Android devicesEU / US (with SCCs)
Apple Inc.Apple Push Notification service — push delivery to iOS devicesEU / US
Stripe, Inc.Card payment processing for Workspace subscriptionsEU / US (with SCCs)
Anthropic PBCClaude API for optional AI features (draft replies, summaries, translation) — only when the Workspace turns them onUS (with SCCs)

Transactional email is sent from our own mail servers, not through a third-party email provider. We may also disclose information if required by law, or to protect the rights, safety and security of our users and the service.

5. Data retention

Conversation data is retained for as long as the Workspace keeps it in the platform, or until the Workspace requests deletion, and for 30 days after the Workspace is terminated. Operational logs are kept for 30 days. Encrypted backups are retained for up to 12 months. Push tokens are removed when you sign out or when the device becomes unreachable.

Platform data is deleted within 30 days of any of the following: the Workspace disconnecting the channel, the Workspace deleting its account, or a verified deletion request from an end user.

6. Data deletion

Disconnecting a channel. A Workspace can disconnect any connected account from inside MirageCHAT. Disconnection revokes the grant with the platform, deletes the stored tokens, stops any scheduled publishing, and triggers deletion of that platform’s data within 30 days. A TikTok account can also be revoked from TikTok itself, at Profile → Settings and privacy → Security and permissions → Apps.

End-user requests. Anyone can request deletion of the data tied to their Facebook user ID, Instagram account, WhatsApp number or TikTok account by writing to privacy@miragechat.io with the subject “Data Deletion Request” and the relevant Page ID, handle or number. We confirm deletion within 30 days. Full instructions, including what is erased and what is kept, are on our data deletion page.

7. Security

Data is transmitted over encrypted connections (HTTPS/TLS 1.2+) and the database is encrypted at rest. Authentication uses short-lived tokens. Access is restricted to the accounts an administrator assigns to each agent, and every query is scoped to a single Workspace — one Workspace can never reach another’s data. Administrative actions are logged. The App offers an optional device-level lock (fingerprint/face and/or a 4-digit PIN); lock secrets never leave the device.

8. Your rights

Depending on your location (for example under the EU/UK GDPR or the California CCPA), you may have the right to access, correct, or delete your personal data, to object to or restrict its processing, to data portability, and to lodge a complaint with your local data protection authority. Because conversation data is controlled by your Workspace, please direct such requests to your Workspace administrator, or contact us and we will assist the controller in responding. We respond within 30 days.

9. Children

MirageCHAT is intended for use by businesses and their staff. It is not directed to children under 16, and we do not knowingly collect their data.

10. International transfers

MirageCHAT is offered globally. Where data is transferred across borders, we rely on appropriate safeguards consistent with applicable law, including Standard Contractual Clauses with the sub-processors listed above.

11. Governing law

This Policy is governed by the laws of the State of Wyoming, United States, without prejudice to the rights of European data subjects under the GDPR.

12. Changes

We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where required, by notifying Workspaces by email at least 14 days before the change takes effect.

13. Contact

Questions about this Policy, and any privacy or data-deletion request, can be sent to privacy@miragechat.io.