MirageCHAT (“MirageCHAT”, “we”, “us”) provides a business messaging platform that lets customer‑support agents receive and reply to conversations from connected channels such as WhatsApp and Instagram. This Privacy Policy explains what information the MirageCHAT mobile application (the “App”) processes, why, and the choices you have.
MirageCHAT is a business‑to‑business tool. Agents access the App using credentials issued by their organization (the “Workspace”). The Workspace is the data controller of the end‑customer conversations processed through the platform; MirageCHAT acts as a data processor on the Workspace’s behalf.
| Category | Examples | Purpose |
|---|---|---|
| Account information | Agent name, email address, role, workspace, and the account permissions assigned by the administrator | Authenticate the agent and show only the accounts they are allowed to use |
| Messages & media | Conversation text, photos, videos, voice notes, and files exchanged with end‑customers through connected channels | Display conversations and let the agent reply. This content belongs to the Workspace. |
| Location — only when shared | The device’s location, read once at the moment the agent taps “Send location” in a chat | Send the location to the customer as a message. It is never read in the background, never tracked, and never stored beyond the sent message. |
| Contacts — only the one chosen | The name and phone number of a single contact the agent picks from the device’s address book | Send that contact card to the customer as a message. The address book is never read as a whole, never uploaded, and nothing is kept apart from the contact actually sent. |
| Device & push token | A push notification token and device model/OS version | Deliver new‑message notifications to the correct device |
| Diagnostics | Crash and error information | Keep the App stable and secure |
The App does not collect your location, contacts, calendar, SMS, or advertising identifier. Camera, microphone, and photo‑library access are used only when you choose to attach or record media inside a conversation.
We do not sell your personal information and we do not use conversation content for advertising.
A Workspace connects its own business accounts. Each connection is made on the platform’s own sign-in screen; we never see or ask for a platform password, and we request only the permissions listed here.
Meta Platforms — WhatsApp Business, Messenger and Instagram.
| Permission | Data received | Purpose |
|---|---|---|
| public_profile | The connecting administrator’s Meta user ID, name and profile picture | Identify who is signed in |
| pages_show_list | The list of Facebook Pages the Workspace manages | Let the Workspace choose which Page to connect |
| pages_manage_metadata | Page subscription to webhooks | Receive inbound Messenger messages in real time |
| pages_messaging | Messenger conversations and message content with the Page | Show the conversation in the inbox and let the agent reply |
| pages_read_engagement | Read and reaction metadata on Page conversations | Show delivery and read receipts |
| instagram_basic, instagram_business_basic | The linked Instagram Business account ID, username and profile picture | Identify the Instagram account inside the inbox |
| instagram_manage_messages, instagram_business_manage_messages | Instagram Direct conversations sent to the connected Business account | Show Instagram DMs and allow replies inside Meta’s messaging window |
| whatsapp_business_messaging | Inbound and outbound WhatsApp Business messages, phone-number IDs, and the templates the Workspace approved with Meta | Two-way WhatsApp messaging with the Workspace’s own clients |
| whatsapp_business_management | WABA ID, phone-number assets, template list and status | Let the Workspace view and pick approved templates |
| Human Agent | — | Allow a human agent (not a bot) to reply inside Meta’s extended messaging window when the client wrote first |
We do not request user emails, friend lists, posts, ads or audiences, or any data unrelated to inbox messaging.
TikTok — used only by Social Auto Pilot, and only for the business’s own account.
| Scope | Data received | Purpose |
|---|---|---|
| user.info.basic | Display name and avatar of the connected account | Show which account a post is about to go to |
| user.info.profile | Profile picture, display name, verified badge, bio and profile link | The connected-account card shown beside the schedule |
| user.info.stats | Followers, likes, following and total videos of the business’s own account | TikTok Insights. Read live each time the panel is opened and never stored |
| video.list | The videos already published to the connected account, with cover image and link | Show what actually went live beside what is still scheduled |
| video.publish | — | Direct Post: publish the content the business uploaded, on the schedule it set |
| video.upload | — | Granted together with the Content Posting API and cannot be unselected. MirageCHAT never uses it — we do not upload drafts to a creator’s TikTok inbox, only Direct Post above |
We store the account’s TikTok identifier and display name, the access and refresh tokens needed to publish on its behalf, and the record of what was posted and when. The counts shown in Insights are not stored. We receive no viewer data and no other account’s content. Every photo and video published is uploaded by the business itself.
We do not sell or rent personal data. We do not use platform data to build advertising profiles or to train foundation models. Data is shared only with the providers needed to run the service:
| Sub-processor | Purpose | Region |
|---|---|---|
| Contabo GmbH | Server hosting, the PostgreSQL database, and stored media | European Union |
| Meta Platforms, Inc. | Inbound and outbound messaging over WhatsApp, Messenger and Instagram | EU / US (with SCCs) |
| TikTok (ByteDance Ltd.) | Publishing to a connected TikTok account, when the Workspace enables it | EU / US (with SCCs) |
| Google LLC | Firebase Cloud Messaging — push notification delivery to Android devices | EU / US (with SCCs) |
| Apple Inc. | Apple Push Notification service — push delivery to iOS devices | EU / US |
| Stripe, Inc. | Card payment processing for Workspace subscriptions | EU / US (with SCCs) |
| Anthropic PBC | Claude API for optional AI features (draft replies, summaries, translation) — only when the Workspace turns them on | US (with SCCs) |
Transactional email is sent from our own mail servers, not through a third-party email provider. We may also disclose information if required by law, or to protect the rights, safety and security of our users and the service.
Conversation data is retained for as long as the Workspace keeps it in the platform, or until the Workspace requests deletion, and for 30 days after the Workspace is terminated. Operational logs are kept for 30 days. Encrypted backups are retained for up to 12 months. Push tokens are removed when you sign out or when the device becomes unreachable.
Platform data is deleted within 30 days of any of the following: the Workspace disconnecting the channel, the Workspace deleting its account, or a verified deletion request from an end user.
Disconnecting a channel. A Workspace can disconnect any connected account from inside MirageCHAT. Disconnection revokes the grant with the platform, deletes the stored tokens, stops any scheduled publishing, and triggers deletion of that platform’s data within 30 days. A TikTok account can also be revoked from TikTok itself, at Profile → Settings and privacy → Security and permissions → Apps.
End-user requests. Anyone can request deletion of the data tied to their Facebook user ID, Instagram account, WhatsApp number or TikTok account by writing to privacy@miragechat.io with the subject “Data Deletion Request” and the relevant Page ID, handle or number. We confirm deletion within 30 days. Full instructions, including what is erased and what is kept, are on our data deletion page.
Data is transmitted over encrypted connections (HTTPS/TLS 1.2+) and the database is encrypted at rest. Authentication uses short-lived tokens. Access is restricted to the accounts an administrator assigns to each agent, and every query is scoped to a single Workspace — one Workspace can never reach another’s data. Administrative actions are logged. The App offers an optional device-level lock (fingerprint/face and/or a 4-digit PIN); lock secrets never leave the device.
Depending on your location (for example under the EU/UK GDPR or the California CCPA), you may have the right to access, correct, or delete your personal data, to object to or restrict its processing, to data portability, and to lodge a complaint with your local data protection authority. Because conversation data is controlled by your Workspace, please direct such requests to your Workspace administrator, or contact us and we will assist the controller in responding. We respond within 30 days.
MirageCHAT is intended for use by businesses and their staff. It is not directed to children under 16, and we do not knowingly collect their data.
MirageCHAT is offered globally. Where data is transferred across borders, we rely on appropriate safeguards consistent with applicable law, including Standard Contractual Clauses with the sub-processors listed above.
This Policy is governed by the laws of the State of Wyoming, United States, without prejudice to the rights of European data subjects under the GDPR.
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where required, by notifying Workspaces by email at least 14 days before the change takes effect.
Questions about this Policy, and any privacy or data-deletion request, can be sent to privacy@miragechat.io.