Plain-language privacy. No dark patterns.
Muhadith is a customer-communication platform. We move messages between your business and your customers across WhatsApp, Instagram, Messenger, Telegram, and email, and we store the minimum data needed to do that reliably. This page explains what we collect, why we need it, where it lives, how long it stays, and what you can ask us to do with it.
What we collect
Workspace account data (your email, billing address, business name) and the conversation content that flows through our inbox (text messages, images, voice notes, order events from Salla / Zid / Shopify webhooks). We do not collect payment card numbers — billing is handled by Stripe and Apple / Google in-app purchase flows with their PCI scope.
Where it lives
Production data lives in encrypted Postgres volumes on AWS me-central-1 (Bahrain) and eu-west-1 (Ireland) for redundancy. Backups age out after 30 days. AI model calls do not leave our VPC — we route them through a private gateway with provider keys stored in HashiCorp Vault. Conversation data is logically isolated per workspace; workspace staff can only see their own data.
Retention and deletion
Conversation history is retained for the life of your workspace. You can delete any conversation from the dashboard on demand — deletion propagates to backups on the next sweep (<24h). Workspace deletion is irreversible: every conversation, customer record, automation, and webhook subscription is purged within 7 days. Email recipients who reply to outbound campaigns can opt out via a one-click link; we honor that immediately.
Your rights
Export your conversations and customer records as JSON or CSV at any time from Settings → Data. Request deletion of personal data not strictly required for billing records by emailing [email protected] — we acknowledge within 7 days, complete within 30. If you are a data subject in the EU, GCC, or UK, the legal basis we rely on (legitimate interest, contract, consent) is documented in the DPA you signed at signup.