Privacy
This explains what Warid stores, why it is stored, who can see it, and how to have it deleted. It is written to be read rather than to be defensible, and where something is a choice we made rather than a legal requirement, it says so.
Last updated 14 August 2026.
Who this is about
Warid is used by two kinds of people, and they have different relationships with us.
A business signs up, connects its own messaging channels, and invites its colleagues. It chose Warid and has an account with us.
The people that business talks to did not. They messaged a shop on WhatsApp or Instagram, and their message arrived here because the shop uses Warid to answer it. They have no account, and we hold their messages on the business’s behalf rather than for our own purposes. If you are one of those people and want your data removed, ask the business you were messaging — and read Deleting your data, which explains what we do when they ask us.
What a business gives us
- An account. Name, email address, and a password we store only as a hash. If two-factor authentication is switched on, the secret behind it and any unused backup codes.
- Channel credentials. The access tokens a business authorises so Warid can send and receive on its behalf — for example an Instagram access token obtained when somebody presses Continue with Instagram. These are held so the connection keeps working, and deleted when the channel is disconnected.
- What the business configures. AI agent instructions, knowledge base documents, saved replies, files uploaded to a personal library, and automation rules.
What arrives through a channel
- Messages sent to and from the business, including the text, and any images, video, audio or documents attached to them.
- Who sent them, as the channel identifies them: a display name, a profile picture, and a channel-specific identifier such as a phone number or an Instagram account id.
- What happened to a message — delivered, read, reacted to, edited or withdrawn — where the channel tells us.
We do not go looking for anything else. Warid does not read a connected Instagram account’s posts, insights, comments or followers, and does not publish on its behalf.
What we collect ourselves
- An audit log of consequential actions inside a workspace — who connected a channel, who reassigned a conversation, who changed a role — so a business can answer “who did this” about its own account.
- Counts of messages and AI replies, for the usage meters and billing.
- Errors, when something breaks, so it can be fixed.
- Notification subscriptions, if a user turns on browser notifications — an endpoint supplied by their browser, and two keys. We never receive the contents of a notification back.
There is no advertising anywhere in Warid, no third-party analytics or tracking scripts, and no cookies beyond the ones that keep somebody signed in and remember their theme and layout preferences.
Who can see it
A workspace’s data is visible to the members of that workspace and to nobody else. Every query the application makes is scoped to one workspace; the separation is enforced in the data layer rather than left to each screen to remember.
Staff operating Warid can reach data when it is genuinely necessary to run or repair the service — restoring a backup, diagnosing a fault a customer has reported. That access is limited to the people who need it, and it is not used to read conversations for any other reason.
We do not sell data, and we do not share it with advertisers.
Where it goes
Data is stored on servers Warid operates. Messages travel to and from the channel providers a business has connected — Meta for WhatsApp and Instagram, Telegram for Telegram — because that is how a message reaches the person it is addressed to. Those providers have their own terms and their own copies.
If a business turns on an AI agent, the conversation text needed to write a reply is processed by a model. Warid runs models on hardware we operate for exactly this reason. Where a business chooses to configure an external model provider instead, the text goes to that provider under its terms, and that is a choice the business makes and can reverse.
Message content is never used to train models — ours or anyone else’s.
How long it is kept
Conversations and their attachments are kept for as long as the business keeps its account, because the point of a shared inbox is that last year’s conversation is still there when the customer comes back. A business can delete individual conversations, contacts and files at any time.
When an account is closed, its data is deleted within 30 days. Backups age out on their own cycle and are deleted within 90 days. Aggregate counts that carry no personal data — how many messages a month, for invoicing — are kept as long as the records they support.
Keeping it safe
Traffic is encrypted in transit. Passwords are hashed, never stored in a form anybody can read. Channel tokens are held only for as long as the channel is connected. Two-factor authentication is available on every account and we recommend it — it is the single most effective thing a person can do here.
No system is perfect. If we discover a breach affecting personal data we will say so, to the businesses affected and to any regulator we are required to tell, without waiting to have a complete picture first.
Your rights
Depending on where you live you may have the right to see the data we hold about you, correct it, export it, or have it deleted, and to object to some processing. Ask us and we will do it — see Deleting your data for how, and how quickly.
If you are one of the people a business talks to, ask that business first: it decides what to keep, and we act on its instruction. If you cannot reach them, write to us and we will help.
Changes
When this changes in a way that matters, the date at the top changes and account holders are told inside the product. We will not quietly broaden what we do with data already collected.
Contact
Warid — [email protected]