swaru's privacy policy
Last updated: 1 October 2026
Who we are
swaru is a product of Magna Legal, located at Calle 5 Esq. C. Ramón Asensio, La Moraleja, Santiago de los Caballeros 51101, Dominican Republic. You can reach us at info@swaru.app with any privacy question.
swaru is a WhatsApp assistant for businesses. A business (swaru's customer) connects its own WhatsApp Business account through Meta's Embedded Signup, and swaru answers that business's customers on WhatsApp using only content the business approved, handing the conversation to a person when needed.
swaru complies with the Meta Platform Terms and Developer Policies, the WhatsApp Business Terms and the WhatsApp Business Messaging Policy.
Roles: who controls the data
When a business uses swaru to serve its own customers, the business is the data controller for that data and swaru acts as a processor, handling it according to the business's instructions and the terms of our agreement with it.
For data swaru collects about the business itself, such as its operator accounts or its configuration, swaru is the controller.
Data we process on a business's behalf
As a processor, we handle, among other things:
- The end customer's phone number and the content of their messages.
- The customer's WhatsApp profile name.
- The raw inbound webhook payloads Meta delivers, which contain the sender's number and the message.
- The text of messages swaru could not match to an approved topic, kept for the business to review.
- The history of hand-offs between swaru and a person.
- Each conversation's state, such as whether swaru or a person is handling it.
- Notes and labels the business adds to a conversation or a customer.
- Survey ratings.
- Message delivery events (sent, delivered, read, failed).
Data we hold about the business
As the controller of this data, we hold:
- Operator accounts: email address, password (stored as a one-way hash), role, sign-in attempt counters and password-reset token hashes.
- The WhatsApp Business Account identifier, phone number identifier, access token and registration PIN; the last two are encrypted at rest.
- The assistant's configuration: approved topics, saved answers, business hours and other settings.
- Access requests submitted through the website form: name, business name, email, phone, request type, language and message.
Who we share data with
We use the following providers (sub-processors) to run the service:
- Meta Platforms, Inc.: the WhatsApp Business Platform, for message delivery.
- Anthropic: our AI model provider. Message text is sent as data to compose replies and classify the topic, never as an instruction to the model. It also receives the recent conversation history and the business's approved content, as data, to draft a reply.
- TypeSafe: an AI judgement service that, only where enabled for a business, receives message text, the drafted reply and the approved content to classify messages and check replies.
- Mailgun: transactional email, such as password reset messages.
- Railway: hosting for our infrastructure.
Business webhooks and tool servers
A business may configure its own outgoing webhooks and external tool servers. Conversation data sent to those endpoints goes where the business chose, and the business is responsible for them.
International transfers
These providers process data outside the Dominican Republic, mainly in the United States, under their own terms and safeguards.
How long we keep data
Conversation data, raw inbound payloads, text of messages not matched to an approved topic and hand-off history are kept while the business's account is active; there is no automatic purge. They are deleted within 30 days after the business requests it or the agreement ends.
Delivery records of notifications swaru sends to a business's own webhook endpoints are deleted after 30 days.
Operator accounts are kept while the account is active and deleted with it.
Access-request form submissions are kept until the request is handled or deletion is requested, then removed within 30 days.
Data under a legal retention duty is kept only as long as the law requires.
Data from Meta's APIs
Through Meta's APIs we obtain the WhatsApp Business Account identifier, the phone number identifier, the access token, the customer's number, profile name, message content and delivery statuses.
We use this data only to provide the service. We never sell it, never use it for advertising or profiling, and share it only with the sub-processors listed above.
Disconnecting a number in the console deletes the stored access token and PIN and stops swaru answering on that number. The identifiers and conversation history stay until the business asks for deletion or the agreement ends, and are then deleted within 30 days.
Businesses using swaru must comply with WhatsApp's Business Messaging Policy, obtain their own customers' opt-in to be messaged, and are responsible for their own privacy notices to those customers.
Cookies
The console sets one strictly necessary session cookie and a CSRF token. We use no advertising or analytics cookies. The public website sets none.
Security
Tokens and PINs are encrypted at rest with a key the application holds, passwords are hashed, technical logs redact secrets and phone numbers by default, and access is limited to the authorised operators of each business.
Your rights
Under Ley núm. 172-13 on the Comprehensive Protection of Personal Data of the Dominican Republic, you have the rights of access, rectification, update, deletion, portability and objection regarding your personal data.
If you are a business's end customer, write first to that business: it is the controller, and swaru carries out your request on its instruction. You may also write to info@swaru.app; we will forward your request to the business and confirm.
If you are not satisfied with the response, you may bring a complaint before the competent courts.
Changes to this policy
We may update this policy from time to time. We will post any change on this page with a new update date.